FunnelFusion

Privacy Policy

This Privacy Policy describes how Elbert Enterprises Corporation ("Elbert Enterprises", "we", "us", or "our") collects, uses, and shares information when you use the FunnelFusion service at https://funnelfusion.io (the "Service"). By using the Service you agree to the terms of this Privacy Policy.

1. Information We Collect

1.1 Account information

When you register, we collect your email address, display name, and a password hash. If you join an existing team via invitation, we also collect the invitation metadata associated with your account.

1.2 Third-party platform data

FunnelFusion integrates with Shopify, Google Ads, Google Merchant Center, and Microsoft Advertising. When you authorise the Service to access these platforms via OAuth, we receive and store:

We request only the OAuth scopes required to perform campaign management, catalogue synchronisation, order attribution, and performance reporting. We do not request write access to any Shopify resource. We do not request or store end-customer personal data from any platform.

1.3 Usage data

We collect standard server logs (IP address, user agent, request path, response code, timestamp) to operate, secure, and improve the Service.

1.4 Billing data

Payments are processed by Stripe. We do not see or store your credit card number. Stripe provides us with a customer identifier, subscription status, and billing email for our records.

2. How We Use Your Information

We use the information we collect to:

3. How We Share Your Information

We do not sell or rent your information. We share information only with:

We do not use your data from one platform to infer or generate insights about a different platform, nor do we aggregate or anonymise your data for sale to third parties.

4. Data Retention

We retain data for the periods described below, or for as long as your account is active, whichever is shorter:

5. Shopify App - GDPR Compliance

FunnelFusion is a Shopify app and complies with Shopify's mandatory GDPR webhook requirements. We have implemented all three Shopify GDPR webhooks:

These webhooks are HMAC-verified using our Shopify app secret before any action is taken.

6. Security

We use industry-standard encryption for data in transit (TLS 1.2+) and at rest (AES-256 on AWS-managed storage). OAuth tokens are stored encrypted in AWS Secrets Manager or equivalent. Access to production systems is restricted to employees with a legitimate operational need and protected by multi-factor authentication.

7. Your Rights

Depending on your jurisdiction, you may have the right to:

To exercise any of these rights, email us at api@elbert-enterprises.com. We respond to all verified requests within 30 days.

Data Processing Agreement (GDPR). If you are established in the European Economic Area, the United Kingdom, or Switzerland, or if your end customers include data subjects in those jurisdictions, a Data Processing Agreement compliant with Article 28 GDPR is available on request by emailing api@elbert-enterprises.com.

8. Revoking Platform Access

You can revoke FunnelFusion's access to any connected platform at any time by:

9. Children's Privacy

The Service is not intended for use by individuals under 16 years of age. We do not knowingly collect personal data from children.

10. International Transfers

We operate on AWS infrastructure in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified to you via email or an in-app notification at least 14 days before they take effect. The "Last updated" date above always reflects the current version.

12. Contact Us

If you have questions about this Privacy Policy or our data practices, email us at api@elbert-enterprises.com.

Elbert Enterprises Corporation
(business address available on request)