Skip to content

Privacy & data

Privacy Policy

ZenProfit helps Shopify merchants estimate store profit by combining Shopify financial facts with merchant-provided costs and authorized advertising data. This policy explains what we process, why we process it, how long we keep it, and how to make a privacy request.

Who Operates ZenProfit and Our Role

ZenProfit is independently operated by Vu Nguyen in Vietnam. For merchant account, support, and product analytics data, ZenProfit acts as the service operator and, where applicable, a data controller. For customer information processed on a Shopify merchant's instructions, the merchant is normally the controller and ZenProfit acts as its service provider or processor.

Privacy questions and requests can be sent to [email protected].

Information We Collect

  • Shop and account information: shop domain, store name, owner/contact email, currency, timezone, locale, installation, onboarding, synchronization, plan, trial, and billing state.
  • Authorization and staff session information: Shopify scopes, access/refresh credentials and, when Shopify supplies them, authorized staff user ID, name, email, locale, and account-role flags needed to operate the embedded app.
  • Shopify product and order facts: product/variant titles and SKUs; order identifiers/numbers, line items, timestamps, status, refunds, country-level shipping data, gateway names, weights, and monetary totals used for profitability calculations.
  • Merchant inputs: product costs, shipping and payment-fee rules, custom expenses, report schedules/recipients, Smart Alert preferences, and historical recalculation requests.
  • Authorized advertising data: provider, account identifiers/names, encrypted OAuth credentials, scopes, campaign names, daily spend, impressions, clicks, conversions, currency, timezone, and synchronization status.
  • Reports and communications: generated report summaries/files, delivery state, and information a merchant chooses to include in support or privacy requests.
  • Customer analytics aggregates: new-versus-returning sales/orders, acquisition cohorts, RFM groups, counts, and observed lifetime revenue supplied by Shopify reports. These records do not contain customer IDs, names, emails, phone numbers, street addresses, tags, or raw report rows.
  • Operational records: webhook and queue status, route/action, timestamps, performance measurements, technical correlation IDs, error fingerprints, and sanitized diagnostics used for security, support, and reliability.
  • Support audit events for material merchant-initiated data or configuration changes and important background-job outcomes. These events may include the shop domain, a hashed actor identifier, outcome, timestamps, technical correlation IDs, and bounded before/after values for non-personal cost settings. They do not include customer/order payloads, access tokens, credentials, or raw error stacks.
  • Privacy-safe product analytics events such as install, onboarding progress, report usage, setup completeness, and billing conversion state. These events use counts, statuses, buckets, and a hashed shop identifier; they do not include customer PII, order details, access tokens, or secrets.

ZenProfit stores order-level financial facts for merchant reporting, but does not intentionally request or store buyer names, buyer email addresses, phone numbers, street addresses, or raw webhook payloads. Please do not send those fields in support requests.

Sources of Information

We receive information from Shopify after app authorization, from merchants when they configure ZenProfit or contact support, from an advertising provider only after the merchant authorizes that connection, and from ZenProfit's own servers, queues, and browser interface when the service is used.

How We Use Information

  • To sync Shopify and advertising data requested by the merchant.
  • To calculate estimated revenue, costs, ad spend, margins, and profit metrics.
  • To display dashboards, reports, and data quality warnings inside the app.
  • To understand activation, conversion, retention, and which setup steps merchants need help with.
  • To process background jobs, webhooks, retries, and app lifecycle events.
  • To explain when profit-affecting data or configuration changed and correlate failed operations with restricted technical logs.
  • To protect the app from abuse, diagnose errors, and improve reliability.

Legal Basis and Merchant Instructions

We process data to perform the ZenProfit service requested by the merchant, meet platform and legal obligations, protect the service, pursue legitimate interests in reliability and product improvement where permitted by law, and use merchant authorization for optional advertising connections. Where consent is legally required, it can be withdrawn without affecting earlier lawful processing. Merchants are responsible for having an appropriate legal basis for information they provide to ZenProfit, including report recipient and support email addresses.

Cookies and Browser Storage

ZenProfit and Shopify may use essential session or authentication cookies so the embedded app can securely recognize an authorized request. Locale or currency preference cookies may also be read when supplied. ZenProfit does not place third-party advertising cookies on its public pages.

The app stores a dashboard date-range preference in browser localStorage until it is reset or browser storage is cleared. Advertising OAuth uses a transient same-origin completion signal that is removed immediately after it is emitted. These are functional preference/status values, not customer/order data.

