Privacy policy

Privacy policy

This policy explains what data ECOM HOUSE Full Funnel Audit ("we", "us") accesses, why, and how long we keep it. Last updated 15 June 2026.

What we access

Shopify: with your explicit OAuth consent, we read your products, orders (up to the last 365 days), and customers. Read-only — we never write to your store. Permissions: read_products, read_orders, read_all_orders, read_customers.

Meta (Facebook): with your explicit OAuth consent, we read your Business Managers, ad accounts, Facebook pages, ad-level campaign metrics, and post-level engagement (likes, comments, shares) for the pages you select. Read-only — we never post, advertise, or modify content on your behalf. Permissions: ads_read, business_management, pages_show_list, pages_read_engagement.

Google Ads: with your explicit OAuth consent, we read your Google Ads campaigns, ad groups, ads, performance metrics (up to the last 24 months), keyword performance and quality scores, search terms, network breakdown (Search, Display, YouTube, Shopping, Performance Max), device breakdown, and conversion-action configuration. Read-only via the official Google Ads API — we never create, modify, pause, delete, or otherwise change campaigns, budgets, bids, ads, or any other entity in your account. Permission: https://www.googleapis.com/auth/adwords.

You: the email address you enter to receive your audit report, an optional mobile number for SMS verification (via Twilio, to prevent abuse), and the business context you provide (revenue band, vertical, growth goals, primary concern).

Why we access it

To generate a one-time AI-powered audit of your e-commerce performance. We correlate your Shopify revenue + product data with your Meta and Google Ads spend, creative performance, keyword behavior, and page engagement to identify funnel issues and recommend prioritized actions.

Google Ads data is used solely to generate the audit report you requested. We do not use Google user data to serve advertising, do not transfer Google user data for advertising purposes, do not use it to determine creditworthiness or for lending purposes, and do not sell it.

ECOM HOUSE's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How long we keep it

Audit records (your selections + the generated report) are stored for 90 days so you can revisit your report URL. Shopify, Meta, and Google access tokens are stored encrypted at rest until you revoke access via the respective platform settings, or until you request deletion (see below).

We never sell, share, or transfer your data to third parties for advertising or marketing purposes. The only third parties that touch your data are subprocessors operating on our instructions:

  • Anthropic Claude API — generates the narrative analysis sections of your audit. We send only aggregated inputs (totals, percentages, top-SKU shares, top-campaign rollups); no raw customer PII, email addresses, or order line-items. Anthropic does not use this data to train models.
  • OpenAI Whisper API — optionally transcribes your top-performing video ad URLs so the audit can analyze script and copy patterns. Only the publicly-hosted video URL is sent; no account credentials.
  • Twilio — SMS phone-number verification to prevent abuse.
  • Vercel + Vercel KV — secure application hosting and short-lived session storage. Data encrypted in transit (TLS) and at rest.

How to delete your data

Meta: remove "ECOM HOUSE Audit Tool" from Facebook → Settings → Apps and Websites. Meta will notify us, and we will purge your Meta token, page tokens, ad-account selection, and cached snapshots within 30 days. You can check the deletion status at /data-deletion-status.

Shopify: uninstall the app from your Shopify Admin → Apps. Shopify will fire our shop/redact and customers/redact webhooks and we will purge associated data within 30 days.

Google: go to myaccount.google.com/permissions, find "ECOM HOUSE Full Funnel Audit", and click Remove access. We then purge your Google access token, refresh token, selected customer ID, and any cached Google Ads snapshots within 30 days.

Manual request: email team@ecomhouse.com with the email address you used to receive your audit. We respond within 7 business days.

Data security

We implement industry-standard security measures: TLS 1.2+ for all data in transit, encryption at rest for stored OAuth tokens and audit records, OAuth 2.0 for all platform authentication (we never see your passwords), short-lived (10-minute) OAuth state tokens to prevent CSRF, and access controls limiting data access to the audit processing system.

Your GDPR rights

As a data subject under the EU General Data Protection Regulation, you have the right to access, rectify, erase, restrict, port, and object to the processing of your data, and to withdraw consent at any time. To exercise any of these rights, email team@ecomhouse.com. We respond within 30 days. You also have the right to lodge a complaint with a supervisory authority.

International data transfers

The Service operates from EU and US infrastructure (Vercel). Where data flows from the EU to the US (Anthropic, OpenAI, Twilio, Vercel), we rely on the EU-US Data Privacy Framework and Standard Contractual Clauses where applicable.

Cookies

The Service uses only essential cookies required for authentication and session management. We do not use advertising or third-party tracking cookies.

Children's privacy

The Service is intended for business operators and not directed at individuals under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, contact us and we will delete it.

Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated revision date. Continued use of the Service after changes constitutes acceptance.

Data Controller

ECOM HOUSE GmbH, registered in Germany. Contact: team@ecomhouse.com.

Terms of service

For the terms under which this service is provided, see /terms.