Last updated: July 28, 2026
OAuth tokens: When you connect Shopify, Meta Ads, or Google Ads via OAuth during launch, we receive access and refresh tokens from the respective platform. Shopify uses rotating, expiring offline tokens. All platform tokens are encrypted at rest in tenant-scoped storage and are never exposed to browser JavaScript.
Ad performance data: We retrieve campaign spend, impressions, clicks, and conversions from connected ad platforms on your behalf. This data is stored in tenant-scoped OneLine storage for aggregation, with non-secret CRM/admin summaries optionally mirrored to Attio.
Shopify order reporting data: OneLine retrieves order identifiers, dates, financial and fulfillment status, totals, tax, currency, and a line-item count. The public Shopify connector does not request or store customer names, email addresses, postal addresses, phone numbers, or payment details.
Publishing and asset data: When you explicitly approve a Meta publishing or ad-management action, we send the selected creative, caption, image URL, destination URL, UTM tags, and campaign asset metadata to Meta on your behalf.
Data collected through connected platforms is used to provide connection status, synchronization, reporting, and user-approved platform actions. Shopify order reporting data is used only for the merchant’s OneLine analytics and is not sent to advertising platforms or CRM customer pipelines. We do not sell this data or use it to advertise our own services.
OAuth tokens are retained only while the connection is active and are deleted when Shopify confirms app uninstallation or revocation. Reporting data is retained only while needed to provide the service or meet legal obligations. Verified Shopify privacy webhooks process customer data requests, customer redaction, and shop redaction. You may also request deletion at any time by emailing dev@sicapo.com.
We do not sell or trade merchant data. Data is processed only by infrastructure providers needed to host and operate OneLine and by a connected platform when the merchant requests an action on that platform. Attio may receive non-secret business administration summaries, but the public Shopify connector does not send Shopify order or customer records to Attio.
The embedded Shopify Admin experience authenticates each backend request with a short-lived Shopify App Bridge session token and does not rely on third-party cookies. The separate OneLine portal uses HTTP-only, secure first-party cookies for signed account sessions. We do not use third-party tracking cookies.
OAuth tokens are encrypted before storage. All data in transit uses HTTPS. Shopify authentication uses Shopify-managed installation, App Bridge session tokens, and rotating expiring offline tokens. Access is tenant-scoped and the Shopify connector requests only read-only order access.
You have the right to access, correct, or delete any personal data we hold about you. Contact us at dev@sicapo.com to exercise these rights. Meta users can also submit a signed data deletion request to /api/meta/data-deletion; the endpoint returns a confirmation code for the request.
Sicapo
dev@sicapo.com