TrackGap is operated by NullLogic s.r.o., a company registered in Slovakia. Contact: karol@nulllogic.eu.
For data protection purposes the merchant installing the app is the data controller. NullLogic s.r.o. acts as a data processor on the merchant's instructions.
| Data | Why |
|---|---|
| Order ID and order number | To match an order against the conversions recorded by your analytics |
| Order total, subtotal, shipping, tax, currency | To detect whether the value sent to analytics matches the order |
| Order timestamp | To respect analytics processing delays |
| Landing page, referrer, UTM parameters | To show which traffic source loses data |
| Financial status, cancellation flag | To exclude cancelled orders from comparisons |
Our optional web pixel reads the Google Analytics client identifier from
the _ga cookie, and advertising click identifiers
(gclid, fbclid and similar) from the page URL.
These are pseudonymous browser identifiers, not personal contact details. They exist so that a conversion we send on your behalf is attributed to the correct visit. Without them we do not send anything, because an incorrectly attributed conversion is worse than a missing one.
If you connect them, we read — read-only — aggregate conversion counts and values from Google Analytics 4 and Meta. We never modify your campaigns, budgets or settings.
On our public product website, Google Analytics 4 helps us understand aggregate page usage. Analytics storage is disabled by default and enabled only if you accept analytics in the consent prompt. Your choice is stored in your browser and can be reset by clearing this site's local storage.
We do not sell data, share it with third parties for their own purposes, use it to train models, or combine data across merchants.
We do not send conversions for visitors who declined consent. This is a hard rule in the product, not a setting. Orders that cannot be recovered for this reason are reported to you with the reason stated.
Data is stored on a dedicated server in the European Union. Access credentials and API tokens are encrypted at rest using AES-256-GCM. Transport is TLS-encrypted throughout.
| Data | Retention |
|---|---|
| Order records | Rolling 90 days |
| Browser identifiers | 30 days |
| Findings and check history | 12 months |
| Everything | Deleted within 48 hours of uninstall |
Under GDPR you may request access, correction, deletion, restriction or portability of personal data, and you may object to processing. Because we do not store customer contact details, most requests are satisfied by confirming that no such data exists.
We honour Shopify's mandatory compliance webhooks
(customers/data_request, customers/redact,
shop/redact) automatically.
Requests: karol@nulllogic.eu. You also have the right to lodge a complaint with the Slovak Data Protection Authority (Úrad na ochranu osobných údajov SR).
| Provider | Purpose |
|---|---|
| Hetzner Online GmbH (Germany) | Server hosting |
| Shopify Inc. | Order data source, billing |
| Google LLC | Analytics and Ads APIs — only if you connect them |
| Google Ireland Limited | Public website analytics — only with consent |
| Meta Platforms Inc. | Conversions API — only if you connect it |
Material changes will be announced in the app at least 14 days before they take effect.