Legal
Privacy Policy
Pixel Proof audits the health of the conversion tracking you already run. It is built so that it never reads, stores, or receives raw customer data.
PCD LEVEL 2 · HASHED PRESENCE ONLY
Last updated: 12 July 2026.
Summary
Pixel Proof is a diagnostic tool for Shopify merchants. It grades the conversion tracking you already send (Meta Conversions API / server-side GTM) for three things — event_id dedup, server-side hit ratio, and match-key completeness (an Event Match Quality proxy). It classifies as Protected Customer Data Level 2: the only customer-related signal it processes is the boolean presence of already-hashed match keys on an event — never a raw identifier. See our Protected customer data disclosure for the full posture.
What we access — and why
read_products
The only Shopify scope Pixel Proof requests. It reads catalog metadata to anchor an audit to your store. It reads no orders, no customers, and no checkouts.
Your conversion-event sample
From the source you connect (Meta Conversions API / server-side GTM): the event_id, whether the event was client- or server-side, the event name, and a yes/no for each already-hashed match key.
Aggregates only
We persist counts and percentages per audit run (dedup %, server-side hit ratio, key coverage) plus the findings. We never persist a per-customer row.
Your shop identifier
Your shop domain, an offline access token, and your billing plan status — the minimum needed to run the app and bill it.
What we never access or store
Raw emails, phone numbers, or IP addresses. Orders, customers, or checkout data. Pixel Proof does not request read_orders or read_customers. Match-key values are reduced to booleans at the source adapter, so the rest of the app is structurally unable to see a raw identifier. Pixel Proof does not use any AI or machine-learning models, and it does not sell or share your data with third parties.
How we use your data
- To run an on-demand audit of your conversion tracking and show you the results in your Shopify admin.
- To store aggregate scores and findings so you can see trends across audit runs.
- To operate billing (Free or Pro) through Shopify's Billing API.
Retention & security
- Encryption in transit: all traffic is served over TLS/HTTPS.
- Token handling: your Shopify offline access token lives only in the app's managed Prisma session store, and is deleted on uninstall and on a shop-redaction request.
- Hashed-presence boundary: raw match-key values are reduced to booleans at the source adapter and never cross into the rest of the app.
- Deleted on uninstall: when you uninstall the app, and again when Shopify sends a shop-redaction request (~48h later), your shop's rows, session, and stored web-vitals are removed.
GDPR / Shopify mandatory webhooks
- customers/data_request: Pixel Proof holds no raw customer data — only aggregate counts of hashed-key presence — so there is no personal customer data to return.
- customers/redact: there is no raw customer PII to erase; this request is acknowledged with no personal data to redact.
- shop/redact: we cascade-delete all rows for your shop — audit runs, findings, billing, tokens, session, and web-vitals.
Contact
Questions about privacy or your data? Email privacy@syncerp.work.