Mcfly Ads
Privacy policy
Last updated: July 28, 2026. We process store and spend data to show Total ROAS — Shopify sales after returns ÷ ad spend (order totals may appear as Ads Manager–comparable) — never path attribution. Opaque order and customer IDs are still personal data under GDPR (pseudonymous) — we minimize them and never build a name/email CRM.
Plain-English summary
- We read Shopify order totals (
read_orders) and classify unique customers as new vs returning using least-privilegeread_customers— opaque customer IDs +numberOfOrdersonly. We do not request name, email, phone, or address. That diet powers Total ROAS, break-even, and allocation. - We persist opaque OrderFact rows (order id, amount, date, opaque customerKey) and CohortFact aggregates for customer lifetime value — still no name/email/phone/address CRM.
- Uninstalling triggers Shopify's
shop/redactwebhook — we delete your Mcfly shop record, settings, spend, OrderFacts, CohortFacts, and related facts.customers/redactdeletes that customer's OrderFacts. - Same Total ROAS religion as the product: we measure money against money, not who "won" the click. The Shopify App Store listing name is Mcfly Analytics (free while we launch); see Pricing for the later flat $39 path via Shopify Billing.
This summary is an orientation, not a substitute — the full policy below governs.
Who we are
Mcfly Ads (“Mcfly,” “we”) is operated by Marty Smithson (Utah, United States). Contact: mcflyadsmmm@gmail.com. Support: mcflyads.com/support.
This policy applies to mcflyads.com and the Shopify app listed as Mcfly Analytics (product brand: Mcfly Ads).
Why we process data
To run the Total ROAS dashboard, break-even Total ROAS, rules-based allocation, and customer lifetime value cohorts; to provide support and security; and to comply with law and Shopify’s app requirements (including GDPR webhooks). We measure money spent on ads against money Shopify recorded as sales — not who “won” the click.
Lawful basis (EU / UK GDPR)
Where GDPR / UK GDPR applies:
- Shopify app processing for merchants — typically performance of a contract (Art. 6(1)(b)) to provide the Total ROAS desk you install, and legitimate interests (Art. 6(1)(f)) for security, abuse prevention, and product reliability — balanced against your rights.
- Waitlist / support contact — consent (Art. 6(1)(a)) and/or steps prior to a contract when you email us or submit the form.
- Legal obligation (Art. 6(1)(c)) — responding to Shopify GDPR webhooks and applicable law.
Merchants are typically the controller of their store customer data; Mcfly acts as a processor for Shopify-sourced store data under the merchant’s instructions and Shopify’s platform rules. For waitlist/support emails you send us directly, Mcfly is the controller. A draft Data Processing Addendum is at /dpa (lawyer review pending before signature).
What we collect
- Waitlist / support contact you give us voluntarily — name, email, and optionally store URL — via the site waitlist (mcflyads.com/support) or email to mcflyadsmmm@gmail.com / Support. Used only to reply and coordinate installs. Not customer CRM. Stored in Cloudflare KV (≤180 days TTL) and may be emailed via Resend and/or FormSubmit.co.
- Shopify shop domain and OAuth session tokens when you install the app.
- Staff Session fields from Shopify login (when the merchant staffer opens the embedded app with an online session): staff
email,firstName,lastName, and related Shopify session flags (account owner / collaborator / locale). These identify the Admin user using the app — not store customers. We do not use staff email for marketing lists. - Order / sales totals and order counts for periods you view (Shopify Admin API scopes
read_ordersand, when approved,read_all_ordersfor deeper history) to compute Total ROAS and AOV. - New vs returning customer counts via minimal scope
read_customers: on each order we read only the opaque customeridandnumberOfOrdersto classify new vs returning. We do not request or store customer name, email, phone, or address, and we do not keep a customer CRM. - OrderFact (persisted): opaque
customerKey(Shopify customer GID or guest marker), Shopify order id, order amount, and order created-at / shop-local date — used to build customer lifetime value. No name, email, phone, or address fields. Opaque IDs remain pseudonymous personal data under GDPR. - CohortFact (persisted aggregates): monthly first-order cohort rollups (customer counts and revenue/orders at 30/90/365 days) derived from OrderFacts — still no CRM PII.
- SalesDayFact / MerSnapshot — day-level sales and Total ROAS snapshot rows for the desk (amounts/dates, not customer directories).
- CashClose — optional Monday Close / Export memo snapshots (period totals, decision labels) when Pro save/export is used.
- ComplianceDataExport (temporary): when Shopify sends
customers/data_request, we store an opaque order package (order ids, amounts, dates, opaque customerKey — never name/email/phone) so the merchant can download it in Settings. Packages are purged by a scheduled job after 60 days, and erased earlier oncustomers/redact,shop/redact, or uninstall. - Ad spend you enter or sync — Free path: paste from Sheets or CSV / manual entry (ad-spend aggregates only). Optional merchant-chosen pipe tools (e.g. SyncWith, Coupler, Supermetrics, Coefficient) may fill a Mcfly CSV template on the merchant’s side — see Processors. Near-term retention path: optional Meta + Google Ads spend OAuth (feature-flagged; never pixels / path data). Settings: margin %, target Total ROAS.
