Ghost Revenue
Privacy Policy
Last updated: September 8, 2026
Who we are
Ghost Revenue is a Shopify app operated by Ghost Revenue LLC. The app analyzes a merchant's store to produce a conversion-optimization audit and recommendations. This policy explains what store data we access, what we do not collect, how we use and protect that data, and how merchants can request deletion.
Contact: carson@ghostrevenue.co. Legal entity: Ghost Revenue LLC. Registered address: 1968 S. Coast Hwy #4588, Laguna Beach, CA 92651, United States. Effective date: September 8, 2026.
What data we access
Ghost Revenue accesses store and business data from Shopify so we can run the audit and recommendations. The scopes we use cover theme, catalog, orders, storefront events, and store content — not customer identity. Specifically, we access:
- Theme files and settings
- Products and collections
- Orders — aggregate totals and timestamps only, used to estimate revenue and conversion. We do not access line items or customer identity on orders
- First-party storefront funnel events collected by the Ghost Revenue web pixel (Shopify standard Customer Events API only — no theme injection, scroll tracking, or heatmaps). For each event we may store: event name, timestamp, shop domain, a rotating anonymous session id (resets daily; no persistent visitor or device id), coarse device category (mobile / tablet / desktop), viewport width bucket (not exact pixels), referrer host (hostname only — never a full URL or path), landing UTM tags parsed from the first page URL in each session (
utm_source,utm_medium, andutm_campaignonly — max 100 characters each; neverutm_contentorutm_term; never the full landing URL), coarse page type (home / collection / product / cart / checkout / other), product id for product and cart-line events, item count on cart and checkout events, order total + currency on cart view, checkout start, and completed checkout, a sanitised search query retained only when the search returned zero results (max 100 characters; queries that look like an email or phone are dropped entirely) plus search result count for all searches, and a normalised alert type for form validation errors (invalid_email, invalid_phone, invalid_address, payment_declined, required_field_missing, other — never the raw error message, which can echo what a shopper typed). We do not collect customer names, email addresses, phone numbers, postal addresses, payment details, IP addresses, verbatim user-agent strings, full URLs or paths, or line-item customer context from checkout events. Measurement respects the merchant's own customer privacy / cookie consent settings (runtime_context = strict): we never receive events Shopify withholds for lack of consent, and we do not work around a missing consent signal. - Store policies and online-store content, including pages and blog posts
- Downscaled screenshots of public storefront pages (home, collection, product, cart, and policies) captured during an audit, used so findings can be checked against what was on the page at audit time. Only public storefront pages are captured — never Shopify Admin or payment interfaces. Customer-facing content already published on the storefront (for example reviews or customer photos) may appear in those screenshots. Screenshots are deleted after 30 days, or earlier when the shop is redacted via Shopify's
shop/redactwebhook, whichever comes first. - Shop metafields
This is merchant store data used to operate the service. It is not a customer CRM or shopper identity database, and we do not use order data to identify shoppers.
What we don't collect
We do not collect or store customer names, email addresses, phone numbers, or postal addresses. We do not build, store, or sell individual shopper profiles. We do not sell personal data. Order access is limited to aggregate totals and timestamps; we do not access line items or customer identity. The storefront pixel allowlists fields server-side and drops any customer-identity keys, full URLs/paths, raw alert message text, IP addresses, and verbatim user-agent strings that a future Shopify event shape might include. We do not inject scripts into the merchant theme for measurement.
How we use it
We use the store data listed above to analyze the merchant's storefront and produce conversion-optimization audits, recommendations, and related in-app insights for that merchant. We do not use this data to advertise to shoppers, and we do not sell it to third parties.
Who we share it with (sub-processors)
To run the service we share data with these providers, only as needed for their role:
- Anthropic (Claude) — store content and metrics sent for AI analysis that powers the audit and recommendations
- Supabase — database and file/screenshot storage
- Trigger.dev — background job processing (for example audit and sync work)
- Resend — notification emails sent to the merchant
- Google PageSpeed Insights — store URLs sent for performance scoring
- Fly.io — application hosting for the Ghost Revenue app
We do not share shopper personal data with these providers because we do not collect it.
Security
Data is encrypted in transit using TLS/HTTPS and encrypted at rest with database-level encryption. Sensitive credentials — such as storefront passwords — are additionally encrypted at the application layer using AES-256-GCM. Access to merchant data is limited to people and systems needed to operate the service.
Data retention & deletion
We retain merchant data while Ghost Revenue is installed on the store. When the app is uninstalled, that data is deleted automatically within 48 hours via Shopify's shop/redact webhook. Raw storefront pixel events are kept for at most 30 days and then pruned; daily funnel rollups are retained while the app is installed and deleted on shop/redact along with the rest of the merchant record. Audit screenshots of public storefront pages are kept for at most 30 days and then pruned, or deleted earlier on shop/redact, whichever comes first.
We honor Shopify's mandatory privacy webhooks: customers/data_request, customers/redact, and shop/redact. Merchants may also email carson@ghostrevenue.co to request deletion.
Merchant rights & choices
Merchants can uninstall the app to trigger automatic deletion, or contact us to request access to or deletion of their store data held by Ghost Revenue. Because we do not store shopper personal data, consumer requests for customer PII generally do not apply to data we hold; we still process Shopify's mandatory privacy webhooks as required.
Aggregated benchmarks
We may use anonymized, aggregated benchmarks across stores to improve insights. These benchmarks apply a minimum threshold of 5 stores (k-anonymity) and never expose store- or merchant-identifying data.
Changes to this policy
We may update this policy from time to time. When we do, we will change the "Last updated" date at the top of this page. Material changes will be reflected here. Continued use of Ghost Revenue after an update means the revised policy applies to that use.
Contact
For privacy or data-protection questions, email carson@ghostrevenue.co.
Ghost Revenue LLC
1968 S. Coast Hwy #4588
Laguna Beach, CA 92651
United States
Related: Terms of Service.