Privacy Policy
Last updated: 2026-09-10
This policy explains what data the Shopify app Capyo: ChatGPT Ads Pixel & ROAS and this website process, why, on what legal basis, and how long it is kept. It is written for the merchant who installs the app. It is not legal advice about your own obligations as an advertiser or as a data controller.
1. Who is responsible
The controller for the processing described here is Capyo, operated by an individual developer. Contact for anything in this document, including all data-protection requests: gimbernat13@gmail.com.
Operator legal name and address: [to be added]
For the personal data of your customers, you remain the controller and Shopify is your processor under Shopify's own terms. Capyo is built to never receive your customers' names, email addresses, phone numbers or physical addresses — see section 2 for exactly what it does read and store.
2. Data the app processes
It comes from Shopify when you install the app, from your storefront's own Web Pixel, and from you. In detail:
- Store record. Your
.myshopify.comshop domain, your store's primary locale and currency, your current plan, and setup state: install and uninstall time, when the pixel first received an event, when the first order was sent, whether the review prompt was shown, your alert email address and alert toggles, whether the feed is enabled, and your data-retention setting. - Sessions. The Shopify access token issued to the app for your store, together with the shop domain, stored so the app can call Shopify's API on your behalf.
- Your OpenAI Ads credentials. The Pixel ID and Conversions API key you paste from your
own
ads.openai.comaccount, encrypted at rest (AES-256-GCM). Capyo uses these only to send your own store's events to your own OpenAI Ads account — see section 3 for how. - Event counters and a short debug log. Hourly counts per event type and source (browser or server) for your usage and the health strip, and a rolling sample of your most recent events — event id, event name, source, the anonymous click id if one was matched, amount, currency and delivery status — kept for 7 days so the Setup screen can show you what's happening.
- An outbox of events awaiting delivery. Each browser event is queued with its full outgoing payload until it is sent to the Conversions API, then the row is deleted 24 hours after it sends.
- Click and order-attribution data — no customer identity. A per-visit attribution touch
(an anonymous browser-generated client id, the ad platform's
opprefvalue, the checkout token once one exists, and the landing page URL, none of which is a name, email or other contact detail), and a record per order: order id, order name, order date, subtotal, total, currency, the matched click id if any, and line items (product id, variant id, title, quantity, amount — never a product's full description). This is the data the revenue report and the product feed are built from. - Delivery records. For each event sent to OpenAI's Conversions API: the event id, event name, related order id where relevant, delivery status, attempt count and the response code. The exact request body is kept for the debug log in test mode and for 7 days in live mode.
- Product feed. The built product feed file itself (served at a private, tokenised URL or delivered over SFTP), a log of each build (item count, size, delivery method, errors), and — if you configure SFTP delivery — your SFTP host, port, username and an encrypted password.
- Alerts. A record of each alert Capyo raised (pixel gone quiet, a checkout with no matching event, the Conversions API failing, a feed run failing, your monthly cap reached), when it opened, whether it's resolved, and — once alert email is available (see section 5) — when it was emailed.
- Product-usage events. Shop domain, an event name from a fixed list (install, pixel activated, first event, test event accepted, first order sent, feed enabled, feed run, alert opened, plan changed, review prompted, cap reached, uninstall) and a timestamp — no personal data, used only to see which setup steps merchants get stuck on.
- Server logs. Standard web-server and application logs: request time, path, status code, IP address, user agent, and error traces for the admin app itself (this is separate from the transient handling of storefront IP/user agent described in section 3).
- Support correspondence. If you email us, we keep the message and our reply.
Where any of this is personal data, it is the personal data of you — the merchant and your staff — not of your customers.
3. What the storefront pixel sends, and what it stores in the browser
The kliq-pixel Web Pixel extension runs inside Shopify's own strict sandbox:
no DOM access, and no vendor script from OpenAI or anyone else is loaded. It subscribes to five standard
Shopify storefront events (page view, product view, add to cart, checkout started, checkout completed)
and sends them in small batches — a single network request per batch, using keepalive so a
closing tab doesn't drop the last one — to Capyo's own /collect endpoint. No third-party
analytics and no advertising tags run alongside it.
