Stellad
  • Home
  • Pricing
  • For Shopify
  • AboutTeam and mission
    Legal
    DPAData processing agreementPrivacyHow we handle dataTermsTerms of service
Sign inLaunch a campaign
  • Home
  • Pricing
  • For Shopify
  • About
Sign inLaunch a campaign
Legal · Privacy

Privacy Policy

How Stellad collects, uses, shares, and protects personal data — written to comply with GDPR, the French Loi Informatique et Libertés, and LCEN.

Effective September 1, 2026Last updated September 1, 2026
Privacy PolicyTerms of ServiceData Processing Agreement
Contents
  • 1. Who we are
  • 2. What Stellad does
  • 3. Merchants
  • 4. Shoppers
  • 4.2 Storefront web pixel
  • 4.4 Order-level records
  • 4.5 Customer reviews
  • 5. Cookies
  • 6. Sub-processors
  • 7. Data deletion
  • 8. Security
  • 9. International transfers
  • 10. Children
  • 11. Changes to this policy
  • 12. Contact

Privacy Policy

Effective date: 2026-09-01 Last updated: 2026-09-01

This Privacy Policy explains how Stellad collects, uses, shares, and protects personal data when you install and use the Stellad app on your Shopify store. It is written to comply with the EU General Data Protection Regulation (GDPR), the French Loi Informatique et Libertés, and the Loi pour la Confiance dans l'Économie Numérique (LCEN).

If you are a shopper buying from a Shopify store that uses Stellad, please read Section 4 — Shoppers (end customers of Stellad merchants) which describes the very limited and indirect way your data is involved.


#1. Who we are

Stellad is operated by:

  • Achille Antoine DECOUTTERE, entrepreneur individuel (French sole trader)
  • SIREN: 984 586 693
  • SIRET: 984 586 693 00017
  • Registered address: 941 Route de Lady Les Granges, 74120 Megève, France
  • VAT: Franchise en base de TVA (no VAT charged)

Throughout this policy, "Stellad", "we", "us", and "our" refer to this entity.

Data Protection contact: privacy@stellad.app

The role of Data Protection Officer is performed directly by Achille Antoine DECOUTTERE. Under GDPR Article 37, no separate DPO designation is mandatory for our processing activities at this scale. You can reach the DPO at privacy@stellad.app.


#2. What Stellad does (so you understand what we process)

Stellad is a Shopify app that creates and manages Meta (Facebook and Instagram) advertising campaigns automatically for Shopify merchants. To do this, we:

  • read your Shopify store data (products, customers, orders, reviews, theme, content)
  • store order-level records of your sales, without any customer identifier, so we can measure which campaigns actually produced revenue
  • generate ad creatives (text, images, videos) using AI, which may quote your published customer reviews verbatim
  • identify target audiences
  • read the list of Facebook Pages you administer, so you can choose which one your ads run from. Every Meta ad must be attributed to a Page, so this choice is required before any ad can be created.
  • read the profile fields of the Page you selected: name, category, profile picture, About text, and website
  • where those profile fields are empty, fill them from your own Shopify store data: your store logo becomes the Page profile picture, your store description becomes the About text, your store URL becomes the website, and, only if you confirm it in the app first, your store category and a username. We only ever write to fields that were empty, only on the single Page you selected, and only during onboarding. We publish no posts, and we never change content that is already on your Page.
  • launch and optimize campaigns through the Meta Marketing API, including automated actions we take on your behalf without asking you first (pausing an ad that is spending with no sales, adjusting budgets)
  • where you ask us to, take protective action on Meta campaigns you created outside Stellad: pause them, or step a budget down. We never raise a budget on a campaign we did not create.
  • install a Meta web pixel on your storefront on your behalf, which sends shopper browsing and checkout events to Meta from the shopper's browser
  • forward purchase and checkout events to Meta via the Conversions API (CAPI), with email, phone, name, and customer ID hashed via SHA-256 before transmission, and IP address and user-agent forwarded in plaintext per Meta's CAPI specification
  • upload hashed customer email lists to Meta to build Custom Audiences

We process two kinds of personal data:

  • Merchant data — about you, the Shopify store owner. This is the main subject of this policy.
  • Shopper data — about people who shop at your store. We process this on your behalf as a data processor / sub-processor; see Section 4.

