Cong Pulse

Privacy Policy

Effective date: July 16, 2026

1. Introduction

Cong Pulse (“we,” “us,” or “our”) is a marketing analytics service provided by Congtent for ecommerce merchants. With your permission, we connect to your Shopify store and your Meta (Facebook/Instagram) Ads account, combine the data, and present it as a dashboard showing campaign performance, attribution, return on ad spend (ROAS), and related metrics.

This policy explains what we collect, why, who we share it with, how long we keep it, and the choices and rights you have. It applies to merchants who use Cong Pulse and to the store data that flows through our service — including limited information about your customers that originates in your Shopify store. We act as a data processor on behalf of the merchant for store and customer data; the merchant is the data controller for their customers' information.

2. Data we collect

We collect data from three sources: your Shopify store, your Meta Ads account, and your Cong Pulse account itself.

a. From your Shopify store

When you connect Shopify, we read order and store data through Shopify's official API. This includes a limited amount of personal information about your customers:

  • Customer identifiers: the Shopify customer ID and the customer email address associated with each order.
  • Order details: order numbers, totals, subtotals, taxes, discounts, shipping amounts, currency, financial and fulfillment status, and order/refund dates.
  • Line items: product and variant IDs, product titles, SKUs, quantities, prices, and (where you provide it) cost of goods sold.
  • Marketing attribution: UTM parameters (source, medium, campaign, content, term) and the landing-page and referring-page URLs recorded on each order.
  • Store metadata: your shop domain, store name, store owner email, currency, timezone, plan, and daily aggregate analytics (sessions, add-to-carts, checkouts started).

b. From your Meta Ads account

When you connect Meta, we read advertising data through Meta's Graph API. This data is aggregated performance data — it describes campaigns, not individual people, and is not personally identifiable:

  • Ad account, campaign, ad set, and ad IDs, names, status, and budgets.
  • Daily performance metrics: spend, impressions, clicks, reach, frequency, CPM/CPC/CTR, conversions and conversion value, add-to-cart and checkout events, and video view counts.
  • Aggregate demographic/geographic breakdowns (age range, gender, country) at the ad level — counts only, never individual identities.

c. Your Cong Pulse account

  • The name and email address you use to sign up and log in.
  • OAuth access tokens for your connected Shopify and Meta accounts, stored encrypted.
  • Basic operational records (for example, when a sync ran and whether it succeeded) used to keep your dashboard up to date.

3. How we use the data

We use the data above solely to provide the service:

  • To build and refresh your analytics dashboard — campaign performance, attribution, ROAS, customer and order trends.
  • To match Shopify orders to Meta ads using the UTM parameters on each order, so you can see which campaigns drove sales.
  • To generate optional AI-written summaries of your results. When this feature is enabled, we send only aggregated, non-personal metrics (such as total spend, total revenue, ROAS, order counts, and conversion rates) to our AI provider. We never send customer emails, customer IDs, or any individual-level data to the AI provider.
  • To operate, secure, debug, and improve the service.

We do not sell your data, and we do not use it for advertising, retargeting, or any purpose other than providing the service to you.

4. Data we do not collect

To be explicit, Cong Pulse does not collect or store:

  • Customer names.
  • Customer phone numbers.
  • Customer billing or shipping addresses.
  • Payment card numbers or any payment credentials (these never leave Shopify; we never see them).
  • Government identifiers or dates of birth.
  • Tracking of individual shoppers across other websites — we do not place cookies or pixels on your storefront.

5. Sharing with third parties (subprocessors)

We do not sell or rent your data. We share it only with the infrastructure providers (“subprocessors”) we rely on to run the service. Each processes data only to perform its function for us:

  • Supabase — hosts our database and authentication. All merchant, store, customer, and Meta data is stored here. Region: Sydney, Australia.
  • Vercel — hosts and runs the application and its background functions. Region: Sydney, Australia.
  • Inngest — runs our background jobs, including the scheduled data syncs and the deletion jobs that fulfill GDPR requests.
  • Anthropic — provides the AI model behind the optional AI Insights feature. It receives only aggregated, non-personal metrics, and only when the feature is in use.

