Privacy Policy
Last updated 27 September 2026
Conversion Monitor is a Shopify app that compares the orders a store actually received against the conversions its tracking pixels and ad platforms recorded, and shows the merchant the difference.
What we store
For each order placed in a store that has installed the app:
- the Shopify order id and order number
- the order total and subtotal, and the currency
- the landing page and referring URL for the visit
- the sales channel, financial status, and whether it was cancelled
- the time the order was placed
For each event our web pixel reports from a shopper’s browser:
- the event name, an event id generated in the browser, and a timestamp
- the order id, total and currency, where the event has them
- the browser user agent string
What we do not store
We do not store customer names, email addresses, postal addresses, phone numbers, payment details, IP addresses, or the contents of any cart or order. We do not attempt to identify individual shoppers, and we do not build profiles of them.
Shopify’s order webhooks contain a customer’s email address. Our code discards it before anything is written to storage.
Why we store it
Solely to count orders and compare that count and its value against what the merchant’s tracking reported, and to show the merchant the gap. The data is not used for advertising, is not used to personalise anything, and is never sold or shared.
Consent
Our web pixel requests the analytics consent category only. Where a shopper must consent before being tracked, Shopify does not run our pixel until they have. Where tracking is on by default and a shopper opts out, the pixel stops reporting from that moment.
Ad platform connections
You can connect a Meta ad account, and doing so is your choice — nothing is connected until you link the account yourself from inside the app. When you do, we store the access token encrypted (AES-256-GCM), the ad account id and name, and which conversion action you chose to count. The token is used for exactly one thing: reading the daily conversion counts and values your ad account recorded, so they can be compared against your orders. We never read audiences, never touch a campaign, a bid or a budget, and send Meta nothing about your store or your customers.
Disconnecting the account in the app deletes the stored token immediately, and revoking the app’s access from Meta’s side has the same effect. The daily totals already recorded stay — they were true when they were recorded — but nothing new is read.
Google Ads, and what we do with your Google account data
You can also connect a Google Ads account. You do that by signing in with Google and approving access, in a tab of your own — nothing is connected until you complete that yourself. The app requests one scope, https://www.googleapis.com/auth/adwords, which is the only scope the Google Ads API offers; it has no narrower or read-only variant.
What Google user data we access. Only these, and only for the accounts you choose:
- The list of Google Ads accounts your Google login can reach — each one’s id, name, and whether it is a manager account — so you can pick the one that advertises this store.
- The conversion actions defined in the account you picked — id and name — so you can tell us which one means somebody bought something.
- Daily totals for the conversion actions you chose: the date, the number of conversions, the conversion value and its currency.
How we use it. For one thing only: to show the number Google recorded beside the orders your store actually received and the purchases our pixel observed, and to alert you when those numbers diverge. That comparison is the whole product.
What we never do. We never read your audiences, customer lists, keywords, creative, billing details, or anything about the people who saw or clicked your ads. We never write: no campaign, ad group, ad, budget, bid, audience or conversion action is ever created, edited, paused or removed by this app. We send Google nothing about your store or your customers.
What we store. The OAuth tokens, encrypted at rest (AES-256-GCM); the id and name of the account you chose; the conversion actions you marked as purchases; and the daily totals read from them. Nothing from your Google account is sold, shared, used for advertising, or used to train any model, and it is not given to anyone outside the processors listed below.
How to end it. Disconnecting in the app deletes the tokens immediately. Removing the app’s access from your Google account, at myaccount.google.com/connections, has the same effect from Google’s side. Either way we stop reading; the daily totals already recorded stay, because they were true when they were recorded.
Conversion Monitor’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Who else sees it
The only companies that process any of this on our behalf are:
- Railway (United States) — hosting and the database where everything above is stored.
- Sentry (European Union) — application errors, with request bodies, headers and cookies stripped before they are sent.
- Resend (United States) — delivery of alert emails. It sees the merchant’s own address and the contents of the alert, which contain order counts and totals but nothing about any customer.
No one else. No analytics on our own service, no advertising networks, and nothing is sold or shared.
How long we keep it
For as long as the app is installed, and within that, no longer than each kind of record is useful:
- Orders: kept while the app is installed. They are the ground truth every figure is measured against, so deleting them early would make the app disagree with what it told you yesterday.
- Pixel events: 730 days. The daily figures are rebuilt from these, for the same reason.
- Resolved alerts: 180 days.
- Webhook delivery records: 30 days. These hold no order data; they exist so a message Shopify sends twice is not counted twice.
When a merchant uninstalls, their store is marked inactive and collection stops. Shopify then sends a redaction request 48 hours later, at which point everything we hold for that store is deleted, orders included.
Security
Data is encrypted in transit and at rest. Every webhook we accept is verified against its cryptographic signature before it is read. Access to production data is limited to the operator of the service.
Shopper requests
Requests to access or erase personal data are made through the merchant, and Shopify forwards them to us automatically. Because we hold no personal data, there is nothing to return and nothing to erase; we confirm this on every request.