Privacy Policy
Version 2.7, effective October 7, 2026. Prior versions will be archived and available on request.
The short version (plain English). HonestTag measures whether ads actually turned into sales. We are built for honest measurement, so we try to be honest about data too.
This policy has three parts. Part A covers this website, honesttag.com. Part B covers the HonestTag app that merchants install in their Shopify admin, its storefront pixel, and the service behind it. Part C covers what applies to both: who we are, your rights, our service providers and how to reach us.
On honesttag.com (Part A)
- This website runs Google Analytics, Google Ads and Meta tags to measure visits and our own ads, and Cloudflare's cookieless Web Analytics; section A3 explains them, section A4 lists their cookies, and section A5 explains how to turn the tags off. In the European Economic Area, the UK and Switzerland they set no cookies until you click Accept.
- Our forms keep what you send us, to answer you. Section A2 lists exactly what each form keeps, including the IP address the support form keeps.
In the Shopify app (Part B)
- We keep almost nothing, briefly. Most of what we store is a random visitor ID and an ad click ID, with automatic expiry timers measured in days to months.
- We keep raw emails and phone numbers out of attribution keys and delivery queues. Email addresses and phone numbers sent to ad platforms are hashed in memory. One exception: on Truth+ and higher plans, a store that connects its own Klaviyo account has the order's email address sent to that account once, unhashed, so Klaviyo can find the shopper's existing profile. Some fields go as recorded because the platform matches on them as given, including advertising click IDs such as TikTok's ttclid, and an order's browser IP address and user agent, which Meta, TikTok, OpenAI Ads, Pinterest, Snapchat and Reddit receive. Meta also receives our random visitor ID as recorded. Shopify webhook payloads can contain raw contact data and are held briefly in our access-controlled processing inbox. Section B3 explains exactly how.
- We never sell or share merchant or shopper data. The data the app handles for a store goes only to the destinations that store connects, and to an agency or AI tool that store approves, on its instruction. The website's Google, Meta and Cloudflare tags never run inside the app or on a merchant's storefront (section B1).
- No data brokers, no enrichment, no hidden match graphs. Our measurement is first-party only.
- Your data works only for you. Customer data is used solely to provide and improve HonestTag for your store. We never sell it, never build cross-store advertising profiles from it, and never hand it to third parties to train their models.
- If you bought something from a store using HonestTag, we handle your data for that store, not for ourselves. Your privacy requests go to the store you bought from (see section B3).
- We honor the consent and opt-out signals your store reports, and Global Privacy Control (GPC) at our server endpoints. An explicit refusal blocks tracking. Section B4 explains exactly how consent handling works today.
- If you connect Google Ads, our use of data received from Google's APIs follows Google's Limited Use requirements. Section B9 states exactly what we access and why.
This box is a summary. The numbered sections below are the operative terms.
How this policy is organized
HonestTag has two separate things that handle personal data, and this policy keeps them apart. The website honesttag.com is where people read about HonestTag, join the waitlist, ask for support or apply to be a partner; we run it for ourselves and we are the controller of what it collects (Part A). The HonestTag app is what a Shopify merchant installs: the screens in the merchant's Shopify admin, the pixel on the merchant's storefront, and the service that joins ad clicks to orders and reports them to the merchant's ad platforms; we are the controller of the merchant's account data and the merchant's processor for shopper data (Part B). What applies to both is stated once, in Part C.
This policy covers personal data for which HonestTag is the controller: visitors to this website, prospective customers, the merchants and their staff who create and manage HonestTag accounts, and the people in agency accounts (section B2). It does not cover the shopper data we process on behalf of merchants; for that, we are a processor acting under the merchant's documented instructions. See section B3.
| Group | Who they are | HonestTag's role |
|---|---|---|
| Merchants | The Shopify store that installs HonestTag | Controller of the account relationship; processor of the shopper data flowing through the service |
| Merchant users | The people (owners, staff, and agencies working in the store's Shopify admin) who log in and configure HonestTag | Controller of their account and usage data |
| Agency users | People in an agency's HonestTag account who read the reports of stores that approved the agency | Controller of their account data |
| Shoppers | People who browse or buy from a merchant's store where HonestTag is installed | Processor only; we act on the merchant's documented instructions |
| Site visitors and prospects | People who visit honesttag.com, join the waitlist, or contact us | Controller |
Part A. The website honesttag.com
This part covers honesttag.com and nothing else. None of it applies to the HonestTag app or to a merchant's storefront (Part B).
A1. Who this part covers
When you visit honesttag.com, read its docs and guides, join the waitlist, send the support form or apply to the partner program, HonestTag is the controller of the personal data this website collects. Merchants who use the app: your account data in the app is covered in section B2, and shoppers are covered in section B3.
A2. What the website collects
When you visit honesttag.com or use one of its forms, we act as a controller. Here is everything this website collects itself; the analytics and advertising tags are in section A3 and their cookies in section A4:
- Waitlist form: the email address you submit, a timestamp, and which page you submitted from. We use it for exactly one purpose: emailing you about HonestTag early access and launch. Unsubscribe or ask for deletion at any time via support@honesttag.com.
