Mcfly Ads

Privacy policy

Last updated: July 28, 2026. We process store and spend data to show Total ROAS — Shopify sales after returns ÷ ad spend (order totals may appear as Ads Manager–comparable) — never path attribution. Opaque order and customer IDs are still personal data under GDPR (pseudonymous) — we minimize them and never build a name/email CRM.

Total ROAS data only Order totals + opaque OrderFact / CohortFact + spend you enter
Never sold Merchant and customer data isn't for sale
No pixels Not a path-attribution product, by design
App Store Free when listed customers/redact clears OrderFacts · shop/redact clears the shop

Who we are

Mcfly Ads (“Mcfly,” “we”) is operated by Marty Smithson (Utah, United States). Contact: mcflyadsmmm@gmail.com. Support: mcflyads.com/support.

This policy applies to mcflyads.com and the Shopify app listed as Mcfly Analytics (product brand: Mcfly Ads).

Why we process data

To run the Total ROAS dashboard, break-even Total ROAS, rules-based allocation, and customer lifetime value cohorts; to provide support and security; and to comply with law and Shopify’s app requirements (including GDPR webhooks). We measure money spent on ads against money Shopify recorded as sales — not who “won” the click.

Lawful basis (EU / UK GDPR)

Where GDPR / UK GDPR applies:

Merchants are typically the controller of their store customer data; Mcfly acts as a processor for Shopify-sourced store data under the merchant’s instructions and Shopify’s platform rules. For waitlist/support emails you send us directly, Mcfly is the controller. A draft Data Processing Addendum is at /dpa (lawyer review pending before signature).

What we collect

What we refuse to do

Shopify GDPR / data requests

When Shopify sends customers/data_request, customers/redact, or shop/redact, we verify the request HMAC and process them per Shopify’s timelines.

California privacy (CCPA / CPRA)

We do not sell personal information and do not share it for cross-context behavioral advertising. We do not use store customer profiles for ads. California residents may request to know, delete, or correct personal information we hold about them (for example waitlist contact or staff session fields) by emailing mcflyadsmmm@gmail.com. Merchants fulfill Shopify customer data requests through Shopify’s GDPR webhooks; Mcfly supports those webhooks as described above. We will not discriminate against you for exercising privacy rights.

Retention

We keep app data while the app is installed. After uninstall / shop redact, we delete merchant app data subject to short backup windows and legal holds. ComplianceDataExport packages from customers/data_request are retained for at most 60 days, then purged by a scheduled worker (and also on Settings list/retrieve), or erased sooner on redact/uninstall. Waitlist/support contacts in Cloudflare KV expire after 180 days (TTL) and can be deleted earlier on request. Email copies in Resend/FormSubmit/your inbox follow those tools’ retention.

Processors

We use infrastructure and service vendors that process data only to provide services to us (and, for the Shopify app, to merchants). Current processors include:

Merchant-chosen spend pipe tools (not Mcfly processors by default): On the Free path you may optionally use SyncWith, Coupler, Supermetrics, Coefficient, or similar tools you contract and pay for to fill a Mcfly CSV / Sheets template, then import that file into Mcfly. Those tools are your processors under your agreements — Mcfly does not operate them, does not receive their OAuth tokens, and does not claim a “Works with” partnership. Mcfly only receives the ad-spend aggregates you paste or upload.

International transfers

Mcfly is operated from the United States. Hosting and processors (Cloudflare, Fly.io, database, email) may process data in the US and other countries. Where required, we rely on appropriate transfer mechanisms (for example Standard Contractual Clauses) and will provide a signed DPA / SCC package on request after legal review — see /dpa.

Cookies & similar tech

See Cookies for the short notice. Summary: we do not run marketing/analytics pixels on mcflyads.com. The site may use essential hosting cookies from Cloudflare, load Google Fonts from Google’s CDN, and store waitlist submissions you send. The embedded Shopify app runs inside Shopify Admin and follows Shopify’s session model.

Your rights

Depending on your location, you may request access, correction, deletion, restriction, objection, or export of personal data, and you may withdraw consent for waitlist contact. Email mcflyadsmmm@gmail.com. Merchants can also uninstall the app to stop processing store data through Mcfly. EU/UK residents may lodge a complaint with their supervisory authority.

Security

See Security. We use HTTPS, Shopify OAuth, HMAC verification on webhooks, scoped Admin API access, and a least-privilege data diet (opaque order ids — no name/email CRM). No security practice is perfect — report issues to mcflyadsmmm@gmail.com.

Governing law

Privacy disputes relating to this site and app are handled under Utah, USA law, consistent with our Terms, except where mandatory local consumer/privacy law cannot be waived.

Children

The service is for businesses, not directed at children under 16.

Changes

We may update this policy. Material changes will be posted here with a new date.