1. Who we are
CODMetrics (“CODMetrics”, “we”, “us”) is an analytics service that connects your advertising accounts to your store’s fulfillment data to calculate performance metrics based on delivered orders. This policy explains how we handle data when you use codmetrics.com and the CODMetrics application (together, the “Service”).
For anything in this policy, you can reach us at support@codmetrics.com.
2. Information we collect
Account information. Your name, email address, and a password (stored only as a secure hash), or your Google account identity if you sign in with Google.
Ad platform data. When you connect an ad account (Meta, Google Ads, or TikTok), we retrieve your campaign, ad set, and ad structure along with spend and performance metrics through each platform’s official API. The OAuth tokens that authorize this access are encrypted before they are stored.
Store and order data. When you connect a store (Shopify or WooCommerce), we retrieve order records — including order status, fulfillment outcome, order value, and the attribution identifiers attached to each order (such as click IDs and UTM parameters) — so we can match orders to the ads that produced them. Order records may include personal data about your customers; see section 8.
Payment information. Payments are processed by Stripe. We never see or store your full card number — we keep only your subscription status, plan, and invoice history.
Usage and diagnostics. We collect product usage events (via PostHog) and error reports (via Sentry) to understand what is breaking and what is worth improving.
3. How we use your data
- To run the Service: syncing your ad and order data, matching orders to campaigns, and calculating your metrics.
- To power the AI assistant when you use it (see section 4).
- To operate your account: authentication, billing, plan limits, and transactional email such as sync-failure alerts and reports.
- To improve the Service, using aggregated usage data and error reports.
- To meet legal obligations, such as tax and accounting rules on invoices.
We do not sell your data, share it with advertising networks, or use your business data to advertise to anyone.
4. AI features
When you use the AI assistant or AI-generated insights, relevant campaign metrics and order statistics from your workspace are sent to our AI providers (Anthropic and OpenRouter) to generate the response. We send the minimum context the feature needs, and our agreements with these providers do not permit them to use your data to train their models. You can simply not use the AI features if you prefer — the rest of the Service works without them.
6. Data retention and deletion
Synced ad and order data is kept for your plan’s retention window — between 30 and 365 days depending on your plan — and an automated cleanup job permanently deletes records older than that window on a rolling basis. Your current retention window is shown in your account settings.
If you disconnect an ad account or store, we stop syncing it immediately. If you delete your account, we delete your account data and synced business data within 30 days, except for invoice records we are legally required to keep.
7. Security
All data is encrypted in transit (TLS) and at rest. OAuth tokens for your connected accounts are additionally encrypted at the application level before being stored. Access tokens are never exposed to your browser. Webhooks from connected platforms are verified with cryptographic signatures before we accept them.
8. Your customers' data
Order records synced from your store can contain personal data about your end customers. For that data, you are the data controller and CODMetrics acts as a processor on your instructions: we use it solely to match orders to ads and compute your metrics, we never contact your customers, and it is deleted under the same retention rules as the rest of your synced data (section 6). It is your responsibility to ensure your own privacy policy covers this processing.
9. Platform-specific commitments
CODMetrics’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data received from Meta and TikTok APIs is used only to provide the analytics features you see in your dashboard, in accordance with each platform’s developer terms.
10. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can disconnect ad accounts and stores or delete your account from your settings at any time, and you can exercise any of these rights by emailing support@codmetrics.com. We respond within 30 days.
11. International transfers
Our providers listed in section 5 may store and process data in the United States and the European Union. Where data moves across borders, we rely on our providers’ standard contractual protections for international transfers.
12. Children
The Service is for businesses and is not directed at anyone under 18. We do not knowingly collect data from children.
13. Changes to this policy
If we make material changes to this policy, we will update the date at the top and notify you by email or in the app before the changes take effect. Continued use of the Service after that means you accept the updated policy.