Privacy policy

Last updated: 26 August 2026

OPERATOR: publishing without a named controller is a deliberate, temporary choice — see §1. Add the name there if Google's OAuth review asks for it, or when a company is registered. Nothing else in this document is a placeholder. It was written from an engineering inventory of what the software actually does (docs/privacy-data-map.md) and has not been reviewed by a lawyer.

In short

CommerceTrace does not read anything about your customers. It reads order numbers and amounts, never the people behind them — no names, email addresses, phone numbers or shipping addresses, because those fields are not part of the query it sends to Shopify.

The personal data it does hold is about you: the email address you sign in with. Order numbers are treated as personal data too, because Shopify can link one back to a person even though we cannot.

Nothing is kept beyond 90 days, and we delete everything sooner if you ask.

This policy explains what CommerceTrace accesses when you connect a Shopify store and a Google Analytics property, why each item is accessed, how it is stored, how long it is kept, and how to have it deleted.

1. Who we are

CommerceTrace (“we”, “the service”) is operated from Romania by the independent developer of the service, who is the data controller for the personal data described in this policy.

For privacy questions, deletion requests, or to identify the controller for a formal request, contact contact@commercetrace.com. We respond to identification requests from data subjects and supervisory authorities.

REVIEW — read this before relying on it: GDPR Article 13 requires the identity of the controller, not only a contact route, and that obligation applies to a sole trader as much as to a company. Publishing without a name is a calculated risk taken because no company is registered yet; the commitment to identify the controller on request is what makes it defensible, and it only stays defensible if that email is genuinely monitored. Expect Google's OAuth verification to ask for it — if it does, add the name rather than arguing the point.

2. What the service does

CommerceTrace compares the orders in your Shopify store against the purchase events your Google Analytics 4 property received, in order to identify orders that are missing, duplicated, or recorded with the wrong value or currency. To do this it needs read access to your Shopify orders and read access to your GA4 reporting data. It does not write to either system.

3. Shopify data we access

We request the read_orders scope only. The Shopify client issues read queries exclusively; there is no write operation anywhere in the code.

DataWhy we need itStored?
Order number and order IDThe key used to match a Shopify order to a GA4 transaction, and to show you which order a finding concernsYes
Confirmation numberGA4 sometimes stores this instead of the order number, so it is an additional match candidateYes
Order creation timeDetermining whether GA4 has had time to process the order, and grouping related failuresYes
Subtotal, total, tax, shipping, discounts, duties, tipsThe value comparison itself, and distinguishing a genuine mismatch from a total-versus-subtotal errorYes
Presentment and shop currencyComparing against the currency the customer was actually charged, not your store's home currencyYes
Test, cancelled, and financial status flagsExcluding test and cancelled orders so they are not reported as tracking faultsYes
Line items: product name, SKU, quantity, priceItem-level reconciliation and detecting purchases that arrive with an empty item listYes
Customer name, email, phone, addressNot requested. The query does not ask for these fieldsNo

Because no customer contact or address fields are requested, the service operates at Shopify's protected customer data Level 1. Shopify still classes orders themselves as protected customer data, and those obligations apply.

4. Google user data we access

4.1 What we request

When you connect Google Analytics, we request a single OAuth scope: https://www.googleapis.com/auth/analytics.readonly. This is read-only. We do not request permission to modify your Analytics configuration, manage users, or access any other Google service.

4.2 What we read with it

We run aggregate reports through the Google Analytics Data API. The dimensions requested are transactionId, dateHour, and currencyCode, with purchase revenue, tax, and shipping metrics.

No user-level dimensions are requested. We do not read user IDs, client IDs, device information, or geographic data through this API.

4.3 How we use it

Solely to compare against your Shopify orders and produce the findings shown in your dashboard. Google user data is not used for advertising, sold, transferred to third parties for their own purposes, used to train machine-learning models, or used to build any profile of you or your customers.

4.4 Limited Use disclosure

CommerceTrace's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

4.5 How your Google authorisation is stored

Connecting Google Analytics produces a refresh token, which lets the service read your reports for scheduled comparisons without asking you to sign in each time. That token is encrypted at rest with AES-256-GCM, bound cryptographically to your store so it cannot be used in another account's context, and is never written to logs.

You can revoke access at any time, either from the service's disconnect control — which also revokes the grant with Google — or directly at myaccount.google.com/permissions. Revoking immediately stops all further access.

5. Account data

We store the email address you sign in with, in order to send sign-in links and to identify your account. Sign-in links are single-use, expire after 15 minutes, and are stored as a hash rather than in a form that could be reused.

6. What we do not collect

7. Cookies

The application sets one cookie, holding your signed session so you stay logged in. It is HttpOnly, SameSite=Lax, and marked Secure over HTTPS. It is strictly necessary for the service to function and is not used for tracking or advertising.

REVIEW: confirm this remains accurate at launch. Adding any analytics, session-recording, or advertising script to this site changes both this section and your consent obligations.

8. Where data is stored and who can access it

Data is stored on servers operated by Railway in the European Union. Access is limited to the operator of the service, and only for operating and supporting it.

Third parties that process data on our behalf:

REVIEW: confirm Resend before publishing — if you switch email provider, this list changes. Both Railway and Resend are US companies processing data in the EU; if you take on EU merchants, confirm each has a Data Processing Agreement in place (both offer one) and record which transfer mechanism it relies on.

9. How long we keep it

Order and analytics data collected for a comparison is retained for 90 days and then deleted, along with the findings derived from it. Ninety days is long enough to compare against a previous period and to detect a regression, and short enough that we are not holding data the service does not need.

The deletion itself is implemented in software — scan runs past the window are removed along with everything attached to them: findings, evidence and trace records. During early access it is run by us on a regular basis rather than by an automatic scheduled job; the scheduled job is being finished. Either way nothing is kept beyond 90 days.

When you close your account, or ask us to delete your data, everything associated with your store is removed regardless of age, within 30 days of the request.

10. Your rights

Depending on where you are, you may have the right to access the data we hold about you, correct it, delete it, export it, or object to its processing. To exercise any of these, contact contact@commercetrace.com. We will respond within 30 days.

You can delete most data yourself: disconnecting Google Analytics revokes the token and clears it, and closing your account removes the stored orders and findings.

11. Data deletion requests

To request deletion of everything associated with your account, email contact@commercetrace.com from the address you signed up with, with the subject “Delete my data”. We will confirm once it is done.

12. Security

No system is perfectly secure, and we do not claim otherwise.

13. Children

The service is a business tool and is not directed at children under 16.

14. Changes to this policy

If we change this policy we will update the date above, and for material changes we will notify account holders by email before the change takes effect.

15. Contact

contact@commercetrace.com
CommerceTrace — operated from Romania