This policy covers CollectionsIQ, the EcomIQ Shopify app that builds and maintains dynamic product collections from your advertising performance and sales data. It supplements the main EcomIQ Privacy Policy, which sets out who we are and your rights.
1. Controller & processor roles
EcomIQ (PBF Piotr Białozor-Fiećko, NIP PL8461552859, ul. Józefa Chełmońskiego 12, 14-200 Iława, Poland) provides CollectionsIQ. For the store, advertising, and sales data you connect, the merchant is the controller and EcomIQ acts as a processor, processing that data only to provide the app’s features on your instructions. For your own account/contact data, we are the controller.
2. Data we access
We access only what is needed for the features you enable, and only for accounts you explicitly connect:
- Shopify store data — shop domain, products, collections, and publications, plus order data. Order data is immediately aggregated into per-product sales metrics (units sold, net sales, order counts); we do not retain order line items or customer details. Scopes requested:
read_products,write_products,read_publications,write_publications,read_orders. - Google Ads data — via the Google Ads API (scope
adwords), read-only aggregate per-product advertising metrics (impressions, clicks, cost, conversions, conversion value) for accounts you connect. - Meta (Facebook/Instagram) data — via the Marketing API (
ads_read) and catalog access (catalog_management), read-only aggregate per-product advertising metrics and product-catalog identifiers for accounts you connect. - Pinterest data — via the Pinterest API (scopes
ads:read,catalogs:read), read-only aggregate per-product advertising metrics and product-catalog identifiers for accounts you connect. - TikTok data — via the TikTok Marketing API (ads reporting, read-only), aggregate per-product advertising metrics for accounts you connect.
- Access tokens — credentials to call Shopify and the platforms you connect, stored encrypted at rest.
We do not collect or store your customers’ personal information. We do not access customer names, emails, addresses, or payment details; orders are reduced to aggregate per-product totals before storage.
3. How we use the data
We use the data solely to provide and improve the features you enable — evaluating your collection rules and keeping your Shopify collections in sync. We do not sell data, use it for advertising, or build profiles. Humans do not access your data except (a) with your consent, (b) for security or to comply with law, or (c) in aggregated/anonymized form for operating the service.
4. Google API Services — Limited Use
EcomIQ’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Data obtained via the Google Ads API is used only to provide and improve the in-app features you enable; is not sold; is not used for advertising; and is not transferred to others except as necessary to provide the service, for security, or to comply with applicable law. We do not allow humans to read this data except in the limited cases above.
5. Meta, Pinterest & TikTok platform data
Our use of data obtained through the Meta APIs complies with the Meta Platform Terms and Developer Policies; through the Pinterest API with the Pinterest Developer Guidelines and Advertising Services Agreement; and through the TikTok Marketing API with the TikTok for Business / Developer Terms. For every one of these platforms the data is read-only, is used only to provide the features you connect, and is never sold or used for unrelated purposes. You can disconnect any platform at any time, which stops further access.
6. Storage, security & transfers
Data is hosted on Cloudflare’s developer platform. Access tokens are encrypted at rest (AES-GCM); all transport is over HTTPS. Where data is processed outside the EEA, we rely on appropriate safeguards (Standard Contractual Clauses and/or the EU–U.S. Data Privacy Framework). We retain only aggregate, non-personal metrics needed to run the features.
7. Retention
Performance and sales metrics are kept on a rolling window (up to 90 days) and refreshed automatically; older data is discarded. Access tokens are kept until you uninstall the app or disconnect the relevant platform.
8. Shopify data-protection requests
As a Shopify app, CollectionsIQ honors Shopify’s mandatory data-protection (GDPR) webhooks:
customers/data_request— if a store customer requests their data, we provide any relevant data we hold to the store owner. (In practice we hold no customer-level personal data.)customers/redact— we delete/redact any data associated with the identified customer.shop/redact— 48 hours after a store uninstalls CollectionsIQ, Shopify notifies us and we erase that store’s data from our systems.
We acknowledge these requests and complete the action within the timeframe Shopify requires.
9. Deletion & your rights
Uninstalling CollectionsIQ stops processing and triggers deletion of your stored access tokens and data, as above. You can also disconnect any connected platform at any time, or request access or deletion via support. See the Data Deletion page and the main Privacy Policy for your full rights and how to exercise them.
10. Sub-processors
Shopify (the platform you install from and that bills the subscription), Cloudflare (hosting and storage), and the advertising platforms you connect (Google, Meta, Pinterest, TikTok). We share data with these providers only to operate the service.
11. Contact
Questions about CollectionsIQ’s data handling: support@ecomiq.tools.
This policy is provided in good faith and accurately describes how CollectionsIQ works today.