Privacy policy
Last updated: August 2026
NDA Signal is a Shopify application that sends conversion events from a merchant's store to advertising platforms. This policy explains what we handle, why, and for how long.
Who is responsible for what
The merchant who installs the app is the data controller: it is their store, their customers, and their decision to send events to an advertising platform. NDA Signal acts as a data processor on their behalf, and only within their instructions. Our contract with merchants is the data processing agreement.
What we process
| Category | Examples | Why |
|---|---|---|
| Order data | Order number, total, currency, line items, fulfilment and payment status | To report a purchase to the advertising platform and to reconcile which orders were actually paid for |
| Customer identifiers | Email address, phone number, first and last name, city, postal code, country | To let the platform match the conversion to the person who saw the ad. These are hashed with SHA-256 before storage and before transmission, as the platforms require. We do not keep a readable copy. |
| Technical identifiers | IP address, browser user agent, advertising click identifiers, cookies set by the advertising platforms | To attribute the conversion to the correct advertisement and to detect automated traffic |
| Store data | Shop domain, plan, installed pixels, app settings | To run the app and to bill the correct subscription |
What we never do
- We do not sell personal data, and we do not share it with anyone other than the advertising platforms the merchant has connected.
- We do not use one merchant's data to serve another merchant. Every store is isolated.
- We do not build advertising profiles of our own, and we do not process payment card details — those never reach us.
Who receives the data
Only the platforms the merchant connects, and only the fields required by each:
- Meta Platforms — through the Conversions API.
- TikTok — through the Events API.
- Google — through the Google Analytics 4 Measurement Protocol.
- Cloudflare, as our infrastructure provider, which stores and processes data on our instruction.
Each of these platforms is an independent controller for what it does with the data afterwards, under its own terms.
Where the data is stored
On Cloudflare's global network. Event records are held in a database with per-store isolation; short-lived caches hold identity data for at most 48 hours. Transfers outside the European Economic Area are covered by the standard contractual clauses in Cloudflare's data processing addendum.
How long we keep it
- Event and dispatch logs — 12 months, then deleted automatically.
- Identity graph entries — 24 months from the last time the visitor was seen.
- Everything belonging to a store — deleted within 30 days of uninstalling, or immediately on request.
Rights of the merchant's customers
Requests to access, correct or delete personal data should be sent to the merchant, who is the controller. When Shopify forwards us a customer redaction request, we delete the matching records and confirm to the merchant. Shoppers may also write to us directly at privacy@ndasignal.com and we will route the request to the correct store.
Cookies
The collection script sets a small number of cookies on the merchant's own domain: a visitor identifier, and copies of the advertising cookies already set by the platforms. They carry no readable personal data. Where the merchant has enabled Shopify's consent API, events are marked with the visitor's marketing consent and the platforms apply it.
Security
All traffic is TLS-encrypted. Access tokens are encrypted at rest. Personal fields are hashed before they are written. Access to production data is limited to the people who operate the service, and is logged.
Contact
NDA Signal — privacy@ndasignal.com
For anything else: support@ndasignal.com