Privacy Policy

TrackGap · Last updated 31 August 2026
The short version: TrackGap reads order IDs, amounts and traffic sources so it can tell you which orders your analytics missed. It does not read, store or process your customers' names, email addresses, postal addresses or phone numbers.

1. Who we are

TrackGap is operated by NullLogic s.r.o., a company registered in Slovakia. Contact: karol@nulllogic.eu.

For data protection purposes the merchant installing the app is the data controller. NullLogic s.r.o. acts as a data processor on the merchant's instructions.

2. What we collect

2.1 From your Shopify store

DataWhy
Order ID and order numberTo match an order against the conversions recorded by your analytics
Order total, subtotal, shipping, tax, currencyTo detect whether the value sent to analytics matches the order
Order timestampTo respect analytics processing delays
Landing page, referrer, UTM parametersTo show which traffic source loses data
Financial status, cancellation flagTo exclude cancelled orders from comparisons
We do not request or store: customer names, email addresses, postal addresses, phone numbers, payment details or line-item contents. We hold Shopify Protected Customer Data Level 1 access only.

2.2 From the storefront (web pixel)

Our optional web pixel reads the Google Analytics client identifier from the _ga cookie, and advertising click identifiers (gclid, fbclid and similar) from the page URL.

These are pseudonymous browser identifiers, not personal contact details. They exist so that a conversion we send on your behalf is attributed to the correct visit. Without them we do not send anything, because an incorrectly attributed conversion is worse than a missing one.

2.3 From connected platforms

If you connect them, we read — read-only — aggregate conversion counts and values from Google Analytics 4 and Meta. We never modify your campaigns, budgets or settings.

2.4 Website analytics

On our public product website, Google Analytics 4 helps us understand aggregate page usage. Analytics storage is disabled by default and enabled only if you accept analytics in the consent prompt. Your choice is stored in your browser and can be reset by clearing this site's local storage.

3. What we do with it

We do not sell data, share it with third parties for their own purposes, use it to train models, or combine data across merchants.

4. Consent

We do not send conversions for visitors who declined consent. This is a hard rule in the product, not a setting. Orders that cannot be recovered for this reason are reported to you with the reason stated.

5. Where data is stored

Data is stored on a dedicated server in the European Union. Access credentials and API tokens are encrypted at rest using AES-256-GCM. Transport is TLS-encrypted throughout.

6. How long we keep it

DataRetention
Order recordsRolling 90 days
Browser identifiers30 days
Findings and check history12 months
EverythingDeleted within 48 hours of uninstall

7. Your rights

Under GDPR you may request access, correction, deletion, restriction or portability of personal data, and you may object to processing. Because we do not store customer contact details, most requests are satisfied by confirming that no such data exists.

We honour Shopify's mandatory compliance webhooks (customers/data_request, customers/redact, shop/redact) automatically.

Requests: karol@nulllogic.eu. You also have the right to lodge a complaint with the Slovak Data Protection Authority (Úrad na ochranu osobných údajov SR).

8. Sub-processors

ProviderPurpose
Hetzner Online GmbH (Germany)Server hosting
Shopify Inc.Order data source, billing
Google LLCAnalytics and Ads APIs — only if you connect them
Google Ireland LimitedPublic website analytics — only with consent
Meta Platforms Inc.Conversions API — only if you connect it

9. Security

10. Changes

Material changes will be announced in the app at least 14 days before they take effect.