Truefold — Data Use Disclosure
Version 1.0 — Effective 2026-08-27
Last updated: 2026-08-28
This disclosure explains, in plain language, what data Truefold accesses when you connect your store and marketing accounts, what we keep, what we deliberately throw away, and what we do with it. It is written for the Shopify App Store listing and is incorporated into the Truefold Privacy Policy (truefold.ai/privacy). Truefold is operated by Auke Vos, Mexico. Questions: privacy@truefold.ai.
What Truefold does
Truefold builds an automated analytics layer over your commerce data: a reviewed data model, dashboards, a blended profit-and-loss view, and an AI assistant you can ask questions in plain English. To do that, it syncs data from the sources you choose to connect — Shopify, Meta Ads, Google Ads and Klaviyo — into a private, isolated dataset that belongs to your store alone.
What we access from Shopify
Read-only access to Orders, Customers and Products. We request access to Shopify's protected customer data because order and customer records are what a profit-and-loss and analytics product is built from. We never write to your store.
What we keep — and what we deliberately discard
We minimise before we store. Every record is filtered the moment it arrives, before anything is written to disk:
| We keep | We discard on arrival — never stored |
|---|---|
| Order, line-item, refund and transaction amounts | Customer names |
| Product and catalog data | Street addresses |
| Customer email — only as an irreversible, store-specific hash | Phone numbers |
| Platform IDs (order IDs, customer IDs) | IP addresses, browser and session identifiers |
| Coarse location: city, region, country, postal code | Payment-card details and metadata (last 4, BIN, AVS) |
| Marketing-consent status | Order note attributes and the embedded customer profile on orders |
The email hash deserves a plain explanation: we replace every customer email with a one-way cryptographic hash keyed uniquely to your store. It lets us recognise that two orders belong to the same customer within your store — which repeat-purchase and LTV analytics need — but it cannot be reversed into the email address, and the same email produces a different hash in every other store, so data can never be correlated across merchants. A hashed email is still personal data under GDPR, and we treat it as such.
What we use your data for — and what we never do
Your data is used for exactly one purpose: providing Truefold's analytics to you. We do not sell your data or your customers' data. We do not use it for advertising. We do not share it with other merchants or combine it across stores. We do not use it to train AI models. We do not make automated decisions about your customers that have legal or similarly significant effects.
How the AI features handle your data
When you ask Truefold's AI assistant a question, the question and the resulting query answers are processed by our AI model provider (currently Google's Gemini, via Google Cloud's Vertex AI) to generate the response. Server-side guardrails we enforce — independently of the AI model — keep columns flagged as personal data out of any query result, so the AI works with your business metrics, not your customers' identities. Raw stored records are not used to train any model, by us or by our providers.
Where your data lives
Your synced data is stored in a dedicated dataset in Google Cloud (BigQuery), one per store, encrypted at rest and in transit. Merchants in the EU can have their dataset pinned to the EU region. Full details, including our sub-processors and international-transfer safeguards, are in the Truefold Sub-processor Register and the Data Residency & International Transfers statement at truefold.ai/legal.
How long we keep it
Raw synced records are kept on a rolling 90-day window. The aggregated analytics built from them are kept for as long as you subscribe. If you uninstall the app or disconnect a source, we delete the associated data within 30 days.
Your customers' rights
Truefold honours Shopify's mandatory privacy webhooks. When one of your customers asks you for their data, we provide you an export of what we hold (customers/data_request); when they ask to be forgotten, we delete their records (customers/redact); when you uninstall and Shopify tells us to redact your store, we delete everything (shop/redact). Because we don't store plaintext identifiers, these requests are matched through the hashed email and platform IDs.
Our role
For your store's data, you are the data controller and Truefold is your data processor. Our Data Processing Agreement (truefold.ai/legal/dpa) — including EU Standard Contractual Clauses for merchants in the EEA, UK and Switzerland — applies automatically when you install the app.