Privacy policy
Veltoza builds Shopify applications that measure advertising performance and deliver product data to advertising platforms. This policy describes what those applications collect and where it goes. It is written to be specific rather than general.
Who we are
Veltoza is a trading name of AFA ECOMMERCE LIMITED. For any privacy question, including access and deletion requests, contact privacy@veltoza.com.
What the storefront pixel collects
Shopify's official Web Pixel runs on the merchant's storefront in Shopify's sandbox. For each of five standard events — page viewed, product viewed, added to cart, checkout started and checkout completed — it sends:
| Field | Example | Why |
|---|---|---|
| Shopify event ID | a UUID | Deduplicating the browser and server copies of one event |
| Shopify client ID | an opaque ID | Joining events from one browsing session |
| Page URL and path | /products/example | Attribution and reporting |
| Product and variant identifiers | SKU, variant ID | Which item was viewed or bought |
| Amount and currency | 19.99 GBP | Conversion value |
| Campaign parameters | utm_source, gclid | Which ad produced the visit |
What we never store
Veltoza stores no customer names, email addresses, postal addresses, phone numbers, payment details or Shopify customer IDs. None of these is ever written to our database.
Customer matching for ad measurement
One narrow exception exists, and only in the tracking application. On a completed purchase, and only where the shopper's marketing consent is granted, the customer's email, phone, name and address are used to match that purchase to the advertisement that produced it — Google Ads calls this enhanced conversions, Meta calls it customer matching.
These values are irreversibly hashed with SHA-256 before they are sent, and they are never written to storage. For Google Ads the hashing happens inside Google's own tag in the shopper's browser, so the plaintext never reaches us at all. For Meta and GA4 the values are hashed in memory on our server at the moment of sending and discarded immediately afterwards. Nothing about a shopper who declines marketing consent is used this way, and a merchant who does not connect an advertising platform triggers none of it.
Where the data goes
Events are sent to the advertising destination the merchant connected. The merchant chooses the destination; we add none. Product feed files are delivered only to the feed connection the merchant created in their own advertising account.
Merchant credentials
API keys, conversion keys and feed passwords a merchant provides are encrypted at rest with AES-256-GCM and decrypted only in memory at the moment they are used. They are never sent to a storefront, written to logs, or exposed in any browser.
Retention
Event records are operational receipts — they exist to prove a conversion was delivered and to retry failures — not a customer profile. When a merchant uninstalls, all of their data — settings, credentials and receipts — is deleted immediately and in full. Shopify's later redaction webhooks are honoured as well, and find nothing left to delete.
Your rights
Because Veltoza stores no personal identifiers, we normally cannot link data to an individual. Where a merchant supplies an order reference through Shopify's customer data request or redaction webhooks, we respond to that request and delete the corresponding records.
Sub-processors
Cloudflare (application hosting and content delivery) and our managed PostgreSQL provider. Advertising destinations are chosen by the merchant and act as independent controllers of the data they receive.
Changes
Material changes will be announced to installed merchants before taking effect.