- Support form: your name, email address, topic and subject, your store's address if you give it, your message, a timestamp, and the IP address the form was sent from. We use it to answer your request, and we email you an automatic confirmation that it arrived.
- Partner application: your name, email address, company, website, where your referrals would come from, how many referrals you expect in the first year, the methodology you describe, and a timestamp. We use it to review your application and reply by email.
- Limits on form abuse: to stop automated abuse, each form counts submissions per IP address; each count is deleted about an hour later.
- Server logs: our infrastructure provider (Cloudflare) processes standard request metadata (IP address, user agent) to serve and secure the site.
- Referral cookie. If you arrive through a partner's referral link, this site also sets a first-party cookie named
ht_pholding that partner's referral code. It lasts 60 days and exists for one purpose: crediting the referring partner if you install HonestTag later. It is not used for analytics or advertising. Ad-click labels also travel in the page web addresses while you move around this site, and HonestTag saves them only if you submit a form (the waitlist or the partner application).
We do not buy, rent, or enrich prospect data with third-party identity or data-broker services.
A3. Analytics and advertising tags
Analytics and advertising tags. This site loads Google Tag Manager, which runs three tags: Google Analytics 4 (pages viewed, scrolling, link clicks, form starts and submits, site searches and file downloads), Google Ads (a conversion linker and a remarketing tag), and the Meta pixel (page views, visits to the pricing, docs and learn pages, clicks on links to our Shopify App Store listing and pricing, and waitlist and support form submits). Google and Meta receive your IP address, browser details, the pages you visit, and the ad click IDs in the page address, and they use cookies to recognize your browser: Google Analytics sets _ga and _ga_<ID> (2 years), Google Ads sets _gcl_au (90 days), and Meta sets _fbp and, after a Meta ad click, _fbc (90 days). We use this to see how people find HonestTag, which ads bring visitors who go on to install the app, and to show our ads to people who visited. The same Google Analytics property and Meta pixel also measure our Shopify App Store listing, where Shopify loads them. When a store installs HonestTag from that listing, Shopify reports the install to them, including the store's name and web address (and, to Google Analytics, the store's Shopify ID); that is the only store information our own advertising tools receive (Shopify: track listing traffic). Google and Meta handle this data under their own privacy policies (Google, Meta).
Cloudflare Web Analytics. Cloudflare, our infrastructure provider, also adds its Web Analytics script to every page of this site. It counts page views and visits, records the referring site, and measures how fast the page loaded; Cloudflare's reports break these down by country, browser, operating system and device type. In Cloudflare's words, it "does not use any client-side state, such as cookies or localStorage, to collect usage metrics", does not "fingerprint" individuals "via their IP address, User Agent string, or any other data for the purpose of displaying analytics", and "does not collect or use your visitors' personal data" (Cloudflare Web Analytics, About Web Analytics). Because it sets no cookie, it runs for every visitor and the cookie choice above does not change it.
A4. Cookies and browser storage
Every cookie and browser storage item this website uses. Google's and Meta's cookies are set on honesttag.com by their scripts. Lifetimes are the vendors' defaults (Google Analytics cookie usage, Google advertising cookies, Meta fbp and fbc).
| Name | Set by | What it is for | How long | Waits for Accept in the EEA, UK and Switzerland |
|---|---|---|---|---|
_ga | Google Analytics | Tells one browser's visits apart from another's | 2 years | Yes |
_ga_<ID> | Google Analytics | Keeps the state of the current visit | 2 years | Yes |
_gcl_au | Google Ads | Links a Google ad click to later visits (the conversion linker) | 90 days | Yes |
_fbp | Meta pixel | A random ID Meta uses to recognize the browser | 90 days | Yes |
_fbc | Meta pixel | Holds the Meta ad click ID, only after a click on a Meta ad | 90 days | Yes |
ht_p | HonestTag | Holds a partner's referral code, only after a visit through a partner's referral link, to credit that partner | 60 days | No |
ht_consent (local storage, not a cookie) | HonestTag | Remembers your Accept or Decline | Until you clear this site's data in your browser | No |
Cloudflare Web Analytics sets no cookie and stores nothing in your browser (section A3).
A5. Your choices: the cookie banner and Global Privacy Control
Your choice. If you visit from the European Economic Area, the UK or Switzerland, these tags set no cookies until you click Accept on the cookie banner: until then Meta receives nothing, and Google receives only cookieless pings with ad click IDs removed (Google calls this consent mode). Everywhere else they run by default, and a browser that sends Global Privacy Control turns off the Meta pixel and Google's advertising cookies, unless you have chosen Accept on this site in that browser. You can change your choice at any time here: Your choice is saved in your browser's local storage, not in a cookie.
When your browser sends Global Privacy Control, a line at the bottom of every page of this site says whether it has been applied in that browser.
California residents: the Google Ads and Meta tags are the only "sharing" on this website, and the two choices above are how you opt out of it; section C3 has the full notice.
