Privacy Policy
Effective date: July 2, 2026
Spagify ("we," "our," or "us") operates Spagify Platform (the "Service"), a software-as-a-service product that helps Shopify merchants create, manage, and optimize Single Product Ad Groups for Google Standard Shopping campaigns. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Service.
By accessing or using Spagify Platform you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of the Service.
1. Information We Collect
a. Account Information
When you register, we collect your name, email address, and (if signing in with Google) your Google account identifier. For password-based accounts we store a one-way bcrypt hash of your password; we never store your plain-text password.
b. Payment Information
Billing is handled by Stripe, Inc. We never store full credit card numbers on our servers. Stripe shares limited billing details (last-four digits, card brand, expiry, billing name) that we display in your account settings.
c. Connected Service Data
Shopify: product catalog, inventory levels, pricing, SKUs, and order data accessed via the Shopify Partner API under your explicit authorization.
Google Ads: campaign performance metrics (spend, revenue, impressions, clicks, conversions, ROAS), keyword data, ad group structures, and audience lists accessed via the Google Ads API under your explicit OAuth grant.
Google Merchant Center: product feed status accessed via the Content API.
This data is used solely to provide the Service. We do not sell or rent it to third parties.
d. Usage and Log Data
We automatically collect log data including IP addresses, browser type, pages visited, and timestamps for security monitoring and debugging purposes. This data is retained for a maximum of 90 days.
e. Cookies and Similar Technologies
We use session cookies necessary to authenticate your session (via NextAuth / Auth.js). We do not use third-party advertising cookies. You may disable cookies in your browser, but the Service will not function without session cookies.
2. Google API and Google Ads Data
Spagify Platformrelies on the Google APIs to operate. When you connect a Google account or a Google Ads account, we access and process the data described below. This section is provided in addition to the disclosures elsewhere in this policy and is intended to satisfy Google's OAuth and Limited Use requirements.
a. Data Accessed from Google
Google account name and email address (used for authentication and to identify the connecting user).
Google Ads customer and account identifiers (manager and child accounts you choose to connect).
Campaigns, ad groups, product groups, and ad assets in connected Google Ads accounts.
Search terms and negative keyword lists associated with connected accounts.
Advertising performance metrics (impressions, clicks, conversions, cost, revenue, ROAS).
Budgets, bids, bid strategies, and impression-share data.
OAuth access and refresh tokens issued by Google during the consent flow.
Spagify Platform does not request access to Gmail, Google Drive, Google Calendar, Google Contacts, Google Photos, or any other Google product outside of Google Ads, Google Merchant Center, and basic Google account profile information.
b. How Google Data is Used
Synchronizing your Google Ads account state with Spagify Platform.
Creating and managing campaigns, ad groups, and product groups at your direction.
Generating product-level reporting, dashboards, and alerts.
Reviewing search terms and pushing negative keywords you authorize.
Applying budget, bid, and bidding-strategy changes that you configure.
Running user-defined rules, alerts, and automations against the Google Ads API.
c. Sharing of Google Data
We do not sell Google user data.
We do not use Google user data for serving or targeting advertising on behalf of Spagify.
We do not transfer Google user data to data brokers, information resellers, or advertising platforms other than the Google Ads account from which it originated.
Google user data may be processed by contracted infrastructure and operational sub-processors (for example, AWS for hosting, monitoring, and database services). These providers are permitted to use the data only to provide services to Spagify.
d. AI Processing of Google Data
Spagify Platform includes AI-assisted features (for example, search-term classification and keyword-intent suggestions). When these features are used, limited Google Ads data — such as search terms, product titles, and aggregated performance signals — may be sent to a third-party AI provider strictly to generate the requested output for your account.
AI processing is only used to power user-requested features inside the Service.
Google user data is not used to train, fine-tune, or otherwise improve generalized or public AI models, whether operated by Spagify or by our AI providers.
AI providers are contractually bound to process the data solely to provide their services to Spagify and to retain it only as long as necessary to do so.
e. Security of Google Data
All Google API traffic is encrypted in transit using TLS 1.2 or higher.
OAuth refresh tokens and other credentials are encrypted at rest and stored in a managed secrets store with restricted access.
Access to Google user data inside Spagify is limited to the smallest set of employees and service accounts that need it to operate the Service.
Authentication, authorization, and administrative actions are audit-logged for security review.
Sub-processors with access to Google user data are reviewed for security posture and bound by written data-processing agreements.
f. Retention and Deletion of Google Data
OAuth tokens are retained while the connection is active and are deleted when you disconnect the Google Ads account or delete your Spagify account.
Operational Google Ads data (campaign structures, metrics history, search-term snapshots) is retained for up to 24 months to power historical reporting, then deleted.
When you disconnect a Google Ads account, we stop calling the Google Ads API for that account and purge associated tokens within 7 days.
When you delete your Spagify account, all Google user data associated with the account is purged within 30 days, subject to limited retention required for legal, tax, or audit purposes.
g. Google API Services User Data Policy — Limited Use
Spagify Platform's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3. Shopify API Data
Spagify Platformconnects to your Shopify store via the Shopify Partner API under your explicit authorization. This section describes what Shopify data we access, how we use it, and your rights regarding that data — including rights arising under Shopify's mandatory GDPR compliance requirements.
a. Data Accessed from Shopify
Product catalog: titles, descriptions, images, handles, vendor, product type, and status.
Product variant data: SKUs, prices, compare-at prices, inventory quantities, and selected options.
