Legal
Privacy Policy
Effective date: [EFFECTIVE DATE, set when this page goes live]. Last updated: [DATE].
This Privacy Policy explains how Upstream, a Shopify app built and operated by Fox & Otter Data ([FULL LEGAL ENTITY NAME], a [ENTITY TYPE, e.g. Oregon limited liability company], "we," "us," or "our"), collects, uses, discloses, and protects information when a merchant installs Upstream on their Shopify store. It is written specifically for what Upstream actually does; it is not generic boilerplate, and every claim below is grounded in the app's current code.
Upstream is installed by a Shopify merchant ("you," the "merchant") onto their store. In most cases we act as a data processor / service provider on the merchant's behalf with respect to their store's order, customer, and product data, and the merchant remains the data controller for their own end customers. If you are a shopper on a merchant's store and have questions about how your data is handled, please contact that merchant directly. We do not have a direct relationship with, or independent means of contacting, a merchant's customers.
What information do we collect through Shopify's APIs?
When a merchant installs Upstream and grants the requested OAuth scopes, our syncShopifyData function pulls the following directly from Shopify's Admin API into our own database, scoped to that store:
- Orders: line items, prices, quantities, order and processed dates, and (once granted) fulfillment/shipping data used to compute true margin.
- Customers: the Shopify customer record associated with each order (name, email, and order history), used to compute per-customer lifetime gross profit, cohorts, and repurchase behavior.
- Products: product and variant details, including Shopify's own recorded unit cost (
InventoryItem.unitCost, via theread_inventoryscope) where the merchant has entered it in Shopify.
We do not request or use any Shopify scope broader than what each feature needs, and a merchant can see exactly which scopes Upstream holds from their Shopify admin at any time.
What information do we collect directly from the merchant?
- Account and billing basics: the merchant's Shopify store domain and the subscription plan they choose. Billing itself runs entirely through Shopify's own subscription-billing APIs (
AppSubscription/ usage billing). We never see or store a credit card or other payment instrument; Shopify bills the merchant directly and Upstream never has access to card data. - Cost and pricing inputs the merchant types in: store-wide default margin, category-level margins, per-product cost (typed by hand, imported via CSV/XLSX, or captured from a lot/landed-cost entry), and shipping/payment-fee assumptions used to compute true profit.
- Third-party integration credentials the merchant supplies: see "Connected integrations" below.
- Support requests: anything a merchant submits through the in-app support form (name, email, store URL, and message).
What information do we collect directly from merchants' customers?
Upstream includes an optional first-party storefront tracking pixel (a Shopify theme app embed) that a merchant can enable to improve ad-attribution accuracy. It is deliberately narrow:
Cart-attribute attribution (always on when the pixel is enabled)
The pixel writes a small set of values into the shopper's Shopify cart as first-party cart attributes, which Shopify carries through to the order:
- a randomly generated session identifier (stored in a first-party cookie on the merchant's own storefront domain);
- the shopper's first-touch landing page URL for that session;
- a Google (
gclid) or Meta (fbclid) ad click identifier, when present in the URL; and - UTM campaign parameters (
utm_source,utm_medium,utm_campaign,utm_content,utm_term), when present.
This mechanism does not collect IP address, device fingerprint, geolocation, browser/user-agent string, or any record of pages visited or products viewed, only the four values above, and only what is already visible in the shopper's own URL and cart. We use it solely to join a completed order back to the ad click or campaign that likely drove it (attribution), never to build a behavioral profile of the shopper.
Optional event stream (only if the merchant additionally installs Upstream's Shopify Web Pixel extension)
Separately, a merchant may add Upstream's Shopify Web Pixel extension, which (where enabled) reports individual storefront events (page views, add-to-cart, search, and purchase) to us in an HMAC-signed batch. Each event carries an event type, the same session identifier described above, the page URL, an order/line value and currency where applicable, a product identifier when relevant, and (only when Shopify itself already knows the shopper as a logged-in customer of that store) that customer's Shopify customer ID. This event stream still does not include IP address, precise geolocation, or browser/device fingerprinting data. Unlike the cart-attribute mechanism above, this optional stream does reflect on-site browsing activity (which pages and products a session interacted with), so we are documenting it separately and explicitly rather than folding it into the narrower claim above. A merchant who has not installed this extension does not generate this data.
Shopify's own Customer Privacy consent framework governs whether trackers may run for a given shopper in regions where consent is required; the merchant is responsible for configuring their store's consent banner and cookie settings correctly, and for their own compliance with applicable consent laws for their storefront.
How do we use the information we collect?
- To compute the merchant's true profit, gross margin, cohort lifetime value, and CAC/LTV ratios from their own order, customer, cost, and attribution data.
- To detect and surface diagnostic insights (e.g. margin-leak alerts, cohort quality grades, stockout risk) inside the merchant's Upstream dashboard.
