Last updated: October 1, 2026
Profit Pie accesses your Shopify store's order data, product data, and payment dispute data to calculate profit margins, COGS, and financial metrics. Customer names and email addresses may be shown in the app (recent orders, cohorts, exports) when you view them — they are read from Shopify and are not stored in our database. We store merchant-entered data: product costs, custom overhead costs, app settings, and optional integration credentials you provide.
This section describes the specific safeguards we use to protect sensitive data, including Google user data obtained through Google OAuth (Google Ads access tokens, refresh tokens, ad account IDs, and ad spend), Shopify access tokens, and other integration credentials. 1. Encryption in transit. All traffic to and from Profit Pie is encrypted with HTTPS/TLS. Our servers force HTTPS and reject plain HTTP. All calls we make to Google APIs (OAuth and the Google Ads API) and to Shopify use HTTPS/TLS. Connections between our application servers and our database are also encrypted with TLS. 2. Encryption at rest. Sensitive data, including Google OAuth access and refresh tokens, is stored in a MongoDB Atlas database whose storage volumes and backups are encrypted at rest with AES-256. In addition, Google OAuth access and refresh tokens are individually encrypted by our application with AES-256-GCM before they are written to the database, using a key held only in our encrypted secrets store, so the database never contains these tokens in readable form. Application secrets (such as our Google OAuth client secret and Google Ads developer token) are kept in Fly.io's encrypted secrets store. They are never written into source code and never sent to the browser. 3. Server-side only token handling. Google OAuth tokens are only used on our servers. They are never sent to the merchant's browser, included in page content, shown in the app, or shared with any third party. 4. Access controls and isolation. Each shop's data, including its Google Ads connection, is stored separately, tied to that shop, and only reachable through that shop's authenticated Shopify session. One merchant can never see another merchant's data. Access to production systems and the database is limited to authorized Primitive Labs personnel who need it to operate the service, and requires authenticated credentials. 5. Secure OAuth flow. The Google OAuth flow uses a cryptographically signed (HMAC-SHA256), time-limited state parameter to prevent cross-site request forgery and to make sure a Google account can only be linked to the shop that started the connection. We request only the single Google Ads scope needed to read ad spend. 6. Data minimization. From Google we only read the ad account ID, account name, and ad spend needed to show the merchant their own advertising costs in profit reports. We do not request or store Google profile data, contacts, or email content. 7. Limited use. Google user data is used only to provide the user-facing ad spend feature. It is not sold, not used for advertising, not used to train AI/ML models, and not transferred to anyone except as needed to provide the feature, comply with law, or protect against security issues. Our use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. 8. Deletion. When a merchant clicks Disconnect for Google Ads on the Integrations page, their stored Google tokens and account selection are permanently deleted right away. When a merchant uninstalls the app, all data stored for the shop, including any Google Ads connection, is permanently deleted when Shopify sends the shop redact request (about 48 hours after uninstall). Merchants can also revoke Profit Pie's access at any time at https://myaccount.google.com/permissions. 9. Incident response. If we become aware of unauthorized access to sensitive data, we will investigate right away, contain the issue, revoke or rotate affected credentials, and notify affected merchants without undue delay as required by applicable law.
Data is used only to show profit and cost breakdowns to the merchant who installed the app. We do not sell data or use it for advertising.
Customer name and email are not persisted in our database. Merchant business settings are kept while the app is installed.
Optional integrations (Meta, Google, TikTok ads; Shippo, ShipStation, EasyPost, Stripe) are only used when you connect them, to pull your spend or cost data. We do not send customer personal data to those services.
If you connect Google Ads, we access your ad account ID and ad spend. We treat this as sensitive data and only pull it after you connect Google. It is used only to show you your own ad spend in your profit reports. Google access tokens and integration credentials are encrypted in transit (HTTPS/TLS) and at rest (AES-256), Google tokens are additionally encrypted by our application (AES-256-GCM) before storage, are stored per shop, and are never sent to the browser. They are not sold or used for advertising. Only your own shop can access its connection and data. See "Data Protection Mechanisms for Sensitive Data" above for the full list of safeguards. You can disconnect Google Ads at any time from the Integrations page, which deletes the stored connection. After you uninstall the app, Shopify sends a shop redact request (about 48 hours later), and we then delete all stored data for your shop, including any Google Ads connection.
We comply with Shopify's mandatory GDPR webhooks. Because we do not store customer PII, customer data requests are acknowledged with no additional records to return.
Privacy questions: hello@profitpieanalytics.io