Privacy Policy

    Last updated: September 2026

    What we collect

    We collect your email address, store data from your connected Shopify store including orders, products, and inventory levels, and advertising spend data from connected ad platforms. We do not collect payment card information.

    Your customers' data

    To attribute orders and calculate per-order profitability, Safwa stores limited personal information about your customers that Shopify provides with each order: name, email address, phone number, and the address an order shipped to. Where your courier returns delivery details with a tracking or settlement update — such as the address a parcel went to, or the name of the person who received it — that response is stored too. We do not store payment details. This information is used only to link orders to repeat customers and to reconcile deliveries and courier charges, and is never sold, shared, or used for advertising.

    Erasure requests

    • Individual customer. When a shopper asks you to erase their data, Shopify notifies Safwa automatically and we delete that person's record. The order itself is kept as your financial record, but it is detached so it no longer identifies anyone.
    • Whole store. 48 hours after you uninstall Safwa, Shopify notifies us and we delete all of your customers' personal information.
    • Data requests. If a shopper asks what you hold on them, Shopify notifies us and we provide it so you can respond within the required window.

    How we use your data

    Your data is used solely to calculate and display profit analytics for your store. We do not sell your data to third parties. We do not use your data for advertising purposes.

    Data storage

    Your data is stored securely using industry-standard encryption. We use Supabase for data storage with servers located in Singapore.

    Third-party services

    We connect to Shopify, Meta Ads, and Google Ads on your behalf, and we never create, change or delete anything in those platforms. Two of the permissions Meta's consent screen lists — managing ads, and managing your business portfolio — would allow that, and we do not use them for it: they are what lets us list the ad accounts you have access to, under the business portfolio that owns them, so you can choose which ones to connect. Safwa reads your advertising results; it does not run your advertising. What we do with Google data specifically is set out in the next section.

    Google user data

    Safwa uses Google OAuth in two places: to connect your Google Ads account, and optionally to sign in to Safwa with your Google account. This section describes exactly which Google user data each one touches, how we use it, where it is kept, and how you take it back. Safwa's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

    What we access

    • Google Ads data (scope https://www.googleapis.com/auth/adwords). When you connect Google Ads we read the list of Google Ads accounts your Google login can access and their names, so you can pick the one to sync. For the account you pick we then read performance data on a schedule: campaign, ad group, ad, placement and search-term metrics (cost, impressions, clicks, conversions and conversion value), the names of your conversion actions, and each ad's tracking template and final URL. Google Ads has a single API scope with no read-only variant; Safwa uses it only to read. It never creates, edits, pauses or deletes anything in your Google Ads account.
    • Basic account information (scopes openid, email, profile). When you connect Google Ads we store the email address and Google user ID of the Google account you used, so the Ad Spend settings page can show which account is connected. If you sign in to Safwa with Google, we receive your email address, name and profile picture to create and identify your Safwa login.

    How we use it

    Only to calculate and show your own analytics inside Safwa: ad spend against cash, ROAS on delivered orders, and per-order, per-product and per-campaign profit. Google data is never used for advertising, never sold, never used to train models, and never shared with any third party. Our hosting provider (Supabase, on AWS in Singapore) stores it on our behalf and has no other access to it. Humans at Safwa read it only to support you when you ask, or to investigate a security incident.

    How we store it

    OAuth tokens and synced Google Ads data are stored in our Supabase database in Singapore, encrypted at rest and in transit. The tokens are readable only by our server-side sync jobs, never by the browser, and are not written to logs. Synced performance data is retained while your subscription is active so historical ROAS stays available, and is deleted within 30 days of account termination or on request.

    How to revoke access, and what happens then

    • Inside Safwa: Ad Spend → Configuration → Disconnect. Safwa immediately revokes its token with Google and deletes the stored credentials.
    • At Google: myaccount.google.com → Security → "Third-party apps & services" → Safwa → Remove access. Our next scheduled sync (within 12 hours) sees the revoked grant, stops, and deletes the stored credentials.
    • Either way, the spend history already in your dashboard stays until you delete your Safwa account or ask us to remove it at [email protected].

