Retrics

LEGAL — PRIVACY

Privacy, in plain language.

Retrics reads your store's history to help you keep your customers. That only works if you can trust us with it. Here is exactly what we collect, why, and what we will never do.

LAST UPDATED · 31 JUL 2026

MATERIAL CHANGES TAKE EFFECT · 14 AUG 2026

01This revision

This document was last updated on 31 July 2026. Where this revision makes a material contractual change, that change takes effect on 14 August 2026. Until then the previous version governs the point it changed. Corrections that only make an existing practice clearer — naming a provider more precisely, describing a capability that is switched off — describe what is already true and are not held back to that date.

Sending from Retrics is unavailable in this release. Direct email to your customers, SMS, WhatsApp, scheduled delivery and the Klaviyo audience handoff are all switched off in code; no plan, setting, account connection or onboarding step turns them on. Where this document describes those channels, it describes a capability that is built and dormant, not one operating today. What is available is the campaign-safe CSV export: you download the frozen audience — with your global control already dropped — and send it from your existing platform.

Retrics also does not draft customer-facing message copy, does not upload any customer list to Google, and does not create, edit, pause or change any advertising campaign. Those are described in place below.

02What we collect

Account data: your name, email address, and workspace settings when you create a Retrics account.

Store data: when you connect a Shopify or Square store, we read customer and order records through the platform's API — customer name, email, phone, SMS-marketing consent, and country/state/city, plus order history and the marketing attribution of each order (referrer, landing page, and UTM tags). We do not read payment credentials or full street addresses. We also keep an irreversible hash of each customer email, which lets us match analytics and advertising audiences without handling the raw address more than necessary.

Abandoned checkouts: where the platform provides it, we store the checkout-recovery link so the win-back outreach you approve can point a shopper back to their cart. In this release that link travels in the campaign-safe CSV you export, not in a message Retrics sends.

Advertising accounts: if you connect a Meta or Google ad account, we read your ad performance and insights so we can attribute your ad spend to store-verified revenue and recommend budget changes for you to apply yourself. Retrics does not create, edit, pause, or budget a campaign — that is switched off in code, as the “Advertising audiences & ad reporting” section below explains. The only customer data we write to any ad account is a custom audience of hashed emails: it goes to Meta, only when you ask for one. A connected Google account is read-only — we read its reporting and never upload your customer list to it. We access only your own connected ad account.

Usage data: standard logs (IP address, browser type, pages viewed) used to keep the service reliable and secure.

03How we use it

To run the product: computing cohorts, scoring lapse probability, predicting each customer's reorder window, and ranking the retention move worth making next. You write the outreach yourself — customer-facing AI drafting is off today, as the “AI processing” section below sets out. Nothing is sent to your customers without your explicit action, and Retrics publishes no advertising at all.

To prepare the outreach you approve for export — Retrics does not deliver messages to your customers in this release; to build a custom audience in your own connected Meta ad account when you ask for one; and to diagnose and report on the advertising you run yourself on Meta and Google, so we can recommend budget changes for you to apply (see the “Message delivery” and “Advertising audiences & ad reporting” sections below).

To operate and improve Retrics: debugging, capacity planning, and aggregate (never customer-identifiable) product analytics.

We do not sell your data or your customers' data, and we never share it with a third party for that party's own purposes. The only data we share is what is needed to carry out the message delivery and to build the advertising audiences you configure, as described below.

04Message delivery

Retrics does not deliver messages to your customers in this release. Direct email, SMS, WhatsApp (via Meta's WhatsApp Business platform), scheduled delivery and the Klaviyo audience handoff are switched off in code, and no plan, setting, account connection or onboarding step turns them on. No customer email address, phone number or message body is passed to any delivery provider for that purpose. What you use instead is the campaign-safe CSV export: you download the frozen audience — your global control already removed, and unsubscribed or bounced addresses excluded — and send it from your existing platform, under your own relationship with that platform.

None of the following happens in this release; it describes exactly what would be shared if and when delivery is enabled, and this section will be updated to say it is live before it is. When you approve outreach, we would pass the minimum needed to the channel you chose so the message reaches your customer: that channel would receive your customer's email address or phone number and first name in plain form, because delivering an addressed message requires it. SMS and WhatsApp would be sent only to customers who are marketing-subscribed. The Klaviyo handoff would stage profiles into your own email-marketing account so you can send the campaign yourself.

05Advertising audiences & ad reporting

If you connect a Meta (Facebook and Instagram) or Google advertising account, Retrics helps you reach your own customers with your own advertising — but the two are not used the same way. Meta is the only advertising platform that receives any customer data. To build a “custom audience” from your customer list, each email address is irreversibly hashed before anything leaves our systems — we send Meta only these hashes and the audience's name, and never a raw email address, name, phone number, or postal address. A connected Google account is read-only: no customer list, hashed or otherwise, is ever uploaded to it. What we read is the same on both — your ad performance and insights from the connected account, so we can measure your ad spend against store-verified revenue and recommend budget changes for you to review and apply yourself. Retrics does not create, edit, pause, or change the budget or status of a campaign: that execution is switched off in code platform-wide, and no plan, setting, or approval turns it on. A recommendation can include suggested campaign wording for you to reuse, but it stays on your screen — no ad copy or creative is sent to Meta or Google. The Meta audience upload described above is the only write we make to any ad account. If campaign execution is ever enabled, this section will be updated to say so before it is. Meta acts as an independent advertising platform and processes the hashes you have it upload for your advertising under its own terms, including the Meta Platform Terms; your Google account, and the reporting we read from it, stay governed by Google's advertising policies. We do not use the Meta Pixel or any server-side conversion tracking. (Separately, WhatsApp outreach would have Meta's WhatsApp Business platform receive a customer's phone number and first name to deliver a message you approved — that channel is switched off in this release and receives nothing; see “Message delivery”.)

