NorthScaleLast updated: June 2026 · GDPR compliant · Shopify App ready
NorthScale is committed to protecting your data. This policy explains what we collect, why, and your rights under GDPR. We process your Shopify and advertising data solely to deliver profit intelligence — never to sell or share with third parties.
NorthScale ("we", "us") is the data controller for personal data processed through this platform. By using NorthScale, you agree to this Privacy Policy. We are committed to processing your data in accordance with the General Data Protection Regulation (GDPR) and applicable national data protection laws.
We collect and process the following categories of data:
Account Data: Name, email address, company name, role — collected when you register.
Store Data: Shopify store domain, orders, products, customer data, inventory levels — synced via the Shopify API with your explicit authorisation.
Advertising Data: Ad spend, campaign performance, ROAS — synced from Meta Ads, Google Ads, and GA4 with your explicit authorisation.
Financial Inputs: COGS estimates, shipping costs, payment fees — entered manually by you.
Usage Data: Pages visited, features used, session duration — for improving the platform.
Payment Data: All billing is processed exclusively through Shopify's native billing system (Shopify App Pricing). NorthScale never collects, stores, or processes payment card details of any kind. Charges appear directly in your Shopify admin.
NorthScale connects to your Shopify store via the Shopify API. Here is exactly what we access and why:
API Scopes Requested:
• read_orders — to calculate true profit, margins, and return rates per product
• read_products — to build your product catalogue and track inventory levels
• read_customers — to calculate LTV, repeat purchase rates, and new vs. returning customer splits (customer email addresses are stored in hashed/anonymised form only and never used for outreach)
• read_inventory — to track stock levels, days-of-stock calculations, and stockout warnings per product
• read_analytics — to supplement session and conversion data where GA4 is not connected
What we never do:
• We never request write scopes — we cannot create, edit, or delete any data in your Shopify store
• We never access your Shopify Payments banking details, payout information, or store owner credentials
• We never access your store theme, checkout configuration, or storefront code
• We never sell, share, or use your store data to benefit other NorthScale customers
App Uninstall:
When you uninstall NorthScale from your Shopify admin, our API access is immediately and permanently revoked. Your data is retained for 30 days to allow you to export it, then permanently and irreversibly deleted from all systems including backups. This complies with Shopify's mandatory GDPR data deletion requirements (customers/redact and shop/redact webhooks).
Shopify Customer Data:
As a Shopify merchant using NorthScale, you remain the data controller for your customers' personal data. NorthScale acts solely as your data processor. We process customer data only to generate profit analytics on your behalf and never contact your customers directly for any reason.
Shopify GDPR Webhooks:
NorthScale supports all three mandatory Shopify GDPR webhooks: customers/data_request, customers/redact, and shop/redact. We respond to these automatically and will notify you if a data request concerns your store.
We process your data on the following legal bases (GDPR Art. 6):
• Contract performance (Art. 6(1)(b)): Processing your store data to deliver the APEX profit intelligence service.
• Legitimate interests (Art. 6(1)(f)): Improving platform features, fraud prevention, and security.
• Consent (Art. 6(1)(a)): Where you have explicitly opted in, e.g. marketing emails.
• Legal obligation (Art. 6(1)(c)): Compliance with tax and invoicing requirements.
Your data is used exclusively to:
• Calculate Apex Scores and profit intelligence for your store
• Generate action recommendations via the NOVA engine
• Provide the "Ask NorthScale" AI assistant grounded in your real data
• Send operational alerts (score drops, stockouts, return spikes)
• Issue invoices and manage subscriptions via Stripe
• Improve platform algorithms (anonymised and aggregated only — never at individual store level)
We do NOT sell your data to third parties. We do NOT use your store's competitive data to benefit other NorthScale customers.
• Account data: Retained for the duration of your subscription + 30 days after cancellation.
• Store & order data: Retained per your subscription tier's data history limit (3–24 months).
• Backups: Encrypted backups retained for up to 90 days.
• You may request deletion of all your data at any time by contacting privacy@northscale.io.
As an EU/EEA data subject, you have the following rights:
• Right of Access (Art. 15): Request a copy of all data we hold about you.
• Right to Rectification (Art. 16): Correct inaccurate or incomplete data.
• Right to Erasure (Art. 17): Request deletion of your data ("right to be forgotten").
• Right to Portability (Art. 20): Receive your data in a machine-readable format.
• Right to Restrict Processing (Art. 18): Temporarily halt processing while a dispute is resolved.
• Right to Object (Art. 21): Object to processing based on legitimate interests.
To exercise any right, email privacy@northscale.io. We will respond within 30 days.
All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Access to production databases is restricted to authorized personnel only, with full audit logging. We conduct regular security assessments and follow industry best practices for data protection.
We use the following sub-processors:
• Shopify Billing (app subscriptions) — all charges processed through Shopify App Pricing; no card data is handled by NorthScale
• Shopify (store data source) — data accessed with your authorisation via OAuth
• Meta / Google (ad data source) — data accessed with your authorisation via OAuth
• OpenAI / Google AI (AI assistant) — prompts contain only anonymised, aggregated store summaries; no raw customer PII is ever sent
All sub-processors are bound by Data Processing Agreements in compliance with GDPR Art. 28.
Where data is transferred outside the EU/EEA, we ensure adequate safeguards are in place through Standard Contractual Clauses (SCCs) or adequacy decisions from the European Commission.
The NorthScale platform is provided in English only. All merchant-facing UI, reports, notifications, and documentation are in English. We do not currently offer localised versions in other languages.
NorthScale uses essential cookies only: session authentication and CSRF protection. We do not use third-party tracking cookies or advertising cookies. No cookie consent banner is required as we rely solely on strictly necessary cookies.
We will notify you by email at least 14 days before making material changes to this Privacy Policy. Continued use of NorthScale after the effective date constitutes acceptance of the updated policy.
For any privacy-related questions or to exercise your rights:
Email: privacy@northscale.io
Subject line: "GDPR Request — [Your Name]"
We take all requests seriously and will respond within 30 days.
Exercise Your Rights
To access, correct, or delete your data — contact us and we'll respond within 30 days.
Email privacy@northscale.io© 2026 NorthScale. All rights reserved.