Privacy policy
Last updated 18 September 2026
Good Merchant is a profit dashboard for Shopify stores. It reads your store’s orders and products, and your ad spend, to show you what you actually made. This policy explains what that involves: what we collect, why, who else handles it, how long we keep it, and how to get it back or have it deleted. Good Merchant is run by Jonathan Chen, in Ontario, Canada.
The short version
- We only read your store. We never create, change or delete anything in it.
- We don’t store your customers’ names, email addresses, phone numbers or postal addresses. Orders are kept with Shopify’s customer ID number only.
- We don’t sell data, share it with other merchants, use it for advertising, or train AI models on it.
- No analytics, advertising or tracking cookies. Only the ones the service needs to work, like keeping you signed in.
- You can download everything we hold, or delete your account and all of it, from Settings at any time.
1. What we collect
Your account. Your email address and password when you sign up, and your first and last name if you add them. Passwords are stored by our login provider as one-way hashes; we can’t see them.
Your store, from Shopify, once you connect it. Your store’s name, address (myshopify.com domain), currency and timezone. For each order: its number, dates, status, totals, tax, shipping, discounts and refunds; the products, SKUs, quantities and prices on it; Shopify’s ID number for the customer; and where the visit came from (the source, UTM tags and referring page Shopify records). For each product: its title, variants, SKUs, prices, stock levels and Shopify’s “Cost per item”.
Your ad accounts, if you connect them. For Meta: the ad account’s ID, name and currency, and daily spend, impressions, clicks, campaign names and the purchases Meta attributes to them.
What you enter. Product costs, other costs such as shipping, packaging, fees and overheads, supplier lead times, and your dashboard preferences.
Your plan. Which plan you’re on, its price and status. Plans are billed by Shopify on your Shopify invoice; we never see or store card details.
What you send us. Emails to us, and messages sent with the “Message the developer” button. For a bug or a number that looks wrong, the message includes the screen you were on, its date range and the figures shown on it, so we can check what you’re asking about. A visitor to the demo store who sends one gives us their email address so we can reply.
Technical information. When something breaks, an error report with the page, the error and your browser type, without your IP address. Our hosting provider keeps standard server logs, which include IP addresses, for a short time for security and troubleshooting.
2. How we use it
- To work out and show your revenue, costs, profit, cash flow, ad performance, cohorts and stock.
- To keep it current by syncing with Shopify and your ad accounts, on a schedule and when things change.
- To manage your plan and send account emails: confirming your email, password resets, and notices about your plan, including telling you before your store outgrows it.
- To answer your questions and investigate numbers you report.
- To keep the service secure and find and fix errors.
We don’t send marketing emails. If that ever changes, it will be opt-in.
4. Your customers' information
For information about your store’s customers, you are responsible for it and we handle it on your behalf, only to provide the dashboard to you. We keep as little as we can: orders carry Shopify’s customer ID number so repeat purchases can be counted, and nothing that identifies the person directly.
When one of your customers asks Shopify for their data, or to be erased, Shopify tells us and we act on it: we gather what we hold about them for you, or remove their ID and the page they arrived from on their orders and make sure later syncs don’t bring it back.
5. How long we keep it
- While your account is open, we keep your store’s history so the dashboard can show it.
- If you uninstall the app from Shopify, its access to your store stops immediately, and your store’s data is deleted 48 hours later, when Shopify asks us to.
- If you delete your account in Settings, the app is removed from your store and your account and all of your store’s data are deleted from our database straight away.
- Deleted data can remain in our database provider’s backups for a limited time until they’re overwritten. Emails you’ve sent us stay in our inbox unless you ask us to delete them.
6. Your choices and rights
- Get a copy. Settings, Data & privacy downloads your orders, costs and ad spend as spreadsheets.
- Delete it. Settings, Data & privacy deletes your account and everything in it.
- Correct it. Change your details and costs in the app, or ask us.
- Disconnect. Disconnect Shopify or an ad account in Settings, or uninstall the app from Shopify.
- Ask. For anything else, including what we hold about you, email jon@goodmerchant.io. We reply within 30 days.
Depending on where you live, privacy laws such as Canada’s PIPEDA, the EU and UK GDPR, or California’s privacy law give you these rights and others, which we’ll honour. If you’re not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada or your local data protection authority.
8. How we protect it
Everything travels over encrypted connections. The keys that let us read your Shopify store and ad accounts are encrypted before they’re stored, and the database keeps each account’s data separate. Only the operator can reach the systems that hold it. No system is perfectly secure, but if a breach affecting your information ever happens, we’ll tell you and the authorities as the law requires.
9. Children
Good Merchant is for businesses and isn’t meant for anyone under 18.
10. Changes to this policy
If this policy changes, the new version will be posted here with a new date. If a change affects how your information is used in a meaningful way, we’ll email you before it takes effect.
11. Contact
Jonathan Chen is responsible for privacy at Good Merchant. Email jon@goodmerchant.io with any question or request about your information.
Questions about this page? Email jon@goodmerchant.io.