We also exchange data with Shopify and Meta as the original sources of your store and advertising data, under your authorization and their respective terms. We may disclose data if required by law or to protect our rights, and we would transfer data as part of a merger or acquisition (you would be notified).

6. Data retention

We keep your data for as long as your account is active and your accounts remain connected, so your dashboard reflects your full history.

  • Records removed at the source.When an order or other record is deleted in Shopify or Meta, we mark our copy as deleted (a “soft delete”) so it no longer appears in your dashboard. This lets us recover from sync errors without losing correct data.
  • After you uninstall the app. Shopify sends us a shop redaction request approximately 48 hours after you uninstall. When we receive it, we open a further 48-hour safety window (in case the uninstall was accidental or reversed), and then permanently deleteall of that store's data — Shopify data, the associated Meta data, connection tokens, and the workspace itself. In practice this means full deletion completes within roughly four days of uninstalling.
  • Compliance records.After a deletion we keep a small, permanent audit record proving the deletion occurred (for example, “store X redacted on date Y, N records deleted”). This record contains no personal information — only the store domain and counts.

7. Data deletion and GDPR requests

Cong Pulse implements Shopify's mandatory privacy webhooks, which are the standard way merchants and their customers request data through Shopify:

  • Customer data request (customers/data_request) — when a customer asks the merchant for their data, we compile the order history we hold for that customer and provide it to the store owner to fulfill the request.
  • Customer redaction (customers/redact) — when a customer asks to be erased, we anonymize that customer's orders by removing their email and customer ID. Aggregate figures (order totals and dates) are kept in de-identified form so your historical analytics remain accurate.
  • Shop redaction (shop/redact) — as described in retention above, this permanently deletes the entire store's data after the 48-hour safety window.

Customers should direct data requests to the store they purchased from; the merchant initiates the request through Shopify, which notifies us automatically. Merchants can also email us directly (see Contact below) to request access to, or deletion of, their data.

8. Security

We protect your data with multiple safeguards:

  • Encryption in transit and at rest. All connections use TLS, and the database is encrypted at rest. OAuth access tokens are additionally encrypted with a separate application key before they are stored.
  • Tenant isolation.Database row-level security ensures each merchant can only ever read their own organization's data.
  • Verified webhooks. Incoming Shopify webhooks are verified with a constant-time HMAC-SHA256 signature check; requests that fail verification are rejected and never processed.
  • Least-privilege access.Internal administrative access is restricted, logged, and read-only when viewing a merchant's workspace.

9. International data transfers

Your store and advertising data is stored in Australia (Sydney region). Some processing happens elsewhere — for example, our AI provider (Anthropic) and our background-job provider (Inngest) operate in the United States, so aggregated metrics or job metadata may be processed there. Where data is transferred across borders, we rely on our providers' contractual data-protection commitments to keep it protected to a comparable standard.

10. Your rights

Depending on your location, you may have the right to access, correct, export (portability), delete, or object to the processing of your personal data. Merchants can exercise these rights at any time:

  • Access & portability: email us and we will provide the data we hold about you in a portable format.
  • Deletion: uninstall the app (which triggers full deletion as described above) or email us to request deletion directly.
  • Correction & objection: email us and we will address your request.

For data about a merchant's customers, requests are handled through the merchant via Shopify's standard process described in section 7.

11. Children's data

Cong Pulse is a business-to-business tool for store owners and is not directed at children. We do not knowingly collect personal data from children under 13 (or the minimum age in your jurisdiction). The customer data we process is incidental order information supplied by the merchant's store, not data we collect from individuals directly.

12. Changes to this policy

We may update this policy as the service evolves or as laws change. If we make a material change, we will update the effective date at the top of this page and notify active merchants by email or an in-app notice before the change takes effect. Continued use of the service after an update means you accept the revised policy.

13. Contact us

Questions, concerns, or requests about this policy or your data? Email our privacy team at analytics@congtent.com.