Privacy Policy
Last updated: 9 August 2026
This Privacy Policy describes how Lodestar ecommerce LLC ("we", "us", "YourTracking") handles data in connection with YourTracking, our server-side conversion tracking service for Shopify merchants, available at yourtracking.ai (the "Service"), and this public website.
1. Who we are
The Service is operated by Lodestar ecommerce LLC, 5830 E 2ND ST, STE 7000 #34998, Casper, WY 82609, United States. For any privacy-related question or request, contact us at info@yourtracking.ai.
2. Our two roles
It matters which data we are talking about, because our role differs:
- Our merchant clients' data (we are the controller). For the account, contact and billing data of the businesses that use YourTracking, and for visitors to this website, we decide the purposes and means of processing. This Policy governs that data.
- End-customer (shopper) data (we are a processor). For the personal data of a merchant's own shoppers that flows through the Service, the merchant is the controller and we act as their data processor, processing it only on the merchant's documented instructions to match and deliver conversions. That relationship is governed by a signed Data Processing Agreement (DPA), and the disclosure to shoppers is made by the merchant in their own privacy policy.
3. Data we process on this public website
- No advertising trackers. This public website does not use advertising cookies, analytics pixels or fingerprinting.
- Authentication cookie. When a client signs in, a single encrypted session cookie is set to keep them signed in. It is strictly necessary for the Service and is not used for tracking.
- Server logs. Our servers keep standard, short-lived technical logs (IP address, request path, timestamp) for security and abuse prevention.
- Enquiries. If you email us, we process the contact details and content you provide in order to respond.
4. Client account data we process (as controller)
To provide and bill the Service, we process the name, email, company and billing details of our merchant clients, together with account and usage data. We use this to operate the Service, provide support, take payment, and communicate about the Service.
5. End-customer data we process (as processor)
On behalf of each merchant, and only on their instructions, the Service processes end-customer personal data solely to match a sale to the advertisement that produced it and deliver that conversion to the merchant's advertising platforms:
- Identifiers used for matching — email, phone, name and address. These are hashed with SHA-256 before they are transmitted to Google or Meta; the plaintext values are never sent to the ad platforms.
- Advertising click identifiers — such as gclid, gbraid, wbraid and fbclid — captured first-party on the merchant's store and associated with the resulting order.
- Order details — order identifier, value and timestamp, used to send the conversion with its true value.
Purchases only. The Service sends completed purchases. It does not send refund, cancellation or non-purchase events to the advertising platforms.
6. Legal bases
Where the GDPR or UK GDPR applies:
- Client and website data — we rely on performance of a contract, our legitimate interest in operating and securing the Service, and compliance with legal obligations such as accounting and tax.
- End-customer data — the lawful basis and, where required, valid consent is the responsibility of the merchant (controller). We process this data only on the merchant's documented instructions and honour the consent signal the merchant configures.
7. Sub-processors and sharing
We do not sell personal data. We share data only with the providers that host and support the Service, under data-protection terms that restrict them to processing on our instructions, and with the advertising platforms to which conversions are delivered:
- Google — delivery of conversions to Google Ads (Data Manager).
- Meta — delivery of conversions to the Conversions API (CAPI).
- Shopify — the merchant's store platform, from which order and customer data is read to match conversions.
- Hetzner — EU-resident hosting (Germany).
- Cloudflare — edge delivery and security.
- Stripe — billing and payments.
8. International transfers
Service infrastructure is hosted in the European Union (Germany). Where personal data is transferred outside the EEA or UK — for example when conversions are delivered to Google or Meta — the transfer relies on appropriate safeguards such as the Standard Contractual Clauses or the UK International Data Transfer Agreement.
9. Retention
Client account and billing data is retained for the duration of the relationship and any statutory retention period (including accounting requirements). End-customer data processed on a merchant's behalf is retained only as long as needed to deliver the Service and is deleted on offboarding in line with the DPA. Technical server logs are kept for a short rolling window.
10. Security
We apply appropriate technical and organisational measures to protect the data we process, including:
- encryption in transit (TLS) and at rest, with encrypted backups;
- SHA-256 hashing of identifiers before any transmission to advertising platforms;
- per-client isolation of data;
- secrets stored by reference in a managed secret store, never in the application database;
- an append-only access audit log and least-privilege access;
- a security incident-response policy, including notifying the affected merchant without undue delay of a personal-data breach.
11. Your rights
Data subjects in the EU/EEA and UK have the right to request access to, correction of, or deletion of personal data, to restrict or object to processing, to data portability, and to lodge a complaint with a supervisory authority. Because we act as a processor for end-customer data, shoppers should exercise these rights through the merchant whose store they purchased from; we assist the merchant in responding. Clients and website visitors can contact us directly at info@yourtracking.ai.
12. Children
The Service is provided to businesses and is not directed at children. We do not knowingly process children's personal data.
13. Changes
We may update this Policy from time to time. The "Last updated" date above reflects the latest revision; material changes will be reflected on this page.