A6. How long website data is kept
| Data | Retention |
|---|---|
| Waitlist and marketing records | Until opt-out or 24 months of inactivity |
| Support correspondence | 24 months after resolution |
| Form abuse counters | About an hour |
Referral cookie (ht_p) and the tag cookies | As listed in section A4 |
| Server and security logs | 30 to 90 days |
Waitlist, partner application and support form entries are also in the nightly backups described in section B7, kept in Cloudflare for 30 days.
Part B. The HonestTag Shopify app
This part covers the HonestTag app: the screens a merchant opens in the Shopify admin, the pixel it places on the merchant's storefront, and the service behind them. It does not cover honesttag.com (Part A).
B1. What the app does and our role
HonestTag is a Shopify app and edge measurement service that provides first-party ad-conversion measurement. In plain terms: we capture advertising click identifiers (for example gclid and fbclid), join them to a merchant's orders through Shopify webhooks, and report conversions back to the advertising destinations that merchant has connected, using SHA-256-hashed identifiers where the destination supports hashed matching (section B3 lists what each destination receives, including what is sent unhashed). HonestTag delivers to Google Ads, Meta, Klaviyo, Microsoft Advertising, TikTok, Google Analytics 4, Pinterest, Snapchat, Reddit and OpenAI Ads. Other destinations are in development and are not available to merchants; this list is updated when one becomes available. Which destinations a given store can connect is shown on that store's Setup tab, and we deliver only to the destinations that store has connected. Our distinctive features include first-click new-customer attribution, refund correction for Google Ads and Microsoft Advertising, refund events to Google Analytics 4 and Klaviyo, refund-signal recording for Meta, TikTok, OpenAI Ads, Pinterest, Snapchat and Reddit, and order proof for every attribution. TikTok delivery uses TikTok Events API for server-side purchases; reporting and spend reads use the connected TikTok account where supported. With the merchant's permission, HonestTag also reads campaign spend, and the conversions the platform reports for itself where it publishes them, from connected Google Ads, Meta, Microsoft Advertising, TikTok, OpenAI Ads and Criteo accounts. Criteo is read-only: HonestTag sends Criteo nothing. On Truth+ and higher plans, when email touches are turned on for a store that has connected Klaviyo, HonestTag also reads that store's email and SMS click events, and the daily order totals Klaviyo attributes to its own sends, from the store's Klaviyo account; section B3 describes exactly what is read and kept.
Our role. For a merchant's account and the people who use it, HonestTag is the controller (section B2). For the data of the merchant's shoppers, the merchant is the controller and HonestTag is its processor, acting only on the merchant's documented instructions (sections B3 to B7).
The website's tags stay on the website. The Google Analytics, Google Ads, Meta and Cloudflare Web Analytics tags described in section A3 run only on honesttag.com, and Shopify runs our Google Analytics and Meta tags on our App Store listing page. None of them is loaded inside the HonestTag app in the Shopify admin, whose pages load only Shopify's own App Bridge script and HonestTag's code, and none of them is placed on a merchant's storefront: the HonestTag pixel there runs inside Shopify's pixel sandbox and sends its events only to HonestTag's own servers.
Merchant and shopper data is never sold, never shared and never used for our own advertising. The data the app handles for a store (its orders and shoppers, its connected ad and email accounts, and the merchant's account) goes only to the destinations that store connects, on its instruction (section B5), to an agency or AI tool the store approves, which sees reporting totals only (section B2), and to the service providers in section C4 that run HonestTag for us. We never upload it to any advertising platform for HonestTag's own ads or audiences. The only store information our own advertising tools receive is the install report Shopify sends from our App Store listing (section A3).
B2. Merchant accounts: what we collect
When you create or use a HonestTag account: name, business email, the Shopify store(s) you connect, role and permissions, authentication and session data, IP address, device and browser information, the product configuration and consent settings you choose, and support correspondence. It comes from you, from the Shopify OAuth handshake, and from your use of the product. We use it to authenticate you, provide and secure the service, respond to support, send service-related messages, and, on a de-identified, aggregated basis only, to understand and improve HonestTag.
AI tools you connect (Scale and Scale+ plans). You can let an AI tool you choose read your store's reporting totals (the scorecard and Gap figures the app shows you) through HonestTag's MCP endpoint, either with your Metrics API key or by approving the tool's sign-in inside the HonestTag app. The access is read-only and covers those totals only: no shopper data, no order rows, and no way to change anything. For each tool you approve we keep its name and client identifier, the address it returns to after sign-in, when it connected and was last used, and hashed copies of its tokens; we never store the tokens themselves. While a sign-in is in progress we also keep the tool's name, its return address and the 8-letter code shown on its sign-in page; that request expires after 10 minutes. HonestTag runs no AI model for this: the tool runs on its provider's systems under that provider's terms. You can disconnect a tool at any time from the Metrics API card. Uninstalling the app ends every connection at once and deletes each connected tool's record.
