This Privacy Policy explains how Performetic OS ("Platform", "we", "us") collects, uses, stores, and protects your personal data and third-party platform data as part of our agency operations and CRM/analytics service. By using the Platform, you agree to the practices described in this policy.
1. Data Controller and Contact
The party responsible for processing your data is Performetic. For any privacy-related questions, requests, or to revoke access, contact us:
- Email: [email protected]
2. Data We Collect
2.1. Account Data
When you register and use your account, we process: name, email address, password (stored only as a secure hash), role and permission information, and the agency/brand you belong to.
2.2. Usage Data
Data about how you use the Platform: sign-in records, action logs (audit logs), device and browser information, IP address, and error logs. This data is processed for security, debugging, and improving service quality.
2.3. Third-Party Platform Data (With Your Consent)
With your explicit authorization, we access data from the advertising, analytics, and e-commerce accounts you connect, solely to provide the features shown to you within the Platform:
- Shopify — aggregated store performance data: order counts, revenue, average order value, discounts, refunds, cancellations, top-selling products, abandoned/recovered checkouts, and new vs. returning customer counts. We do not read or store customer names, email addresses, phone numbers, or postal addresses. Only aggregated daily metrics are retained.
- Google Ads — campaign, ad, spend, and performance metrics.
- Google Analytics — site/app traffic and conversion metrics.
- Meta Ads (Facebook / Instagram) — campaign and ad performance metrics.
- TikTok Ads — campaign and ad performance metrics.
This data is accessed only when you authorize the relevant integration, and you can revoke access at any time (see Section 8).
3. Google API Services — Limited Use Disclosure
Performetic's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Data received from Google is used only to provide the features shown to the user.
- This data is not sold or marketed to any third party.
- This data is not used for advertising.
- Humans do not read or access this data, except with the user's explicit consent or as required for security, compliance, or legal obligations.
Sharing, transfer, and disclosure of Google user data
We do not share, transfer, or disclose Google user data to any third party, except in the following limited cases:
- Service providers (sub-processors): with infrastructure providers strictly necessary to operate the Platform — currently Hetzner Online GmbH (server and database hosting, EU / Germany) — which process the data only on our behalf, under contractual confidentiality obligations, and solely to provide the service. We do not disclose Google user data to our email provider (Amazon SES) or to any advertising, analytics, or marketing partner.
- With your consent: when you explicitly direct or authorize us to do so.
- Legal requirements: when we are required to comply with applicable law, regulation, legal process, or an enforceable governmental request.
We do not transfer or disclose Google user data to third parties for purposes other than the ones described above. In particular, we never use, transfer, or sell Google user data for: targeted, personalized, interest-based, or retargeted advertising; selling to data brokers or information resellers; determining credit-worthiness or for lending purposes; or any purpose unrelated to providing or improving the Platform's user-facing features.
4. Shopify Data — Protected Customer Data and Compliance
Performetic accesses Shopify order and store data via the official Shopify Admin API (GraphQL) over HTTPS. We process only aggregated metrics and do not store customer personal data (name, email, phone, or address).
We implement Shopify's mandatory data-protection (GDPR) webhooks and verify every webhook delivery with an HMAC signature:
- customers/data_request — acknowledged; we hold no customer personal data to return.
- customers/redact — acknowledged; no customer personal data is stored.
- shop/redact — all data associated with the store is deleted.
- app/uninstalled — the store integration is disconnected and data access stops immediately.
5. Data Storage and Retention
Your data is stored in our databases hosted on Hetzner infrastructure located in the European Union (Germany). Third-party integration credentials (tokens/secrets) are stored encrypted with AES-256-GCM and are never returned in plaintext in API responses.
We retain your data for as long as your account is active and to the extent necessary to provide the service. When you close your account or remove an integration, the related data is deleted or anonymized within a reasonable period, subject to legal retention obligations.
6. Sub-processors
To provide the service, we use the following infrastructure providers:
- Hetzner Online GmbH — server and database hosting (EU / Germany)
- Amazon SES (Amazon Web Services) — transactional email delivery
These providers access only the data required to provide the service, under their own contractual and legal obligations.
7. Security
We apply industry-standard measures to protect your data: TLS encryption in transit, AES-256-GCM encryption at rest for sensitive credentials, role-based access control (RBAC), session- and request-level authorization, rate limiting, and audit logging. While no method is 100% secure, we make all commercially reasonable efforts to protect your data.
8. Revoking Access
You can revoke a connected third-party account's (Google, Meta, TikTok, Shopify, etc.) access to the Platform at any time:
- By removing the integration from within the Platform.
- For Google, additionally from the Google Account Permissions page.
- For Shopify, by uninstalling the app from your Shopify admin.
- To request deletion of all your data, by contacting us at [email protected].
When you revoke access, we stop fetching new data from the relevant platform.
9. Your Rights under GDPR and KVKK
Under the EU General Data Protection Regulation (GDPR) and Turkey's Personal Data Protection Law (KVKK No. 6698), you have the right to: access your data, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, objection to processing, and withdrawal of consent. To exercise these rights, contact [email protected]; we respond within the legally required timeframes.
10. Cookies
The Platform uses cookies necessary for session management and core functionality. These cookies authenticate you and remember your preferences (e.g., theme, language). We do not use marketing or third-party tracking cookies. You can manage cookies from your browser settings; however, disabling necessary cookies may prevent the Platform from functioning.
11. Changes
We may update this Privacy Policy from time to time. For significant changes, we will revise the "Last updated" date on this page and notify you where appropriate. Updates take effect when published on this page.
12. Contact
For questions about this policy: [email protected]
Account Deletion (Google Play / App Store)
To request deletion of your Performetic OS account and associated personal data:
1. Send an email titled "Account Deletion Request" to [email protected] from your registered email address, or create a request via the in-panel support section. 2. Once verified, your account and personal data (name, email, phone, profile details, notification history, device registrations) are permanently deleted within 30 days. 3. Records subject to statutory retention (such as invoices and financial records) are kept for the legally required period and deleted afterwards.
You may also request deletion of specific data without deleting your account through the same channel.