Privacy policy
Last updated: 11 October 2026
Pixel Ledger ("the app") is a Shopify app published by Elektraset, s.r.o. ("we", "us"). It checks whether every order of a Shopify store produced exactly one purchase event in the store's browser pixel and in the analytics and advertising platforms that the merchant connects (Google Analytics 4, Meta, TikTok). This policy explains which data the app processes, why, and for how long.
Website of the app: https://pixel-ledger.apps.elektraset.com · Contact: help@elektraset.com
Roles
The merchant who installs the app is the controller of the data of their store and their customers. Elektraset, s.r.o. processes that data on the merchant's behalf, only to provide the app (as a processor). For the merchant's account data (shop domain, settings) we are the controller.
Data that the app processes
Store data (from Shopify, after the merchant installs the app)
- Shop domain, the access token that Shopify issues to the app, the app settings and the plan.
- For each order of the last 60 days and each new order: order ID and number, creation time, total and currency, payment gateway names, sales channel (source), checkout token, test flag, financial status, cancellation time and refunded amounts.
- Only when the merchant turns on server-side delivery: a SHA-256 hash of the customer's email address, to send it to Meta or TikTok as their APIs require. The app never stores the email address itself.
The app does not store customer names, postal addresses, phone numbers or payment card data.
Web pixel data (from the store's checkout)
The app installs a Shopify web pixel. Shopify loads it only for visitors who allow analytics in the store's consent banner. For checkout events (checkout started, payment information submitted, checkout completed) it records: the Shopify event ID, the event name, the order ID and checkout token, the time, the value and currency, the payment gateway, the visitor's consent choices (analytics, marketing, preferences, sale of data), the browser's user agent and the device type derived from it. When the visitor allows analytics it also records the Google Analytics client ID (_ga cookie); when the visitor allows marketing it records the Meta (_fbp, _fbc) and TikTok (_ttp) browser IDs. The app does not set cookies and does not store IP addresses.
Channel data that the merchant provides
Exports, acknowledgements or API results that list order IDs, event IDs, event times, counts and values of purchases in GA4, Meta or TikTok. API credentials that the merchant enters (GA4 service account key and API secret, Meta and TikTok access tokens, Slack or webhook URLs) are stored encrypted (AES-256-GCM).
Why we process it
- To build the order ledger and compare it with the pixel and channel data (coverage, duplicates, latency, consent conflicts).
- To send purchases server-side to GA4, Meta or TikTok, only when the merchant turns this on and only when the visitor's recorded consent allows it.
- To send the alerts and reports that the merchant configures.
- To bill the subscription through Shopify and to give support.
The legal basis is the performance of our contract with the merchant and, for the merchant's customers, the merchant's instructions; consent-dependent data is collected only with the consent that the store's banner records through Shopify's Customer Privacy API.
Sharing
We do not sell data and do not use it for our own advertising. Data goes to:
- Shopify, which hosts the store and handles billing.
- Google, Meta and TikTok, only when the merchant connects them, and only the purchase data described above.
- Slack or the webhook target that the merchant sets for alerts (aggregate numbers, no customer data).
- Our hosting provider, which runs the app servers for us.
Retention and deletion
- Orders, pixel events and channel evidence are deleted automatically 90 days after the order or event.
- When the merchant uninstalls the app, collection stops at once; Shopify then sends a
shop/redactrequest (48 hours after uninstall) and we delete all data of the store. - For a
customers/redactrequest we delete the email hash, the browser IDs and the user agent of that customer's orders, and earlier data request exports of that customer. For acustomers/data_requestwe collect the data we hold for the listed orders and show it to the merchant on the app's "Data requests" page, so the merchant can send it to the customer.
Security
Connections use HTTPS. Credentials are encrypted at rest. Access to the servers is limited to Elektraset staff who run the app.
Your rights
Customers of a store should contact the store first; the merchant can ask us to access, correct or delete data. Merchants can write to help@elektraset.com. You may also complain to your data protection authority.
Changes
We will post changes on this page and update the date above.