Agency access. A store's account owner can let an agency the store works with read that store's HonestTag reports, by entering a code from the agency in the HonestTag app (Setup tab, Agency access) and approving it. The people in that agency's HonestTag account can then read the store's web address and plan, its Mirror, scorecard totals, weekly verdicts, connection health and how many alerts are open, and only what the store's own plan shows. They see totals only, never the store's customers, orders or contact details, and they cannot change anything. We give this access only on the merchant's instruction: we keep who approved it and when, record which person in the agency approved, viewed or removed the store (views at most once an hour per person), show the most recent entries of that record in the app, including those people's email addresses, and keep it for 400 days or until the store's data is deleted. Access ends on the agency's next request when anyone who can open HonestTag in the store revokes it, when the store uninstalls HonestTag, and when the agency removes the store or closes its account. People in the agency can also ask us a question about a store that has approved it; we answer about that store only while the approval stands.
For the people in an agency account, HonestTag is the controller of their account data: the agency's name, each person's email address and role, sign-in times and sessions, a log of the account's actions (codes made, people invited or removed, stores approved or removed, and support questions, which name the store asked about), and the support questions themselves. Sign-in links last 15 minutes, codes 10 minutes, and sessions at most 7 days (12 hours without use). The account's log is kept for 400 days, and support correspondence as section B7 says. A person's account is deleted when they are removed from the agency or the agency closes its account; their email address then remains only in the access records of the stores they approved, viewed or removed, for up to 400 days, and in support correspondence they sent us. The agency's owner can close the account from its Team page, and anyone in it can ask for deletion at support@honesttag.com.
B3. Shoppers: we are only a processor
If you are a shopper who bought from, or browsed, a store that uses HonestTag, this policy does not govern that data. The store you bought from is the controller. We process shopper data only under that merchant's documented instructions.
Where to send your request: to exercise your privacy rights as a shopper (access, deletion, correction, opt-out), contact the store you purchased from. If you contact us directly, we will forward your request to the relevant merchant or ask you to contact them, unless the law requires us to act ourselves.
For transparency, the shopper data we process is deliberately minimal and pseudonymous: a random visitor ID, advertising click IDs, order and checkout linkage tokens, and reported conversion values. HonestTag minimizes raw shopper contact data. Raw email and phone are not placed in attribution keys or conversion-delivery queues. Shopify webhook payloads can contain raw contact data, so HonestTag writes the original payload to an access-controlled durable inbox before acknowledging the webhook. The payload is removed when processing succeeds. A failed payload may remain in the dead-letter inbox for up to 30 days for recovery and investigation, then is deleted. Identifiers sent to a connected destination are hashed in memory where that destination supports hashed matching: the order's email address and phone number travel as SHA-256 hashes to eight of those destinations, Google Ads, Meta, Microsoft Advertising (only to conversion goals that have enhanced conversions turned on), OpenAI Ads, Pinterest, Snapchat, Reddit and TikTok, and the random visitor ID travels as a SHA-256 hash to TikTok, OpenAI Ads, Pinterest, Snapchat and Reddit. Meta receives the random visitor ID as recorded, not hashed, in its external_id field, with each purchase and, when the store turns on browse-event forwarding to Meta, with those browse events. When an order has no visitor ID, Meta receives a SHA-256 hash of the store's Shopify customer ID in that field instead, never the customer ID itself, or the hashed email address when the order has no customer ID either. The browser IP address and user agent that Shopify recorded on the order travel as recorded, not hashed, because those platforms match on them as given: they are sent to Meta, TikTok, OpenAI Ads, Pinterest, Snapchat and Reddit when the store delivers a purchase to that destination; Google Ads does not receive them, and neither do Microsoft Advertising, Google Analytics 4 or Klaviyo. Google Analytics 4 receives no email address or phone number either: a purchase or refund event carries the client ID the store's own Google Analytics tag set in the shopper's browser (or, when the store has no such tag, a pseudonymous ID derived from the random visitor ID), the order ID, value, currency, shipping, product lines, and whether the buyer is new or returning. Klaviyo receives purchase and refund events keyed on the random visitor ID or Klaviyo's own click ID, never an email address in the event. On Truth+ and higher plans, when the store has connected Klaviyo, HonestTag also sends the order's email address to that store's Klaviyo account once, unhashed, at the time of the order, so Klaviyo can find the shopper's existing profile; HonestTag keeps only the profile ID Klaviyo returns, for up to 365 days, and does not store the email address. They ride in the delivery queue only until that delivery is made or abandoned, and HonestTag does not build a shopper profile from them. When a store's delivery is paused for billing, HonestTag keeps each order it holds back with its ad click IDs and value only, and when billing resumes it sends that order with those alone: the hashed email address and phone number, the visitor ID, and the IP address and user agent, are not kept for it and are not sent. A TikTok purchase event also carries the TikTok click ID (ttclid) as recorded when we have one, the order value, currency and order ID, whether the buyer is new or returning, a page URL, and up to ten product lines. TikTok browse events (add to cart, checkout started and payment info added) are sent only when the merchant turns that option on, and only for a visitor with a TikTok click ID. They carry the click ID, the hashed visitor ID, the IP address and user agent of the visitor's browser, and the store's web address, never email or phone. A Pinterest checkout event also carries the Pinterest click ID (epik) when the shopper's visit came from a Pinterest ad link we recorded, the order ID, the order value without tax and shipping, currency, product IDs, prices and quantities, and the order's landing page address. HonestTag sends Pinterest no browse events and no refund events. A Snapchat purchase event also carries the Snapchat click ID (ScCid) when the shopper's visit came from a Snapchat ad link we recorded, the order ID, the order value without tax, currency, product IDs, prices and quantities, and the order's landing page address. HonestTag sends Snapchat no browse events and no refund events. A Reddit purchase event also carries the Reddit click ID (rdt_cid) when the shopper's visit came from a Reddit ad link we recorded, the order ID, the order value, currency, the item count and the products. HonestTag sends Reddit no browse events and no refund events. This is separate from the request metadata this website's own server logs hold, described in section A2.
