Effective August 21, 2026 · Version 1.0
AdsBro privacy
AdsBro helps Shopify merchants audit structured product data, generate advertising feeds, and measure consent-eligible commerce events. This notice describes the information AdsBro processes for those services and incorporates BroFam’s shared privacy notice by reference.
Information processed
AdsBro processes the merchant’s shop domain, durable installation identity, approved Shopify access scopes, configuration, and operational status. Product services process catalog information such as product and variant identifiers, titles, descriptions, URLs, images, prices, currency, inventory, availability, brand, SKU, GTIN, MPN, shipping, and return-policy settings.
Conversion measurement processes pseudonymous event identifiers, event type and time, consent state, hashed Shopify product, variant, and order identifiers, SKU when present, and minimized value and currency. The current browser-event envelope does not request or retain customer email, phone number, postal address, payment information, or unrestricted page URLs. Advertising-provider access tokens and account selections are processed only when a merchant connects a provider.
How information is used
Information is used to authenticate and isolate the merchant; audit and optionally publish structured product data; generate, host, validate, and deliver feeds; deduplicate and diagnose events; deliver conversions when the merchant enables an officially supported capability; secure and support AdsBro; and meet Shopify or legal obligations. AdsBro does not sell personal information, overwrite Shopify source product data, or use one merchant’s data for another merchant.
Consent and provider boundaries
The Shopify Web Pixel receives Shopify customer events according to the merchant’s privacy configuration and Shopify’s consent behavior. AdsBro rejects conversion attribution or delivery when the implemented consent requirements are not met. Amazon Web Services hosts AdsBro’s encrypted application infrastructure in the United States. Shopify supplies authorized store data. Google, Microsoft, or OpenAI receives data only when the merchant configures the applicable destination and the capability is available. Provider accounts, approvals, retention, and independent processing are governed by that provider. See BroFam’s subprocessor notice.
Retention, disconnect, and deletion
Raw browser-event records expire after 30 days. Replay-protection receipts contain no webhook body or customer data and expire after seven days. Unused OAuth state contains no provider token and expires after ten minutes. Feed artifacts and operational projections are retained only while needed to provide and diagnose the service.
Disconnecting a destination removes AdsBro’s stored authorization and account binding for that destination. A verified uninstall immediately disables the installation, removes Shopify and connector credentials, and queues tenant-scoped deletion of AdsBro products, settings, events, diagnostics, conversion receipts, feeds, and provider selections. AdsBro retains a non-secret installation tombstone to preserve durable installation identity and prevent authorization confusion on reinstall. Shopify’s shop-redaction webhook deletes remaining tenant records, including that tombstone and replay receipts.
Merchant choices and privacy requests
Merchants can disable AdsBro’s theme app embed, disconnect destinations, or uninstall through Shopify. Shopify’s mandatory privacy webhooks support customer data requests, customer redaction, and shop redaction. Because the current event envelope stores no customer identity or contact fields, a customer request ordinarily produces no customer-linked AdsBro record.
Privacy requests: contact form. Do not email tokens, hosted-feed URLs, passwords, or customer information. Material changes receive a new version and effective date.
Change history
Version 1.0 — initial AdsBro notice prepared August 21, 2026.