#3. Merchants (Shopify store owners)

#3.1 Personal data we collect

When you install Stellad and connect your accounts, we collect:

| Category | Examples | Source | | --- | --- | --- | | Account identity | First name, last name, email address, company name, job title, phone | You, during onboarding | | Authentication | Supabase user ID, OAuth tokens for Shopify and Meta (encrypted at rest with AES-256-GCM) | Shopify, Meta, Supabase | | Shop information | Shop domain, shop name, shop owner email, billing address, shop currency | Shopify API | | Catalog and content | Product titles, descriptions, prices, images, inventory, blog posts, pages, theme metadata | Shopify API | | Aggregated customer / order data | Counts, averages, top regions, repeat rate, cohort buckets, payment gateway distribution. No individual customer rows are stored. See Section 4. | Computed in memory from Shopify API | | Order-level sales records | One row per order: amount, currency, refunds, financial status, order date, Shopify order ID, and the ad-click keys found on the order (landing page URL, order note attributes, Meta campaign / ad set / ad IDs). No email, name, phone, address, or Shopify customer ID is stored on these rows. The landing page URL and note attributes can contain a Meta click identifier, which is a pseudonymous online identifier: see Section 4.4. | Shopify API and orders/create webhook | | Published customer reviews | Review text and rating as published on your storefront, read from your reviews app's product metafields, used to understand your buyers and to quote in ad copy | Shopify API | | Facebook Page data | The list of Pages you administer (ID, name, category) so you can pick one to advertise from, and the selected Page's profile fields: name, category, profile picture, About text, website. Where those fields are empty we write them from your Shopify store data (logo, description, store URL, and — only with your in-app confirmation — category and username). We read no posts, comments, messages, or follower data; we publish no posts; we change no existing Page content. | Meta API | | Campaign and performance data | Meta campaign IDs, ad creatives we generated for you, performance metrics (spend, ROAS, CTR), brand DNA we synthesized about your store | Stellad-generated, Meta API | | Billing and subscription | Subscription plan (Principal / Scale), Shopify subscription state, billing history | Shopify Billing API | | Communications | Emails you send us, in-app feedback, alert preferences | You | | Technical | Browser type, IP address, log entries, error events | Your browser; Sentry |

#3.2 Why we process it (legal bases under GDPR Art. 6)

| Purpose | Legal basis | | --- | --- | | Provide the service you signed up for (running ads, generating creatives, billing) | Contract — Art. 6(1)(b) | | Comply with French and EU law (tax, accounting, GDPR webhooks, Shopify obligations) | Legal obligation — Art. 6(1)(c) | | Send service emails (incidents, billing, account, security) | Contract / legitimate interest — Art. 6(1)(b) and (f) | | Send product updates and tips | Consent — Art. 6(1)(a) — you can opt out at any time | | Detect fraud, abuse, security incidents | Legitimate interest — Art. 6(1)(f) | | Improve Stellad (aggregate analytics; we do not train AI models on your data) | Legitimate interest — Art. 6(1)(f) |

#3.3 How long we keep merchant data

| Data | Retention | | --- | --- | | Active account data (while you have Stellad installed) | Kept for the duration of the contract | | Order-level sales records | Kept for the duration of the contract; deleted with everything else on uninstall / shop redaction | | All merchant data after uninstall / shop redaction | Deleted within the Shopify-mandated 48-hour window via a full database cascade (see Section 7) | | Backups | Per Supabase's automated backup retention; deleted on the rolling backup schedule (typically up to 30 days) | | Billing records required by French tax law | Retained up to 10 years (Code de commerce L123-22) — minimal data only (invoice, amount, date, identity) | | Sentry error logs | 30 days default retention |