Email touches (Klaviyo, Truth+ and higher plans). When email touches are turned on for a store that has connected its Klaviyo account, HonestTag reads from that account, once an hour, the store's Clicked Email and Clicked SMS events. For each click it requests only the time of the click, the event's properties, and one field of the shopper's Klaviyo profile: the external ID. HonestTag uses that field only when it holds a random visitor ID that HonestTag itself attached to the profile at an earlier order; any other value is discarded and not stored. HonestTag never requests the profile's email address, phone number, name or any other profile field, and never reads the store's lists or segments. From each matched click it keeps the time, whether it was email or SMS, and Klaviyo's message ID and campaign or flow ID, stored against that random visitor ID. A click with no HonestTag visitor ID is added to a daily count and then discarded: HonestTag never creates a visitor ID or a Klaviyo profile from an email or SMS click. HonestTag also reads two things that name no shopper: the number and value of orders Klaviyo attributes to its own email and SMS sends each day, and the account's reporting currency. These touches are used only to show the store where an email or SMS click came before an order: they appear as assists in that order's proof and in the store's Email reporting row, they never change first-click credit, and HonestTag sends them to no advertising destination. Reading stops within the hour after the store disconnects Klaviyo or email touches are turned off; touches already recorded expire on the schedule in section B7.
B4. The HonestTag pixel on merchant storefronts
When installed by a merchant, HonestTag runs as a Shopify Web Pixel. On the storefront it may set one first-party cookie (ht_vid) holding a random visitor ID used to link an ad click to a later order. It contains no email, phone, or name. Here is how consent handling works today, stated exactly:
- The pixel reads the consent and opt-out state reported by Shopify's Customer Privacy API and subscribes to consent events. An explicit refusal blocks tracking at a single choke point: the
ht_vidcookie is not written and attribution events are not collected or delivered. - Where Shopify reports no decision yet (an "unknown" state), the pixel currently initializes and may set
ht_vidso the landing page's click identifiers are not lost. A later explicit refusal stops tracking. If your storefront or applicable law requires consent before any tracking cookie, you are responsible for configuring your consent platform and Shopify Customer Privacy so the required state is exposed to apps; do not rely on HonestTag to withhold the cookie in the unknown state. - Our server endpoints additionally honor Global Privacy Control (GPC) and Do Not Track signals.
- For EU, EEA, UK, and Swiss orders: a conversion with no visitor record is blocked and no identifiers are sent. Where a visitor record exists, hashed identifiers are sent to the merchant's configured platforms with the consent state we actually have: a conversion with an explicit grant carries that grant (consented EU conversions carry Google Consent Mode v2 signals), a conversion where the merchant's Shopify privacy settings require consent in the shopper's region and Shopify reports it given carries a grant too, and any other conversion is transmitted to Google with its consent state marked unknown rather than claimed as granted.
The merchant is the controller of storefront tracking and is responsible for configuring consent, providing notice, and disclosing HonestTag in the merchant's own privacy policy. We are working to align the pixel's unknown-state behavior with regional prior-consent requirements and will update this section when that behavior changes.
B5. Ad and analytics destinations a store connects
Advertising and analytics destinations the merchant configures (today: Google Ads, Meta, Klaviyo, Microsoft Advertising, TikTok, Google Analytics 4, Pinterest, Snapchat, Reddit and OpenAI Ads): they receive conversion data on that merchant's instruction and act under the merchant's own arrangement with them; they are not our subprocessors merely because the merchant connects them. When a store turns on email touches, HonestTag also reads from that store's Klaviyo account on the merchant's instruction, as section B3 describes; that does not make Klaviyo our subprocessor either. A store delivers only to the destinations connected in that store, and the app's Setup tab shows which those are. We update this list when a destination becomes available to merchants. Section B9 describes how we handle the data we receive from Google's APIs when a merchant connects a Google Ads account. Each destination publishes its own privacy policy, which this policy incorporates by reference for how that destination separately handles the data it receives: Google (covers Google Ads and Google Analytics 4), Meta, Microsoft, TikTok, OpenAI, Pinterest, Snapchat, Reddit, and Klaviyo.
Section B3 lists exactly what each destination receives.
B6. Shopify privacy webhooks (automated)
HonestTag automatically honors Shopify's three mandatory privacy webhooks, authenticated and fail-closed:
- Customer data request: we compile everything linkable to the customer's orders into a report, email the merchant that the request arrived, and send the report to the merchant to fulfill. Neither the email nor the report contains the customer's email or phone.