Advertising Platform Data

If a merchant connects a supported advertising platform, ZenProfit uses the granted reporting permissions to import advertising performance and spend data for reporting. We do not create, edit, or delete ads on the merchant's behalf. Ad platform OAuth tokens are encrypted before storage. Disconnecting in ZenProfit stops future synchronization; the merchant should also revoke access in the provider's settings to remove the provider-side grant.

International Processing

ZenProfit is operated from Vietnam. Service providers used for hosting, databases, queues, email delivery, logging, and advertising integrations may process data in other countries. Where required, we use contractual and technical safeguards appropriate to those transfers.

Data Sharing

We do not sell merchant or customer data and do not share it for third-party targeted advertising. We disclose information only as needed to operate ZenProfit, follow merchant instructions, protect the service, or meet legal obligations.

  • Shopify, for app installation, authentication, billing, Admin API access, and mandatory privacy webhooks.
  • Hosting, database, Redis/queue, logging, and monitoring providers used to operate and secure the app.
  • SMTP/email providers used to send merchant-configured report emails and operational notifications.
  • Exchange-rate and advertising platform APIs only when the related feature is configured or connected by the merchant.
  • Professional advisers or authorities when legally required or necessary to protect rights and service security.

The exact provider set can change as infrastructure changes. Material changes that affect this policy will be reflected here.

Data Retention and Deletion

  • Active-store operational data is retained while needed to provide ZenProfit, then deleted through uninstall, privacy-webhook, or verified deletion workflows.
  • Ready report artifact content is available for the configured retention window—90 days by default—then removed by maintenance. Report metadata remains while the store is active so an expired history item can be explained.
  • Merchant audit events are retained for up to 90 days. Internal product analytics events are retained for up to 395 days; merchants can opt out of future collection in Settings.
  • Privacy-safe customer analytics aggregate snapshots may be retained for up to 395 days and are deleted with the store tenant data.
  • Pending advertising-account selections expire after 15 minutes. Active provider connections remain until disconnect, uninstall, or verified deletion.
  • Terminal webhook records containing a shop domain are retained for up to 30 days. A hashed proof that a mandatory Shopify privacy webhook completed may be retained for up to 395 days. Unresolved failed receipts may be retained while the failure is investigated.
  • Resolved or dismissed Smart Alert occurrences and completed delivery records may be retained for up to 180 days for product reliability and support. Open alerts and unresolved delivery failures remain available while action or investigation is required.
  • After uninstall, the main tenant data and sessions are deleted and a minimal shop lifecycle record is retained for up to 30 days before maintenance deletes it.
  • Technical logs and protected backups follow separate restricted operational lifecycles and are not used as merchant-facing audit history. Residual backup copies are removed through their normal protected rotation.

Uninstall and Shopify Privacy Webhooks

An authenticated app/uninstalled webhook triggers deletion of the store's ZenProfit configuration, sessions, orders, products, costs, expenses, advertising connections, alerts, reports, merchant audit events, and internal product analytics. Reinstalling requires fresh authorization and does not automatically restore an advertising connection.

Shopify's authenticated shop/redact webhook is the hard-delete path for remaining shop and lifecycle records. ZenProfit also acknowledges authenticated customers/data_request and customers/redact webhooks. Because ZenProfit does not intentionally store customer identity fields, those customer requests normally have no identity record to return or redact.

Privacy Rights and Requests

Depending on applicable law, merchants and individuals may request access, correction, deletion, restriction, objection, or a portable copy of relevant personal information. Send the request from the store owner's verified business email, identify the Shopify shop, and do not include customer data, passwords, or tokens. We may verify store ownership before acting.

Customer requests relating to a merchant's store should normally be submitted to that merchant, who can invoke Shopify's mandatory privacy request process. You may also complain to a competent privacy or data-protection authority where applicable law gives you that right. Contacting us first gives us an opportunity to address the concern.

Start a privacy request or review safe request guidance on our Support page.

Security

We use reasonable technical and organizational safeguards to protect merchant data, including access controls, encrypted connections, tenant-scoped queries, restricted operational logs, bounded retention, and background queues for supported asynchronous operations. Ad platform OAuth tokens are encrypted at rest. No method of storage or transmission is completely secure. Report a suspected issue through our Support page; never email a credential or token.

Children

ZenProfit is a business service for Shopify merchants and is not directed to children. We do not knowingly collect children's personal information through the service.

Changes to This Policy

We may update this policy when ZenProfit's features, data practices, providers, or legal obligations change. The current effective date appears at the top of this page. Material changes will be communicated through the app or an appropriate merchant contact channel when required.

Contact

Operator and privacy contact: Vu Nguyen, Vietnam. Email: [email protected].