← TrueMargin

Privacy policy

Last updated 7 September 2026

TrueMargin: Profit Tracker is provided by Fleeta Limited. It is an admin-only Shopify app that calculates contribution margin from a merchant's own Shopify orders, product costs and cost rules. It has no storefront, no customer-facing page and sends no email or other message to anyone.

Access we request from Shopify

The app requests three read-only Shopify scopes: read_products, read_inventory and read_orders. It holds no write scope, so it can never change anything in a Shopify store, and it does not request read_customers.

Data we read from Shopify

We read the shop name and currency, product identifiers, and orders with their Shopify order identifier, order number, creation date, financial status, order total, total discounts, and for each line item its identifier, quantity, product title, variant identifier, SKU, line total after discounts and the inventory unit cost recorded in Shopify. We do not request or receive customer names, email addresses, phone numbers, shipping or billing addresses, or payment card data.

Data we store

We store the shop domain and its Shopify shop identifier; the Shopify access session, with the access token and the full session payload encrypted before they are written to the database; the cost rules a merchant enters, which are business assumptions such as a rule name, scope, cost category, fixed amount or percentage, currency, tax treatment, effective date and free-text notes; an audit record of each saved rule, holding the rule content and the Shopify session that saved it; the raw payloads of the product, inventory and uninstall webhooks Shopify sends us; and an internal queue entry that points at a stored webhook while it is processed. If a merchant answers the in-app feedback prompt we store the message text and the optional one-to-five score. The app is free for every store, so no billing, subscription or plan record is created.

Because TrueMargin uses Shopify online access tokens, the session record also holds the Shopify staff user's identifier, first name, last name, email address, locale, whether Shopify has verified that email address, and account-owner or collaborator flags as supplied by Shopify. That is information about the merchant's own staff, not about the store's shoppers. Those fields are stored as ordinary database columns; the encryption described in the security section covers the access token and the session payload.

Margin figures are calculated when a page loads and are not stored. A CSV report is built by the app at the moment it is requested and returned straight to the download. It is never written to our database or saved to disk.

Why we process it

We use this data to authenticate the embedded app, read the orders and costs needed to calculate contribution margin, apply the merchant's own cost rules, produce reports and exports, keep an auditable record of who changed a cost assumption, respond to support requests, protect the service against abuse and meet legal obligations. We do not sell any of it, we do not use it for advertising, and we do not build profiles.

Sharing and third parties

Application data is held on our own hosting in the United Kingdom and is not shared with any analytics, advertising or data-broker service. There is one exception, disclosed here in full: the first time a store installs the app, we send a single install notification to Shoffi, an app-attribution provider, containing the store's myshopify.com domain, our application identifier and the IP address the install request came from. No order, product, cost or customer data is included, and no further request is made after the install. Shopify itself is the source of the data the app reads and is also our processor for hosting the embedded admin surface.

Retention

We keep shop-scoped data for as long as the app stays installed. When a merchant uninstalls the app, Shopify sends the uninstall webhook and we delete the shop record and everything linked to it: sessions and stored access tokens, cost rules, feedback, audit records, queue entries and stored webhook payloads. The same deletion runs when Shopify sends a shop redaction request. We do not run a separate time-based purge, so nothing is deleted earlier than that, and nothing shop-scoped survives it.

Shopify privacy webhooks

The app subscribes to the three mandatory topics: customers/data_request, customers/redact and shop/redact. Requests are verified and acknowledged, and their payloads are stored only as a redacted marker rather than in full. Because the app never requests or stores customer personal data, a customer data request has no customer records to return and a customer redaction request has no customer records to erase. A shop redaction request deletes all data for that store immediately, as described above.

Security

The app is served over HTTPS. Shopify access tokens and session payloads are encrypted with AES-256-GCM authenticated encryption before they are stored, using a key derived from our application secret. Every incoming webhook is verified against Shopify's HMAC signature before it is accepted. Records are isolated per store and per app, so one installation can never read another's data. No customer personal data is stored, which is the strongest control the app has.

Your choices and rights

A merchant can review and change every cost rule in the app, can decline the feedback prompt, and can remove all of the data described here by uninstalling the app. Under UK and EU data-protection law the merchant's staff may ask us to access, correct or delete the personal data we hold about them. Write to accounts@fleeta.co.uk and we will respond within 30 days.

Roles

For a merchant's business data, Fleeta Limited acts as a processor on the merchant's instructions. For the staff account details Shopify passes to us as part of the login session, and for the install notification described above, Fleeta Limited is the controller.

Contact

Fleeta Limited, United Kingdom. Privacy and security enquiries: accounts@fleeta.co.uk.