Privacy Policy
This Privacy Policy explains how Satisfy & I B.V. ("we", "us") processes data in NORTHMAST (the "app"), an embedded Shopify application that turns a merchant's revenue, cost of goods, advertising cost and operating cost data into a single profit view.
It distinguishes throughout between two very different things: order data relating to a merchant's customers, and account data relating to the merchant and their staff. The app treats them differently, and this policy describes each separately.
NORTHMAST was formerly developed under the working name Clearboard Analytics. It is the same application, provided by the same legal entity, and this document replaces the corresponding document published under that working name.
Who we are
Satisfy & I B.V., Kloosterpark 12, 5554 GP Valkenswaard, The Netherlands. Chamber of Commerce number: 94013195. VAT identification number: NL866603839B01. E-mail: info@satisfyi.nl.
We are the provider of the app and the party you contract with. Questions about this policy, and requests relating to your personal data, can be sent to info@satisfyi.nl.
Our roles
Which data protection role we hold depends on the data, and the difference matters for who you should address a request to.
- Processor — for order data relating to the merchant's customers. The merchant decides why and how that data is processed; we process it only to provide the app to that merchant. Satisfy & I B.V. acts solely as processor here, under the Data Processing Addendum.
- Independent controller — for merchant and staff account data, support correspondence, security records, and our own legal and administrative records. We decide the purposes of that processing ourselves, and this Privacy Policy describes it.
Order data relating to your customers
To calculate profit, the app stores financial order data retrieved from Shopify's Admin API. Specifically:
- Orders — the Shopify order identifier, creation date, processing date, cancellation date, test flag, financial status, currency, order totals, discounts, taxes and shipping revenue.
- Order line items — the Shopify line item identifier, variant identifier, SKU, quantity, price, tax amounts and a cost price snapshot.
- Refunds — the Shopify refund identifier, processing date and currency.
- Refund line items — the refunded quantity, subtotal and tax per line.
- Refund transactions — the amount, currency, kind, status, dates and test flag of each refund transaction.
- Refund duties, order adjustments and refund shipping lines belonging to those refunds.
What we do not process about your customers
NORTHMAST does not request and does not store the customer name, customer e-mail address, customer telephone number, billing address, shipping address of your customers. None of these fields are queried from Shopify, none are stored in our database, and none appear in any export the app generates.
There is one narrow exception, and it exists only because Shopify requires it. When Shopify sends a customers/data_request or customers/redact webhook, that webhook carries a numeric Shopify customer identifier and a list of order identifiers. We store those identifiers on the resulting privacy request record so that the request can be answered and audited. They are pseudonymous identifiers, not contact details, and they are subject to the retention limits described below.
Special categories of personal data
The app is not designed for, and is not intended to process, special categories of personal data within the meaning of Article 9 GDPR — such as data revealing health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, or data concerning a person's sex life or sexual orientation. The app queries no field of that kind. Merchants must not knowingly supply such data to the app, including through free-text configuration fields, without a separate written agreement with us first.
Merchant and staff account data
Separately from order data, the app stores the Shopify session records that make the embedded app work. Shopify supplies these; they can include the store domain, a Shopify user identifier, first name, last name, e-mail address, locale, and flags indicating whether the user is the account owner, a collaborator, or has a verified e-mail address, together with the access token and refresh token for the store.
This is merchant and staff data, not customer data. It is used to authenticate the app against Shopify and to run synchronisations on the store's behalf.
Merchant configuration and advertising data
- Configuration you enter in the app, such as transaction fee settings, named shipping rates and language preference.
- Advertising cost data from an advertising platform you choose to connect, currently Meta: campaign, ad set and ad names and identifiers, date, spend, currency, impressions, clicks and click-through rate.
- The connection details for that platform: the advertising account identifier and name, the connecting user's platform identifier, granted scopes, and the access token, which is stored encrypted (AES-256-GCM) and never in plain text.
Technical infrastructure data
The app itself does not store IP addresses, device identifiers or browsing behaviour. It contains no cookies for analytics, no tracking pixel and no third-party analytics script, and it does not build a profile of you or of your customers.
Our hosting and database providers do, however, necessarily process connection metadata — such as the IP address a request comes from, timestamps, the requested path and error information — in their own infrastructure logs, because a request cannot be delivered or a database connection established without it. That processing takes place under those providers' own terms and retention periods, which we do not control. We use it only where it reaches us as part of diagnosing an operational fault.
The app writes its own synchronisation logs, described under retention below. Those record which sync ran and whether it succeeded, and are deliberately constructed to carry fixed, safe codes rather than tokens, payloads or personal data.
Why we process this data
- To provide analytics and revenue reporting.
- To calculate profit, contribution margin and cost of goods sold.
- To calculate advertising cost and return on ad spend alongside Shopify data.
- To secure the service, including authenticating requests and verifying webhooks.
- To provide support when you contact us, and to meet our legal obligations.
Legal bases for the processing we control
This section concerns only the processing for which we are an independent controller — merchant and staff account data, support, security and administration. For customer order data we act as processor, and the merchant is responsible for establishing the legal basis.
- Performance of a contract — to give you access to the app, authenticate your store against Shopify, run synchronisations on your behalf and answer your support requests. Without this processing we cannot provide the service you installed.
- Compliance with a legal obligation — to meet our obligations under tax, accounting and data protection law, including responding to a supervisory authority.
- Legitimate interests — to keep the service secure and operable, to detect and resolve faults, to prevent misuse and unauthorised access to another merchant's data, and to keep records of what happened when something goes wrong. We have weighed these interests against your rights and limited the processing to what the service actually requires.