    Meta user data

    Safwa uses Facebook Login for Business to connect your Meta Ads account. This section describes exactly which Meta data we touch, how we use it, where it is kept, and how you take it back. Safwa reads; it never manages. We do not request the permissions that would let us create, edit, pause or spend on your ad accounts.

    What we access

    • Ad performance (permission ads_read). We read the list of ad accounts your Meta login can access and their names, so you can pick which to sync, and each account's currency. For the accounts you pick we then read daily performance on a schedule, per ad and per placement: spend, impressions, reach, frequency, clicks, link clicks, CPM, CPC, and the aggregate action counts and values Meta reports against each ad. We also read your ads' tracking parameters and destination links so spend can be matched to the orders it produced.
    • Your Facebook name and user ID (granted with login). Shown on the Ad Spend settings page so you can see which account is connected, and used to recognise your account if Meta later tells us you have removed Safwa or asked for your data to be deleted.
    • Your Pages (permissions pages_show_list and pages_read_engagement). An ad boosted from an existing Page post carries no link of its own — the destination lives on the post. We list your Pages and read the destination of the posts your ads promote, so boosted-post spend can be attributed like any other ad. We do not read your Page's messages, comments, followers or audience.

    We receive no personal data about your shoppers from Meta: no Pixel event data, no customer-level conversion events, and no Custom Audience member lists. The action figures we store are the aggregate per-ad, per-day counts Meta returns — never individual people.

    How we use it

    Only to calculate and show your own analytics inside Safwa: ad spend against cash, ROAS on delivered orders, and per-order, per-product and per-campaign profit. Meta data is never used for advertising, never sold, never used to train models, and never shared with any third party or with other Safwa customers. Our hosting provider (Supabase, on AWS in Singapore) stores it on our behalf and has no other access to it. Humans at Safwa read it only to support you when you ask, or to investigate a security incident.

    How we store it

    Access tokens, Page tokens and synced Meta Ads data are stored in our Supabase database in Singapore, encrypted at rest and in transit, and scoped by row-level security so one merchant's data is unreachable from another's account. The tokens are readable only by our server-side sync jobs: the database withholds those columns from the browser entirely, so they cannot be read by your own logged-in session, and they are not written to logs. Synced performance data is retained while your subscription is active so historical ROAS stays available, and is deleted within 30 days of account termination or on request.

    How to revoke access, and what happens then

    • Inside Safwa: Ad Spend → Configuration → Disconnect. Safwa revokes its access with Meta and deletes the stored credentials. Spend stops syncing immediately; the ad history already in your dashboard stays, and you can reconnect at any time.
    • At Facebook: Settings & privacy → Settings → Apps and websites → Safwa → Remove. Meta notifies Safwa, and we delete the stored credentials and stop syncing without waiting for the next scheduled run.
    • Deleting the data itself: removing the app also lets you send a data deletion request from the same Facebook screen. That deletes the advertising data we received from Meta on your behalf — your ad accounts, campaigns, ad sets, ads, their daily spend and results, and the tokens — and returns a confirmation code you can check at safwa.io/data-deletion. Your own store's orders and costs belong to you and are not affected. You can also email [email protected] and we will action it by hand.

    Data deletion

    You can request deletion of all your data at any time by emailing [email protected]. We will permanently delete your account, store data, order history, and all connected platform data within 30 days. To disconnect Safwa from your Shopify store, uninstall the app from your Shopify admin — syncing stops immediately, and your customers' personal information is deleted automatically 48 hours later.

    Data retention

    • Shopify store data: Retained while your subscription is active. Deleted within 30 days of account termination.
    • Google Ads data: Retained for the duration of your subscription for historical ROAS analysis. Deleted within 30 days of termination.
    • Meta Ads data: Retained for the duration of your subscription. Deleted within 30 days of termination.
    • Courier data (Leopards, PostEx, etc.): Retained for 90 days minimum to settle billing disputes. Deleted within 30 days of account termination.
    • We do not use your data to train machine learning models or build aggregated analytics products.

    Contact

    For privacy questions: [email protected]

    Mailing address
    Safwa — Office # 01, Falcon Complex, Malir Cantt, Karachi, Pakistan