#3.4 Your rights as a merchant

Under GDPR Articles 15–22 and the French Loi Informatique et Libertés, you have the right to:

  • Access — get a copy of your data
  • Rectify — correct inaccurate data
  • Erase — request deletion ("right to be forgotten")
  • Restrict — limit how we process your data
  • Portability — receive your data in JSON (machine-readable, structured)
  • Object — object to processing based on legitimate interest
  • Withdraw consent — for any processing based on consent
  • Lodge a complaint with the CNIL (the French data-protection authority) at https://www.cnil.fr or with your local supervisory authority

To exercise any right, email privacy@stellad.app. We respond within 30 days (extendable by 60 days for complex requests, per GDPR Art. 12).

You can also trigger account deletion by uninstalling the app from your Shopify admin (which fires the shop/redact webhook and cascades the deletion).


#4. Shoppers (end customers of Stellad merchants)

This section is important and is written plainly because the data flow is unusual.

Stellad does not store shopper identity data. No row in our database is keyed on, or contains, a shopper's email, name, phone, address, or Shopify customer ID. We have audited this and re-audit before any change to our Shopify scopes or our Meta integration.

Two things follow that are less absolute than that sentence, and we state them plainly rather than leave them implied:

  • We store order-level records. They carry no customer identifier, but they do carry the Meta click identifier attached to the order where one exists. See Section 4.4.
  • We store published customer reviews as they appear on the merchant's storefront, our AI reads them, and it may quote them verbatim in an ad. See Section 4.5.

Everything else about shoppers is processed transiently: read in memory, forwarded, discarded. Throughout, the merchant is the data controller; Stellad is a sub-processor; Meta is a separate processor that the merchant has chosen to use.

#4.1 Conversions API (CAPI) event forwarding

When a shopper places an order or starts a checkout on a Shopify store using Stellad, Shopify sends Stellad a webhook. Stellad:

  1. Verifies the webhook's HMAC signature
  2. Reads the shopper's email, phone (if present), first name, last name, and Shopify customer ID in memory only
  3. Hashes each field with SHA-256
  4. Sends the hashed values to Meta's Conversions API as event data so the merchant's pixel can attribute conversions to the right campaigns
  5. Discards the in-memory data

No raw or hashed shopper data is written to Stellad's database at any step.

In addition to the SHA-256-hashed identifiers above, each CAPI event includes the shopper's IP address and user-agent string in plaintext, as required by Meta's Conversions API specification for server-side attribution and iOS measurement. These values are read from the Shopify webhook payload, forwarded to Meta in the same network request, and never persisted in Stellad's database. The legal basis for this processing is the merchant's legitimate interest in measuring the performance of their own advertising campaigns (GDPR Art. 6(1)(f)).

#4.2 The storefront web pixel

When a merchant installs Stellad and connects Meta, Stellad installs a Shopify Web Pixel on the merchant's storefront on the merchant's behalf. This is the pixel the merchant would otherwise install by hand; Stellad only automates it.

The pixel runs inside Shopify's sandboxed customer-events worker and sends the merchant's own Meta pixel these events as the shopper browses: PageView, ViewContent, Search, AddToCart, InitiateCheckout, AddPaymentInfo, Purchase. Each event carries the page URL, referrer, product IDs, cart or order value, and currency, and for a Search event the search terms the shopper typed. The request goes from the shopper's browser to Meta directly. Meta may set or read its own cookies on that request under Meta's own terms. Stellad sets no cookie on the storefront.

Consent. The pixel is a marketing technology, and every send is gated on Shopify's Customer Privacy API: nothing fires unless the shopper's marketingAllowed status is true, and the pixel re-evaluates on every consent update. Where the merchant operates a consent banner, that banner governs.

