Sutyx by Tanturo
Privacy Policy
Effective September 15, 2026
Sutyx by Tanturo is operated by Ecomm Optimiser Private Limited. This policy explains how the app processes data when a merchant connects a Shopify store or another supported marketing and analytics service.
Data we process
The app may process the shop domain, order identifiers, order dates, totals, financial and fulfilment status, refunds, cancellations, product-level order data, and available attribution data such as UTM parameters, referring sites, and customer-journey events. We do not request protected customer name, email, phone, or address fields from Shopify.
When a merchant connects advertising, analytics, checkout, or operational services, the app also processes the reporting data needed to build the merchant's funnel and calculate attribution, revenue, and return on ad spend.
How we use data
We use merchant data only to provide attribution analytics, reconcile orders and revenue, operate and secure the service, troubleshoot failures, and meet legal obligations. We do not sell customer or merchant data and do not use it to advertise to individual customers.
Storage and retention
For self-service beta workspaces, raw order reports are processed in memory. Event metadata is retained for 7 days, sync records and usage for 30 days, and reporting aggregates and privacy suppression hashes for up to 396 days. Disconnecting deletes stored access credentials immediately; workspace deletion removes its active reporting data and memberships. Encrypted recovery snapshots expire after 30 days. Deletion receipts are kept separately for 32 days and reapplied before a restored database serves customers. Your app identity may remain for your other workspaces; contact support for account deletion.
Raw webhook events are redacted on receipt and retained for no more than 90 days. Aggregated reporting data is retained while the merchant uses the service. Encrypted connection tokens are retained only while the integration remains connected. Shopify customer and shop redaction requests delete the corresponding stored webhook, connection, and derived shop data as applicable.
Security and service providers
Data is encrypted in transit using HTTPS. Access tokens and application secrets are encrypted before database storage, and access is limited to authorized services and users. The service uses Railway for application hosting and managed database infrastructure, and uses the services a merchant chooses to connect for authentication and data retrieval.
Merchant choices
Merchants control which services they connect. They can revoke a connection or uninstall the app. Requests to access, correct, export, or delete merchant data can be sent to the contact below. We also respond to Shopify's mandatory privacy webhooks.
International processing and changes
Data may be processed in countries where our service providers operate, subject to appropriate safeguards. We may update this policy as the service or applicable requirements change; the effective date above will be updated when we do.
Contact
Ecomm Optimiser Private Limited
shouvik.gr@gmail.com