CPIXEL PRIVACY POLICY Last Updated: August 2026 cPixel is provided by B2B Gold, Ho Chi Minh City, Vietnam ("we," "us," or "our"). This Privacy Policy explains what the app processes, why, how long it is kept, and who it is shared with. By installing or using the app, you agree to this policy. 1. THE TWO ROLES - Storefront and order data belongs to you, the merchant. We process it on your instructions, as your processor (service provider). You remain the controller and are responsible for telling your own customers about it, and for obtaining any consent your customers' jurisdiction requires. - Merchant account and contact data — your store details, your settings, and the store owner's email address — we process as the controller, to run the app and to send you service notices about your own tracking. 2. WHAT THE APP DOES cPixel sends storefront and order events from your store to the advertising and analytics platforms you connect: Meta, TikTok, Google Analytics 4 and OpenAI Ads. You choose which platforms receive data, and you supply their credentials. If we offer further platforms, this policy is updated before any data can reach them. 3. WHAT THE APP PROCESSES 3.1 Merchant data - Your Shopify store domain, plan, installed status, and the app's own settings (connected platform IDs, targeting rules, per-account options). - The access tokens you enter for your own advertising accounts. - The store owner's email address received from Shopify, used to send you a notice when your tracking stops working. 3.2 Storefront and order data When a visitor browses your store or places an order, the app forwards an event to the platforms you connected. That event can contain: - the page or product viewed, the cart contents, and the order value, currency and line items; - order and checkout identifiers; - advertising click identifiers and cookies set by the advertising platforms themselves (for example _fbp, _fbc, ttclid, gclid); - the visitor's IP address and browser user agent. 3.3 Customer identifiers used to match a conversion An advertising platform has to match a conversion back to the ad that produced it. Where a platform you connected accepts customer identifiers for that, the app can send: - The customer's email address and phone number, SHA-256 HASHED before they leave your store. Only the hash is transmitted, never a readable address or number, and we do not store either one. Sent to Meta and TikTok. - The identifier of the customer's Shopify account — a number, not a name and not an address. Sent hashed to Meta and OpenAI Ads, and to Google Analytics 4 in Google's user_id field, which that platform accepts unhashed. This happens only where Shopify has approved this app's Protected Customer Data access, and the app enforces that in its own code rather than by policy: a build running without that approval withholds all of it and matching falls back to advertising click identifiers, IP address and user agent. Customer names and postal addresses are NEVER sent to any advertising platform. The app does not request them from Shopify at all. 4. WHAT WE KEEP, AND FOR HOW LONG The app does not store your event data. Events pass through, are forwarded to the platforms you chose, and are not retained. What is stored: - Match data for a checkout — advertising click identifiers, platform cookies, the visitor's IP address and browser user agent. Kept 7 DAYS, then deleted automatically by a daily job. This is what allows an order sent from our servers to be attributed to the visit that produced it. - An order record used for reconciliation — the Shopify order and checkout reference, the order total, whether the browser reported the sale, and which ad platform's click the order arrived with. Kept 45 DAYS, then deleted automatically. For orders sent to Google Analytics 4 it also holds that visitor's Google Analytics client and session identifier, because a refund arrives weeks after the sale and must be reported under the same identifier the sale used — the 7-day record above is long gone by then. It holds no event payload, no email address and no phone number. - NOTHING from a debug session. While a session is running, each event is redacted (personal fields removed, IP addresses masked to the /24 network), sent to your browser, and discarded. No transcript is written, at any retention period, on any plan. The only copy of a session is the one in your own browser tab, and any file you export from it. - Order identifiers (the identifier only) for purchases that could not be sent immediately, so they can be sent when sending resumes. Kept 7 DAYS. - Your store configuration and the advertising credentials you entered, kept until you uninstall the app. - Anonymous aggregate counts — how many events were sent, how many failed. These contain no individual records. We store IP address and browser user agent unmasked for up to 7 days. These are personal data, and we name them here rather than describing our storage as containing no personal data, which would not be accurate. 5. WHO ELSE RECEIVES DATA - The advertising and analytics platforms you connect, listed in section 2. Each handles the data under its own terms with you. - Cloudflare, Inc., which provides all of our infrastructure: compute, database, storage and email delivery. - Shopify Inc., the platform the app runs on and the source of order data. That is the complete list. We use no analytics, advertising, session-recording or error-tracking service of our own on merchant or visitor data. 6. CONSENT Before sending anything, the app checks the visitor's choices as recorded by Shopify's Customer Privacy API. A visitor who has not granted marketing consent has no marketing events sent on their behalf, and analytics events are gated separately on the analytics purpose. That API already applies your own regional settings. In a region you have configured to require consent, a visitor who has not answered counts as not having granted it, and nothing is sent until they do. In a region where consent is not required, that API reports the non-essential purposes as permitted and the app follows it. We do not run a geography model of our own and we do not override your Shopify configuration in either direction. If the API returns no answer at all, the app treats it as not granted and sends nothing. 7. YOUR CONTROLS AND CUSTOMER REQUESTS - You can remove any connected platform, or uninstall the app, at any time. When you uninstall, Shopify removes the app's pixel, its settings entry and its app embed automatically. No code is left in your theme. - Customer data request: the app holds no customer profile, no name, email or address, and no identifier that can be linked to a named individual. There is nothing to export. - Customer redaction: we delete the match data described in section 4 for the orders named in the request, together with any expired records for your store. In practice these have already expired — they are kept 7 days, and Shopify sends the request no earlier than 10 days after it is made. - Shop redaction: we delete everything held for your store. Individual shoppers should contact the store they shopped with. That merchant is the controller of their data; we act on the merchant's instructions. 8. SECURITY, TRANSFERS AND OTHER INFORMATION - Security: data is encrypted in transit with TLS, and encrypted at rest by our infrastructure provider (Cloudflare). Access to production is limited to authorized personnel and is authenticated with hardware-backed passkeys, not passwords. Every administrative action taken against a merchant's store is recorded in an audit log. - Advertising credentials you enter are stored in our database and rely on that infrastructure encryption; we do not apply a second layer of encryption on top of it. They are never written to logs, alerts or debug sessions, and they are never sent back to the app: once saved, a credential can be replaced or cleared, but it cannot be read out again by anyone using the app. - International transfers: data may be processed anywhere on Cloudflare's global network. Cloudflare's data processing terms and transfer mechanisms apply. Where you select European data residency for Google Analytics 4, events for that property are sent to Google's EU endpoint. - Children: the app is not directed at children and we do not knowingly process their data. - Changes: we will update this policy when what we do changes, and update the date at the top. Material changes will be notified in the app. 9. CONTACT US - Email: b2bgold.dev@gmail.com - Website: https://cpixel.afixer.app/ END OF PRIVACY POLICY