Privacy Policy
Last updated: 2026-06-06
Who we are
Aftercosts ("we", "us") is a B2B software service operated by Aftercosts, registered in the Netherlands (KvK 93574290). Our service is intended exclusively for business users, specifically Shopify merchants acting in the course of their trade or profession.
For privacy questions, see the contact section at the bottom of this page.
What we collect
- Account data: a store account created automatically when you install the app from Shopify, identified by an app-generated email address. You authenticate through Shopify, so we store no password. Managed via Supabase Auth.
- Store data: order totals, product names, refunds, and revenue figures pulled from your connected Shopify store. We pull aggregate order data. We do not store the names, email addresses, or personal details of your end customers.
- Ad spend data: campaign-level spend, impressions, clicks, and conversions pulled from your connected ad platforms (Google Ads and Meta). We read metrics only. We never access audience data, creative assets, or customer lists.
- Email channel data: revenue attributed to email flows and campaigns, pulled via your Klaviyo API key. Metric totals only, with no subscriber lists or contact details.
- Billing data:your subscription is managed through Shopify's built-in app billing. We store only your subscription status and plan tier. Shopify handles payment details.
- Cookies: one session cookie (Supabase Auth) and one non-tracking preference cookie (
selected_store_id). No analytics cookies, no advertising pixels.
Why we collect it
Solely to provide the profit dashboard you signed up for. We do not sell, share, or train AI models on your data. Legal basis under GDPR: performance of a contract (Art. 6(1)(b)).
Ad-platform data & Google API Limited Use
When you connect Google Ads or Meta, we read only campaign-level spend and performance metrics (impressions, clicks, conversions) to calculate your net profit. We never create or modify your campaigns, and we never use this data for advertising, resale, credit decisions, or training AI models.
Aftercosts's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect any platform or delete all stored data at any time See Data deletion to remove your data.
Shopify data requests
As a Shopify app, we are required to handle Shopify's mandatory GDPR webhooks. When Shopify forwards a customer data request (customers/data_request), customer redact request (customers/redact), or shop redact request (shop/redact) to us, we process it in accordance with Shopify's API Terms of Service. Because we do not store end-customer personal data (see “What we collect” above), customer data requests result in a confirmation that no personal data is held.
Subprocessors
We rely on these third parties to provide the service:
- Supabase (EU region): database, authentication, and storage. DPA
- Vercel: application hosting and edge delivery. DPA
- Shopify: order data sync and subscription billing (you authorise via OAuth).
- Resend: transactional email delivery (e.g. subscription notifications sent to your account email). DPA
- Meta / Google Ads / Klaviyo: ad-spend and email metrics sync (you authorise via OAuth or API key).
Data residency
Production data is stored in the EU (Supabase EU region). Vercel may serve static assets globally via CDN, but all application data and database queries are processed and stored within the EU.
Retention
We retain your data for as long as your account is active. If you cancel your subscription, we keep your data for 12 months in case you return, after which it is permanently deleted. You can request immediate deletion at any time via Data deletion.
Your rights
Under GDPR you have the right to:
- Export all your data: Account → Export
- Delete your account and all data by request: Data deletion
- Disconnect a platform and wipe its synced data: Data deletion
- Correct any data via the dashboard, or contact us (see below) for help.
- Complain to your local data protection authority. In the Netherlands: Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl.
Security
Third-party access tokens (Shopify, Meta, Google Ads, Klaviyo) are encrypted at rest with AES-256-GCM before being stored. Database access is row-level isolated per user. All traffic is TLS-only with HSTS enforced.
Contact
For privacy requests or questions about this policy, contact us. We usually respond within 24 to 48 hours.
Aftercosts
Reuvekamp 20, Eibergen, The Netherlands
Company number (KvK): 93574290
Tax number (BTW/VAT): NL005028148B54
Email: support@aftercosts.com