ProfitTap Privacy Policy
ProfitTap shows one product recommendation on your product pages and charges a commission only on the sales it generates. To do that it needs very little data — and this page sets out exactly what it holds, why, for how long, and what you can ask us to do about it.
The short version. We never store your shoppers' names, email addresses, postal addresses, phone numbers or IP addresses. For each sale we attribute we keep a pseudonymous cart and order reference, the recommended product variant and the value of the sale — the minimum needed to attribute that sale and invoice the commission. Those references are erased after 24 months. We use no analytics, no advertising and no tracking of any kind.
1. Who we are
ProfitTap is operated by Joaquim Llort Grau (trading as Web Forge Pro), a sole trader established in Molins de Rei, Barcelona, Spain, tax identification number 34760392D.
For any question about this policy or about your data, write to info@webforgepro.net. Given the scale and nature of our processing we are not required to appoint a Data Protection Officer, so that address reaches us directly.
2. Who this policy is for
It covers two different groups, and our responsibilities differ for each:
- Merchants — the Shopify store owners and staff who install and use ProfitTap. For their data we act as the controller: we decide why and how it is processed.
- Shoppers — the customers of those stores. For the little we hold about them we act as a processor on the merchant's behalf: the merchant decides the purpose, and we act on their instructions and on Shopify's.
If you are a shopper and want your data erased, the fastest route is to ask the store you bought from. Shopify passes that request to us automatically and we act on it — see section 9.
3. What we process
Merchant data
| Data | Why we hold it | Legal basis |
|---|---|---|
| Your store domain and the Shopify access token issued when you install the app | To connect to your store and do what the app does at all | Performance of our contract with you |
| Your app settings: recommendation rules, chosen products, panel language, trial start date | To run the app the way you configured it | Performance of our contract |
| Billing state: your Shopify subscription reference, approved spending limit and currency | To charge the commission through Shopify and to show you what you owe | Performance of our contract, and legal obligation for accounting records |
Shopify's session record can also carry the name, email address and locale of the staff member who installs an app. ProfitTap uses offline access tokens, so those fields stay empty in our database; if that ever changes, this policy will be updated before it does.
Shopper data
| Data | Why we hold it | Retention |
|---|---|---|
| A pseudonymous cart token issued by Shopify | To link an item added through our banner to the order it ends up in | 24 months |
| The order reference of an attributed sale | To prove which sale a commission relates to, if a merchant queries an invoice | 24 months, or longer while a commission for it is still unpaid |
| The recommended product variant, the quantity our button added, the sale value and currency, and the date | To calculate the commission. These identify no one | Kept as the merchant's billing record |
A cart token identifies a shopping session rather than a person, but under the GDPR it is still an online identifier and therefore personal data. We treat it as such, which is why it is listed here and why it expires.
What we never collect. No names, no email addresses, no postal addresses, no phone numbers, no IP addresses, no browsing history, no cookies of our own, no fingerprinting, and no profiles of any kind. We run no analytics and no advertising, and we sell nothing to anybody.
4. Where shopper data comes from
We do not collect it from shoppers directly. It reaches us in two ways, both from Shopify:
- When a shopper taps our banner, the storefront tells us which variant was added and passes the cart token for that session.
- When an order is paid, Shopify sends us a notification about that order. That notification can contain more than we need — we read only the line items, the amounts, the currency and the order reference, and store nothing else from it.
5. Why we process it
- To provide the service — showing the recommendation and attributing the sales it produces. Basis: performance of our contract with the merchant.
- To invoice the commission through Shopify's billing. Basis: performance of our contract, plus our legal obligation to keep accounting records.
- To keep the service working and secure — technical logs recording which store an operation belonged to and whether it succeeded. Basis: our legitimate interest in operating a reliable service. Those logs record store domains and order references, never shopper identities.
6. Who else is involved
- Shopify. Both the source of the data and the channel through which commissions are charged. Your own relationship with Shopify is governed by Shopify's terms and privacy policy, not by this one.
- Hostinger, our hosting provider, which operates the servers and the database where the data above is stored. They act on our instructions and have no independent use for it.
That is the entire list. ProfitTap uses no analytics provider, no advertising network, no customer-support platform, no email marketing tool and no content delivery network of its own. We never sell, rent or share personal data, and we never use it to train anything.
7. Where your data is stored
ProfitTap's application and database run on servers located in France, and backups are held in Lithuania — both within the European Union. We make no transfers of personal data outside the European Economic Area for our own purposes.
Data that reaches us through Shopify travels through Shopify's own infrastructure first, governed by your agreement with Shopify rather than by this policy.
8. How long we keep it
- Merchant data — for as long as the app is installed. When you uninstall, Shopify notifies us and your access tokens are deleted immediately; the remaining store record is erased when Shopify sends the store-erasure request that follows an uninstall.
- Shopper identifiers — 24 months from the date of the event, after which an automated job erases the cart token and the order reference and keeps only the anonymous commercial facts. The one exception: where a commission for that sale has not yet been charged, the order reference is kept until it is, because it is the evidence behind an invoice we are legally required to be able to justify.
- Technical logs — retained by our hosting provider under their own rotation policy.
9. Your rights
You have the right to access your data, to have it rectified or erased, to restrict or object to its processing, and to receive it in a portable format. You can object at any time to processing based on our legitimate interest.
To exercise any of them, write to info@webforgepro.net. We answer within one month, extendable by two further months if the request is complex — in which case we will tell you before the first month is up. We do not charge for this.
Shopify also gives shoppers an automated route. When a shopper asks a store for their data or for erasure, Shopify forwards that request to us and we handle it:
- Data request — we report every identifier we hold for the orders concerned.
- Erasure — we remove the cart token and the order name for those orders. Where a commission for the sale has not yet been charged, the bare order reference is kept on the legal basis described in section 8; nothing that names or contacts the shopper is retained, because we never held it.
- Store erasure — when a merchant leaves Shopify, everything we hold for that store is deleted.
If you believe we have handled your data badly, please tell us first — we would rather fix it. You also have the right to complain to the Spanish Data Protection Agency (AEPD) or to the supervisory authority of the country you live in.
10. Security
All traffic between your store, your shoppers and ProfitTap travels over HTTPS. Access to the database is restricted to the application itself, over an authenticated connection. The app requests only read permissions on your store's products and orders — it cannot modify your catalogue, your orders or your theme. There is no ProfitTap account, no password for you to manage and no admin console outside your own Shopify admin.
We are a small operation and we would rather be honest about the limits of that: we hold the minimum data possible precisely because the strongest protection for information is not to have it.
11. Changes to this policy
If we change what we process or why, we will update this page and change the version and date at the top before the change takes effect. Material changes will also be announced in the app.
Free to install. No monthly fee. You pay 3% only on the sales ProfitTap generates for you — and nothing on the rest of the order.
Install on Shopify30-day free trial · Monthly cap you approve · Turn it off yourself, any time