The extension stores one value in the browser: the ad platform's attribution identifier
(oppref), read from the landing page URL when a shopper arrives from a ChatGPT ad, kept for
90 days in localStorage (key kliq_oppref) with a same-purpose cookie
(_kliq_oppref) as a fallback. This value identifies an ad click, not a person, and exists
solely so that an order placed later in the same browser can be matched back to the ad that brought the
visit. Whether the extension runs at all, and whether this value is written, is governed by Shopify's own
Customer Privacy API: your consent configuration decides, and events Shopify itself drops for lack of
consent never reach Capyo.
IP address and user agent. The /collect request Shopify's sandbox makes
carries your visitor's IP address and user agent, the way any web request does. Capyo holds these values
in memory for up to 10 minutes, only to attach them to the outbound Conversions API event so OpenAI can
match it, and then discards them. They are never written to disk or to the database —
neither in the event outbox, the debug samples, nor anywhere else described in section 2.
4. What we never process
- Your customers' names, email addresses, postal addresses or phone numbers.
- Payment or card data.
- A product's full description — only its id, variant id, title, quantity and amount, for the line items on an order.
- Your theme code. Capyo installs a Web Pixel extension through Shopify's own API; it does not edit theme files.
- Anything from a sales channel other than the store that installed the app.
Order id, order totals, line items and the anonymous click-attribution data in section 2 are processed — that is the app's purpose — but none of it identifies your customer as a person.
Shopify sends every public app the two mandatory customer-privacy webhooks
(customers/data_request and customers/redact). Capyo acknowledges them; because
it holds no customer personal data, there is nothing to return, and customers/redact erases
the delivery records and click ids tied to the named orders as a precaution.
5. This website
This site is a set of static pages. It sets no cookies, runs no analytics, and contains no tracking pixels, no advertising tags and no embedded third-party content. The typeface is self-hosted rather than loaded from a font CDN. The host of these pages processes the ordinary request data any web server sees, including your IP address, to deliver them.
6. Why we process it, and on what legal basis
- To provide the app you installed — relaying events, building the feed, computing the revenue report, applying your plan's limits. Legal basis: performance of a contract, Art. 6(1)(b) GDPR.
- To send your events to OpenAI, using the Pixel ID and Conversions API key you provided, so your own ad account can measure the ads you're already running. Legal basis: performance of a contract with you and, for the underlying advertising measurement, your own instruction and lawful basis as the business running those ads — this is disclosed in this policy so you can reflect it in your own store's privacy notice to shoppers if your legal advice says you should.
- To bill you through Shopify's Managed Pricing. We read which plan is active; Shopify performs the billing. Legal basis: Art. 6(1)(b) GDPR.
- To keep the service secure and working — server logs, error traces, abuse prevention, and the usage events that show which setup steps fail. Legal basis: legitimate interests, Art. 6(1)(f) GDPR.
- To answer support requests. Legal basis: Art. 6(1)(b) and (f) GDPR.
- To meet legal obligations, including Shopify's mandatory compliance webhooks. Legal basis: Art. 6(1)(c) GDPR.
We do not use your data for our own advertising, we do not profile you, and we never sell or rent it.
7. How long we keep it
- Sessions: deleted immediately when Shopify sends the
app/uninstalledwebhook. - Debug samples: 7 days on a rolling basis.
- Outbox rows: deleted 24 hours after a successful send.
- Delivery payloads (the exact request body sent to OpenAI): kept 7 days in live mode.
- Order-attribution records: kept for the retention period you configure in Settings, 400 days by default.
- Everything else about your shop — the store record, alerts, usage events, feed
history: deleted when Shopify sends the
shop/redactwebhook, 48 hours after uninstall. On that webhook, data is purged in this order: event samples, hourly event counters, the event outbox, click-attribution touches, delivery records, order-attribution records, feed run history, the feed file itself, SFTP configuration, alerts, monthly usage counters, queued jobs, your OpenAI credentials, product-usage events, then the store record and the session. Ask us to delete earlier and we will. - Server logs: kept no longer than 30 days, then rotated out.
- Support correspondence: kept up to 24 months, deleted sooner on request.