The relay. Two of those events, ViewContent and AddToCart, are additionally POSTed to a Stellad endpoint, which forwards them to Meta server-side under the same event ID so Meta counts the pair once. That request reaches Stellad carrying the shopper's IP address and user-agent. Stellad forwards them to Meta and persists nothing from it beyond an internal counter recording that a send occurred. Purchase and InitiateCheckout never use this relay: they come from the authenticated Shopify webhook described in Section 4.1.

Before the merchant connects Meta, the pixel holds no pixel ID and does nothing. A merchant who does not want it can delete it from their Shopify admin.

#4.3 Custom Audience uploads

For each connected merchant, Stellad:

  1. Pulls up to 2,000 customer email addresses from Shopify, once when Meta is connected and then refreshed weekly. Where Shopify's protected customer data rules close the customer channel, Stellad falls back to reading buyer emails from up to 2,000 orders in the last 365 days.
  2. Hashes each email with SHA-256 in memory
  3. Uploads the hashed list to Meta to create or update two Custom Audiences: all purchasers, used to exclude existing customers from cold ads, and top-spending purchasers, used as a lookalike seed
  4. Stores only the resulting Meta audience ID and a count
  5. Discards all email data

In addition, when a new order arrives, that buyer's email is hashed in memory, added to the same purchaser audience, and discarded.

The hashed emails are not written to Stellad's database. Counts and audience IDs are not reversible to individual shoppers.

#4.4 Order-level records

Stellad stores one row per order so it can tell the merchant which campaign produced which revenue, and so refunds can be netted out of the numbers Meta reports.

What the row holds: Shopify order ID, order date, amount, currency, refunded amount, financial status, cancellation date, the order's landing page URL, the order's note attributes, and the Meta campaign / ad set / ad IDs the order was matched to.

What it does not hold: email, name, phone, address, or Shopify customer ID. Nothing on the row can be looked up by a shopper's identity.

The caveat we want stated: the landing page URL and the note attributes can contain a Meta click identifier (fbclid, or a _fbc cookie value that the store's theme copied there). Under GDPR that is a pseudonymous online identifier. It is stored because it is the only reliable way to attribute a sale to the ad that caused it. It is never used to identify a person, never joined to identity data, and deleted with the rest of the merchant's data.

#4.5 Published customer reviews

Where a merchant uses a reviews app (Judge.me, Loox, Yotpo, Stamped, Okendo, Shopify Product Reviews and similar), Stellad reads the review text and rating already published on the merchant's storefront and stores it alongside the merchant's store data.

That review text is sent to Anthropic, our AI sub-processor, to understand who the store's buyers actually are, and a review line may be quoted verbatim in a generated ad. Quoting a real line is the point: an automated check discards any quote that is not an exact substring of a real review.

Reviews are read as published, from the merchant's own storefront metafields. Stellad does not read reviewer names, email addresses, or any reviewer contact detail, and stores none. Where a shopper's review text itself contains a name or other personal detail, that content is carried as written; a shopper who wants such a review changed or removed should ask the merchant, who controls it in the reviews app.

#4.6 What this means for shoppers

If you are a shopper, the merchant — not Stellad — is the data controller for your data. To exercise your GDPR rights against your shopping data:

  1. Contact the merchant directly. They have access to Shopify and to the Meta tools needed to honor erasure of Custom Audience entries and Off-Facebook activity.
  2. You may also contact us at privacy@stellad.app and we will forward the request to the merchant and confirm we hold no records keyed on your identity. If you can identify the order to the merchant, they can point us at the corresponding order-level row to delete.
  3. Shopify provides a built-in shopper-data-request flow that we participate in via the customers/data_request and customers/redact webhooks. When triggered, we confirm we have no records to return or delete.

#5. Cookies and similar technologies

On stellad.app and in the Stellad dashboard. Stellad sets only what the service needs to work: session cookies issued by Supabase Auth to keep you signed in, and the cookies Vercel sets to route and secure requests. These are strictly necessary and carry no advertising or analytics purpose. Stellad runs no advertising or analytics tracker of its own on its own site.