- Job / WebhookDelivery / ApiToken — operational rows (job type, shop, delivery keys, hashed API tokens) for reliability and optional merchant API access. Webhook delivery ledgers do not store full order PII packages.
- Technical / host logs — our hosts and CDN may record standard request metadata (timestamps, paths, status codes, IP addresses, user agents) for security and reliability. Application bot detection may use user-agent strings. Compliance webhook application logs do not dump order amount packages.
What we refuse to do
- We do not sell merchant or customer data.
- We do not run path-attribution pixels as a product.
- We do not build a customer CRM from your orders — no name/email/phone/address directory.
- We do not train public AI models on your store data.
Shopify GDPR / data requests
When Shopify sends customers/data_request, customers/redact, or shop/redact, we verify the request HMAC and process them per Shopify’s timelines.
customers/data_request: we do not store customer email, name, phone, or address. We store a Level-1 opaque order package (ComplianceDataExport: order ids, amounts, dates, opaque customerKey) for merchant fulfillment and acknowledge with HTTP 200. Merchants download packages in-app (Settings). Packages are purged by a scheduled worker after 60 days, and are erased earlier oncustomers/redact,shop/redact, or uninstall.customers/redact: we delete OrderFact rows for that shop whose opaque customerKey matches the Shopify customer id (or order ids inorders_to_redact), erase that customer’s Level-1 data_request package, and recompute CohortFacts from remaining OrderFacts.shop/redact(and uninstall): we delete your Mcfly shop record and cascaded data — settings, spend entries, Total ROAS snapshots, sales-day facts, OrderFacts, CohortFacts, staff sessions (including staff email/name), Level-1 data_request packages, and related rows.
California privacy (CCPA / CPRA)
We do not sell personal information and do not share it for cross-context behavioral advertising. We do not use store customer profiles for ads. California residents may request to know, delete, or correct personal information we hold about them (for example waitlist contact or staff session fields) by emailing mcflyadsmmm@gmail.com. Merchants fulfill Shopify customer data requests through Shopify’s GDPR webhooks; Mcfly supports those webhooks as described above. We will not discriminate against you for exercising privacy rights.
Retention
We keep app data while the app is installed. After uninstall / shop redact, we delete merchant app data subject to short backup windows and legal holds. ComplianceDataExport packages from customers/data_request are retained for at most 60 days, then purged by a scheduled worker (and also on Settings list/retrieve), or erased sooner on redact/uninstall. Waitlist/support contacts in Cloudflare KV expire after 180 days (TTL) and can be deleted earlier on request. Email copies in Resend/FormSubmit/your inbox follow those tools’ retention.
Processors
We use infrastructure and service vendors that process data only to provide services to us (and, for the Shopify app, to merchants). Current processors include:
- Cloudflare — marketing site hosting (Pages), CDN, DNS, email obfuscation scripts, and waitlist KV storage.
- Fly.io — application host for the embedded Shopify app.
- Managed Postgres (via Fly / Neon-class provider as configured) — application database.
- Shopify — OAuth, Admin API, webhooks, App Store distribution.
- Resend — transactional email when configured (
RESEND_API_KEY) for waitlist/support notifications. - FormSubmit.co — fallback email relay for waitlist/support form posts when Resend is not configured.
- Google Fonts — font files loaded from Google’s CDN on the marketing site (see Cookies).
Merchant-chosen spend pipe tools (not Mcfly processors by default): On the Free path you may optionally use SyncWith, Coupler, Supermetrics, Coefficient, or similar tools you contract and pay for to fill a Mcfly CSV / Sheets template, then import that file into Mcfly. Those tools are your processors under your agreements — Mcfly does not operate them, does not receive their OAuth tokens, and does not claim a “Works with” partnership. Mcfly only receives the ad-spend aggregates you paste or upload.
International transfers
Mcfly is operated from the United States. Hosting and processors (Cloudflare, Fly.io, database, email) may process data in the US and other countries. Where required, we rely on appropriate transfer mechanisms (for example Standard Contractual Clauses) and will provide a signed DPA / SCC package on request after legal review — see /dpa.
Cookies & similar tech
See Cookies for the short notice. Summary: we do not run marketing/analytics pixels on mcflyads.com. The site may use essential hosting cookies from Cloudflare, load Google Fonts from Google’s CDN, and store waitlist submissions you send. The embedded Shopify app runs inside Shopify Admin and follows Shopify’s session model.
Your rights
Depending on your location, you may request access, correction, deletion, restriction, objection, or export of personal data, and you may withdraw consent for waitlist contact. Email mcflyadsmmm@gmail.com. Merchants can also uninstall the app to stop processing store data through Mcfly. EU/UK residents may lodge a complaint with their supervisory authority.
Security
See Security. We use HTTPS, Shopify OAuth, HMAC verification on webhooks, scoped Admin API access, and a least-privilege data diet (opaque order ids — no name/email CRM). No security practice is perfect — report issues to mcflyadsmmm@gmail.com.
Governing law
Privacy disputes relating to this site and app are handled under Utah, USA law, consistent with our Terms, except where mandatory local consumer/privacy law cannot be waived.
Children
The service is for businesses, not directed at children under 16.
Changes
We may update this policy. Material changes will be posted here with a new date.