Retrics

RETENTION · DATA & PRIVACY APPENDIX

What Retention
reads, and why.

The company policies below apply to everything Retrics runs. This page is the part that is specific to this product — the data it touches, and who else sees it.
LIVE
RetentionLIVE
RUNS ONapp.retrics.ai
CUSTOMER GRAPHOn the shared graph
DATA FLOW DECLAREDYes

THIS PAGE IS THE URL THIS PRODUCT’S APP LISTING SUBMITS

WHERE IT STANDS

Installable and billable today.

THE DATA FLOW

Five questions, answered plainly.

WHAT IT READS
  • Orders, customers and products from Shopify, on read-only scopes
  • Ad spend and campaign performance from Meta and Google, where connected
WHAT IT STORES
  • A customer profile per shopper: order history, predicted reorder window, lifecycle stage
  • Every audience it freezes, including which customers were withheld as the control
  • A bounded shop-level Retention report: cohort sizes, active-customer counts, cohort revenue, currency coverage, cutoff dates, and source-sync provenance
HOW IT IS PROTECTED
  • Shopify access tokens and ad-platform access and refresh tokens are encrypted with AES-256-GCM before they are stored — never written down in plain text
  • The cipher key is not the configured master key: it is derived from it by HKDF under a named purpose, so no two features ever share a key and a future one cannot read this one's data
  • The customer selectors inside an erasure request are encrypted at rest, so a request to delete somebody does not itself sit in the database naming them
  • Where an email has to be matched rather than read, it is matched by SHA-256 hash
HOW LONG IT IS KEPT
  • A Shopify customer data request is answered inside the 30-day window Shopify sets — the deadline is computed when the request arrives, not when someone gets to it
  • A customer erasure and a shop uninstall are both handled as Shopify sends them, and the erasure removes the customer rather than blanking a name
WHO ELSE SEES IT
  • Meta receives a hashed audience — an irreversible email hash, never an address — and only when the merchant asks for one
  • A connected Google account is read-only: Retrics reads its reporting and never uploads a customer list to it
  • Klaviyo receives nothing automatically; the campaign-safe CSV is exported by the merchant
  • Slack receives aggregate retention metrics and open-opportunity summaries only through a merchant-authorized connection and merchant-selected channel

AND THE COMPANY POLICIES IT SITS UNDER

These apply to everything Retrics runs.

They are linked rather than repeated here. Twelve copies of the same policy is twelve things that drift apart.

THIS APPENDIX IS MAINTAINED WITH THE PRODUCT · EDITING IT CHANGES NOTHING ELSE