Who We Are
Prime Ads (“we,” “our,” or “us”) provides an advertising workspace, campaign optimization engine, compliance pre-check tooling, and tracking pixel software accessible via https://www.prime-ads.ai and connected applications, including the Prime Ads 1-Click Shopify application.
Our service is operated by the following legal entity:
Company Name: WCATFM LLC (“Prime Ads”)
Registered Address: 1507 Lampman Ct, Cheyenne, WY 82007-3341, United States
Privacy & DPO Inquiries: privacy@prime-ads.ai
With respect to merchant account information, Prime Ads acts as a Data Controller. With respect to end-customer behavioral and conversion data transmitted from the merchant's online store via our tracking pixel, Prime Ads acts as a Data Processor (or Service Provider under US privacy laws), processing data solely on behalf of and according to the instructions of the merchant, who acts as the Data Controller.
Data Collected from Merchants
When a merchant registers for Prime Ads and connects their Shopify store using our application, we collect and store specific merchant business and authentication records necessary to provide the service:
- Shop Information: Your Shopify store name, primary
.myshopify.comdomain, and store vanity URL. - Authentication & API Tokens: Secure OAuth access tokens issued by Shopify (encrypted at rest), the authorization scopes granted by the merchant — currently limited to
write_pixels,read_pixels, andread_customer_eventsonly — and unique integration record identifiers. - Installation References: The unique identifier of the Shopify Web Pixel registered on your store (
web_pixel_id). - Account Credentials & Profile: Merchant user email address, cryptographically hashed password, business/brand name, designated brand website URLs, and membership role within the workspace.
- Advertising Configuration: Campaign draft parameters, ad account associations, budgets, target destination URLs, and creative assets uploaded by the merchant.
We do not store or process merchant payment card numbers directly; billing and payment operations are handled through authorized payment processors.
Data Collected from the Merchant's Customers Through the Pixel
When the Prime Ads Shopify Web Pixel (or the optional browser script / pixel.gif beacon on non-Shopify sites) is active, it measures visits and conversion events. Data practices differ by path:
A. Events Tracked
The pixel may emit standard conversion and engagement events, including:
| Event Code | Event Name | Trigger & Description |
|---|---|---|
page / PageView | Page View | Recorded when a page loads where the pixel is active. |
view_content | View Content | Triggered when a visitor views a product, collection, or offer page. |
add_to_cart | Add to Cart | Triggered when a visitor adds an item to the cart or visits the cart page. |
purchase | Purchase | Triggered on order confirmation. Includes order ID, monetary value, and currency. |
lead | Lead | Triggered upon newsletter signup, inquiry, or contact form submission (when configured). |
B. Technical Signals Processed Server-Side
- IP Address & User Agent: Read from request headers at our collection endpoint (
/api/tracking/collect). They are used for rate limiting on every request. When the merchant workspace has Co-op enabled, the same values may also be forwarded to Meta's Conversions API (CAPI) for attribution. They are not stored as customer-level records keyed to a Shopify customer identity. - Destination URL & Referrer: Page URL and referring URL associated with the event.
- Event Timestamp & Event ID: Timing and deduplication identifiers (client-generated or order-derived).
- Anonymous Visitor Identifier (non-Shopify script path): Where the optional browser script forwards events to advertising APIs, a salted SHA-256 of IP + User Agent (prefixed with
prime_) may be derived for deduplication without storing plaintext contact data.
C. Shopify Web Pixel — No Customer-Level Records
The Prime Ads Shopify Web Pixel Extension does not collect, transmit, or store customer email addresses, phone numbers, names, postal addresses, or Shopify customer IDs. Checkout and purchase events from the Shopify extension include only commercial metrics (such as order identifier, currency, and transaction value) plus page URL / referrer. Because we keep no customer-level personal recordsfrom this path, a Shopify customers/redact webhook has nothing customer-specific to delete in our systems beyond acknowledging the request.
On non-Shopify websites where a merchant embeds the optional Prime Ads browser script and chooses to supply advanced-matching contact fields, those fields are normalized and cryptographically hashed with SHA-256 before database storage and before transmission to advertising platforms. Plaintext email addresses, phone numbers, or customer names are never stored in our tracking event logs.
App scopes are limited to write_pixels, read_pixels, and read_customer_events. The Shopify web pixel path does not request or retain customer email or phone numbers. Merchant OAuth tokens used to install the pixel are encrypted at rest.
Purpose of Data Processing
All collected data is processed strictly for legitimate commercial and operational purposes:
- Advertising Performance Measurement: Calculating return on ad spend (ROAS), cost per acquisition (CPA), conversion rates, click-through rates, and campaign engagement.
- Campaign Optimization: Supplying verified conversion signals to advertising algorithms to improve ad delivery efficiency and minimize wasted advertising budget.
- Conversion Deduplication: Aligning browser-side pixel signals with server-side conversion API events to prevent double-counting of purchases.
