Privacy Policy
Last updated: July 30, 2026
1. General Information
Protecting your personal data is of the highest importance to us. This Privacy Policy explains what data we collect, how we use it, and what rights you have under the EU General Data Protection Regulation (GDPR).
2. Controller
KPIQ – Alter Günes Pechleraustr. 15 83308 Trostberg, Germany Email: support@kpiq.info
3. Types of Data Processed
We process:
- Contact data (name, email)
- Account & usage data (login data, settings)
- KPI and marketing analytics data provided by users
- Technical data (IP address, browser information, device information, logs)
- Data from integrations (e.g., Shopify) when a user connects external services (details in Section 7)
- Advertising performance data from connected ad platforms (details in Section 8)
4. Purpose of Processing
- Providing KPIQ functions and services
- Analytics, reporting, and optimization of digital performance indicators
- Customer communication, support, and maintenance
- IT security, error management, and fraud prevention
- Compliance with legal requirements
5. Legal Bases
- GDPR Art. 6(1)(b) – contract performance
- GDPR Art. 6(1)(a) – consent (e.g., analytics, tracking)
- GDPR Art. 6(1)(f) – legitimate interest (IT security, improvement of the platform)
6. Data Retention
We store personal data only as long as necessary for the purposes described above or to meet legal obligations.
6a. Storage, Processing and Anonymization of User Data
KPIQ processes analysis and business data provided by users solely to deliver the functionality of the platform.
All processing is performed server-side within KPIQ's infrastructure, hosted on AWS in the European Union (Frankfurt region, eu-central-1).
The processing includes:
- Initial temporary storage: Data entered by users or retrieved from connected platforms is first stored in a secure processing area to enable calculations and analysis.
- Processing and analysis: The data is analyzed to generate metrics, reports, and AI-based insights.
- Anonymization: Personal identifiers are removed or anonymized so that no individual can be identified.
- Archiving anonymized data: Only anonymized data may be stored long-term for system improvement, quality assurance, or statistical evaluation.
- Deletion of personal data: Personal data that is no longer required for platform operation is deleted unless legal retention duties apply.
These processing steps are not related to cookies and apply exclusively to server-side processing necessary to provide KPIQ services.
7. Shopify App / Shopify Integration
The KPIQ Shopify App is active and available on the Shopify App Store.
7.1 Data Processed
If a user installs the KPIQ Shopify App, we may process:
- Store information (store name, domain)
- API scopes granted by the merchant
- Order data (financial totals such as order value and order count) and product data
- Performance and marketing metrics provided by the merchant or connected ad platforms
- Metadata related to app usage and API load
Protected Customer Data — Data Minimization
Shopify's orders permission includes customer personal details (such as name, address, email, and phone number) by default. KPIQ requests order data at the minimum access level required and does not collect, process, or store these customer personal fields. We process only aggregate order financial values (such as total revenue and average order value) together with product and performance metrics. No individual customer is identified or profiled, and raw order records are not retained — only the computed diagnostic output is stored. In short: KPIQ never collects or stores customer details — only your sales and product metrics.
7.2 Purpose
- Syncing data between Shopify and KPIQ
- Providing analytics and performance insights
- Improving app features
7.3 Data Deletion upon Uninstall
Upon uninstall:
- Access to Shopify data is immediately revoked
- All associated personal data is deleted within 30 days, with one exception: a minimal, pseudonymized free-trial marker (see 7.6) is retained for up to 180 days to prevent repeated use of the free trial.
7.4 Merchant Rights
Shopify merchants may:
- Request a copy of their stored data
- Request deletion at any time
Contact: support@kpiq.info
7.5 AI Processing
Performance data submitted by merchants or retrieved from connected ad platforms may be processed by our AI service provider (Anthropic) to generate narrative analytics insights. No personal customer data is transmitted to AI providers. Only aggregate KPI data (such as ROAS, CTR, conversion rate) is used for this purpose.
7.6 Free-Trial Abuse Prevention
KPIQ grants each store one free trial diagnostic report. To prevent abuse — for example, a store uninstalling and reinstalling to obtain repeated free reports — we retain a minimal marker indicating that a store has already used its free trial. This marker contains no order data and no customer contact details (no name, email, address, or phone); it consists only of a pseudonymized store reference (or the Shopify-assigned account identifier) together with a "used" flag. It is retained on the basis of our legitimate interest in preventing repeated misuse of the free trial (GDPR Art. 6(1)(f)) and is automatically deleted within 180 days. This is the only information intentionally retained beyond the deletion described in Section 7.3.
