Legal

Privacy Policy

Last updated: May 5, 2026

Summary: We collect only what we need to run Metricty. We never sell your data. We use your store data solely to generate your reports. You can delete your account and all data at any time.

1. Information We Collect

We collect information you provide directly when you create an account, connect integrations, or contact us:

  • Account information: Name, email address, and password.
  • Store data: When you connect Shopify or WooCommerce, we access order data, product information, revenue figures, and related metrics solely to generate your reports.
  • Ad platform data: When you connect Meta Ads or Google Ads, we access spend data, campaign metrics, and ROAS figures.
  • Payment information: Billing is handled by Stripe. We store your Stripe customer ID but never your card details.
  • Usage data: How you interact with our dashboard, pages visited, and features used.

2. How We Use Your Information

We use your information to:

  • Generate your weekly profit reports and AI summaries
  • Send your weekly report emails
  • Process payments and manage your subscription
  • Respond to support requests
  • Improve Metricty's features and performance
  • Send product updates and announcements (you can opt out at any time)

We never use your store data to train AI models, sell to third parties, or benchmark against other users without explicit consent.

3. Data Sharing

We share your data only in these limited circumstances:

  • Service providers: We use Supabase (database), Stripe (payments), Resend (email), and Anthropic (AI summaries). Each is bound by their own privacy policies and data processing agreements.
  • Legal requirements: We may disclose information if required by law, court order, or to protect the rights and safety of Metricty and its users.
  • Business transfers: In the event of a merger or acquisition, your data may transfer to the new entity under the same privacy commitments.

We do not sell, rent, or trade your personal information to any third party.

4. Data Retention

We retain your data for as long as your account is active. When you delete your account:

  • Your personal information is deleted within 30 days
  • Your store data and reports are deleted immediately
  • Backup copies are purged within 90 days

We may retain anonymized, aggregated data (e.g., average margin across all users) that cannot identify you.

5. Security

We take security seriously:

  • All data is encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Access tokens for connected integrations are stored encrypted
  • Our infrastructure runs on DigitalOcean with regular security updates
  • We use Supabase Row Level Security so each user can only access their own data
  • Admin access is restricted and logged

No system is 100% secure. If you discover a vulnerability, please report it to [email protected].

6. Your Rights

You have the right to:

  • Access: Request a copy of all data we hold about you
  • Correction: Update inaccurate information via your account settings
  • Deletion: Delete your account and all associated data at any time
  • Portability: Export your report data as CSV
  • Opt-out: Unsubscribe from marketing emails at any time

To exercise these rights, email [email protected].

7. Cookies

We use essential cookies only:

  • Authentication cookies: To keep you logged in to your dashboard
  • Preference cookies: To remember your dashboard settings

We do not use advertising or tracking cookies. We do not use Google Analytics or any third-party analytics that track you across websites.

8. Contact Us

If you have questions about this Privacy Policy, contact us:

This policy is effective as of May 5, 2026. We will notify you of significant changes by email or via a banner in your dashboard.