- To generate optional, merchant-confirmed actions, such as a Shopify product price change, or (see "Connected integrations" below) pushing a lookalike-audience seed to a connected ad account. Nothing is written back to Shopify or to a connected ad or email platform without the merchant explicitly reviewing and confirming that specific action first.
- To operate, secure, and support the app itself (billing status, error diagnosis, responding to support requests).
We do not sell merchant or customer personal information, and we do not use it to serve the merchant (or anyone else) third-party advertising unrelated to the merchant's own store.
Connected integrations
Upstream can optionally connect to the following third-party services, each only once a merchant supplies their own credentials or completes that platform's own OAuth flow. A merchant who does not connect an integration does not generate any of the data flows below.
- Klaviyo: using a private API key the merchant generates and pastes in, or Klaviyo's own OAuth. We write a bundle of computed metrics back to the merchant's Klaviyo profiles (namespaced
upstream_*properties: predicted/net lifetime gross profit, CAC, LTGP:CAC, payback status, return rate, order count, AOV, repurchase probability, days-to-second-order, and a compounding/one-hit/trap/drain segment label), and read the merchant's existing Klaviyo segments to show an overlap comparison. We never write a Klaviyo property whose value we cannot verify was actually computed. - Meta Ads and Google Ads: via each platform's OAuth. We read the merchant's campaign-level ad spend for CAC/ROAS calculations, reconciled against the platform's own account-level total spend so nothing is silently undercounted. Where a merchant explicitly confirms a "push audience" action, we upload a seed list of the merchant's own customer email addresses, always SHA-256 hashed before it leaves our servers, never in plaintext, so the ad platform can build a Custom Audience / Customer Match list and an expansion (lookalike) audience from it. We do not have the ability to reverse a hash back into an email address.
- WooCommerce: a merchant running a secondary WooCommerce store can connect it with a REST consumer key and secret generated in their own WooCommerce admin, to pull orders for a unified cross-channel profit view. This is only ever the merchant's own self-hosted store; we do not access any other WooCommerce site.
We do not share merchant or customer data with any other third party for that third party's own independent purposes.
For how long do we store or retain the data we collect?
- We retain a store's synced Shopify data, computed results, and connected-integration data for as long as the app remains installed and connected.
- If a merchant disconnects their store or downgrades to the Free plan, their Shopify subscription is cancelled through Shopify's billing API and their pixel tracking token is revoked immediately; their historical data is kept so the store can pick back up if they reinstall.
- A merchant can permanently delete all of their store's synced and computed data at any time from Settings ("Delete all store data"), which is irreversible.
- If a merchant uninstalls Upstream from their Shopify admin, Shopify notifies us via its mandatory
shop/redactwebhook approximately 48 hours later, and we permanently erase that store's orders, customers, products, tracking events, and all computed results at that time. - If a shopper submits a data-erasure request to a merchant and Shopify forwards us a
customers/redactwebhook, we permanently delete that specific shopper's synced customer record, computed profile, and any tracking events tied to their Shopify customer ID.
Your rights, and Shopify's mandatory privacy webhooks
We support Shopify's three mandatory compliance webhooks for every installed store:
customers/data_request: acknowledged so the merchant can fulfil a shopper's data-access request.customers/redact: erases that shopper's data from our systems, described above.shop/redact: erases the whole store's data after uninstall, described above.
Depending on where you are located, you may have rights under the EU/UK GDPR, the California Consumer Privacy Act (as amended by the CPRA), or similar state and national privacy laws, including the right to access, correct, delete, or export your personal information, and to object to or restrict certain processing. A merchant can exercise most of these rights directly inside Upstream (Settings → Delete all store data; Klaviyo/WooCommerce/ad-platform disconnect controls). To make any other request, or if you are a shopper on a merchant's store, contact us at [SUPPORT EMAIL] and we will respond within the time required by applicable law.
Where is data processed?
[PLACEHOLDER: confirm hosting region(s) for the app's database/compute and any sub-processors, e.g. "We are based in the United States and our infrastructure is hosted in [REGION]. We are not established in the European Economic Area or United Kingdom. Data from EU/UK merchants may be transferred to and processed in the United States."] This section must be finalized against where the underlying platform (Base44) actually hosts data before this policy is published.
Security
Storefront pixel batches and Shopify webhooks are verified with HMAC signatures before we accept them. Third-party integration credentials the merchant supplies (Klaviyo API keys, WooCommerce consumer secrets, ad-platform OAuth tokens) are stored as secrets, not returned to the browser. No payment card data ever reaches our systems. Shopify handles billing directly. No system is perfectly secure, and we cannot guarantee absolute security of information transmitted to us.
Children's privacy
Upstream is a business analytics tool for Shopify merchants and is not directed at, and does not knowingly collect personal information from, children.
Changes to this policy
We may update this Privacy Policy from time to time. If we make a material change, we will update the "Last updated" date above and, where required by law, provide additional notice.
Contact
Questions about this policy or your data can be sent to [SUPPORT EMAIL], or by mail to [FULL LEGAL ENTITY NAME AND MAILING ADDRESS].
See also our Terms of Service.