Privacy Policy
Last updated: 5 September 2026
1. Who we are
TrackAlive is operated by Aurevia Systems Pty Ltd, a company based in Melbourne, Australia. For any privacy question, email hargravelabs@gmail.com.
This policy is written to meet the Australian Privacy Act 1988 (Cth), the EU General Data Protection Regulation (GDPR), the UK GDPR and the California Consumer Privacy Act (CCPA). For GDPR and UK GDPR purposes, TrackAlive acts as a processor for the merchant (the controller) in respect of daily order counts, checkout tokens and GA4 purchase counts, and as a controller for the merchant’s own account data, such as a contact email address and an optional Slack webhook URL. TrackAlive does not sell personal information, as that term is defined under the CCPA.
2. What TrackAlive does
TrackAlive is a Shopify app. Each day it compares three numbers for a merchant’s store: the number of Shopify orders, the number of checkout-completed events recorded by TrackAlive’s own web pixel, and the number of purchase events recorded in the merchant’s own Google Analytics 4 (GA4) property. When those numbers split apart in a way that suggests conversion tracking has broken, TrackAlive alerts the merchant by email or Slack so they can fix it quickly instead of losing weeks of ad data.
3. Data we collect from the merchant
When a merchant installs TrackAlive, we collect and store:
- the shop domain and the shop’s timezone
- a contact email address for alerts
- an optional Slack webhook URL, if the merchant enables Slack alerts
- a Google OAuth refresh token, encrypted at rest, if the merchant connects Google Analytics
- the GA4 property ID the merchant selects
4. Data we collect from the storefront
TrackAlive’s web pixel records a checkout token and a timestamp when a checkout completes and the buyer has granted analytics consent. We do not collect or store names, email addresses, postal addresses, phone numbers, line items, or order amounts from the storefront. The checkout token is an opaque identifier of a checkout, not of a person.
5. Google user data
TrackAlive requests read-only access to Google Analytics 4 (the analytics.readonly scope) for the single GA4 property the merchant selects. This access is used only to read a daily count of purchase events for that property, so TrackAlive can compare it against Shopify’s order count and its own pixel count. This data is never transferred to any other app or party, never sold, never used for advertising, and never read by a human except where the merchant has given consent or where necessary for security or to comply with the law.
TrackAlive’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Retention
- Daily reconciliation stats are kept for 90 days.
- Checkout tokens recorded by the pixel are kept for 45 days.
- When a merchant uninstalls TrackAlive, Shopify sends us a
shop/redactwebhook roughly 48 hours later, and we delete every row associated with that shop, including the encrypted Google refresh token, within 48 hours of receiving it.
7. Processors
We share data with the following processors, only as needed to run TrackAlive:
- Railway, for application hosting and the Postgres database
- Google, for reading GA4 purchase-event counts
- Resend, for sending alert emails
- Slack, for posting alert messages, if the merchant enables Slack alerts
8. Merchant rights
A merchant can ask us to access, export or delete their account data at any time by emailing hargravelabs@gmail.com. A merchant can disconnect Google Analytics inside the TrackAlive app at any time, and can revoke TrackAlive’s access to their Google account directly at myaccount.google.com/permissions.
We handle merchant account data in line with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles. If a merchant is unsatisfied with how we have handled a privacy request, they may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
9. Customer rights
TrackAlive holds no personal data about a merchant’s own customers. We do not store customer names, emails, addresses or order contents. When Shopify sends us the customers/data_request or customers/redact compliance webhooks on behalf of a merchant’s customer, we respond within the required time and confirm we hold nothing to return or delete.
10. Security
All data in transit is encrypted with TLS. Google refresh tokens are encrypted at rest with AES-256-GCM. Access to production systems is limited to what each service needs to run, on a least-privilege basis.
11. Changes and contact
We may update this policy from time to time. Material changes will be reflected in the “Last updated” date above. Questions about this policy can be sent to hargravelabs@gmail.com.