Persequor ("we," "us," or "Persequor") provides an ad-attribution analytics platform that helps businesses measure the performance of their paid advertising. This Privacy Policy explains what information we collect, how we use it, and the choices you have.
1. Information we collect
We collect the following categories of information:
- Account information: name, email address, and workspace details you provide when signing up.
- Third-party integration data: when you connect a Meta (Facebook/Instagram) ad account, Google Ads account, TikTok Ads account, or Shopify store, we receive OAuth access tokens and read-only data from those platforms — including ad accounts, campaigns, ad sets, ads, spend, impressions, clicks, conversions, lead-form submissions, and orders. We only request the minimum scopes needed to provide the service (for Meta:
ads_readandread_insights; for TikTok: Ad Account Information, Ads Management read, Ad Insight Report, and Leads Retrieval). - Website analytics: when the Persequor pixel is installed on a customer's website, we collect pageviews, UTM parameters, device/browser type, and anonymous session identifiers to attribute conversions to ad campaigns.
- Usage data: logs of how you interact with the Persequor dashboard, used for debugging and product improvement.
2. How we use information
- To provide, operate, and maintain the Persequor platform.
- To sync advertising spend and conversion data so you can see attribution reports in your dashboard.
- To communicate with you about your account, security, and product updates.
- To comply with legal obligations and enforce our terms.
We do not sell your data, and we do not use your data or your customers' data to train machine-learning models for third parties.
3. Data from Meta Platforms
When you connect a Meta ad account, we request only ads_read and read_insights — read-only scopes that let us pull ad account structure and performance insights. We do not create, edit, pause, or delete any ads on your behalf. Tokens are stored server-side only — see Security for how they are protected.
Disconnecting. You may disconnect Meta at any time from the Settings page. That marks the integration inactive and deletes our stored copy of your access token, so no further sync can run. To be precise about what it is not: we do not call Meta to revoke the grant itself. To revoke Persequor's access on Meta's side, remove the app under Facebook → Settings & Privacy → Settings → Apps and Websites. That is the action that actually invalidates the token, and it takes effect whether or not we are listening. Meta also notifies a callback we have registered for it, and we use that to deactivate the integration matching the Meta user ID recorded when you connected and drop our stored token.
Deletion. Neither disconnecting nor removing the app erases the Meta data we already pulled — that is kept so your historical reports don't go blank. Erasing it is a separate request: email us and we complete the deletion within 30 days of verifying the request, and in no case later than 90 days. Step-by-step instructions are on our Data Deletion page.
3a. Data from TikTok for Business
When you connect a TikTok Ads account, we request only read scopes — Ad Account Information, Campaign/Ad Group/Ad read, Ad Insight Report, and Leads Retrieval — that let us pull advertiser info, campaign structure, daily spend/impressions/ clicks/conversions, and TikTok Lead Ads form submissions. We do not create, edit, pause, or delete any ads or audiences on your behalf. Access tokens are stored server-side only — see Security.
Disconnecting. You may disconnect TikTok at any time from the Settings page. That marks the integration inactive and deletes our stored copy of your access token, so no further sync can run. As with Meta, it does not revoke the grant on TikTok's side — remove Persequor from your TikTok for Business account settings to do that.
Deletion. Disconnecting does not erase the TikTok data we already pulled. Erasing it is a separate request: email us and we complete the deletion within 30 days of verifying the request, and in no case later than 90 days. See our Data Deletion page.
3b. Data from Shopify
When you connect a Shopify store, we request only read-only scopes — read_orders, read_products, and read_inventory — that let us pull order data (order totals, line items, and the buyer name and email associated with each order) and product/inventory cost data used to calculate profit and ROAS. We do not create, edit, or delete orders, products, customers, or themes on your behalf.
