YourTracking connects to Google Ads, Meta and Shopify to deliver server-side conversion tracking on behalf of each merchant. This page describes what each integration accesses, for what purpose, and the commitments that govern the data involved. It supplements our Privacy Policy and Terms of Service.
The company behind YourTracking is named in our Privacy Policy. For any end-customer data, YourTracking acts as a data processor on behalf of the merchant (the controller), under our Data Processing Agreement, which forms part of our Terms and applies from the moment the merchant creates an account.
Google Ads API
The Service connects to the Google Ads API for the Google Ads accounts a merchant chooses to connect, in order to:
What it does
- Conversion delivery: uploading server-side purchase conversions (offline conversions / Data Manager) with the real order value, using click identifiers captured first-party on the merchant's store.
- Setup: creating and configuring the conversion actions the Service needs on the connected account (one purchase action for delivery plus companion actions that stay Secondary, for comparison only), and switching auto-tagging on so ad clicks carry the identifiers we track with. New actions activate within hours.
- Verification: checking that the conversions we send were accepted, so measurement stays accurate.
- Reporting: reading the connected account's spend and campaign results to show them on the merchant's dashboard.
What it never does
- No connections to Google Ads accounts a merchant has not connected.
- No resale, licensing or sharing of Google Ads data.
- No use of one merchant's data for the benefit of any other merchant or advertiser.
- No building of advertising profiles of individuals.
Data obtained through the Google Ads API is used only for these conversion-delivery and measurement purposes, in compliance with the Google APIs Terms of Service and the Google Ads API policies.
Shopify API
The Service installs as a Shopify app and reads order data from the merchant's store (order identifiers, values, timestamps and status) as the source of truth that every conversion is matched and reconciled against.
To match a sale to the advertisement that produced it, the Service accesses the following Shopify Protected Customer Data fields: email, phone, name and address. These fields are used only for conversion matching and are put to the permitted Analytics and Advertising uses; they are hashed with SHA-256 before transmission to Google or Meta, except the postal code and country, which Google requires as they are. The Service also reads Shopify's own customer identifier for the buyer, the account number assigned inside that store. For delivery to Meta only, it is hashed the same way and sent alongside the hashed email so that one buyer is recognised as one person; it is never sent to Google.
What it does
- Reads orders for the connected store to detect purchases and their value.
- Uses email, phone, name and address, and for Meta the store's own customer number, only to match a purchase to the click that produced it (Analytics and Advertising).
What it never does
- Customer identifiers are hashed before they reach an ad platform, except the fields a platform requires as they are (postal code and country for Google, IP address and browser for Meta).
- No use of customer data for anything beyond conversion matching for that same store.
- No sale, rental or sharing of customer data.
Meta Conversions API (CAPI)
The Service sends completed purchases, and the page views and product views of visitors Meta can recognise, to Meta's Conversions API server-side; its own tracker in the store's browser adds add to cart, checkout started and payment info. Its server copy and its browser copy of a purchase carry the same order id, so Meta counts that sale once. Matching identifiers are hashed before transmission.
What it does
- Delivers purchases and the steps before them (page views, product views, add to cart, checkout started, payment info) to the merchant's Meta dataset, matched to the click.
- Deduplicates its server purchase against its own browser copy by order.
What it never does
- No refund, cancellation or adjustment events.
- No unhashed identifiers.
- No cross-merchant use of data.
Klaviyo (optional)
When a merchant adds a Klaviyo key, the Service reads the account's email results to show them and uses it to match sales. It never writes to Klaviyo.
Commitments
- Purchases and the steps before them. The Service sends completed purchases and the shopping steps that lead to them (such as page views, product views, add to cart and checkout); it never sends refunds or cancellations to any ad platform. On Google it may correct the value of a purchase it already sent, when a paid order grows after checkout.
- Hashed before it leaves. Customer identifiers are hashed with SHA-256 before they are sent to Google or Meta, except the fields a platform requires as they are (postal code and country for Google, IP address and browser for Meta).
- No sale of data. Nothing the Service processes is sold, rented or shared with unrelated third parties.
- Per-client isolation. One merchant's data is never used for the benefit of another merchant or advertiser, and clients' data is isolated.
- Least privilege & security. Each integration carries only the access it needs; data is encrypted in transit and at rest, secrets are stored by reference, and access is audited. See our Privacy Policy for the full security and GDPR detail.
Sub-processors
The Service is hosted on Google Cloud (EU-resident hosting, managed database and TLS edge in europe-west1, Belgium). Google, Meta, Shopify and Klaviyo receive or provide data because the merchant connects them. See our Sub-processors page.
Contact
Questions about our data practices can be sent to info@yourtracking.ai.