This policy explains how AppMexa collects, uses and protects information when merchants install or use our Shopify applications and websites.
Information we collect
We receive merchant and store information required to install, authenticate and operate an app, such as shop domain, Shopify identifiers, subscription state and relevant configuration. PixelHarbour stores the Meta Pixel ID, optional test-event code and Conversions API token supplied by the merchant. Sensitive tokens are encrypted at rest.
For event delivery, Shopify provides supported commerce and device context, such as product, cart, checkout, order, URL, browser and Meta cookie values. PixelHarbour creates a one-way identifier from Shopify's browser client ID before transmission to Meta. It does not retain raw event payloads as customer profiles or use them to build advertising profiles of its own.
Operational diagnostics may include app name, release, route, error message, timestamps and a one-way shop identifier. Known credentials and request secrets are removed before a diagnostic record is stored.
How we use information
- Provide, secure and improve the requested app.
- Deliver merchant-configured events to Meta.
- Manage plans and billing through Shopify.
- Respond to support and diagnose reliability issues.
- Meet legal, security and Shopify platform obligations.
Consent and lawful use
Our apps honour supported Shopify customer privacy signals. Merchants remain responsible for configuring consent collection and for determining the lawful basis for their advertising and analytics use.
Sharing
We share information only with processors needed to operate the service, with Shopify, with merchant-selected services such as Meta, or when legally required. We do not sell personal information.
Retention and deletion
Configuration is retained while an app is installed and for only as long as needed after uninstall to complete mandatory deletion workflows. PixelHarbour event receipts are retained for up to eight days. Individual AppMexa diagnostic occurrences are retained for 30 days and resolved diagnostic groups for 180 days. Resolved support conversations and operational audit records are retained for up to 365 days. Unresolved support or security matters may be kept while they remain necessary for service, safety or legal obligations.
International transfers
AppMexa serves merchants worldwide. Information may be processed outside your country using contractual and technical safeguards appropriate to the service.
Your choices
Merchants may update app configuration, uninstall an app or request access, correction or deletion. Shopify privacy webhooks are used for required customer and shop data requests.
Contact
Questions or privacy requests can be sent to support@appmexa.com or through our support form.
Changes
We may update this policy as our products or legal duties change. Material revisions will be dated here.