Privacy Policy
Last updated: June 3, 2026
1. Introduction
q-tracker (“the App”, “we”, “us”, or “our”) is a Shopify application that provides real-time profit & loss (P&L) analytics for Shopify merchants, accessible at https://q-tracker.app.
q-tracker is a product developed and operated by Qazar, owned and operated by Denis Thomas. Qazar is the legal entity responsible for this App and for all data processing described in this policy.
By installing or using q-tracker, you agree to the practices described in this policy. If you do not agree, please uninstall the App and cease use of the service.
This policy is intended to comply with applicable privacy laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), Shopify's own privacy requirements for apps listed on the Shopify App Store, and Google's API Services User Data Policy.
2. Information We Collect
2.1 Data obtained via Shopify APIs
When you install q-tracker and authorize it through Shopify OAuth, we access the following data from your Shopify store via Shopify's APIs:
- Order data: order numbers, line items, pricing, currency, exchange rates, fulfillment status, financial status, payment gateway, cancellation and refund information
- Product and variant data: product titles, variant titles, SKUs, Shopify variant IDs (used to configure cost of goods)
- Shipping data: shipping country, shipping cost per order
- Store metadata: shop domain, currency settings
We do not access or store personally identifiable information about your customers (e.g., names, emails, addresses, payment card details). Order data is aggregated at the order level; no individual customer profile is built or stored.
2.2 Data you provide directly
- Account credentials (email address and hashed password) when you create a q-tracker account
- Cost of goods (COGs) configurations you enter for your products and variants
- Fee rules (payment gateway fees, VAT rates, commissions) you configure
- Additional cost entries (monthly subscriptions, one-time expenses) you add
2.3 Google Ads integration (optional)
If you choose to connect a Google Ads account, we access the following data via the Google Ads API, exclusively for read-only reporting purposes:
- A Google Ads OAuth 2.0 access token and refresh token (used solely to fetch campaign metrics on your behalf)
- Your Google Ads Customer ID, account name, and account currency
- Campaign-level ad spend, impressions, and clicks aggregated by day
We use Google Ads data exclusively to display advertising metrics within your q-tracker dashboard. We do not create, modify, or delete any Google Ads campaigns, ad groups, ads, keywords, or settings. We do not share Google Ads data with any third party. Our use of Google Ads API data complies with Google API Services User Data Policy, including the Limited Use requirements.
2.4 Meta Ads integration (optional)
If you choose to connect a Meta (Facebook) Ads account, we receive and store:
- A Meta access token (used solely to fetch ad spend figures)
- Your Meta ad account ID, account name, and account currency
- Daily ad spend totals for the last 90 days
We do not access creative assets, audience data, or any other Meta Ads data beyond aggregated daily spend figures.
2.5 Technical and usage data
- Server-side request logs (IP address, timestamp, HTTP method, endpoint) retained for up to 30 days for security and debugging purposes
- Session tokens (stored server-side; no tracking cookies are set on end users)
- EUR/USD exchange rates fetched from a public API and cached in our database
3. How We Use Your Information
We use the information we collect exclusively to provide and improve the q-tracker service:
- P&L calculation — computing revenue, COGs, fees, ad spend, returns, and net profit for your store
- Order synchronization — importing and keeping order data current via Shopify webhooks or manual sync
- Google Ads reporting — displaying Google Ads spend metrics (read-only) alongside your Shopify revenue to calculate ROAS and net profit
- Meta Ads reporting — displaying Meta Ads spend alongside your Shopify revenue so you can calculate ROAS and net profit
- Authentication — identifying your session and ensuring your data is isolated from other merchants
- Service integrity — detecting errors, preventing abuse, and maintaining uptime
We do not sell, rent, or share your data with third parties for marketing purposes. We do not use your data to build advertising profiles or train AI models.
4. Data Retention
- Order data — retained for as long as your account is active. Deleted within 30 days of account closure or store disconnection.