On the merchant's storefront. Stellad installs the merchant's Meta web pixel (see Section 4.2). Stellad sets no cookie there. The pixel's requests go to Meta, and Meta may set or read its own cookies on the shopper's browser under Meta's terms. Those sends fire only where the shopper's marketing consent is granted through Shopify's Customer Privacy API. Under the ePrivacy Directive and the CNIL's guidance, obtaining and honouring that consent on the storefront is the merchant's responsibility as the site operator; Stellad's role is to respect the answer, which it does on every event.


#6. Sub-processors

Stellad uses the following sub-processors. All EU-bound data transferred outside the EU is covered by Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and, where applicable, additional safeguards required by the Schrems II ruling.

| Sub-processor | Role | Region | Data category | | --- | --- | --- | --- | | Supabase | Database, authentication, file storage | European Union | Merchant data, aggregates, encrypted tokens | | Vercel | Application hosting, edge functions, cron jobs | Global edge; primary compute in EU and US | Merchant data in transit; the storefront pixel relay request (shopper IP and user-agent, not persisted) | | Anthropic | AI models (Claude) for ad copy generation, recommendations, evaluations | US | Merchant brand aggregates, product catalog, and the customer reviews published on the storefront (see Section 4.5). No shopper identity data: no email, name, phone, address, or customer ID. | | fal-ai | AI image generation for ad creatives | US | Product images, generation prompts | | Higgsfield | AI video / creative generation | US | Product images, generation prompts | | Resend | Transactional email delivery | US | Merchant email address, message body | | Sentry | Error monitoring, observability | EU / US | Stack traces, request metadata, merchant user ID | | Shopify | Primary data source, OAuth provider, billing | Global | All merchant and shop data we read | | Stripe | Payment processing for grandfathered subscriptions only; no new subscriptions billed via Stripe | US | Merchant billing data (no shopper PII) | | Meta (Facebook) | Ad platform, OAuth provider, recipient of hashed shopper PII via CAPI and Custom Audiences | Global | Ad campaign data; hashed shopper PII forwarded on the merchant's behalf | | Replicate | Image embedding model inference (CLIP) for AI creative diversity scoring | US | AI-generated product image URLs (no merchant or shopper PII) |

Legacy Stripe billing: Stellad bills all new merchant subscriptions exclusively through the Shopify Billing API. A legacy Stripe billing integration is retained solely to service grandfathered subscriptions created prior to Stellad's migration to Shopify Billing; no new subscriptions can be created via Stripe.

We require all sub-processors to provide protections at least equivalent to those we offer you (GDPR Art. 28(4)).


#7. Data deletion

#7.1 When you uninstall the app

Shopify fires a shop/redact webhook 48 hours after uninstall. On receipt, Stellad runs the same erasure the in-app delete runs: we first clear, by name, the tables that hold per-ad performance rows and forwarded shopper event ids, then we delete the underlying Supabase auth user, which causes every remaining database row referencing that user (across all foreign-keyed tables that reference the merchant account) to be deleted automatically through ON DELETE CASCADE foreign keys. If any part of that erasure fails, Stellad answers the webhook with an error so Shopify re-delivers it, rather than reporting a deletion that did not happen.

This includes:

  • merchant profile, preferences, billing records (kept only as required by French tax law in a separate, minimized record)
  • Shopify connection, encrypted access token, raw catalog snapshot
  • Meta connection, encrypted access token, audience IDs and counts
  • all generated creatives, campaigns, recommendations, performance metrics, brand dossiers, stored reviews
  • all order-level sales records (Section 4.4)

Backups roll off according to Supabase's retention schedule.

#7.2 Shopper redaction

If a shopper requests deletion via the Shopify customers/redact webhook, we confirm to Shopify that we hold no records keyed on that shopper. Our order-level records (Section 4.4) are keyed on the Shopify order ID and hold no customer identifier, so there is nothing on them to redact against a shopper's identity; on a merchant's request naming a specific order we will delete that row. The merchant remains responsible for any deletion required at Meta (via Custom Audience and Off-Facebook activity tools).