- Pixel Health & Verification: Validating that tracking scripts are correctly installed and actively emitting signals on the merchant's verified domain.
Sharing & Data Recipients
We do not sell personal data, nor do we disclose customer personal information to unauthorized third parties. Data is shared exclusively with the following categories of recipients:
- Advertising platforms: Conversion signals, event telemetry, and cryptographically hashed matching attributes are transmitted via secure APIs to third-party advertising platforms (such as Meta and TikTok) designated by the merchant to attribute and optimize advertising campaigns.
- Infrastructure and hosting providers: Cloud computing, serverless execution environments, managed relational databases, and content delivery networks (specifically AWS, Vercel at
ads-manager-tracking.vercel.app, and Supabase) utilized to host, secure, and deliver the Prime Ads platform and tracking collection endpoints.
Consent & Privacy Controls (Shopify Web Pixel Extension)
On Shopify storefronts, the Prime Ads tracking pixel is deployed as an official Shopify Web Pixel Extension operating in a strict, isolated Web Worker sandbox managed by Shopify.
Our Web Pixel extension declares and strictly adheres to Shopify's Customer Privacy API settings (analytics = true, marketing = true, and sale_of_data = enabled). If a storefront visitor has not provided requisite affirmative consent, or has opted out of advertising measurement or data sale/sharing in relevant jurisdictions (such as the EEA, UK, or California), Shopify's runtime engine automatically suppresses pixel event emission.
Merchants remain the Data Controllers responsible for configuring their storefront cookie banners and consent management rules. Prime Ads respects these preferences automatically at the platform level.
Data Retention, Purge Schedule & Deletion on App Uninstall
We apply strict data minimization and verified automated retention schedules:
- Event Telemetry Retention (90 Days Maximum): Raw and hashed tracking event telemetry (such as page views, product views, and conversion timestamps) are retained in our operational database for a maximum of ninety (90) days to support ad attribution and conversion deduplication. Records older than 90 days are systematically and automatically purged on a daily basis via an automated scheduled cron job.
- Deletion on App Uninstall (app/uninstalled): When a merchant uninstalls the Prime Ads Shopify app, we process
app/uninstalledand delete Shopify-sourced data for that shop only: OAuth tokens / integration records, Shopify pixel readiness flags for that shop URL, pending install state, and Co-op event rows whose page URL references that shop. Other Co-op telemetry for the same workspace (non-Shopify sources) is not wiped by uninstall. - Store Data Erasure (shop/redact): Upon receiving the GDPR
shop/redactwebhook, we apply the same shop-scoped Shopify data purge described above. - Customer Data Erasure (customers/redact): Because the Shopify Web Pixel path stores no customer-level personal records,
customers/redactis acknowledged and logged; there is nothing customer-specific to delete from that path. - Customer Data Request (customers/data_request): We log the request and email the merchant owner (when known) and privacy@prime-ads.ai with a statement that no personal data is stored for that customer from the Shopify pixel.
- Statutory Business Records: Business billing and invoicing records are maintained for up to seven (7) years solely to comply with applicable tax, accounting, and legal requirements.
GDPR and CCPA Rights
Depending on your location, you and your customers may have specific statutory rights under data protection laws, including the EU/UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA):
- Right of Access: The right to request copies of personal data held about you.
- Right to Rectification: The right to request correction of inaccurate or incomplete data.
- Right to Erasure (“Right to be Forgotten”): The right to request deletion of your personal data.
- Right to Restrict or Object: The right to restrict processing or object to processing based on legitimate interests.
- Right to Data Portability: The right to receive your data in a structured, machine-readable format.
- California Privacy Rights (CCPA/CPRA): The right to know what personal information is collected, the right to delete personal information, the right to opt out of the sale or sharing of personal information, and the right to non-discrimination for exercising these rights. We do not sell personal data.
Merchants may exercise their privacy rights by contacting us directly at privacy@prime-ads.ai.
End-customers of a merchant store should submit privacy requests directly to the respective merchant (the Data Controller). As a Data Processor, Prime Ads will assist merchants in fulfilling verified customer requests within statutory timeframes.
International Data Transfers
Prime Ads operates globally, with core database infrastructure and hosting regions situated in the European Union and the United States. When data is transferred internationally, we ensure that adequate safeguards are in place, including Standard Contractual Clauses (SCCs) adopted by the European Commission, UK International Data Transfer Agreements, and reliance on equivalent adequacy frameworks to ensure your data receives comparable protection.
Contact & Inquiries
If you have questions, comments, or requests regarding this Privacy Policy or our data protection practices, please contact our designated Data Protection Officer:
Entity: WCATFM LLC (“Prime Ads”)
Postal Address: 1507 Lampman Ct, Cheyenne, WY 82007-3341, United States
Direct Email: privacy@prime-ads.ai