Privacy policy

DayTech Ad Audiences is operated by Day Marketing. This notice describes customer and shop data the app processes when a merchant installs it on Shopify.

What we process

Shop domain, Shopify offline session tokens, Google OAuth tokens, selected Google Ads account IDs, segment names, and sync metadata live in our Cloudflare D1 database. When a merchant enables a segment, we read customer name, email, phone, country, and postcode from Shopify so we can hash those identifiers and send them to Google's Data Manager API for Customer Match.

If a member cannot be uploaded, we may keep the customer's display name, email, and phone in an upload-failure row so the merchant can see why the row was skipped.

Why we process it

The only purpose is to keep the merchant's chosen Shopify segments mirrored as Google Ads Customer Match audiences. We do not sell customer data or use it for our own advertising.

Consent

Merchants must attest that every enabled segment contains only customers who consented to ad-user-data and ad-personalization use, and that sharing those identifiers with Google is lawful. The app does not read per-customer consent flags from Shopify. If a customer opts out, the merchant must remove them from the enabled segment or disable the segment.

Who we share data with

Hashed customer identifiers go to Google, in the merchant's Google Ads account, after the merchant connects Google and attests policy. Shopify receives webhook acknowledgements only. We do not send customer records to any other processor for this product.

Retention

Shopify session tokens are deleted on uninstall. Shop rows, Google connections, segment metadata, upload failures, and pending data exports stay until Shopify sends shop/redact, or until the merchant disconnects Google and we delete that connection. A customers/redact webhook deletes that customer's failure rows and data-request exports, then rebuilds enabled audiences from current Shopify membership.

Customer Match lists stay in the merchant's Google Ads account after uninstall. We do not delete those lists on shop/redact. The merchant can remove them in Google Ads.

Access, export, and deletion

When Shopify sends customers/data_request, we collect matching upload-failure rows and show them to the merchant in Settings. Email support@day.technology for other access or deletion requests.

Security

Traffic uses HTTPS. Google refresh tokens are encrypted at rest in D1. Production data is not used in local development databases.

Questions: support@day.technology.