- Customer redact: we delete the order-to-visitor joins, reported values, click, email and SMS touch, consent and browsing records for every listed order, any data-request report and any failed webhook payload that names those orders or that customer, with an audit log.
- Shop redact: removal of the store's data from active service systems within 48 hours of Shopify's signal, with an isolated, access-restricted safety snapshot deleted within 30 days, as described in section B7.
B7. Retention and deletion of app data
We retain personal data only as long as needed, then delete or de-identify it. Every key in our measurement data plane carries an automatic expiry, and the keys that name a store are deleted with that store's data, with one exception: the per-order delivery record. It notes which advertising destinations an order, refund, cancellation or order edit was sent to, keyed by its Shopify order or refund ID, and holds no visitor ID, email, phone or other contact details. It has no expiry timer. A customer erasure request deletes the delivery records of the orders it names, and deleting a store deletes the delivery records of its orders whose reported conversion value is still kept (180 days). The delivery records of refunds, cancellations and order edits, and of orders older than that, are not yet reached by either deletion and remain stored.
Merchant account data (HonestTag as controller)
| Data | Retention |
|---|---|
| Merchant account records | Duration of the relationship + 24 months, then deletion or de-identification |
| Billing and tax records | As required by law (typically up to 7 years) |
| Support correspondence | 24 months after resolution |
| Server and security logs | 30 to 90 days |
Shopper data (HonestTag as processor)
| Store | Contents | Retention |
|---|---|---|
| Visitor identity | A random visitor ID (random characters, never derived from the shopper), plus a lookup entry built from a hashed IP and browser type that lets the same device find its own random ID again. Section B4 describes when the pixel sets this ID. | Random visitor ID cookie: 365 days; hashed IP and browser lookup: 30 minutes |
| Click stores | Ad click IDs + timestamps | 90 to 365 days |
| Email engagement touches | For each random visitor ID, up to the 20 most recent Klaviyo email and SMS clicks: the time, the channel, and Klaviyo's message and campaign or flow IDs; never email, phone, or name. Klaviyo event IDs already read are kept for 7 days so a click is not counted twice. Section B3 describes when these are collected. | 90 days. A copy of the touches that came before an order is kept in that order's evidence record, for that record's retention. |
| Email daily totals | Per store per day: email and SMS click counts, how many of those clicks had no visitor ID, and the orders and order value Klaviyo attributes to its own sends, in the Klaviyo account's currency; no shopper identifiers | 25 months |
| Order and checkout joins | Order/checkout token to visitor link | 30 to 90 days |
| Reported conversion values | Value, currency, classification (no identifiers) | 180 days |
| Orders held while a store's delivery is paused | Order ID, event ID, ad click IDs, value, currency, classification, the destinations the order was meant for, and what was sent when billing resumed; never email, phone, IP address or browser details | 100 days |
| Evidence records | Per-order attribution proof: click IDs, any email and SMS touches, join method, classification inputs, delivery and refund outcomes; never email, phone, or name | 400 days (paid plans; the free Mirror keeps none) |
| Analytics event rows | Visitor ID, order ID, page path and referring page, the network prefix of the IP address (never the full address), country, region and city as Cloudflare derives them, device and browser type; never email or phone | Three months in Cloudflare Analytics Engine. A copy is kept in the store's own raw event archive for 25 months, with referring-page URLs stored without their query strings. A customer erasure request removes that customer's rows from the archive. A second copy of the archive is kept in a separate Cloudflare storage bucket and follows it: a day the archive deletes or rewrites is deleted or rewritten in the second copy at the next nightly copy. |
| Webhook inbox payloads | Original Shopify webhook payload, which can include shopper contact and order data | Until successful processing; failed dead-letter payloads up to 30 days |
| Archives and control plane | Rollups, tenant configuration (credentials envelope-encrypted) | Until purge on uninstall |
After Shopify sends shop/redact (which Shopify delivers about 48 hours after uninstall), HonestTag removes the store's data from active service systems within 48 hours. Before that deletion, HonestTag creates an isolated safety snapshot so an authenticated but mistaken purge cannot irreversibly destroy the store's data. Safety snapshots and ordinary backups are not used for advertising delivery or normal product access, are access-restricted, and are deleted on a rolling schedule within 30 days. Ordinary backups include a nightly backup of our measurement data store (click stores, email touches, order and checkout joins, reported conversion values, held orders, evidence records, consent state and survey answers; not analytics event rows or webhook payloads) and of waitlist, partner application and support form entries, kept in Cloudflare for 30 days and then deleted. A restore from a backup skips every store deleted since the backup was taken and every store with a customer erasure recorded since then, so an erasure is not undone by a restore. The data-request reports we compile when Shopify sends customers/data_request are also copied to the second storage bucket that holds the raw event archive copy; a report that a customer erasure request removes is deleted from that bucket at the next nightly copy, and when a store is deleted, its archive copy and reports in that bucket are deleted at the next nightly copy too. Limited audit or financial records may be retained when needed to document the deletion or meet legal and accounting obligations; they are not used to continue tracking. The per-order delivery records described at the start of this section that store deletion does not reach also remain.
