Legal

Privacy Policy

Last updated: 5 October 2026

This Privacy Policy describes how YourTracking ("we", "us") handles data in connection with our server-side conversion tracking service for Shopify merchants, available at yourtracking.ai (the "Service"), and this public website.

1. Who we are

The Service is operated by Lodestar Ecommerce LLC, 5830 E 2ND ST, STE 7000 #34998, Casper, WY 82609, United States. For any privacy-related question or request, contact us at info@yourtracking.ai.

2. Our two roles

It matters which data we are talking about, because our role differs:

  • Our merchant clients' data (we are the controller). For the account, contact and billing data of the businesses that use YourTracking, and for visitors to this website, we decide the purposes and means of processing. This Policy governs that data.
  • End-customer (shopper) data (we are a processor). For the personal data of a merchant's own shoppers that flows through the Service, the merchant is the controller and we act as their data processor, processing it only on the merchant's documented instructions to match and deliver conversions. That relationship is governed by our Data Processing Agreement, which forms part of our Terms and which the merchant accepts when creating an account; the disclosure to shoppers is made by the merchant in their own privacy policy.

3. Data we process on this public website

  • No advertising trackers. This public website uses no advertising cookies and no third-party analytics. We count visits with our own measurement. It sets no cookie, keeps a visit number in your browser tab until you close it, and uses a code made from your IP address and browser that changes every day, so we can count visitors without recognising anyone from one day to the next.
  • The checkout tracker on a merchant's store. The YourTracking app installs a web pixel on the merchant's store that sends us technical identifiers of the order and the visit, with the visitor's consent state; it sends no name, email address or phone number. The merchant is the controller for that data and we process it on their documented instructions.
  • Authentication cookie. When a client signs in, a single encrypted session cookie is set to keep them signed in. It is strictly necessary for the Service and is not used for tracking.
  • Server logs. Our servers keep standard, short-lived technical logs (IP address, request path, timestamp) for security and abuse prevention.
  • Enquiries. If you email us, we process the contact details and content you provide in order to respond.

4. Client account data we process (as controller)

To provide the Service and administer any separately-agreed managed-service plan, we process the name, email, company and billing details of our merchant clients, together with account and usage data. We use this to operate the Service, provide support, and communicate about the Service.

5. End-customer data we process (as processor)

On behalf of each merchant, and only on their instructions, the Service processes end-customer personal data solely to match a sale, and the shopping steps before it, to the advertisement that produced them and deliver them to the merchant's advertising platforms:

  • Identifiers used for matching: email, phone, name and address. These are hashed with SHA-256 before they are sent to Google or Meta, except where a platform requires a field as it is: the postal code and country for Google. For delivery to Meta only, the merchant's own customer number for that shopper, the account identifier Shopify assigns inside that store, is hashed the same way and sent alongside the hashed email so that one buyer is recognised as one person. It is never sent to Google.
  • Advertising click identifiers, such as gclid, gbraid, wbraid and fbclid, captured first-party on the merchant's store and associated with the resulting order.
  • Order details: order identifier, value and timestamp, used to send the conversion with its true value.
  • Device and connection signals: for delivery to Meta only, the visitor's IP address and browser user-agent are transmitted to Meta in the form it requires (not hashed), used solely to match the event.

Purchases and the steps before them. The Service sends completed purchases and the shopping steps that lead to them, such as page views, product views, add to cart and checkout. It never sends refunds or cancellations to the advertising platforms. It may update a purchase it already sent, for example when a paid order grows after checkout.

6. Legal bases

Where the GDPR or UK GDPR applies:

  • Client and website data: we rely on performance of a contract, our legitimate interest in operating and securing the Service, and compliance with legal obligations such as accounting and tax.
  • End-customer data: the lawful basis and, where required, valid consent is the responsibility of the merchant (controller), and so is the cookie setting the merchant chooses in the Service. We process this data only on the merchant's documented instructions and follow that setting.

7. Sub-processors and sharing

We do not sell personal data. We share it with the providers that host and run the Service for us, under data-protection terms that restrict them to our instructions: Google Cloud (EU-resident hosting, managed database, secret storage, and the load balancer and TLS edge, europe-west1) and Resend (sending our emails to clients). Shopper data also goes to the platforms a merchant connects, on the merchant's instruction and under the merchant's own agreement with them: Google (Google Ads), Meta (Conversions API), Shopify (the store, from which order and customer data is read) and, when the merchant connects it, Klaviyo. The current list is on our Sub-processors page.

8. International transfers

Service infrastructure is hosted in the European Union (Google Cloud, europe-west1, Belgium). The company that runs the Service is based in the United States. Where personal data leaves the EEA or the UK, through our own access to it or through a delivery a merchant instructs to Google or Meta, the transfer relies on the EU Standard Contractual Clauses (with the UK Addendum), which form part of our Data Processing Agreement, or on the EU-US Data Privacy Framework where the recipient is certified under it.

9. Retention

Client account and billing data is retained for the duration of the relationship and any statutory retention period (including accounting requirements). End-customer data processed on a merchant's behalf is retained only as long as needed to deliver the Service and is deleted on offboarding in line with the DPA. Technical server logs are kept for a short rolling window.

10. Security

We apply appropriate technical and organisational measures to protect the data we process, including:

  • encryption in transit (TLS) and at rest, with encrypted backups;
  • SHA-256 hashing of identifiers before any transmission to advertising platforms;
  • per-client isolation of data;
  • secrets stored by reference in a managed secret store, never in the application database;
  • an append-only access audit log and least-privilege access;
  • a security incident-response policy, including notifying the affected merchant without undue delay of a personal-data breach.

11. Your rights

Data subjects in the EU/EEA and UK have the right to request access to, correction of, or deletion of personal data, to restrict or object to processing, to data portability, and to lodge a complaint with a supervisory authority. Because we act as a processor for end-customer data, shoppers should exercise these rights through the merchant whose store they purchased from; we assist the merchant in responding. Clients and website visitors can contact us directly at info@yourtracking.ai.

12. Children

The Service is provided to businesses and is not directed at children. We do not knowingly process children's personal data.

13. Changes

We may update this Policy from time to time. The "Last updated" date above reflects the latest revision; material changes will be reflected on this page.