Privacy Policy

Last updated: August 11, 2026

This page is maintained by Ozeefy (“we”, “us”, “our”) to explain how Smart Analytics (the “Service”) collects, stores, uses, and protects information. Smart Analytics is an analytics workspace used to produce daily performance reports from connected advertising and commerce platforms.

1. Who this policy applies to

This policy applies to authorized users of Smart Analytics workspaces and to the platform data clients authorize us to access on their behalf (as data processor for merchant customer and order analytics).

2. Information we collect

  • Account information. Name, work email, and role, used to authenticate you and control access.
  • Connected platform data. When a client connects an account (Google Ads, Meta Ads, Snapchat Ads, TikTok Ads, Shopify), we retrieve read-only reporting data such as campaigns, ad spend, impressions, clicks, conversions, revenue, orders, products, and inventory.
  • Shopify Analytics (ShopifyQL). To show merchants Overview KPIs that match Shopify Admin Analytics (sessions, net sales, product and country sales), we call Shopify’s shopifyqlQuery API. Shopify requires Level 2 protected customer data access (name, address, email, and phone fields) for that API. Smart Analytics uses this access only to retrieve aggregated analytics metrics. We do not display raw customer name, email, phone, or street address in the product UI, and we do not store those fields in our analytics database.
  • Shopify order lines. For Local vs International and product/collection reporting we store commercial line fields (product, quantities, revenue) and shipping country code only—not full addresses or contact details.
  • OAuth tokens. Access and refresh tokens issued by each platform, stored as secrets in our managed database (HTTPS in transit; provider disk encryption and database access controls at rest). Tokens are used only to fetch the reporting data the connection was authorized for.
  • Shopify compliance audit metadata. When Shopify sends mandatory privacy webhooks, we log shop domain, topic, Shopify customer/order IDs (when provided), and a processing summary—without persisting customer email, phone, or name from the webhook.

3. How we use information

We use this information only to operate dashboards, generate and deliver reports, enforce access control, improve reliability, and provide support—matching the purposes disclosed to merchants when they connect Shopify and other platforms. We do not sell personal information. We do not use Shopify protected customer data for CRM, email marketing, advertising to end-customers, or unrelated profiling.

4. Consent, messaging, and automated decisions

Smart Analytics does not send messages, ads, or marketing to a merchant’s customers using Shopify data. Connecting the app (and granting scopes) is the merchant authorization for reporting access; uninstalling or disconnecting stops further access. We do not provide a separate end-customer consent UI because we do not message or market to those customers. We do not make automated decisions that produce legal or similarly significant effects on individual customers.

5. Sharing

We do not sell personal information. We share data with infrastructure sub-processors that host and operate the Service, and with authorities where required by law. Merchants remain controllers of their store customer data; we process Shopify data on their instructions.

6. Retention

Workspace and reporting data is retained while an account is active. Disconnecting Shopify from Integrations or the embedded App Home stops further sync and clears OAuth tokens. Historical Shopify reporting rows (order lines, collections, Shopify daily metrics) are automatically purged 90 days after disconnect. Uninstall triggers immediate token clear (app/uninstalled); Shopify shop/redact deletes shop-linked data within required timelines. We honor customers/data_request, customers/redact, and shop/redact — data requests export commercial order-line fields to the store owner (workspace email) when available.

7. Security

See our Security page. Traffic is served over HTTPS. OAuth tokens are treated as secrets under database access controls. Access to production systems is limited to authorized Ozeefy staff.

8. Related documents

9. Contact

Privacy requests: privacy@ozeefy.com. Security reports: security@ozeefy.com.