06AI processing

Customer-facing AI drafting is switched off today, platform-wide and in code. Retrics does not produce outreach copy or ad creative for you: you write the message, and no message content and no customer record are sent to an AI provider for that purpose. What follows describes exactly what would be shared if and when it is enabled, and this section will be updated to say it is live at that point.

If and when drafting is enabled: Retrics uses a third-party AI provider, under a data-processing agreement. The provider would receive your brand voice and store currency and an aggregate factual brief for each opportunity (for example customer counts, average lifetime value, and reorder intervals). It would not receive your customers' names, email addresses, phone numbers, addresses, or individual purchase histories. Its inputs and outputs are not used to train models for other customers. Drafting would remain optional; with it off, Retrics uses standard templates and sends nothing to the AI provider for drafting.

Two merchant-facing AI features do run today, where your workspace has them, and neither involves your customers' personal data. The audience composer turns a plain-English description of the audience you want into a rule that Retrics then validates and runs itself: the provider receives your description, your store currency, and the titles and internal ids of your top products and collections. A one-line audience summary for your own screen is generated from the audience's name, its rule, how many customers currently match, and the value at stake. Neither sends names, email addresses, phone numbers, addresses, or individual purchase histories, and neither writes anything that reaches a customer.

07Geo Redirects & Store Locator (Shopify app)

Retrics also operates Geo Redirects & Store Locator, a Shopify app that routes visitors to the right regional storefront and powers a store locator. It is built to need as little data as possible and stores no Shopify customer records or direct customer identifiers.

Visitor location (transient): to decide a redirect, the app reads a visitor's approximate location (country, and optionally region/city) from Shopify and edge-network geolocation headers. A raw IP address may pass through the request in memory to make that decision, but it is never written to our database or returned in any response.

Aggregate analytics: we store per-day, per-country counts of geo events (a redirect fired, a banner shown, a country blocked) and an opaque, non-identifying per-visitor id. No names, emails, addresses, or raw IP addresses.

Order totals by country (optional): for merchants who enable revenue attribution, we read order counts and revenue aggregated by country through the Shopify Admin API. We use only the order total and the shipping country code — we do not read or store customer identities, order line items, or any other personal order data.

Locator searches (coarse): when a shopper uses the store locator we record the searched city/ZIP text and an origin rounded to about 11 km, plus how many stores were shown, so merchants can see unmet demand — never an IP address, a precise location, or an identity. Store addresses and the text a shopper types into the locator search box are sent to a third-party geocoding service to obtain map coordinates.

Store locations are merchant-provided business data. We also store the shop domain, plan, and the merchant's Admin API token (encrypted at rest). We honor Shopify's mandatory data-erasure webhooks: because this app holds no Shopify customer record or direct customer identifier to match, customer data-request and redact webhooks have no customer record to return or erase; shop redact removes the uninstalled shop's app-owned data.

08Subprocessors

We rely on a small set of vetted providers, each under a data-processing or platform agreement: cloud hosting and database providers that run the service; a third-party AI provider for the AI features described above, which today means the merchant-facing audience composer and audience summary and not customer-facing drafting; the advertising platforms you connect — Meta, which receives an audience of hashed emails when you ask for one and reports on the campaigns you run yourself, and Google, which only reports and never receives your customer list — and Meta's WhatsApp Business platform if you use WhatsApp; and email and SMS delivery providers. Production access is restricted and audited. A current list of the subprocessors we use is available on request at legal@retrics.ai.

09Retention & deletion

We keep store data while your workspace is active. For a verified Shopify customers/redact request, Retrics automatically stops the current store sync, deletes the matching customer record and derived memberships, and removes that person's identity and sequence fields from retained order, checkout, and channel facts. To prevent a later Shopify sync from recreating that identity, Retrics retains only keyed, one-way match hashes of the erased customer and order selectors; the raw selectors are not stored in these prevention records. The installation-scoped copy is removed with that installation on shop/redact. A limited workspace-scoped, non-reversible prevention receipt remains until workspace deletion so reinstalling or reauthorizing the store cannot undo the verified erasure. These prevention hashes are separate from unsubscribe, bounce, or complaint suppressions, which remain as an irreversible email hash so a deletion cannot make us contact someone who opted out; the erasure request does not create a new suppression. Automatic Retrics erasure does not remove a copy the merchant previously sent or exported to its own external destination; the merchant must use that provider's privacy controls to complete the request there. A customers/data_request delivery creates a count-only audit receipt and an encrypted, privacy-minimized case. An authorized owner/admin can compile the current matching Retrics-held records as a no-store download; Retrics does not automatically email or otherwise deliver that report. Case selectors expire at the earlier of the legal deadline or seven days after first delivery. When you uninstall Retrics, we honor Shopify's shop/redact webhook and purge the exact disconnected installation, its encrypted access token, and its connection-owned synced graph while preserving an active reauthorization and minimized workspace-level audit, suppression, and erasure-prevention records. If you ask us to delete your workspace, we action it manually and aim to complete it within 30 days; disconnecting a store inside the app changes its status but does not by itself delete data already synced.

10Your rights

You can request a copy, correction, or deletion of your personal data at any time. Where GDPR or CCPA/CPRA apply, we honor access, portability, deletion, and opt-out rights — including the right to opt out of the sharing of personal information for cross-context behavioral advertising. Write to us and we'll respond within 30 days.

11Contact

Retrics operates the Retrics platform and the Geo Redirects & Store Locator Shopify app, and is responsible for the data practices described in this policy — which is the single privacy policy covering both.

Privacy questions, requests, or concerns: legal@retrics.ai.

Read the terms of service