8. Advertising Platform Integrations (Meta, TikTok, Google Ads)
KPIQ allows users to connect their advertising accounts (currently TikTok for Business, Meta (Facebook/Instagram) Ads, and Google Ads) so that advertising performance data can be retrieved automatically instead of being entered manually.
8.1 Connection and Authorization
Connections are established via the official OAuth authorization flow of the respective platform. KPIQ receives an access token limited to the scopes the user has explicitly granted (for example, read-only access to advertising performance data such as Meta's ads_read permission). KPIQ never receives or stores the user's platform password. Access tokens are stored encrypted within our infrastructure and are used exclusively to retrieve the data described below.
8.2 Data Retrieved
From connected advertising accounts, KPIQ retrieves only advertising performance data, such as:
- Campaign, ad set, and ad level performance metrics (e.g., impressions, clicks, CTR, CPM, spend, conversions, ROAS)
- Account and campaign metadata (e.g., campaign names, ad account identifiers) required to attribute metrics correctly
KPIQ does not retrieve or process personal data of the end users or customers who see or interact with the advertisements (no audience lists, no individual user profiles, no contact details).
8.3 Purpose and Legal Basis
The retrieved data is used solely to generate diagnostic reports, performance analyses, and growth signals for the connecting user. The legal basis is contract performance (GDPR Art. 6(1)(b)), as data retrieval is initiated by the user connecting their account.
8.4 Disconnecting
Users can disconnect a platform at any time within KPIQ. Upon disconnection, the stored access token is invalidated and deleted, and no further data is retrieved from that platform. Users can additionally revoke KPIQ's access directly in the settings of the respective platform (e.g., Facebook Business Integrations settings, Google account permissions).
8.5 Security of Processing (Technical and Organizational Measures)
We protect all sensitive data — including advertising performance data retrieved from connected platforms such as Google Ads, Meta, and TikTok — with the following technical and organizational measures:
- Encryption in transit: All data is transmitted exclusively over TLS/HTTPS, both between your browser and KPIQ and between KPIQ and platform APIs (including the Google Ads API).
- Encryption at rest: OAuth tokens and platform credentials are stored in encrypted form on AWS infrastructure (AWS Secrets Manager and encrypted databases in the EU Frankfurt region, eu-central-1). Refresh tokens are never exposed to the browser and are never stored client-side.
- Access control: Access to production systems follows the least-privilege principle. Advertising data is only ever displayed to the authenticated user who owns the connected account; no other user or third party can access it.
- Data minimization: We retrieve only the campaign performance metrics required to generate reports, for the reporting period selected by the user (see Section 8.2). Deletion and disconnection rights are described in Sections 8.4 and 9.
8.6 Google API Services — Limited Use Disclosure
KPIQ's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used solely to provide the reporting features visible to the user within KPIQ. It is never sold, never transferred to third parties except as necessary to provide these features (see Section 10), never used for advertising purposes, and never used to train generalized machine-learning models.
9. Data Deletion
You can request the deletion of your personal data at any time:
- Shopify App: Uninstalling the KPIQ app from your Shopify store triggers the deletion process described in Section 7.3.
- Advertising platform connections: Disconnecting a platform within KPIQ, or revoking KPIQ's access in the platform's own settings, stops all data retrieval; the associated access token is deleted (Section 8.4).
- Deletion request by email: You may request complete deletion of all personal data associated with your account by writing to support@kpiq.info. We will confirm and complete the deletion within 30 days, unless legal retention duties apply. The only data intentionally retained beyond this is the pseudonymized free-trial marker described in Section 7.6, which is automatically deleted within 180 days.
10. Sharing with Service Providers
Data is shared only with carefully selected and GDPR-compliant processors, including:
- Hosting providers (Amazon Web Services, EU region Frankfurt)
- AI service providers (Anthropic) — aggregate KPI data only, see Section 7.5
- Security and analytics providers
- Email service providers for support communication
11. International Transfers
Transfers outside the EU are conducted only with GDPR-compliant safeguards (e.g., Standard Contractual Clauses).
12. User Rights
Under the GDPR, you have the following rights:
- Right of access
- Right to rectification
- Right to erasure
- Right to restriction of processing
- Right to data portability
- Right to withdraw consent
- Right to lodge a complaint with a supervisory authority
13. Contact
For data protection inquiries: support@kpiq.info