Privacy policy
Last updated: 26 August 2026
docs/privacy-data-map.md) and has not been reviewed by a lawyer.
In short
CommerceTrace does not read anything about your customers. It reads order numbers and amounts, never the people behind them — no names, email addresses, phone numbers or shipping addresses, because those fields are not part of the query it sends to Shopify.
The personal data it does hold is about you: the email address you sign in with. Order numbers are treated as personal data too, because Shopify can link one back to a person even though we cannot.
Nothing is kept beyond 90 days, and we delete everything sooner if you ask.
This policy explains what CommerceTrace accesses when you connect a Shopify store and a Google Analytics property, why each item is accessed, how it is stored, how long it is kept, and how to have it deleted.
1. Who we are
CommerceTrace (“we”, “the service”) is operated from Romania by the independent developer of the service, who is the data controller for the personal data described in this policy.
For privacy questions, deletion requests, or to identify the controller for a formal request, contact contact@commercetrace.com. We respond to identification requests from data subjects and supervisory authorities.
2. What the service does
CommerceTrace compares the orders in your Shopify store against the purchase events your Google Analytics 4 property received, in order to identify orders that are missing, duplicated, or recorded with the wrong value or currency. To do this it needs read access to your Shopify orders and read access to your GA4 reporting data. It does not write to either system.
3. Shopify data we access
We request the read_orders scope only. The Shopify client issues read queries
exclusively; there is no write operation anywhere in the code.
| Data | Why we need it | Stored? |
|---|---|---|
| Order number and order ID | The key used to match a Shopify order to a GA4 transaction, and to show you which order a finding concerns | Yes |
| Confirmation number | GA4 sometimes stores this instead of the order number, so it is an additional match candidate | Yes |
| Order creation time | Determining whether GA4 has had time to process the order, and grouping related failures | Yes |
| Subtotal, total, tax, shipping, discounts, duties, tips | The value comparison itself, and distinguishing a genuine mismatch from a total-versus-subtotal error | Yes |
| Presentment and shop currency | Comparing against the currency the customer was actually charged, not your store's home currency | Yes |
| Test, cancelled, and financial status flags | Excluding test and cancelled orders so they are not reported as tracking faults | Yes |
| Line items: product name, SKU, quantity, price | Item-level reconciliation and detecting purchases that arrive with an empty item list | Yes |
| Customer name, email, phone, address | Not requested. The query does not ask for these fields | No |
Because no customer contact or address fields are requested, the service operates at Shopify's protected customer data Level 1. Shopify still classes orders themselves as protected customer data, and those obligations apply.
4. Google user data we access
4.1 What we request
When you connect Google Analytics, we request a single OAuth scope:
https://www.googleapis.com/auth/analytics.readonly. This is read-only. We do
not request permission to modify your Analytics configuration, manage users, or access any
other Google service.
4.2 What we read with it
We run aggregate reports through the Google Analytics Data API. The dimensions requested
are transactionId, dateHour, and currencyCode, with
purchase revenue, tax, and shipping metrics.
No user-level dimensions are requested. We do not read user IDs, client IDs, device information, or geographic data through this API.
4.3 How we use it
Solely to compare against your Shopify orders and produce the findings shown in your dashboard. Google user data is not used for advertising, sold, transferred to third parties for their own purposes, used to train machine-learning models, or used to build any profile of you or your customers.
4.4 Limited Use disclosure
CommerceTrace's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4.5 How your Google authorisation is stored
Connecting Google Analytics produces a refresh token, which lets the service read your reports for scheduled comparisons without asking you to sign in each time. That token is encrypted at rest with AES-256-GCM, bound cryptographically to your store so it cannot be used in another account's context, and is never written to logs.
You can revoke access at any time, either from the service's disconnect control — which also revokes the grant with Google — or directly at myaccount.google.com/permissions. Revoking immediately stops all further access.
5. Account data
We store the email address you sign in with, in order to send sign-in links and to identify your account. Sign-in links are single-use, expire after 15 minutes, and are stored as a hash rather than in a form that could be reused.
6. What we do not collect
- Customer names, email addresses, phone numbers, or shipping addresses
- Payment card details — we never see them, and Shopify does not expose them to us
- User-level analytics identifiers from GA4
- Website analytics on this marketing site. REVIEW: if you later add analytics or any cookie beyond a session cookie, this section and the cookie section must be updated, and an EU cookie banner will be required.
7. Cookies
The application sets one cookie, holding your signed session so you stay logged in. It is
HttpOnly, SameSite=Lax, and marked Secure over HTTPS.
It is strictly necessary for the service to function and is not used for tracking or
advertising.
8. Where data is stored and who can access it
Data is stored on servers operated by Railway in the European Union. Access is limited to the operator of the service, and only for operating and supporting it.
Third parties that process data on our behalf:
- Railway — hosting and database, EU region
- Resend — delivery of sign-in emails
- Google — the Analytics Data API, which is the source of the analytics data being compared
9. How long we keep it
Order and analytics data collected for a comparison is retained for 90 days and then deleted, along with the findings derived from it. Ninety days is long enough to compare against a previous period and to detect a regression, and short enough that we are not holding data the service does not need.
The deletion itself is implemented in software — scan runs past the window are removed along with everything attached to them: findings, evidence and trace records. During early access it is run by us on a regular basis rather than by an automatic scheduled job; the scheduled job is being finished. Either way nothing is kept beyond 90 days.
When you close your account, or ask us to delete your data, everything associated with your store is removed regardless of age, within 30 days of the request.
10. Your rights
Depending on where you are, you may have the right to access the data we hold about you, correct it, delete it, export it, or object to its processing. To exercise any of these, contact contact@commercetrace.com. We will respond within 30 days.
You can delete most data yourself: disconnecting Google Analytics revokes the token and clears it, and closing your account removes the stored orders and findings.
11. Data deletion requests
To request deletion of everything associated with your account, email contact@commercetrace.com from the address you signed up with, with the subject “Delete my data”. We will confirm once it is done.
12. Security
- All traffic is served over HTTPS
- Google refresh tokens are encrypted at rest with AES-256-GCM and bound to their store
- Credentials are never written to logs; error output is redacted before being recorded
- Every request is scoped to your own store, and access to another store's data is refused rather than filtered
- The service holds read-only access and cannot modify your store or your Analytics property
No system is perfectly secure, and we do not claim otherwise.
13. Children
The service is a business tool and is not directed at children under 16.
14. Changes to this policy
If we change this policy we will update the date above, and for material changes we will notify account holders by email before the change takes effect.
15. Contact
contact@commercetrace.com
CommerceTrace — operated from Romania