We also back up our control database every night: store accounts and settings, billing records, envelope-encrypted credentials, rollups and order ID registers. The full copy, which includes any Shopify webhook payloads still waiting in the processing inbox at that moment, is kept in Cloudflare. It is deleted after 30 days.
B8. Our data-broker commitment
We do not buy, rent, sell, or enrich personal data with third-party identity graphs, data brokers, or match services. Our measurement is first-party and honors the consent signals described in section B4. The only identifiers we handle arrive through the merchant's own store and advertising click parameters, and the marketing platforms the merchant connects (such as their email platform). Email addresses, phone numbers and the Shopify customer ID are hashed before they are sent to an advertising platform. The one unhashed email is the Klaviyo profile lookup section B3 describes, sent to the store's own Klaviyo account. Section B3 lists every identifier each destination receives, including the ones sent unhashed. Customer and shopper data is used only to provide and improve HonestTag for the merchant it belongs to; we never provide it to third parties to train their models.
B9. Google user data and the Google API Services User Data Policy
When a merchant connects a Google Ads account, HonestTag accesses Google user data through Google's APIs. HonestTag's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. This section states exactly what we access, how we use it, how we store it, and how we share it.
What we access. With the merchant's OAuth consent, HonestTag requests four scopes:
- openid and email: the email address of the connected Google account. We use it only to show "connected as" in the app and to detect when a reconnect uses a different Google user. We do not use it for marketing and do not share it.
- Google Ads (
https://www.googleapis.com/auth/adwords): reading the merchant's own campaign spend, clicks, impressions, and Google-reported conversions, which we display next to the store's own Shopify orders; creating and managing HonestTag's own conversion actions in the one ad account the merchant selects; and uploading refund adjustments so a refunded order corrects the previously reported conversion. HonestTag never creates, edits, or pauses campaigns, ad groups, ads, or budgets, and never modifies conversion actions it did not create. - Data Manager (
https://www.googleapis.com/auth/datamanager): server-side delivery of the merchant's own conversion events into those HonestTag conversion actions, unless the merchant chooses, from the app's setup screen, to send purchases into one existing conversion action they pick instead; even then, HonestTag never changes that action's own settings. Customer identifiers in these events are hashed with SHA-256 before they leave HonestTag.
How we use it. Only to provide and improve the merchant-facing measurement features described above, for the merchant who granted access. Google Ads data is bound to the single ad account the merchant selects. We do not use Google user data for our own advertising, do not build cross-store profiles from it, do not sell it, and do not use it to train models, including AI or machine-learning models. The free plan is read-only and never writes to the merchant's Google Ads account.
How we store it. The OAuth refresh token is envelope-encrypted at rest and scoped to the merchant's tenant. Spend and platform-reported conversion figures are stored as reporting rows for that merchant's own dashboards. The connected account email is stored in the merchant's configuration. This data is removed with the rest of the store's data on uninstall, as described in section B7.
How we share it. We do not sell or share Google user data, and we transfer it only: back to Google itself on the merchant's instruction (the conversion deliveries described above), to the infrastructure providers in section C4 acting on our behalf, and to authorities where legally required (section C6). Our personnel access Google user data only to operate, support, and secure the service, to comply with applicable law, or with the merchant's permission.
Disconnecting. A merchant can disconnect Google Ads inside the app at any time, or revoke HonestTag's access at myaccount.google.com/permissions. On disconnect or uninstall, HonestTag revokes its own access token and marks the conversion actions it created as removed in the merchant's account; their history remains with the merchant.
Part C. Applies to both parts
This part applies to the website and the app alike.
C1. Who we are
Controller: HonestTag Inc, a Delaware corporation ("we," "us"), 8 The Green, Ste B, Dover, DE 19901. Privacy contact: support@honesttag.com.
C2. Legal bases (GDPR / UK GDPR)
Where GDPR or UK GDPR applies to our controller-side processing, we rely on: performance of a contract (Art. 6(1)(b)) for accounts, service delivery, and transactional messages; legitimate interests (Art. 6(1)(f)) for service security, fraud prevention, de-identified product improvement, B2B marketing (opt-out always available), and defending legal claims; consent (Art. 6(1)(a)) where local law requires it, withdrawable at any time; and legal obligation (Art. 6(1)(c)) for tax, accounting, and lawful requests. Shopper data is processed on the merchant's legal basis, not ours; the merchant is responsible for obtaining any required consent.
C3. California notice at collection (CCPA/CPRA)
As a controller (for merchant users, people in agency accounts, prospects, and site visitors; not shopper data, see section B3), we collect these CCPA categories: identifiers (name, business email, account ID, IP address, store domain), customer records (business contact and billing contact), commercial information (subscription plan, product configuration), internet activity (pages viewed, feature usage, session logs), coarse geolocation (IP-derived region), and professional information (job role, company). Sources: you, the Shopify OAuth handshake, and your use of the site and product. Purposes: providing and securing the service, support, billing, and product improvement.
