Legal • AI Ads Tracker

Privacy Policy

Last updated: September 2, 2026

1. Introduction

This Privacy Policy describes how Trakit - AI Ads Tracker(the "App"), operated by Trakit ("we", "us", or "our"), collects, processes, and safeguards information when installed on your Shopify-supported store.

The App provides attribution, telemetry, and server-side Conversions API (CAPI) integrations for emerging Artificial Intelligence (AI) advertising networks, conversational search engines, and AI shopping assistants (including OpenAI / ChatGPT Ads, Perplexity, and Google Gemini).

We are committed to operating in full compliance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and Shopify Partner Program requirements.

2. Information the App Collects & Processes

To attribute customer visits and purchases originating from AI search platforms and dispatch server-side conversion telemetry, the App processes the following categories of data:

A. Merchant Store Details

  • Shopify store domain, shop ID, store email, currency, and timezone.
  • Merchant-configured credentials for AI advertising networks (such as OpenAI Ads Pixel IDs and Conversions API secret tokens).

B. AI Referral & Conversion Telemetry

When a visitor arrives at your storefront from an AI search engine, sponsored recommendation, or conversational ad placement, our Shopify storefront integration captures session attribution signals:

  • AI Attribution Tokens: Ad referral query parameters and tracking tokens (such as OpenAI oppref tokens, referral campaign parameters, and conversational search source headers).
  • Event Types: Storefront interaction signals including Page Views, Product Views (ViewContent), Add to Cart, Initiate Checkout, and Completed Orders (Purchase).
  • Order Attributes: Order ID, currency, purchase value, product IDs, and purchased items.
  • Cryptographic Matching Parameters: When server-side conversion dispatch is enabled for ad attribution, customer email addresses and phone numbers are cryptographically hashed using SHA-256 before transmission to authorized AI ad endpoints.

3. How We Use Collected Data

Collected data is processed strictly for the following purposes:

  • To transmit server-side conversion events directly to merchant-authorized AI ad endpoints (such as the OpenAI Conversions API at bzr.openai.com).
  • To provide real-time attribution dashboards showing revenue, conversions, and ROAS generated from AI search and ad channels.
  • To track organic and paid referral telemetry from AI models and conversational engines (ChatGPT, Claude, Perplexity, Gemini).
  • To eliminate duplicate event recording between browser events and server-side conversion dispatches.
  • To provide technical merchant support and vital service notifications.

We do NOT sell, rent, trade, or monetize your store data or customer information to any third parties or data brokers.

4. Third-Party Destinations

The App transmits conversion telemetry exclusively to AI ad platforms that the merchant explicitly configures and authorizes:

  • OpenAI / ChatGPT Ads: Server-side Conversions API for attributing ad performance and conversion values.
  • Emerging AI Ad Networks: Authorized endpoints for conversational search commerce as configured by the merchant.
  • Secure Cloud Infrastructure: Amazon Web Services (AWS EventBridge / Lambda) and Vercel for high-throughput, encrypted conversion event processing.

5. Shopify Mandatory Privacy Webhooks (GDPR & CCPA)

The App strictly honors Shopify's mandatory data privacy webhooks:

  • Customer Data Requests (customers/data_request): When a customer requests their data via your store, Shopify notifies us and we compile any associated event log records.
  • Customer Data Erasure (customers/redact): When a customer requests erasure of their personal information, we scrub and anonymize all matching records within 30 days.
  • Shop Data Erasure (shop/redact): 48 hours following an App uninstallation, all store tokens, AI credentials, and event logs are permanently purged from our databases.

6. Data Security & Retention

All data in transit is encrypted using modern TLS 1.3 / HTTPS encryption. AI platform access keys and API credentials are encrypted at rest. Event telemetry logs are retained for a maximum of 60 days to allow attribution reconciliation, after which they are permanently deleted.

7. Contact Information

For questions or privacy requests regarding this Privacy Policy, please contact:

Email: privacy@trakit.store
Support: support@trakit.store
Website: https://trakit.store