Skip to content
Fabrik Analytics™
Legal

Privacy policy

Last updated 1 October 2026

1. Introduction

Fabrik Analytics ("we", "us", "our") provides an analytics platform that connects to ecommerce stores. This policy explains what data we collect, how we use it, and the choices available to merchants and their customers.

2. Data we collect

  • Store data, orders, products, inventory, and customer records accessed via the Shopify Admin API using scopes authorised during installation.
  • Analytics events, page views, add-to-cart, and purchase events collected via our first-party pixel with customer consent.
  • Ad platform metrics, spend, impressions, clicks, and attributed revenue from connected advertising accounts.

3. How we use data

We aggregate and present data in dashboards, reports, and alerts to help merchants understand performance and make better decisions. We do not sell personal data.

4. Data sharing

We do not share personal data with third parties except: (a) service providers who process data on our behalf under contract, (b) as required by law, or (c) with the merchant's explicit consent.

5. Data retention

We retain store data for the duration of the merchant's subscription. Storefront events are kept for a fixed time and then deleted: browser pixel events for 90 days, and server-side events for 365 days.

When a merchant uninstalls the app, we disconnect the store straight away and stop collecting data from it. The data already held is kept until Shopify sends us a deletion request for the store (shop/redact), which Shopify does 48 hours after the uninstall. When that request arrives we erase that store's shoppers' personal data and order-level data: the store's customer records, orders, storefront events and sessions, consent records, survey answers, order attribution, and the daily sales figures calculated from them. If the store has installed the app again by then, nothing is deleted.

We keep figures that identify no one: spend and performance from connected advertising and email accounts (Meta, Google and Klaviyo), which do not come from the store, and anonymous totals such as product and traffic figures.

6. Customer rights

End customers may request access to or deletion of their data through the merchant, who can initiate requests via Shopify's customer data tools. Shopify passes these requests to us through its mandatory privacy webhooks, and we act on each one when it arrives:

  • Access requests (customers/data_request): we gather all the personal data we hold about the customer into one file and email the store owner a secure link to it, valid for 14 days. The file is deleted after 30 days.
  • Deletion requests (customers/redact): we delete the customer's record and storefront events, remove their name and email from their orders (street addresses and phone numbers are stripped before orders are stored), and unlink their survey answers from them. Order totals remain in the store's reports without identifying the customer.

Merchants can also erase a customer's data themselves from the app's settings.

7. Security

All data is encrypted in transit (TLS) and at rest. Access tokens are stored securely and scoped to the minimum permissions required.

8. Contact

For privacy inquiries, contact us at privacy@fabrik.ae.