Privacy Policy

Last updated: 23 September 2026

In short. AdSignal is an app installed into a Shopify or Shopline store. To send conversion events to advertising platforms, we process customer email addresses and phone numbers in one-way hashed form, together with IP address and user agent. We do not store email addresses or phone numbers in readable form, we do not sell data, and we do not use one store's data to serve another.

1. Who controls the data

For store customer data, the merchant is the data controller and AdSignal is the processor: we process only on the merchant's instructions, expressed through the settings they configure in the app.

For the merchant's own account data (login email, app usage logs), AdSignal is the controller.

Operated by Công ty TNHH Lục Đường, registered at TDP Hữu, P. Chũ, T. Bắc Ninh, Vietnam. Privacy contact: privacy@allsignalme.com.

2. What we process

2.1. Store customer data

TypeWhy it is needed
Hashed email address and phone number (SHA-256) Advertising platforms use these to match an event to a user account. The hash is one-way, so the original value cannot be recovered.
IP address, user agent Required by the Conversions API for event matching and fraud prevention.
Commerce events: product view, add to cart, begin checkout, purchase (order ID, value, currency, products) The content of the conversion event itself.
The shopper's cookie consent state Determines whether an event is permitted to leave the store at all.

We do not store customer names, shipping addresses or payment details in our systems. Our authorised staff may read this data on your store while diagnosing a problem you have reported — see staff access for support below.

2.2. Store data

Product catalogue, collections and inventory — used to generate feeds. Shopify/Shopline access tokens and advertising platform tokens are stored encrypted with AES-256-GCM, never in plaintext.

2.3. App user data

Email address, name, password (bcrypt hashed), and a log of actions taken in the app.

2.4. Staff access for support

When you ask us for help, an authorised member of our team may need to read data on your store to find the cause — for example whether a product is published to a sales channel, whether the tracking pixel is installed, or why a specific order did not produce a conversion event.

This access follows a need-to-know rule: only staff whose role requires it, under a confidentiality obligation, and only for as long as the request needs. Customer identifiers such as email addresses, phone numbers and shipping addresses are masked by default; seeing them in full requires a separate action and a stated reason.

Every such access is logged — who, which store, what was run, and when. That log is a record of our own staff's actions, so we keep it on our own retention schedule even after an app uninstall. It is designed not to hold customer personal data: it keeps what was run and the outcome (success or failure, with a short error summary) — not the data your store returned, and not the values staff passed alongside the query — and email addresses and phone numbers are removed from everything it records.

3. Legal basis

4. How long we keep it

DataRetention
Raw conversion events (hashed email/phone, IP, user agent) 7–28 days depending on event type, then deleted automatically
Event deduplication records35 days
App usage logs90 days
Daily aggregates (contain no personal data)Retained long term
Access tokensRotated near expiry, deleted when the app is uninstalled
Cold archive (only if the store opts in) Long term; wiped entirely when the store uninstalls the app

5. Who we share it with

We do not sell data. Data is sent only to:

5.1. Advertising platforms — chosen by the merchant

Meta (Facebook), Google, TikTok, Pinterest, Snapchat. Only platforms the merchant actively connects receive any data, and only the events within the scope they configure.

5.2. Infrastructure providers

ProviderRoleLocation
Vultr HoldingsApplication servers and databaseUnited States
CloudflareCDN, object storage, attack mitigationGlobal
ShopifyThe commerce platform the app runs onPer Shopify

6. Security

7. Your rights

You have the right to request access to, correction of, deletion of, or a copy of your data.

7.1. Store customers

Please contact the store you purchased from — they are the data controller. When the store submits a request through Shopify, we handle it automatically:

7.2. Merchants

Uninstalling the app from your store triggers data deletion through Shopify's process. You may also contact privacy@allsignalme.com.

8. International transfers

Our servers are located in the United States. If you are elsewhere, your data will be transferred to and processed there.

9. Changes to this policy

Where changes are material, we update the date at the top of this page and notify you in the app before the change takes effect.

10. Contact

privacy@allsignalme.com
Công ty TNHH Lục Đường — TDP Hữu, P. Chũ, T. Bắc Ninh, Vietnam