At ProfitIQ, accessible from https://www.profitiq.tech, your privacy is a core priority. This policy explains what data we collect, how we use it, and your rights as a user.
1. Information We Collect
We only collect information that is strictly necessary to provide you with accurate financial and marketing analytics:
Account Credentials — Email address and basic profile information when you register.
Store Integration Data — Synced orders, products, refunds, and shipping costs from connected platforms (Shopify, WooCommerce, eBay, Amazon).
Marketing API Data — Ad campaigns, clicks, and daily ad spend from Meta Ads, Google Ads, and TikTok Ads — pulled in read-only mode to calculate your ROAS, AOV, and P&L metrics.
2. Your Customers' Personal Data (Data Minimization)
When you connect a store, some order records contain personal data about your customers. We deliberately process the minimum required to cost your orders, and no more:
Customer name — used only as the order's display name in your dashboard and to flag repeat-return customers (return-risk scoring).
City (from the shipping or billing address) — used only for courier-by-city delivery and return analytics.
We do NOT collect, store, or process customer email addresses, phone numbers, or street/postal addresses from your store.
From Shopify specifically, ProfitIQ requests only the read_orders and read_products scopes (plus read_all_orders, which extends order access beyond 60 days for historical profit reporting without adding any new data type), and persists only the customer name and city described above. We never use customer personal data for marketing or advertising, and we never sell, rent, or share it with third parties.
3. How We Use Your Information
All collected data is used exclusively to serve your business analytics and platform functionality:
Operate and maintain real-time Profit & Loss dashboards.
Calculate marketing campaign Return on Ad Spend (ROAS).
Estimate COGS margins, courier delivery ratios, and platform fees.
Generate automated financial reports and AI insights for your connected stores.
We never sell, rent, trade, or distribute your store data, your customers' personal data, or ad spend information to third-party marketing services.
4. Our Role & Legal Basis
For personal data about your customers, you (the merchant) are the data controller and ProfitIQ acts as your data processor: we process that data only to provide the analytics you have asked us to provide, under your instructions, and never for our own purposes.
Our processing terms are set out in the Data Processing Agreement contained in our Terms of Service, which forms a binding privacy and data-protection agreement between you and ProfitIQ.
5. Data Security & Storage
ProfitIQ uses industry-standard security controls:
Encryption in transit — all traffic is served over HTTPS/TLS.
Encryption at rest — API credentials (Meta system tokens, Shopify access/refresh tokens) are encrypted with AES-256-GCM before storage, and the database (and its backups) are encrypted at rest by our infrastructure providers.
Tenant isolation — zero-trust, row-level isolation enforced per account, so your data is never co-mingled with other tenants.
Access controls — staff access to production data is restricted to authorized personnel, access to personal data is logged, and staff accounts require strong passwords. Test and production data are kept separate.
Governance — we maintain an access control policy, a data retention policy, a data-loss-prevention strategy, and a security incident response policy.
6. Data Retention
We keep personal data only as long as needed to provide the service:
Access/refresh tokens are retained while an integration is connected and deleted when you disconnect or uninstall the app.
Order records (used for your financial history) are retained in your ProfitIQ account until you delete them or close your account.
On uninstall, Shopify sends a shop/redact request 48 hours later; we then delete the store's stored credentials and connection. Customer redaction requests are applied as described below.
7. Third-Party Connections & Sub-processors
We integrate with Shopify, WooCommerce, eBay, Amazon, Meta Developers, and ad platforms. Connecting these integrations grants ProfitIQ read-only API access to your store and marketing data. We encourage you to review each provider's privacy policy.
To operate the service we use a small set of sub-processors: our cloud hosting/edge provider (Vercel) and our managed database provider (Supabase). These providers process data solely to host and store your account and are bound by their own security and privacy commitments.
8. Data Deletion & Shopify Compliance Webhooks
You can request full data removal at any time:
Disconnect Integrations — Settings → Integrations → "Disconnect" immediately invalidates stored API tokens and halts syncing.
Submit a Deletion Request — email support@profitiq.tech from your registered address with the subject "Data Deletion Request". We verify identity and permanently delete all records, sync logs, and credentials within 48–72 hours, followed by a confirmation email.
For Shopify stores, we honor the mandatory compliance webhooks: customers/data_request (we report the data we hold), customers/redact (we scrub the stored customer name for that customer), and shop/redact (we delete the store's stored credentials and connection).
9. Contact Us
For questions about this Privacy Policy, or to exercise any data right, contact our compliance team at support@profitiq.tech.