- Configuration data (COGs, fees, costs) — retained until you delete them or close your account.
- Google Ads tokens and spend data — retained for as long as the Google Ads integration is active. OAuth tokens and all associated data are permanently deleted immediately upon disconnection or upon your request.
- Meta Ads spend data — retained for as long as the Meta integration is active. Removed immediately upon disconnection.
- Server logs — retained for up to 30 days, then permanently deleted.
- Account credentials — retained until account deletion is requested.
When you disconnect your Shopify store from within q-tracker settings, all imported orders, line items, returns, and ad spend records are deleted immediately. Your COGs, fee configurations, and account remain intact unless you also request account deletion.
5. Data Storage and Security
Your data is stored in a PostgreSQL database hosted on Railway (infrastructure located in the United States). The application is deployed on Vercel (infrastructure located in the United States and European Union edge regions).
We implement the following security measures:
- All data in transit is encrypted using TLS 1.2 or higher
- Passwords are hashed using a strong one-way algorithm (bcrypt) and never stored in plain text
- Shopify OAuth tokens are stored encrypted at rest
- Multi-tenant data isolation: each merchant can only access their own store data
- API endpoints are authenticated and session-protected
No security system is perfect. In the event of a data breach that affects your personal information, we will notify you by email within 72 hours of becoming aware of the breach, in accordance with GDPR requirements where applicable.
6. Data Sharing and Third Parties
We share data with the following third-party service providers solely to operate the App:
We do not share your data with any other third parties. We do not use advertising networks, analytics platforms, or data brokers.
7. Cookies and Tracking
q-tracker uses a minimal, session-only cookie to maintain your authenticated session. This cookie is:
- HttpOnly and Secure — not accessible to JavaScript and transmitted only over HTTPS
- Session-scoped — expires when you close your browser or sign out
- Not used for tracking, advertising, or cross-site identification
We do not set third-party cookies, pixel trackers, or any persistent tracking identifiers on merchants or their end customers.
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Right of access — request a copy of the personal data we hold about you
- Right to rectification — request correction of inaccurate data
- Right to erasure — request deletion of your personal data (“right to be forgotten”)
- Right to restriction — request that we limit how we process your data
- Right to data portability — request a machine-readable export of your data
- Right to object — object to processing based on legitimate interests
- Right to opt out of sale — we do not sell personal data; this right is therefore automatically satisfied
To exercise any of these rights, contact us at contact@q-tracker.app. We will respond within 30 days. We may ask you to verify your identity before processing your request.
9. Merchant Customers
q-tracker processes Shopify order data that may be derived from transactions with your customers. However, we do not have a direct relationship with your customers, and we do not collect, store, or process any individually identifiable customer data (names, email addresses, phone numbers, billing or shipping addresses, or payment information).
Order records stored by q-tracker contain only aggregate financial fields (order total, currency, line item quantities and prices, shipping cost, country code) sufficient to compute P&L metrics. If your customers contact us directly regarding their personal data, we will direct them to you as the data controller.
10. International Data Transfers
Our infrastructure is located primarily in the United States. If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, your data may be transferred to and processed in the United States. Such transfers are made in accordance with applicable data protection laws, relying on Standard Contractual Clauses (SCCs) or other appropriate safeguards as offered by our sub-processors (Vercel, Railway).
11. Children's Privacy
q-tracker is a business tool intended for adult merchants. We do not knowingly collect personal information from individuals under the age of 16. If you believe a minor has provided us with personal information, please contact us and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other reasons. When we make material changes, we will update the “Last updated” date at the top of this page and notify active users by email at least 14 days before the changes take effect.
Your continued use of q-tracker after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or the way we handle your data, please contact us:
q-tracker — a product of Qazar
Operated by: Denis Thomas (Qazar)
Email: contact@q-tracker.app
App URL: https://q-tracker.app
This Privacy Policy does not constitute legal advice. If you have specific legal questions about data protection obligations in your jurisdiction, we recommend consulting a qualified legal professional.