Privacy policy
Effective August 6, 2026. This policy explains what the app processes, why it is needed, and how merchants can request help or deletion.
Information the app processes
- Shopify store identity, installation sessions, and authorized product and legal-policy data.
- Product titles, descriptions, prices, inventory, images, identifiers, variants, collections, and publication status needed to build the feed.
- Catalog coverage, ad-readiness results, change previews, sync history, Feed Guardian alerts, authorized-user audit events, billing-plan records, retained feed files, and promotion records.
- Optional expert-setup intake details, including the team contact, target country, budget range, notes, charge status, and fulfillment status.
- SFTP host, username, path, and encrypted password or private key supplied by the merchant.
- If the merchant enables Hosted URL delivery, an encrypted opaque URL token, its non-reversible lookup hash, rotation time, and last access time. The hosted file contains the same product-feed catalog retained for SFTP delivery.
- An optional encrypted OpenAI Ads API key, account and feed identifiers, campaign summaries, product-serving metrics, conversion source and definition records, attribution-parameter configuration, advanced-matching privacy-review records, account-readiness results, daily campaign, ad-group, and ad performance, product cost and inventory coverage, profit estimates, recommendation records, and paused campaign draft details when the merchant enables Ads intelligence.
- When the merchant separately enables conversion tracking, five standard Shopify customer events: page views, product views, adds to cart, checkout starts, and completed checkouts. The app processes the event time, product identifiers and names, quantities, purchase value and currency, a URL with query strings and fragments removed, browser user agent, Shopify consent state, and OpenAI-provided opaque attribution references when available. For merchant reporting, the app may also retain non-customer campaign, ad-group, ad, and ad-account identifiers captured from configured landing-page parameters. Query strings and fragments are removed before URLs are stored.
The app does not request or store Shopify customer records, orders, or payment card data. Conversion tracking does not request or transmit customer names, email addresses, phone numbers, street addresses, or Shopify customer records.
The optional custom-audience assistant reads a merchant-selected file only inside that user's browser. Raw email addresses and phone numbers are normalized and SHA-256 hashed locally, then downloaded by the user. The file and identifiers are not transmitted to or stored by BridgeSFTP. The merchant separately chooses whether to upload the prepared file in OpenAI Ads Manager.
How information is used
Information is used to scan product eligibility, score catalog ad readiness, preview feed changes, create and deliver the complete coverable product feed, test and operate the merchant-provided SFTP connection, monitor delivery and specification health, send optional alerts, maintain an authorized-user audit trail, provide optional Ads intelligence and merchant-requested Ads API actions, secure the service, validate attribution parameters, record merchant-reviewed privacy and readiness settings, provide merchant-confirmed paused bulk campaign creation or campaign pauses, and respond to support requests.
Conversion tracking is disabled by default. When a merchant enables it, Shopify's web pixel consent controls determine when the app receives events. The app honors data-sale opt-out signals by marking those events for limited use. Merchants can test or disconnect tracking in the app.
If expert setup is made available and requested, intake details are used only to coordinate and fulfill that campaign service. Account passwords and private keys must not be submitted in the intake form.
Storage and sharing
Application data is hosted in the United States. SFTP credentials are encrypted at rest. Product feed data is transmitted to the SFTP destination configured by the merchant. When Hosted URL delivery is enabled, the latest retained feed is available at a high-entropy HTTPS address chosen by the app for OpenAI retrieval; rotating or disabling the address revokes it. Service providers may process data only to host, secure, monitor, or bill the app. Information is not sold.
When conversion tracking is enabled, the selected conversion events are transmitted to OpenAI at the merchant's direction for advertising attribution and measurement. The OpenAI Conversions API key is encrypted at rest and never exposed in storefront code. The pixel uses a separate, store-specific relay token that cannot access the merchant's OpenAI account or reveal the Conversions API key.
BridgeSFTP does not add customer names, email addresses, phone numbers, or postal addresses to its server-side conversion events. If OpenAI Ads advanced matching is enabled for a web pixel, Ads Manager controls that setting. The app may retain the merchant's recorded review status and timestamp, but it does not change the setting in Ads Manager.
If the merchant enables email alerts, the destination email address, store domain, alert title, severity, and message are sent to the transactional email provider solely to deliver the notification.
Retention and deletion
Operational store data is retained while the app is installed. The app deletes store configuration, product index, sync records, Feed Guardian alerts, audit events, billing ledger, optional Ads connection records, expert-setup requests, promotion redemption, and Shopify sessions after an uninstall or Shopify shop-redaction request. Up to 30 delivered feed files and 10 feed previews are retained while the app is installed so the merchant can audit, download, compare, or redeliver a file. Older files are deleted automatically. Infrastructure logs may remain for up to 30 days.
Successful OpenAI delivery records retain operational metadata such as event type, time, source path, status, and attempt count. When Ads intelligence is enabled, a separate first-party measurement record may retain product identifiers and names, quantities, purchase value and currency, and non-customer Ads resource IDs so the merchant can view funnel and product-profit reporting. These measurement records are automatically deleted after 90 days. They do not retain opaque OpenAI references, customer identifiers, URL query strings, or browser user agents. A failed event's sanitized OpenAI payload is encrypted only for retry and is deleted after successful delivery or no later than the seven-day delivery window.
Merchant choices
Merchants can replace or remove SFTP and optional Ads API credentials, rotate or disable a hosted feed, change the alert email, uninstall the app, or request access, correction, or deletion by emailing privacy@bridgesftp.com.
Security and contact
We use access controls, encryption, TLS, least-privilege Shopify scopes, and restricted infrastructure access. No system is risk-free. Report privacy or security concerns to support@bridgesftp.com.