Privacy Policy — Realized Ledger
Last updated: 11 October 2026
Realized Ledger ("the app") is a Shopify app published by Elektraset, s.r.o. ("we", "us"). It reconciles a merchant's Shopify orders, refunds, returns and costs with the merchant's Meta Ads and Google Ads spend, and shows customer acquisition cost (CAC), ROAS and returns-adjusted profit per campaign, cohort, product and order. This policy explains what data the app processes, why, and for how long.
Website: https://elektraset.com/ · Contact: help@elektraset.com · App: https://realized-ledger.apps.elektraset.com
Who is the controller
The merchant who installs the app is the controller of their store data and of their customers' data. We process this data on the merchant's behalf, only to provide the app. For the merchant's account and billing data we are the controller.
Data we process
From Shopify (Admin API scopes read_orders, read_customers, read_products, read_inventory, read_returns, and write_pixels + read_customer_events for the web pixel):
- Shop: domain, currency, time zone, the app subscription plan.
- Orders of the import window (up to the last 60 days): order ID and number, date, test and cancelled flags, amounts (line items, discounts, shipping, tax, total), product IDs and titles, quantities, product cost per item, refunds (dates, amounts, refunded quantities), return status, and payment transaction fees.
- Customer data, limited to: the Shopify customer ID and the customer's order number (first, second order …), and the customer's store visits as Shopify reports them in the customer journey: landing page URL, referrer URL, visit time and UTM parameters, including click IDs (gclid, fbclid) in the landing page URL.
- The app does not read or store customer names, email addresses, phone numbers, postal addresses or payment card data.
From Meta Ads and Google Ads (only when the merchant connects an account, read-only):
- OAuth access and refresh tokens (stored encrypted with AES-256-GCM).
- Ad account ID, name and currency; daily campaign, ad set / ad group and ad spend, clicks and impressions; for Google Ads, the Google click IDs (gclid) of the last 14 days with their campaign and ad group.
Uploaded by the merchant: ad spend CSV files (campaign names and IDs, dates, spend, clicks, impressions).
Session data: the Shopify session token that Shopify issues to the app for the store.
From the Realized Ledger web pixel (storefront): the app activates a Shopify web pixel, which runs in Shopify's sandbox and only for visitors who allow analytics and marketing tracking under the store's cookie consent. It keeps the first and the last landing page URL that carries UTM parameters or ad click IDs (with the referrer URL and time) in the visitor's browser storage for up to 90 days, and when a checkout completes it sends these URLs and the order ID to the app. It reads no name, email, address, payment or cart contents, and it loads no third-party script.
Why we process it
Only to provide the app's features: import, attribution of orders to campaigns, the reports, CSV exports, the daily sync, billing through Shopify, and support. We do not sell data, do not use it for advertising, do not combine data of different merchants, and do not use it to train AI models.
Where data is stored and who receives it
Data is stored in a database on the app's server operated by Elektraset, s.r.o. Data is sent only to:
- Shopify (the platform the app runs on), to read store data and to process the app subscription.
- Meta Platforms and Google, only the API requests needed to read the merchant's own ad accounts after the merchant connects them.
Retention and deletion
- When the merchant uninstalls the app, we delete the Shopify session and all Meta and Google tokens at once.
- 48 hours after uninstall Shopify sends the
shop/redactrequest; we then delete all data of the store (ledger, spend, settings, logs). - Orders older than the import window are deleted at each sync.
- On a
customers/redactrequest we remove the customer ID and the visit data of that customer's orders. The order amounts remain in the merchant's totals without any link to the person. - On a
customers/data_requestthe merchant can see the data linked to the customer in the app's order ledger; contact us for an export. - The merchant can disconnect an ad account at any time; its tokens and imported spend are deleted.
Security
HTTPS for all traffic, encryption of ad platform tokens at rest, verification of every Shopify webhook signature (HMAC), access to store data only through Shopify's authenticated session, and least-privilege read-only scopes.
Your rights
Merchants and their customers can request access, correction or deletion of personal data. Customers should contact the merchant first; the merchant or the customer can also write to help@elektraset.com. Where the GDPR applies you also have the right to object, to data portability and to complain to a supervisory authority.
Changes
We will post changes on this page and update the date above. Material changes are announced in the app.
Contact
Elektraset, s.r.o. — help@elektraset.com — https://elektraset.com/