Privacy policy

Last updated 11 August 2026

Veltoza builds Shopify applications that measure advertising performance and deliver product data to advertising platforms. This policy describes what those applications collect and where it goes. It is written to be specific rather than general.

Who we are

Veltoza is a trading name of AFA ECOMMERCE LIMITED. For any privacy question, including access and deletion requests, contact privacy@veltoza.com.

What the storefront pixel collects

Shopify's official Web Pixel runs on the merchant's storefront in Shopify's sandbox. For each of five standard events — page viewed, product viewed, added to cart, checkout started and checkout completed — it sends:

FieldExampleWhy
Shopify event IDa UUIDDeduplicating the browser and server copies of one event
Shopify client IDan opaque IDJoining events from one browsing session
Page URL and path/products/exampleAttribution and reporting
Product and variant identifiersSKU, variant IDWhich item was viewed or bought
Amount and currency19.99 GBPConversion value
Campaign parametersutm_source, gclidWhich ad produced the visit

What we never store

Veltoza stores no customer names, email addresses, postal addresses, phone numbers, payment details or Shopify customer IDs. None of these is ever written to our database.

Customer matching for ad measurement

One narrow exception exists, and only in the tracking application. On a completed purchase, and only where the shopper's marketing consent is granted, the customer's email, phone, name and address are used to match that purchase to the advertisement that produced it — Google Ads calls this enhanced conversions, Meta calls it customer matching.

These values are irreversibly hashed with SHA-256 before they are sent, and they are never written to storage. For Google Ads the hashing happens inside Google's own tag in the shopper's browser, so the plaintext never reaches us at all. For Meta and GA4 the values are hashed in memory on our server at the moment of sending and discarded immediately afterwards. Nothing about a shopper who declines marketing consent is used this way, and a merchant who does not connect an advertising platform triggers none of it.

Where the data goes

Events are sent to the advertising destination the merchant connected. The merchant chooses the destination; we add none. Product feed files are delivered only to the feed connection the merchant created in their own advertising account.

Merchant credentials

API keys, conversion keys and feed passwords a merchant provides are encrypted at rest with AES-256-GCM and decrypted only in memory at the moment they are used. They are never sent to a storefront, written to logs, or exposed in any browser.

Retention

Event records are operational receipts — they exist to prove a conversion was delivered and to retry failures — not a customer profile. When a merchant uninstalls, all of their data — settings, credentials and receipts — is deleted immediately and in full. Shopify's later redaction webhooks are honoured as well, and find nothing left to delete.

Your rights

Because Veltoza stores no personal identifiers, we normally cannot link data to an individual. Where a merchant supplies an order reference through Shopify's customer data request or redaction webhooks, we respond to that request and delete the corresponding records.

Sub-processors

Cloudflare (application hosting and content delivery) and our managed PostgreSQL provider. Advertising destinations are chosen by the merchant and act as independent controllers of the data they receive.

Changes

Material changes will be announced to installed merchants before taking effect.