Privacy Policy

Last updated: August 2026

1. Who we are and what this covers

Tomify GTM Pixel Pro ("the App") is a Shopify application, operated by Tomify eCommerce Strategy, that connects a Shopify store to Google Tag Manager and — when the merchant enables it — forwards conversion events from our servers to the advertising and analytics destinations the merchant has configured.

This policy explains what data the App processes, why, for how long, and who else sees it.

2. Our role

For data about the merchant's own account and configuration, we act as a controller.

For data about the merchant's customers, the merchant is the controller and we act as a processor: we process that data only on the merchant's documented instructions — the settings they choose in the App — and never for our own purposes. We do not use it to build profiles, we do not enrich it with other sources, and we do not reuse it across merchants.

3. Data we process

3.1 Merchant and store data

3.2 Events on the storefront

On the merchant's storefront and checkout, the App writes ecommerce events into the browser's GTM dataLayer. These events are not sent to our servers. They are handled by the merchant's own Google Tag Manager container, under the merchant's configuration and their agreement with Google. What those events contain — including whether they carry a logged-in customer's email or phone number — is determined by the merchant's settings in the App.

3.3 Advertising identifiers attached to orders

So that conversions can be attributed correctly, the App copies advertising and analytics identifiers that already exist in the shopper's browser (such as the Google Analytics client ID and Meta's _fbp cookie, plus ad click identifiers present in the URL) into an attribute on the merchant's cart, which Shopify carries through to the order. The recorded consent state travels in the same attribute.

These identifiers are stored inside the merchant's own Shopify data, not on our servers, and the merchant can inspect them on any order. Only identifiers that already exist are copied: where consent has been refused, the corresponding cookies are absent and nothing is copied.

3.4 Server-side conversion forwarding (only if enabled)

If the merchant enables server-side forwarding, order data reaches our servers through Shopify webhooks and is forwarded to the destinations the merchant has configured. This data can include:

This processing does not happen unless the merchant turns it on and configures a destination.

4. What we never do

5. Consent

Where the merchant uses Shopify's native cookie banner, the App reads the shopper's choice through Shopify's Customer Privacy API and records it alongside the event. Where the merchant uses an external consent platform, consent is governed by that platform at tag level and we record that we could not determine the state ourselves — we do not assume consent was given.

Server-side forwarding respects the recorded consent state. Where consent cannot be determined, forwarding takes place only if the merchant has explicitly enabled it, taking responsibility for the lawful basis of that processing.

6. Who else processes the data

We do not transfer data outside the European Union ourselves. Where a merchant configures a destination outside the EU, that transfer is made on the merchant's instruction and under the merchant's own agreement with that provider.

7. How long we keep it

8. Data subject requests

Shoppers should address their requests to the merchant, who is the controller of their data. We respond to Shopify's customers/data_request, customers/redact andshop/redact webhooks, and we assist the merchant in fulfilling access, correction, deletion, restriction and portability requests.

9. Security

10. Changes

When what the App does with data changes, this policy is updated at the same time. The date at the top reflects the most recent change.

11. Contact

For questions about this Privacy Policy, or to exercise a right, contact us at support@tomify.it.