What we never do
- We do not sell personal data.
- We do not use your data, or your customers' data, for personalised advertising.
- We do not carry out automated decision-making that produces legal effects or similarly significant effects on any individual.
- We do not use your data for purposes unrelated to providing the service.
How long we keep data
Detailed order data — orders, order line items, refunds, refund line items and refund transactions, together with the related refund duties, order adjustments and refund shipping lines — is retained for a maximum of 24 calendar months, measured from the Shopify order creation date. Records past that limit are deleted automatically by a daily retention job, and orders older than the limit can no longer be imported or re-created.
Synchronisation logs, which record when a sync ran and whether it succeeded, are retained for a maximum of 90 days.
Completed customers/data_request records, including the generated export payload, are retained for a maximum of 30 days after completion and are then deleted in full.
Merchant settings, shipping rates and advertising cost records are kept for as long as the app is installed for your store, because the app needs them to calculate profit. They are deleted on shop/redact.
Deletion requests from Shopify
When Shopify sends a customers/redact request, the affected order data is deleted immediately and a minimal technical marker is kept for as long as the app remains installed for that store. That marker exists for one purpose only: to stop a later synchronisation from re-importing the deleted order. It contains the store key, a fixed topic, the order identifier and a status — no name, e-mail address, telephone number, address, customer identifier, amount or payload fragment.
When Shopify sends a shop/redact request, all stored data for that store is deleted, including orders, line items, refunds and refund components, ad spend, settings, shipping rates, synchronisation logs, privacy request records and any advertising platform connection.
When the app is uninstalled, the Shopify session records for that store — which hold the staff account details and access tokens — are deleted immediately. The remaining store data is kept only until Shopify's shop/redact request arrives, so that Shopify's mandatory compliance flow can be completed correctly, and is deleted at that point.
Shopify
Shopify is the platform the app runs on and the source of the order data described above. Shopify is not a subprocessor engaged by us: the merchant has their own direct relationship with Shopify, and Shopify determines its own processing under its own terms. We access store data through Shopify's official Admin API using the permissions the merchant granted at install.
Advertising platforms
A merchant may voluntarily connect Meta. This connection is started by the merchant and never by us, and the app works without it. If they do connect it, the app reads advertising cost and performance data for the selected ad account using the read-only ads_read permission. No order data and no customer data is ever sent to Meta. A merchant can disconnect at any time, which clears the stored token and account details and stops all further access.
An advertising platform connected this way is not a subprocessor engaged by us either. We read data from it on the merchant's instruction; we do not send it data to process on our behalf.
Subprocessors
A subprocessor is a provider we engage to process data on our behalf. This is a different category from Shopify, which the merchant has their own relationship with, and from an advertising platform the merchant chooses to connect. We engage the following providers:
- Vercel — Application hosting and the serverless runtime that executes the app, including the daily scheduled job. Data categories: All data processed in transit by the application: Shopify order and refund data, advertising cost data, merchant configuration, and Shopify session data. Processing context: Serverless execution and hosting infrastructure operated by Vercel, processing the application traffic and the data required to serve a request. We have not established that execution is limited to a single region.
- Supabase — Managed PostgreSQL database where all application data is stored. Data categories: Orders, order line items, refunds and refund components, advertising cost records, merchant settings and shipping rates, synchronisation logs, privacy request records, Shopify session records, and encrypted advertising platform tokens. Processing context: The primary database is hosted in a European Supabase project region. Supabase may carry out supporting processing, such as operations and support, outside that region; we do not claim that all Supabase processing takes place exclusively within the EEA. Contract: We have concluded a Data Processing Addendum with Supabase. Transfers: That Data Processing Addendum incorporates the EU Standard Contractual Clauses where these are required for a transfer.
Security
We apply technical and organisational measures appropriate to the data we process. In practice this includes: every database read and write is scoped to a single store, so one merchant's data cannot be reached from another's context; advertising platform tokens are encrypted at rest with AES-256-GCM and are never logged; incoming Shopify webhooks are verified by HMAC before any action is taken; OAuth state values are stored hashed and can be used only once; and logs and error messages are constructed to carry fixed, safe codes rather than tokens, payloads or personal data.
We hold no security certifications, and we make no absolute guarantee. No method of transmission or storage is completely secure.
Your rights
Depending on where you are located, you may have the right to access, correct, delete, port, or restrict the processing of your personal data, and to object to it. Where we act as a processor on a merchant's behalf — which is the case for all customer order data — requests from a customer should be directed to the merchant, and we will assist the merchant in answering them. To exercise rights in relation to data for which we are the controller, such as merchant account and support data, contact us using the details below.
To make a request, e-mail info@satisfyi.nl and describe what you want. We may need to ask you for information to confirm who you are, so that we do not disclose or delete data on the basis of a request from someone else. We answer without undue delay and in any event within the period applicable data protection law allows. Exercising these rights is free of charge.
If you are not satisfied with how we handle your request, you have the right to lodge a complaint with your local supervisory authority. For us that is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Contact
Satisfy & I B.V., Kloosterpark 12, 5554 GP Valkenswaard, The Netherlands. Chamber of Commerce number: 94013195. VAT identification number: NL866603839B01. E-mail: info@satisfyi.nl.
Changes to this policy
Each document carries its own version number and effective date. A material change results in a new version number and a new effective date shown at the top of the page. Minor corrections that do not change your rights or our obligations — such as a typographical fix — do not.