Privacy Policy

Prime Ads Privacy Policy

This Privacy Policy describes how Prime Ads collects, processes, and protects information when merchants use our platform and install the Prime Ads Shopify tracking pixel.

Last updated: October 3, 2026·Official Legal Policy
Section 1

Who We Are

Prime Ads (“we,” “our,” or “us”) provides an advertising workspace, campaign optimization engine, compliance pre-check tooling, and tracking pixel software accessible via https://www.prime-ads.ai and connected applications, including the Prime Ads 1-Click Shopify application.

Our service is operated by the following legal entity:

Data Controller & Operator

Company Name: WCATFM LLC (“Prime Ads”)
Registered Address: 1507 Lampman Ct, Cheyenne, WY 82007-3341, United States
Privacy & DPO Inquiries: privacy@prime-ads.ai

With respect to merchant account information, Prime Ads acts as a Data Controller. With respect to end-customer behavioral and conversion data transmitted from the merchant's online store via our tracking pixel, Prime Ads acts as a Data Processor (or Service Provider under US privacy laws), processing data solely on behalf of and according to the instructions of the merchant, who acts as the Data Controller.

Section 2

Data Collected from Merchants

When a merchant registers for Prime Ads and connects their Shopify store using our application, we collect and store specific merchant business and authentication records necessary to provide the service:

  • Shop Information: Your Shopify store name, primary .myshopify.com domain, and store vanity URL.
  • Authentication & API Tokens: Secure OAuth access tokens issued by Shopify (encrypted at rest), the authorization scopes granted by the merchant — currently limited towrite_pixels, read_pixels, and read_customer_events only — and unique integration record identifiers.
  • Installation References: The unique identifier of the Shopify Web Pixel registered on your store (web_pixel_id).
  • Account Credentials & Profile: Merchant user email address, cryptographically hashed password, business/brand name, designated brand website URLs, and membership role within the workspace.
  • Advertising Configuration: Campaign draft parameters, ad account associations, budgets, target destination URLs, and creative assets uploaded by the merchant.

We do not store or process merchant payment card numbers directly; billing and payment operations are handled through authorized payment processors.

Section 3

Data Collected from the Merchant's Customers Through the Pixel

When the Prime Ads Shopify Web Pixel (or the optional browser script / pixel.gif beacon on non-Shopify sites) is active, it measures visits and conversion events. Data practices differ by path:

A. Events Tracked

The pixel may emit standard conversion and engagement events, including:

Event CodeEvent NameTrigger & Description
page / PageViewPage ViewRecorded when a page loads where the pixel is active.
view_contentView ContentTriggered when a visitor views a product, collection, or offer page.
add_to_cartAdd to CartTriggered when a visitor adds an item to the cart or visits the cart page.
purchasePurchaseTriggered on order confirmation. Includes order ID, monetary value, and currency.
leadLeadTriggered upon newsletter signup, inquiry, or contact form submission (when configured).

B. Technical Signals Processed Server-Side

  • IP Address & User Agent: Read from request headers at our collection endpoint (/api/tracking/collect). They are used for rate limiting on every request. When the merchant workspace has Co-op enabled, the same values may also be forwarded to Meta's Conversions API (CAPI) for attribution. They are not stored as customer-level records keyed to a Shopify customer identity.
  • Destination URL & Referrer: Page URL and referring URL associated with the event.
  • Event Timestamp & Event ID: Timing and deduplication identifiers (client-generated or order-derived).
  • Anonymous Visitor Identifier (non-Shopify script path): Where the optional browser script forwards events to advertising APIs, a salted SHA-256 of IP + User Agent (prefixed with prime_) may be derived for deduplication without storing plaintext contact data.

C. Shopify Web Pixel — No Customer-Level Records

The Prime Ads Shopify Web Pixel Extension does not collect, transmit, or store customer email addresses, phone numbers, names, postal addresses, or Shopify customer IDs. Checkout and purchase events from the Shopify extension include only commercial metrics (such as order identifier, currency, and transaction value) plus page URL / referrer. Because we keep no customer-level personal recordsfrom this path, a Shopify customers/redact webhook has nothing customer-specific to delete in our systems beyond acknowledging the request.

On non-Shopify websites where a merchant embeds the optional Prime Ads browser script and chooses to supply advanced-matching contact fields, those fields are normalized and cryptographically hashed with SHA-256 before database storage and before transmission to advertising platforms. Plaintext email addresses, phone numbers, or customer names are never stored in our tracking event logs.

Shopify Protected Customer Data

App scopes are limited to write_pixels, read_pixels, and read_customer_events. The Shopify web pixel path does not request or retain customer email or phone numbers. Merchant OAuth tokens used to install the pixel are encrypted at rest.