Buyer personal information. Order data may include a buyer's name and email. We process this solely to attribute orders to ad campaigns and produce analytics for the merchant, who remains the data controller for their customers' information. We handle Shopify's three mandatory data-protection webhooks, and they do different things:
- customers/data_request — we record the request for audit and acknowledge it. We do not assemble or send a data export ourselves; the merchant is the controller and answers the shopper from the data already visible in their dashboard.
- customers/redact — we erase that shopper's identifying information: name, email, phone and Shopify customer ID on orders and leads, plus the anonymous identifier that links those rows together, the IP address, user agent and ad-click identifiers on their sessions, the raw submitted form payloads on their events, and any stored copy of an outbound webhook we sent about them. The order and lead records themselves remain, de-identified, so the merchant's totals still add up.
- shop/redact — sent by Shopify roughly 48 hours after uninstall. The same erasure applied to every workspace connected to that shop, plus deactivating the integration and clearing its tokens. If a workspace is still in active use for other integrations, we erase what is demonstrably that shop's data rather than the whole workspace.
Access tokens are stored server-side only. Disconnecting from the Settings page removes the webhooks we installed on your store, then deletes our stored access token. If a webhook won't delete, we abandon the disconnect and ask you to retry rather than destroying the only credential that could ever remove it. The one case we proceed without removing them is when the token is already dead — which is what happens if you uninstalled the app first, and in that case Shopify has already dropped the subscriptions itself.
Uninstalling from your Shopify admin revokes the token on Shopify's side, and we deactivate the integration when Shopify tells us.
Neither one deletes the orders we already received. Shopify's redaction webhooks above erase the personal data in them automatically; removing the records entirely is a deletion request — see our Data Deletion page.
4. Data sharing
We share data only with service providers acting on our behalf (cloud hosting, database, product analytics, error monitoring, payment processing, email delivery) under contracts that restrict their use of the data to providing services to us. We may disclose information when required by law, to enforce our terms, or to protect our rights and users' safety.
5. Data retention
We retain account and analytics data while your account is active. Disconnecting an integration stops new data arriving and, for every platform where we hold a token, deletes that token — but it deliberately does not delete the data already synced, so your historical reports survive a token rotation.
Deleting that data is handled as a request rather than a button: email us and we complete the deletion within 30 days of verifying the request, and in no case later than 90 days, except where retention is required for legal, accounting, or fraud-prevention purposes. Shopify's customer- and shop-redaction webhooks erase personal data automatically when Shopify sends them, without a request from you. Our Data Deletion page lists exactly what a full deletion removes and what outlives it.
6. Your choices and rights
From the Settings page you can view and change your account and workspace details, and connect or disconnect any integration. There is no self-serve “delete my account” control in the product today, and we would rather say that plainly than send you looking for one — deletion is handled as an email request to privacy@persequor.ai from the address on your account, and a person on our side runs it. Our Data Deletion page has the full process.
Depending on your jurisdiction, you may have additional rights under GDPR, CCPA, or similar laws (access, correction, deletion, portability, objection). Send any such request to the same address and we will action it.
7. Security
Rather than claim a grade, here is what we actually do. All traffic runs over TLS. Integration credentials live only in our database and never reach the browser: the database roles the dashboard connects with are not granted read access to the columns holding access tokens, refresh tokens and connection metadata, so the dashboard is served a plain “connected / not connected” flag instead of the token. Data is partitioned by workspace and enforced with row-level security that checks your role, not just your membership, and background jobs run under least-privilege service accounts. Our database provider encrypts its storage at rest; we do not add a second layer of application-level encryption on top of that, and we would rather say so than let “encrypted at rest” imply more than it does.
No system is perfectly secure — you are responsible for keeping your login credentials private.
8. Children
Persequor is a business-to-business product and is not directed to children under 16. We do not knowingly collect information from children.
9. Changes to this policy
We may update this policy from time to time. We will post the updated version on this page and update the "Last updated" date. Material changes will be communicated by email to account owners.
10. Contact
Questions about this policy or a data request: privacy@persequor.ai.