Privacy Policy
Last updated: 2026-07-23
This Privacy Policy describes how CAPI Relay ("the App", "Service"), operated by Namah ("we", "us"), collects, uses, shares, and deletes information when you use our Shopify application, Agency portal, and related websites.
This is Namah's own privacy policy for CAPI Relay. It is not Meta's, Shopify's, TikTok's, or Google's privacy policy.
Who we are
The application name is CAPI Relay. CAPI Relay helps Shopify merchants send storefront and order conversion events to advertising platforms (including Meta Conversions API, TikTok Events API, and Google Ads click conversion uploads via uploadClickConversions) for ads measurement and optimization.
Google user data (OAuth)
When a merchant uses Continue with Google inside CAPI Relay, Google OAuth may provide access to the merchant's Google account information needed to connect Google Ads — typically an OAuth access token and refresh token, Google account email (if returned), accessible Google Ads customer IDs, and conversion action IDs. CAPI Relay uses this Google user data only to:
- Let the merchant select a Google Ads account and conversion action
- Upload Purchase click conversions (gclid / wbraid / gbraid) with the Google Ads API
uploadClickConversionsmethod for ads measurement
We do not use Google user data to manage campaigns, create Customer Match audiences, build advertising profiles, or sell personal data. Tokens are encrypted at rest (AES-GCM). Merchants can disconnect Google in-app or revoke access in their Google Account permissions at any time.
Information we collect
We collect and process the following categories of information:
- Merchant / agency account data: Shopify shop domain, app sessions, encrypted platform credentials (Pixel IDs / access tokens), billing identifiers (Shopify Billing and/or Paddle customer / subscription IDs), Agency account email and password hash, invite codes.
- Google OAuth / Google Ads: As described in Google user data (OAuth) above — OAuth tokens and Google Ads account / conversion identifiers used only to upload click conversions for the merchant.
- Facebook Login for Business (Meta): When a merchant uses Continue with Facebook, Meta may provide an access token, Facebook user ID, Business Manager / ad account IDs, and Pixel IDs. We use these only to connect the merchant's Pixel and send Conversions API events for Shopify measurement. Tokens are encrypted at rest (AES-GCM). We do not store Facebook consumer profiles.
- Event / conversion data: Web Pixel and Shopify order/refund webhooks send event payloads to our ingest relay. Before we store a pending outbox job, we SHA-256-hash customer identifiers (email, phone, name, address fields) when present. Click IDs, browser cookies (_fbp/_fbc), IP, and user-agent may remain plaintext only while a job is pending, because ad platforms require them raw. After a successful send (or skip), we replace the outbox payload with a redacted stub (event name + id only).
- Usage / diagnostics: Aggregated event counts and truncated API error messages for delivery health. We do not keep long-term customer profiles from storefront events.
- Payment data: Agency plan payments are processed by Paddle (Merchant of Record). We do not store full card numbers. Solo Shopify plans are billed by Shopify.
- Automatically collected technical data: Standard server logs such as IP address, user-agent, and request timestamps may be processed for security, rate limiting, and abuse prevention.
Audience Sync (Meta Custom Audiences)
On Growth and higher plans, merchants may optionally enable Audience Sync inside CAPI Relay. This feature is opt-in: the merchant must check consent before any audience is created.
- Purchasers: We read paid order email/phone from the Shopify Admin API (scopes the merchant already granted), normalize and SHA-256-hash them, and upload hashed identifiers to a Meta Custom Audience on the merchant's selected ad account.
- AddToCart / ViewContent / InitiateCheckout (no purchase): We create website Custom Audiences tied to the merchant's Meta Pixel using event inclusion/exclusion rules. Meta populates these from pixel / CAPI events — we do not upload customer PII for these rules.
Hashed identifiers and audience metadata are sent to Meta only, using the merchant's own access token. We do not sell audience data, build cross-merchant profiles, or create campaigns / spend UI. Merchants can disable sync or disconnect Meta at any time; uninstall / shop redact removes stored audience sync config.
How we use information (purposes)
- To provide the Service: connect Pixels / tokens and deliver conversion API tracking for the merchant
- To operate billing, refunds, and abuse prevention
- To show delivery health and usage in dashboards
- When the merchant opts in: to create and refresh Meta Custom Audiences from purchaser / funnel signals (see Audience Sync)
- To respond to support, compliance, and complaints
- To meet legal obligations (including GDPR webhooks from Shopify)
How we share information
Event data is forwarded to Meta, TikTok, and/or Google Ads on behalf of the merchant using credentials the merchant provides or authorizes via Meta Login for Business, TikTok OAuth, or Google OAuth. Agency charges are processed by Paddle.com as Merchant of Record. Solo app charges are processed by Shopify Billing. We do not sell personal data. Google user data obtained via OAuth is used only as described in Google user data (OAuth).
How to request deletion of your data
You can request deletion of your data as follows (choose what applies):
- Facebook / Meta Login users: Use Facebook's remove-app / data deletion flow for CAPI Relay. Our callback clears Login staging data and returns a confirmation code. Check status at
https://meta-capi-relay-app.pages.dev/privacy?deletion=CONFIRMATION_CODEor email shubhra0790@gmail.com with that code. - Shopify merchants: Disconnect Meta / platforms in-app, or uninstall the app. Shopify
customers/redactandshop/redactwebhooks trigger deletion of shop-scoped configuration and related data per Shopify's timelines. - Google OAuth users / merchants: Disconnect Google Ads inside CAPI Relay, or revoke CAPI Relay in your Google Account → Security → Third-party access. You may also email shubhra0790@gmail.com to request deletion of stored Google OAuth tokens and Google Ads connection data.
- Anyone else: Email shubhra0790@gmail.com or use our Contact page to request access, correction, or deletion. We will respond within a reasonable period as required by applicable law.
Meta App Dashboard fields: Privacy Policy URL is this page (https://meta-capi-relay-app.pages.dev/privacy). User Data Deletion instructions may point to this same URL or https://meta-capi-relay-app.pages.dev/privacy#data-deletion. Callback URL: https://meta-capi-relay-app.pages.dev/webhooks/meta/data-deletion.
Retention
Merchant configuration is retained while the app is installed and the subscription is active. After Shopify's shop/redact webhook we delete the shop's stored configuration and sessions. Agency account data is retained while the account exists or as required for tax/accounting.
Security
Platform access tokens are encrypted at rest. The Web Pixel never receives platform secrets (ingest HMAC is browser-reachable by design and is rate-limited). Pixel sends respect Shopify Customer Privacy marketing consent when the merchant enables a cookie banner. Our site is served over HTTPS.
Your rights
Depending on your location you may have rights to access, correct, or delete personal data. Contact shubhra0790@gmail.com. Merchants are responsible for customer-facing privacy disclosures and consent on their storefronts.
Contact
Namah
1/172 Viraj Khand, Gomti Nagar, Lucknow, Uttar Pradesh 226010, India
shubhra0790@gmail.com
+91 81699 41891
Contact page