Privacy Policy
Last updated: July 10, 2026
This Privacy Policy explains how StoreMetrics ("we," "us," or "our"), the operator of storemetrics.app, handles personal data. StoreMetrics is a privacy-first web analytics tool for e-commerce sites.
It is important to understand the two different roles we play:
- For our own account holders (our customers): we act as a data controller. This covers the personal data we collect to run accounts, billing, and support.
- For the visitor data collected through the tracking script on our customers' websites: we act as a data processor on behalf of our customer, who is the controller of that data. If you are a visitor to a website that uses StoreMetrics, the operator of that website is responsible for its own privacy practices, and you should refer to that website's privacy notice.
1. Data We Collect
Account data (we are the controller)
When you sign up for and use StoreMetrics, we collect:
- Account details: name, email address, and login credentials.
- Billing data: subscription plan and payment information processed via Stripe (we do not store full card numbers).
- Usage and technical data: information about how you use the Service, log data, and device/browser information.
- Support communications: the content of messages you send us.
Visitor data (we are the processor)
When a customer installs our tracking script on their website, StoreMetrics processes analytics data about that website's visitors on the customer's behalf, which may include:
- Analytics events: pageviews, product views, cart and checkout events, and order and revenue data.
- Approximate location: IP addresses are masked or derived to an approximate location (such as country or city) and are not stored in raw form as an identifier for analytics display.
- Device/browser information: such as device type, browser, operating system, and referrer.
- Order attribution data: where the customer connects integrations such as Shopify or Stripe, this may include customer names, email addresses, phone numbers, and order details used to attribute orders and revenue.
We process visitor data only to provide the analytics Service to our customers and according to their instructions.
2. Cookies and Similar Technologies
Our tracking script uses a first-party cookie to store a visitor identifier so that pageviews and events can be associated with a session and distinguished from other visitors on the customer's own domain. This cookie is set in the context of the customer's website (first-party), not shared across unrelated sites, and is not used for cross-site advertising.
On the StoreMetrics website and app itself, we use cookies that are necessary to operate the Service (such as authentication) and may use limited cookies to remember preferences.
Because the tracking cookie is set on the customer's website, the customer is responsible for providing any cookie notice or obtaining consent required in their visitors' jurisdictions.
3. How We Use Data
For account data (as controller), we use data to:
- Provide, maintain, and improve the Service.
- Process payments and manage subscriptions.
- Communicate with you about your account, security, and Service updates.
- Provide support and respond to your requests.
- Comply with legal obligations and protect against fraud or abuse.
For visitor data (as processor), we use it only to deliver analytics to the relevant customer and as instructed by that customer.
4. Legal Bases (GDPR)
Where the GDPR applies, we rely on the following legal bases for processing account data: performance of a contract (to provide the Service), legitimate interests (to secure and improve the Service), consent (where required), and legal obligation (for example, tax and accounting). For visitor data, our customer is responsible for establishing the appropriate legal basis for the collection they direct.
5. Sub-processors and Third Parties
We use trusted third parties to operate the Service. Where they process personal data on our behalf, they act as sub-processors under appropriate agreements:
- Supabase — database and hosting.
- Vercel — application hosting and delivery.
- Stripe — payment and subscription processing.
- Resend — transactional and account email delivery.
In addition, where a customer chooses to connect them, the following integrations exchange data at the customer's direction:
- Shopify — store, order, and customer data for analytics and attribution.
- Stripe — payment and order data for revenue analytics.
- TikTok Ads — advertising performance data.
We may update this list as our providers change and will reflect changes in this Policy.
6. Data Retention
- Account data is retained for as long as your account is active and for a reasonable period afterward to comply with legal, tax, and accounting obligations, then deleted or anonymized.
- Visitor data is retained for as long as needed to provide analytics to the relevant customer, subject to any retention period configured or agreed with that customer. When a customer's account is terminated, we delete or anonymize their visitor data within a reasonable period, except where retention is required by law.
7. International Transfers
We and our sub-processors may process data in countries other than your own, including outside the European Economic Area. Where personal data is transferred internationally, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or equivalent mechanisms.
8. Your Rights
GDPR (EEA/UK)
If you are in the EEA or UK, you have the right to access, correct, delete, restrict, or object to the processing of your personal data, the right to data portability, and the right to withdraw consent. You also have the right to lodge a complaint with a supervisory authority.
CCPA/CPRA (California)
If you are a California resident, you have the right to know what personal information we collect, to access and delete it, to correct it, and to opt out of any "sale" or "sharing" of personal information. We do not sell your personal information. We will not discriminate against you for exercising your rights.
To exercise any of these rights for account data, contact us at privacy@storemetrics.app. If your request concerns visitor data collected on a customer's website, please contact that website operator (the controller); we will assist our customers in responding to such requests as a processor.
9. Security
We take reasonable technical and organizational measures to protect personal data, including encryption in transit, access controls, and reliance on reputable infrastructure providers. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
10. Children's Privacy
The Service is not directed to children, and we do not knowingly collect personal data from children. Customers must not use the Service to knowingly collect data from children where prohibited by applicable law.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice. The "Last updated" date at the top reflects the latest version.
12. Data Processing Agreement and Contact
If you are a customer and require a Data Processing Agreement (DPA) covering our processing of visitor data on your behalf, contact us at privacy@storemetrics.app.
For any privacy questions or requests, contact us at privacy@storemetrics.app.