Section 4

Purpose of Data Processing

All collected data is processed strictly for legitimate commercial and operational purposes:

  • Advertising Performance Measurement: Calculating return on ad spend (ROAS), cost per acquisition (CPA), conversion rates, click-through rates, and campaign engagement.
  • Campaign Optimization: Supplying verified conversion signals to advertising algorithms to improve ad delivery efficiency and minimize wasted advertising budget.
  • Conversion Deduplication: Aligning browser-side pixel signals with server-side conversion API events to prevent double-counting of purchases.
  • Pixel Health & Verification: Validating that tracking scripts are correctly installed and actively emitting signals on the merchant's verified domain.
Section 5

Sharing & Data Recipients

We do not sell personal data, nor do we disclose customer personal information to unauthorized third parties. Data is shared exclusively with the following categories of recipients:

  • Advertising platforms: Conversion signals, event telemetry, and cryptographically hashed matching attributes are transmitted via secure APIs to third-party advertising platforms (such as Meta and TikTok) designated by the merchant to attribute and optimize advertising campaigns.
  • Infrastructure and hosting providers: Cloud computing, serverless execution environments, managed relational databases, and content delivery networks (specifically AWS, Vercel at ads-manager-tracking.vercel.app, and Supabase) utilized to host, secure, and deliver the Prime Ads platform and tracking collection endpoints.
Section 7

Data Retention, Purge Schedule & Deletion on App Uninstall

We apply strict data minimization and verified automated retention schedules:

  • Event Telemetry Retention (90 Days Maximum): Raw and hashed tracking event telemetry (such as page views, product views, and conversion timestamps) are retained in our operational database for a maximum of ninety (90) days to support ad attribution and conversion deduplication. Records older than 90 days are systematically and automatically purged on a daily basis via an automated scheduled cron job.
  • Deletion on App Uninstall (app/uninstalled): When a merchant uninstalls the Prime Ads Shopify app, we process app/uninstalled and delete Shopify-sourced data for that shop only: OAuth tokens / integration records, Shopify pixel readiness flags for that shop URL, pending install state, and Co-op event rows whose page URL references that shop. Other Co-op telemetry for the same workspace (non-Shopify sources) is not wiped by uninstall.
  • Store Data Erasure (shop/redact): Upon receiving the GDPR shop/redact webhook, we apply the same shop-scoped Shopify data purge described above.
  • Customer Data Erasure (customers/redact): Because the Shopify Web Pixel path stores no customer-level personal records, customers/redact is acknowledged and logged; there is nothing customer-specific to delete from that path.
  • Customer Data Request (customers/data_request): We log the request and email the merchant owner (when known) and privacy@prime-ads.ai with a statement that no personal data is stored for that customer from the Shopify pixel.
  • Statutory Business Records: Business billing and invoicing records are maintained for up to seven (7) years solely to comply with applicable tax, accounting, and legal requirements.
Section 8

GDPR and CCPA Rights

Depending on your location, you and your customers may have specific statutory rights under data protection laws, including the EU/UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA):

  • Right of Access: The right to request copies of personal data held about you.
  • Right to Rectification: The right to request correction of inaccurate or incomplete data.
  • Right to Erasure (“Right to be Forgotten”): The right to request deletion of your personal data.
  • Right to Restrict or Object: The right to restrict processing or object to processing based on legitimate interests.
  • Right to Data Portability: The right to receive your data in a structured, machine-readable format.
  • California Privacy Rights (CCPA/CPRA): The right to know what personal information is collected, the right to delete personal information, the right to opt out of the sale or sharing of personal information, and the right to non-discrimination for exercising these rights. We do not sell personal data.
Exercising Your Rights

Merchants may exercise their privacy rights by contacting us directly at privacy@prime-ads.ai.
End-customers of a merchant store should submit privacy requests directly to the respective merchant (the Data Controller). As a Data Processor, Prime Ads will assist merchants in fulfilling verified customer requests within statutory timeframes.

Section 9

International Data Transfers

Prime Ads operates globally, with core database infrastructure and hosting regions situated in the European Union and the United States. When data is transferred internationally, we ensure that adequate safeguards are in place, including Standard Contractual Clauses (SCCs) adopted by the European Commission, UK International Data Transfer Agreements, and reliance on equivalent adequacy frameworks to ensure your data receives comparable protection.

Section 10

Cookies and Similar Technologies

The Prime Ads platform and pixel utilize standard web technologies to fulfill tracking and security functions:

  • Session Cookies: Used on the Prime Ads portal for authenticated merchant login sessions, CSRF protection, and account workspace routing.
  • Tracking Beacons & Scripts: The pixel script (script.js) dynamically loads client-side tracking functions and dispatches asynchronous beacons (via navigator.sendBeacon or HTTP POST) to our collection endpoint.
  • 1x1 Transparent Pixel GIF: Provided as a fallback noscript tag (/p/{tenantId}/pixel.gif) to record basic PageView signals when JavaScript is disabled.
Section 11

Contact & Inquiries

If you have questions, comments, or requests regarding this Privacy Policy or our data protection practices, please contact our designated Data Protection Officer:

Data Protection Office

Entity: WCATFM LLC (“Prime Ads”)
Postal Address: 1507 Lampman Ct, Cheyenne, WY 82007-3341, United States
Direct Email: privacy@prime-ads.ai