Back to Home

Privacy Policy

Last updated: January 18, 2026

GDPR Compliant

Full compliance with EU data protection regulations

Data Encrypted

All data encrypted in transit and at rest

30-Day Retention

Personal data automatically deleted after 30 days

No Data Selling

We never sell your data to third parties

1Introduction

North Star Metric ("we", "our", or "us") provides analytics and attribution services for Shopify merchants. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our services.

We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws.

2Data We Collect

2.1 For Merchants (Our Customers)

  • Account information (email, store name, Shopify store URL)
  • Billing information (processed securely via Shopify)
  • Usage data (how you interact with our dashboard)

2.2 For Store Visitors (End Users)

When visitors browse stores using our service, we collect:

  • Device fingerprint hashes — Non-reversible hashes derived from browser characteristics (canvas, WebGL, audio context). These cannot identify a person directly.
  • Session data — Pages viewed, time on site, referrer URL
  • Marketing attribution — UTM parameters, click IDs (gclid, fbclid)
  • IP address — Stored as hashed CIDR ranges, not full IP addresses
  • Order data — Only when a purchase is made, via Shopify webhooks

What We DON'T Collect

  • Full names or addresses (only from Shopify order webhooks, hashed)
  • Credit card information (handled by Shopify)
  • Passwords or login credentials
  • Sensitive personal data (health, religion, etc.)

3Legal Basis for Processing (GDPR)

We process data under the following legal bases:

  • Contract Performance — To provide our services to merchants
  • Legitimate Interest — For fraud prevention, bot detection, and service security
  • Consent — For fingerprinting and cross-device tracking (when required by merchant's cookie banner)

Merchants are responsible for obtaining appropriate consent from their visitors through their cookie consent management platform (CMP).

4Data Retention

Data TypeRetention Period
Device fingerprints30 days
Session events30 days
Attribution clicks30 days
Order/conversion data2 years (for merchant reporting)
Merchant account dataDuration of service + 30 days

Data is automatically deleted after the retention period expires using database TTL policies.

5Third-Party Data Sharing

When a merchant explicitly connects an advertising platform through our Integrations page, we forward hashed and anonymized conversion data to that platform on the merchant's behalf. This is server-side forwarding initiated by the merchant's configuration.

The platforms that may receive data include:

  • Meta (Facebook) — via the Conversions API (CAPI). Hashed email, phone, and order value for ad optimization.
  • Google Ads — via the Google Ads API. Hashed customer identifiers and conversion value.
  • TikTok — via the TikTok Events API. Hashed identifiers and conversion events.

No data is shared with these platforms unless the merchant activates the integration. All personally identifiable information is hashed (SHA-256) before transmission.

Data is stored in ClickHouse, an analytical database hosted within the EU (Hetzner, Germany), with automatic TTL-based deletion as described in Section 4.

6Your Rights (GDPR)

Under GDPR, you have the following rights:

Right to Access

Request a copy of your data

Right to Erasure

Request deletion of your data

Right to Portability

Receive your data in a portable format

Right to Restrict

Limit how we process your data

To exercise these rights, contact us at privacy@northstarmetric.io

7Opt-Out for Store Visitors

Store visitors can opt out of tracking in several ways:

  • Cookie Banner — Decline cookies/tracking in the store's consent banner
  • Browser Console — Run NSM_optOut() in the browser console
  • Contact Store — Ask the store merchant to delete your data

When you opt out, we immediately stop tracking, clear all stored identifiers, and send a deletion request to our servers.

8Data Security

We implement industry-standard security measures:

  • TLS 1.3 encryption for all data in transit
  • Encrypted storage for sensitive data at rest
  • SQL injection protection with parameterized queries
  • Regular security audits and monitoring
  • Access controls and authentication

9Data Transfers

Our servers are located in the European Union (Germany). Data may be processed by sub-processors in compliance with GDPR requirements and appropriate safeguards (Standard Contractual Clauses where applicable).

10Contact Us

For privacy-related inquiries:

Privacy Contact

Email: privacy@northstarmetric.io

We aim to respond to all privacy requests within 30 days.

11Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.