Inventory levels: stock availability per location.
Order data: order IDs, order numbers, total price, currency, and line items (variant IDs, quantities, prices). We capture the Shopify numeric customer ID only — we do not store customer names, email addresses, physical addresses, or phone numbers.
Shop owner email address (used once during installation to create your Spagify account; not retained as a separate record).
Shopify OAuth access token (encrypted at rest; used to call the Shopify API on your behalf).
b. How Shopify Data Is Used
Populating your Spagify Platform product catalog for campaign building and automation.
Keeping inventory and pricing information current so Shopping ads reflect accurate product data.
Attributing Google Ads conversions to orders using the GCLID captured at purchase time.
Shopify data is never used to target advertising for Spagify's own marketing, sold to third parties, or used to train generalized AI models.
c. GDPR Compliance Webhooks
Shopify requires all apps to respond to three mandatory GDPR webhooks. Here is how Spagify handles each:
customers/data_request: When a customer of your shop requests their data, Shopify notifies us. We compile the order-level records (order IDs, amounts, conversion signals) associated with their Shopify customer ID and email a summary to the shop owner so you can fulfill the request within Shopify's 30-day SLA.
customers/redact: When a customer redaction request is confirmed, we permanently delete all order records and associated offline-conversion data linked to that Shopify customer ID within 48 hours of receiving the webhook.
shop/redact: Fired 48 hours after uninstall. We permanently delete all shop-specific data: integration connection (including the encrypted access token), all synced products, all order records, and all offline conversions associated with the store. Your Spagify workspace and Google Ads data are not affected.
d. Token Encryption
Shopify OAuth access tokens are encrypted before storage using AES-256-GCM envelope encryption. In production, encryption keys are managed by AWS Key Management Service (KMS) with automatic annual key rotation. Tokens are decrypted only in memory at the moment an API call is made and are never written to logs.
e. Retention and Deletion of Shopify Data
Access tokens are deleted when you disconnect the integration or when Shopify sends the shop/redact webhook.
Product catalog data is deleted as part of the shop/redact flow (48 hours after uninstall).
Order and conversion data is deleted on shop/redact or immediately on customers/redact for individual customer requests.
Deleting your Spagify account purges all remaining Shopify-sourced data within 30 days.
4. How We Use Your Information
To create and manage your account and workspace.
To provide, operate, and improve the Service, including automating campaign management on your behalf.
To process payments and send billing-related communications.
To send transactional emails (account confirmations, password resets, team invitations, critical service alerts). You may not opt out of transactional emails while your account is active.
To detect, prevent, and respond to fraud, abuse, and security incidents.
To comply with legal obligations.
With your consent, to send product updates or marketing communications. You may opt out at any time.
We do not use your Google Ads or Shopify data to train machine-learning models for any purpose other than providing the Service to you.
5. Sharing and Disclosure
We do not sell your personal information. We share data only in the following limited circumstances:
Service Providers: Sub-processors who help us deliver the Service (Stripe for payments, AWS / cloud infrastructure, email delivery providers, AI inference providers). Each is bound by a data processing agreement.
Google LLC: We transmit data to and from Google APIs strictly to execute the automation actions you configure.
Shopify Inc.: We read and write data through the Shopify API strictly to sync product data as authorized by you.
Legal Compliance: We may disclose information when required by law, subpoena, or governmental authority, or to protect the rights, property, or safety of Spagify, our users, or the public.
Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you via email and/or prominent notice on the Service before your data becomes subject to a different privacy policy.
6. Data Retention
We retain your account data for as long as your account is active or as needed to provide the Service. Upon account deletion, we purge personal data within 30 days, except where retention is required for legal, tax, or audit purposes (up to 7 years for billing records).
Google Ads and Shopify operational data (metrics history, campaign logs) is retained for up to 24 months to power historical reporting features, then deleted.
7. Data Security
We implement industry-standard security measures including:
Encryption in transit via TLS 1.2+.
Encryption at rest for database volumes.
OAuth 2.0 authorization-code flow for all third-party integrations; OAuth tokens are encrypted at rest.
Role-based access controls within workspaces.
Audit logging for authentication and administrative actions.
Regular dependency updates and vulnerability scanning.
No method of transmission or storage is 100% secure. In the event of a data breach that poses a risk to your rights or freedoms, we will notify affected users and relevant authorities within 72 hours as required by applicable law.
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
Access: Request a copy of the personal data we hold about you.
Rectification: Request correction of inaccurate data.
Erasure: Request deletion of your personal data (subject to legal retention obligations).
Portability: Receive your data in a structured, machine-readable format.
Objection / Restriction: Object to or restrict certain processing activities.
Withdraw Consent: Where processing is based on consent, withdraw it at any time.
CCPA (California residents): You have the right to know, delete, and opt out of the sale of personal information. We do not sell personal information.
To exercise any of these rights, contact us at legal@spagify.com. We will respond within 30 days. If you are in the EEA/UK and believe we have violated your data rights, you have the right to lodge a complaint with your local supervisory authority.
9. International Transfers
Spagify is operated from the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate. By using the Service, you consent to this transfer. Where required, we rely on Standard Contractual Clauses or equivalent mechanisms for cross-border transfers.
10. Children's Privacy
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that a child under 16 has provided us with personal data, we will delete such information promptly.
11. Third-Party Links
The Service may contain links to third-party websites (e.g., Google, Shopify). We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the effective date, and by emailing you if the changes are significant. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.
13. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
Spagify
Email: legal@spagify.com