Privacy Policy
Last updated 19 August 2026
Conversion Monitor is a Shopify app that compares the orders a store actually received against the conversions its tracking pixels and ad platforms recorded, and shows the merchant the difference.
What we store
For each order placed in a store that has installed the app:
- the Shopify order id and order number
- the order total and subtotal, and the currency
- the landing page and referring URL for the visit
- the sales channel, financial status, and whether it was cancelled
- the time the order was placed
For each event our web pixel reports from a shopper’s browser:
- the event name, an event id generated in the browser, and a timestamp
- the order id, total and currency, where the event has them
- the browser user agent string
What we do not store
We do not store customer names, email addresses, postal addresses, phone numbers, payment details, IP addresses, or the contents of any cart or order. We do not attempt to identify individual shoppers, and we do not build profiles of them.
Shopify’s order webhooks contain a customer’s email address. Our code discards it before anything is written to storage.
Why we store it
Solely to count orders and compare that count and its value against what the merchant’s tracking reported, and to show the merchant the gap. The data is not used for advertising, is not used to personalise anything, and is never sold or shared.
Consent
Our web pixel requests the analytics consent category only. Where a shopper must consent before being tracked, Shopify does not run our pixel until they have. Where tracking is on by default and a shopper opts out, the pixel stops reporting from that moment.
Ad platform connections
You can connect a Meta ad account, and doing so is your choice — nothing is connected until you link the account yourself from inside the app. When you do, we store the access token encrypted (AES-256-GCM), the ad account id and name, and which conversion action you chose to count. The token is used for exactly one thing: reading the daily conversion counts and values your ad account recorded, so they can be compared against your orders. We never read audiences, never touch a campaign, a bid or a budget, and send Meta nothing about your store or your customers.
Disconnecting the account in the app deletes the stored token immediately, and revoking the app’s access from Meta’s side has the same effect. The daily totals already recorded stay — they were true when they were recorded — but nothing new is read. The app does not connect to Google Ads or any other platform yet; when that ships, this page will say so first — until you read it here, it does not exist.
Who else sees it
The only companies that process any of this on our behalf are:
- Railway (United States) — hosting and the database where everything above is stored.
- Sentry (European Union) — application errors, with request bodies, headers and cookies stripped before they are sent.
- Resend (United States) — delivery of alert emails. It sees the merchant’s own address and the contents of the alert, which contain order counts and totals but nothing about any customer.
No one else. No analytics on our own service, no advertising networks, and nothing is sold or shared.
How long we keep it
For as long as the app is installed, and within that, no longer than each kind of record is useful:
- Orders: kept while the app is installed. They are the ground truth every figure is measured against, so deleting them early would make the app disagree with what it told you yesterday.
- Pixel events: 730 days. The daily figures are rebuilt from these, for the same reason.
- Resolved alerts: 180 days.
- Webhook delivery records: 30 days. These hold no order data; they exist so a message Shopify sends twice is not counted twice.
When a merchant uninstalls, their store is marked inactive and collection stops. Shopify then sends a redaction request 48 hours later, at which point everything we hold for that store is deleted, orders included.
Security
Data is encrypted in transit and at rest. Every webhook we accept is verified against its cryptographic signature before it is read. Access to production data is limited to the operator of the service.
Shopper requests
Requests to access or erase personal data are made through the merchant, and Shopify forwards them to us automatically. Because we hold no personal data, there is nothing to return and nothing to erase; we confirm this on every request.