We do not sell personal information as the CPRA defines it. The Google Ads and Meta tags on this website, described in section A3, may count as "sharing" for cross-context behavioral advertising under the CPRA; they use only site visitors' browsing data on honesttag.com and the installs Shopify reports from our App Store listing (section A3), never merchant account data held in the app or shopper data. To opt out, use the Cookie choice button in section A5 or turn on Global Privacy Control in your browser, which this site honors. We do not collect sensitive personal information as defined by the CPRA. We do not knowingly collect or sell the personal information of individuals under 16.
How long we keep each category: sections A6 and B7.
C4. Service providers and sub-processors
We disclose personal data to service providers that help us run HonestTag, including the following, to the destinations a merchant connects (section B5), and to an agency or AI tool a merchant approves (section B2), and we never sell or share merchant or shopper data:
| Provider | What it does for us | Used for |
|---|---|---|
| Cloudflare, Inc. | Application compute, storage, queues, and network services for the app and this website, and the cookieless Web Analytics on this website (section A3). Merchant credentials are envelope-encrypted at rest. | Website and app |
| Resend, Inc. | Sends HonestTag's own transactional email to merchants and to people in agency accounts, including agency sign-in links and invitations, and delivers support and waitlist form submissions, and support questions sent from agency accounts, to us. | Website and app |
| Google Workspace | Hosts our support and business email, so support correspondence is processed there. | Website and app |
| Discord Inc. | Our team's internal notification channel. It receives a copy of each waitlist signup from this website (including the email address), notices about the support requests we receive by email or through this website's support form (who wrote, their store and what they asked), and operational alerts about merchant stores, which name the store and the problem. Discord stores this in the United States under its own privacy policy. | Website and app |
| Shopify Inc. | The platform that supplies the app, consent surface, orders, and webhooks. | App |
| Google LLC and Meta Platforms, Inc. | The Google Analytics, Google Ads and Meta tags on this website (section A3). They receive site visitors' browsing data and the installs Shopify reports from our App Store listing (section A3), never merchant account data held in the app or shopper data. | Website only |
| Professional advisers and authorities | Where legally required (see section C6). | Website and app |
The advertising and analytics destinations a merchant connects are not our sub-processors; section B5 explains their role.
We will publish and maintain a dedicated list of shopper-data subprocessors with purposes, locations, and transfer mechanisms alongside our Data Processing Addendum, and we will give merchants advance notice of any new or replacement shopper-data subprocessor with a mechanism to object, as set out in that DPA once executed.
C5. International transfers
HonestTag operates from the United States on Cloudflare's global edge network. Where a transfer of EEA, UK, or Swiss personal data legally requires the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or the Swiss adaptations, those terms will be provided through our Data Processing Addendum, which is in final preparation; we will not onboard a merchant whose transfers legally require those executed terms before they are in place. We do not claim certification under the EU-US Data Privacy Framework and will not represent participation unless actually certified. We do not promise EU-only or country-specific data residency.
C6. Legal disclosures
We may disclose personal data where required by law, subpoena, court order, or valid governmental request, or to protect our rights, users, or the public. Where we act as a processor and are legally permitted, we will notify the relevant merchant before disclosing shopper data so they may seek to challenge or narrow the request.
C7. Security
We apply technical and organizational measures appropriate to the risk: encryption in transit (TLS 1.2+) and at rest; envelope encryption for merchant credentials; data minimization and pseudonymization by design; automatic expiry on every data-plane key except the per-order delivery records described in section B7; strict per-tenant isolation; least-privilege access; and automated privacy-compliance tests run before every deploy. We are not currently certified under SOC 2 or ISO 27001 and do not claim to be. No system is perfectly secure; if a breach affecting merchant or shopper data occurs, we will notify affected merchants without undue delay.
C8. Your privacy rights
The rights available to you depend on where you live and our role. Shoppers: contact the merchant you purchased from (section B3).
- EEA, UK, Switzerland: access, rectification, erasure, restriction, portability, objection (including to direct marketing, which we always honor), and withdrawal of consent. You may lodge a complaint with your supervisory authority (in the UK, the ICO; in Switzerland, the FDPIC).
- California: know/access, correct, delete, opt out of sale or sharing (we do not sell; section A5 explains how to opt out of the website tags that may count as sharing), non-discrimination, and appeal of a denial.
- Other US states: residents of states with comparable privacy laws have analogous rights to access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and certain profiling. We honor these on the same basis.
To exercise your rights: email support@honesttag.com. We will verify your identity using information already associated with your account and respond within the timeframes required by applicable law. You may use an authorized agent with proof of authorization. If we deny a request, you may appeal by replying to our decision. We honor the Global Privacy Control browser signal as a valid opt-out where applicable.
C9. Children
HonestTag is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16, and merchants are instructed not to deploy HonestTag on stores directed at children. If you believe a child has provided us data, contact support@honesttag.com and we will delete it.
C10. Changes to this policy
When we update this policy, we will change the version number and effective date above and post the revised version at this URL. For material changes, we will provide additional notice by email or an in-product banner before the change takes effect.
C11. Contact
HonestTag
Privacy and all other requests: support@honesttag.com
By mail: HonestTag Inc, 8 The Green, Ste B, Dover, DE 19901
Shoppers: please contact the store you purchased from. HonestTag processes your data on that store's behalf and will redirect your request to them.