8. Who else is involved (sub-processors)
| Sub-processor | Company country | What they do | Where the servers are |
|---|---|---|---|
| Shopify International Ltd | Ireland | The platform the app runs on and the source of all store data; also handles billing | Per Shopify's own DPA |
| OpenAI | United States | Receives the events Capyo relays (page views, product views, cart adds, checkout and order data — ids, amounts, currency, no customer identity) at your own instruction, through your own Pixel ID and Conversions API key, into your own OpenAI Ads account — not an account Capyo controls | Per OpenAI's own terms |
| Resend | United States | Would deliver alert emails to the address you set, to your address only — not active today. It starts processing data only once a sending domain is bought and verified; until then, alerts are shown as in-app banners and Resend receives nothing | Per Resend's own terms |
| Hostinger International Ltd | Cyprus | Application hosting — the virtual server the app runs on | Boston, Massachusetts, United States |
| netcup GmbH | Germany | Database hosting — the PostgreSQL database holding everything in section 2 | Manassas, Virginia, United States |
| GitHub, Inc. | United States | Hosting of this website only — no app data reaches it | GitHub Pages global infrastructure |
There is no analytics provider, no error-tracking SaaS, no email marketing tool and no CRM in this list. We will update this table before any new sub-processor starts processing, including when Resend becomes active.
9. International transfers
Merchant data processed through the app is stored on servers located in the United States — the application server in Boston, Massachusetts and the database in Manassas, Virginia. Both are operated for us by European companies (Hostinger International Ltd, Cyprus; netcup GmbH, Germany), but the processing itself happens outside the EEA, which engages Chapter V of the GDPR. The events Capyo relays to OpenAI, and any future alert email through Resend, also involve United States-based processors.
For those transfers we rely on the Standard Contractual Clauses included in those providers' data processing terms, together with the technical and organisational security measures in section 10. The app stores no end-customer personal data, so nothing about your shoppers is transferred anywhere beyond the anonymous click-attribution values described in section 3. What crosses the border is the store configuration, order-attribution records, feed data and access tokens listed in section 2.
Hosting locations can change; any change of hosting location or sub-processor is announced in the app and on this page before it takes effect. Shopify may transfer data internationally under its own DPA and transfer mechanisms, which govern the Shopify-to-merchant relationship independently of this policy.
10. Security
- All traffic to the app and to this website is served over HTTPS/TLS. There is no plaintext endpoint.
- Your Conversions API key and SFTP password are encrypted at rest (AES-256-GCM) and are never shown again once saved, except as a masked placeholder.
- The database is not exposed to the public internet: the firewall accepts PostgreSQL connections from the application server's IP address only, over an encrypted connection with password authentication.
- Shopify access tokens are stored in that database and are never written to logs or shown in the UI.
- Administrative access to the server and the database is limited to the operator, over SSH with key authentication.
- Webhook requests from Shopify are verified by HMAC signature before anything is acted on.
- The app requests the minimum Shopify scopes it needs: read orders, read products, manage pixels, and (for order-level protected customer data used only for attribution, never stored as customer identity) read customer events.
We do not claim a formal certification (no ISO 27001, no SOC 2) and we do not claim encryption at rest beyond what the hosting providers apply to their own storage.
11. Protected customer data
Capyo requests Shopify's Level 1 protected customer data (order information) so that order totals and line items can be attributed to a ChatGPT ad click and shown in your revenue report. It does not request, and does not use, customer name, email, phone or address fields. A request for Level 2 fields (for hashed match keys, a possible future feature) would only follow a separate Shopify approval and a change to this policy before it started.
12. Your rights
Under the GDPR you can ask us to:
- confirm what we hold about you and give you a copy (access, Art. 15);
- correct anything inaccurate (rectification, Art. 16);
- delete it (erasure, Art. 17);
- restrict what we do with it (Art. 18);
- hand it over in a machine-readable form, or send it to another provider (portability, Art. 20);
- stop processing based on legitimate interests (objection, Art. 21).
Email gimbernat13@gmail.com and we will answer within one month. You do not need to justify a request. Uninstalling the app triggers deletion automatically, as described in section 7.
You can also complain to a data-protection supervisory authority — normally the one where you live, work, or where you believe the problem occurred.
13. Changes to this policy
When this policy changes, the new version appears on this page with a new date at the top. The version in force is the one published here.
14. Contact
gimbernat13@gmail.com — data-protection requests, security reports and everything else. See also our Terms of Service and the Data Processing Agreement.