Realized LedgerSupportPrivacyTerms

Privacy Policy — Realized Ledger

Last updated: 11 October 2026

Realized Ledger ("the app") is a Shopify app published by Elektraset, s.r.o. ("we", "us"). It reconciles a merchant's Shopify orders, refunds, returns and costs with the merchant's Meta Ads and Google Ads spend, and shows customer acquisition cost (CAC), ROAS and returns-adjusted profit per campaign, cohort, product and order. This policy explains what data the app processes, why, and for how long.

Website: https://elektraset.com/ · Contact: help@elektraset.com · App: https://realized-ledger.apps.elektraset.com

Who is the controller

The merchant who installs the app is the controller of their store data and of their customers' data. We process this data on the merchant's behalf, only to provide the app. For the merchant's account and billing data we are the controller.

Data we process

From Shopify (Admin API scopes read_orders, read_customers, read_products, read_inventory, read_returns, and write_pixels + read_customer_events for the web pixel):

From Meta Ads and Google Ads (only when the merchant connects an account, read-only):

Uploaded by the merchant: ad spend CSV files (campaign names and IDs, dates, spend, clicks, impressions).

Session data: the Shopify session token that Shopify issues to the app for the store.

From the Realized Ledger web pixel (storefront): the app activates a Shopify web pixel, which runs in Shopify's sandbox and only for visitors who allow analytics and marketing tracking under the store's cookie consent. It keeps the first and the last landing page URL that carries UTM parameters or ad click IDs (with the referrer URL and time) in the visitor's browser storage for up to 90 days, and when a checkout completes it sends these URLs and the order ID to the app. It reads no name, email, address, payment or cart contents, and it loads no third-party script.

Why we process it

Only to provide the app's features: import, attribution of orders to campaigns, the reports, CSV exports, the daily sync, billing through Shopify, and support. We do not sell data, do not use it for advertising, do not combine data of different merchants, and do not use it to train AI models.

Where data is stored and who receives it

Data is stored in a database on the app's server operated by Elektraset, s.r.o. Data is sent only to:

Retention and deletion

Security

HTTPS for all traffic, encryption of ad platform tokens at rest, verification of every Shopify webhook signature (HMAC), access to store data only through Shopify's authenticated session, and least-privilege read-only scopes.

Your rights

Merchants and their customers can request access, correction or deletion of personal data. Customers should contact the merchant first; the merchant or the customer can also write to help@elektraset.com. Where the GDPR applies you also have the right to object, to data portability and to complain to a supervisory authority.

Changes

We will post changes on this page and update the date above. Material changes are announced in the app.

Contact

Elektraset, s.r.o. — help@elektraset.com — https://elektraset.com/