Privacy Policy — Agentic Ads Pixel
Last updated: 2026-07-20
This Privacy Policy explains how Melaudic ("we", "us", "our") handles information in connection with the Shopify app Agentic Ads Pixel (the "App"). For the personal data described here, the merchant is the data controller and Melaudic acts as their data processor — handling data only on the merchant's instructions and only as described below.
1. What the App does
The App installs a Shopify Web Pixel extension on a merchant's storefront. It measures standard shopping activity across the storefront funnel — from page and product views through cart, checkout, and completed orders — and forwards it to the merchant's OpenAI Ads account for advertising measurement. The App does not display advertising; it relays measurement data on the merchant's behalf.
2. Information we process
From the Shopify merchant (store-level data)
When a merchant installs the App, Shopify provides the shop's myshopify.com domain, an access token used to install and maintain the pixel, and the granted access scopes. We also store the OpenAI Ads Pixel ID the merchant enters and the identifier of the pixel we install for them. This data operates the App. We collect anonymous admin-usage analytics (such as page views and clicks) that contain no customer or order information.
From storefront activity
Through Shopify's Customer Events, the pixel measures standard shopping activity across the storefront funnel. For each event it builds a minimal record — an event identifier and timestamp, the page context, and the product, cart, or order details Shopify exposes (such as item identifiers, titles, currency, and amounts), together with the merchant's Pixel ID — and relays it to the merchant's OpenAI Ads measurement endpoint.
If the merchant enables server-side delivery (Conversions API), each paid order also contributes the customer's email address and coarse location — country, city, and postal code — along with the order value and items. We never process customers' names or phone numbers, and we never see login credentials or payment card details.
Identity data and consent
Email addresses are irreversibly hashed (SHA-256) before they leave our systems; we transmit only the hash, never the raw email. Coarse location and order value let OpenAI match a purchase to an ad click for the merchant. For orders from the EU, EEA, and United Kingdom, we attach this hashed identity only when the customer has given marketing consent; without consent, the sale is still measured but with no personal data attached. The browser pixel independently honors each visitor's tracking-consent choice through Shopify's Customer Privacy framework.
3. How we use the information
- Store-level data operates the App: authenticating requests to Shopify, installing and maintaining the pixel, communicating with the merchant, and billing the App subscription through Shopify.
- Event data is relayed to OpenAI Ads for the merchant's advertising measurement. OpenAI is the sole recipient, chosen by the merchant when they connect their OpenAI Ads account.
We do not sell, rent, or share data with any third party beyond this relay. We do not use event data for our own marketing, analytics, or model training.
4. Data retention
- Customer personal data: not retained. Hashes are generated in transit and are not stored, and we keep no raw customer personal data at rest.
- Aggregate measurement data: to power the merchant's in-app performance reporting, we retain non-identifying aggregates — such as event counts, order values, and order identifiers — that do not identify any individual.
- Store-level data: retained while the App is installed. On uninstall, Shopify sends a
shop/redactrequest 48 hours later, at which point we delete the shop's data. - Backups: routine rolling backups may retain deleted data briefly before being overwritten.
5. Customer data requests (mandated privacy webhooks)
We support Shopify's three mandated privacy webhooks:
customers/data_request— we hold no raw customer personal data to provide; any measurement records we retain are aggregated and non-identifying.customers/redact— we hold no raw customer personal data to delete.shop/redact— we delete the data we hold about the shop.
6. Security
- Data is encrypted in transit (TLS). The stored OpenAI Ads key is encrypted at rest with authenticated encryption (AES-256-GCM).
- We minimize what we handle: email is hashed before transmission, names and phone numbers are never processed, and no raw customer personal data is stored.
- We follow Shopify's recommended practices: least-privilege access scopes, HMAC verification on incoming webhooks, session-token authentication on admin requests, and access controls on our systems.
7. International transfers
The App is operated from infrastructure in the United States, and OpenAI Ads operates its own infrastructure. By installing the App, the merchant authorizes the transfer of the data described above to these processors.
8. Children's privacy
The App is for merchants operating businesses. It is not directed to children, and we do not knowingly collect data from children.
9. Changes to this policy
We may update this policy from time to time; material changes will be reflected by the "last updated" date above.
10. Contact
Questions or concerns: support@melaudic.com.