Meta CAPI Relay Privacy Policy
Last updated: 2026-07-21
Who we are
Meta CAPI Relay is operated by Namah ("we", "us"). The Service is a Shopify application and Agency portal that helps merchants send storefront conversion events to Meta, TikTok, and Google advertising APIs.
Data we process
- Merchant / agency data: Shopify shop domain, app sessions, encrypted platform credentials (pixels / tokens), billing identifiers (Shopify Billing and/or Paddle customer / subscription IDs), Agency account email and password hash, invite codes.
- Facebook Login (Meta): When a merchant uses Continue with Facebook, Meta may provide an access token, Facebook user ID, Business Manager / ad account IDs, and Pixel IDs. We use these only to connect the merchant's Pixel and send Conversions API events for Shopify measurement. Tokens are encrypted at rest (AES-GCM). We do not store Facebook consumer profiles. Merchants can disconnect in-app or uninstall; Meta data-deletion / deauthorize callbacks clear Login staging data and issue a confirmation code (see
/privacy?deletion=CODE). Shop-scoped Pixel credentials are removed on disconnect or Shopifyshop/redact. - Event telemetry: Aggregated event counts and truncated API error messages for debugging. We do not keep long-term customer profiles from storefront events.
- Event payloads: Web Pixel and Shopify order/refund webhooks send event payloads to our ingest relay. Before we store a pending outbox job, we SHA-256-hash customer identifiers (email, phone, name, address fields). Click IDs, browser cookies (_fbp/_fbc), IP, and user-agent may remain plaintext only while a job is pending, because ad platforms require them raw. After a successful send (or skip), we replace the outbox payload with a redacted stub (event name + id only). We do not keep long-term customer profiles.
- Payment data: Card payments for Agency plans are processed by Paddle (Merchant of Record). We do not store full card numbers. Solo Shopify plans are billed by Shopify.
How we use data
- To deliver conversion API tracking for the merchant
- To operate billing, refunds, and abuse prevention
- To show delivery health and usage in dashboards
- To respond to support and complaints
Data sharing
Event data is forwarded to Meta, TikTok, and/or Google on behalf of the merchant using credentials the merchant provides. Agency charges are processed by Paddle.com as Merchant of Record. Solo app charges are processed by Shopify Billing. We do not sell personal data.
Retention
Merchant configuration is retained while the app is installed and the subscription is active. After Shopify's shop/redact webhook we delete the shop's stored configuration and sessions. Agency account data is retained while the account exists or as required for tax/accounting.
Security
Platform access tokens are encrypted at rest. The Web Pixel never receives platform secrets (ingest HMAC is browser-reachable by design and is rate-limited). Pixel sends respect Shopify Customer Privacy marketing consent when the merchant enables a cookie banner. Our site is served over HTTPS.
Your rights
Depending on your location you may have rights to access, correct, or delete personal data. Contact shubhramishra137@gmail.com. Merchants are responsible for customer-facing privacy disclosures and consent on their storefronts. Facebook Login users can request deletion via Meta; status pages use /privacy?deletion=CONFIRMATION_CODE.
Contact
Namah
1/172 Viraj Khand, Gomti Nagar, Lucknow, Uttar Pradesh 226010, India
shubhramishra137@gmail.com
+91 81699 41891
Contact page