#7.3 Manual deletion

You can delete your account and all of its data yourself, at any time, from inside the app: go to Account → Delete account, type DELETE to confirm, and the same full cascade described in Section 7.1 runs immediately, removing your Shopify and Meta connections, their encrypted access tokens, your campaigns, creatives, order records, and your Stellad login itself.

You can also request immediate deletion at any time by emailing privacy@stellad.app. We will execute the deletion within 30 days, sooner where feasible.


#8. Security

We protect personal data with measures appropriate to the risk, in line with GDPR Art. 32:

  • HTTPS everywhere, HTTP Strict Transport Security (HSTS) in production
  • AES-256-GCM encryption at rest for sensitive tokens (Shopify and Meta access tokens)
  • HMAC verification with constant-time comparison (timingSafeEqual) on every webhook
  • Row-Level Security (RLS) enforced on every Supabase table holding merchant data
  • Stellad does not store passwords in its own database. Merchant authentication is managed by Supabase Auth using email-based magic links and OAuth flows.
  • Principle of least privilege on all sub-processor accounts
  • Continuous error monitoring via Sentry with alerting on anomalous patterns

Stellad is not itself SOC 2 certified. Several of our sub-processors are (Supabase, Vercel, Stripe), and we rely on their certifications for their respective parts of the stack.

For security-sensitive disclosures (vulnerabilities, suspected breaches), please email security@stellad.app.

In the event of a personal data breach affecting your data, we will notify you within 72 hours of becoming aware of the breach, in accordance with GDPR Art. 33–34. Where Stellad acts as data controller (for merchant data), we will also notify the CNIL within the same timeframe. Where Stellad acts as data processor on the Merchant's behalf (for shopper data), the Merchant remains responsible for notifying their competent supervisory authority, and Stellad will provide reasonable assistance.


#9. International transfers

Some of our sub-processors are based outside the European Economic Area (notably in the United States). For those transfers we rely on:

  • the European Commission's Standard Contractual Clauses (SCCs) where applicable
  • the EU-US Data Privacy Framework where the sub-processor is certified
  • supplementary technical measures (encryption in transit, hashing of shopper PII before any transfer to Meta, encryption at rest)

You can request a copy of the SCCs in force for any sub-processor at privacy@stellad.app.


#10. Children

Stellad is a B2B service for Shopify merchants and is not directed at children. We do not knowingly process personal data of anyone under 16. If you believe we hold data about a child, contact privacy@stellad.app and we will delete it.


#11. Changes to this policy

We may update this policy. Material changes will be notified by email to your account email and via in-app notification at least 30 days before they take effect. The "Last updated" date at the top is always current.


#12. Contact

| Topic | Email | | --- | --- | | Privacy, GDPR, DSAR | privacy@stellad.app | | Security disclosures | security@stellad.app | | Legal notices | legal@stellad.app | | Support | support@stellad.app |

Postal mail: Achille Antoine DECOUTTERE 941 Route de Lady Les Granges 74120 Megève France

You may also contact the CNIL (Commission Nationale de l'Informatique et des Libertés) at https://www.cnil.fr if you believe your rights have not been respected.

Questions about this document?

Reach our team directly — we usually reply within one business day.

privacy@stellad.app
Also seeTerms of ServiceThe rules of using Stellad.Also seeData Processing AgreementGDPR Art. 28 obligations between Stellad and you as a merchant.

Achille Antoine Decouttere

Stellad

Five-minute Meta ads for Shopify. Generated, launched, autopiloted.

Product
  • How it works
  • Pricing
For Shopify
  • Integration
Company
  • About
  • Contact
Legal
  • Privacy
  • Terms
  • DPA
© 2026 Stellad · Made for solo Shopify merchants. · ACHILLE ANTOINE DECOUTTERE, ENTREPRENEUR INDIVIDUELv0.1 · beta