Legal

Privacy Policy

Last updated: August 18, 2026

BlindSpot Apps (“BlindSpot,” “we,” “us,” or “our”) provides ecommerce monitoring and incident-response software. This policy explains what information we process when you visit our website or use BlindSpot applications, including BlindSpot Monitor and its optional advertising guardrails.

1. Information we collect

  • Account and contact data: names, email addresses, support communications, and account administration details you provide.
  • Shop and configuration data: Shopify shop domain, plan and entitlement state, monitor and alert settings, selected public monitoring targets, incident records, notification destinations, and audit history.
  • Technical and security data: IP address, browser/device information, authentication sessions, request metadata, error data, and security or service-health events.
  • Connected-service data: credentials and configuration needed for integrations you choose to connect, such as Slack, Meta Ads, or Google Ads.

2. Meta Ads and Google Ads data

Ads Guardrails is optional. When you connect it, BlindSpot processes only the provider data needed to configure and operate the feature.

  • Meta Ads: the connecting Meta user ID and display name, accessible ad-account identity, campaign ID/name/status, your selected account and campaign allowlist, an encrypted access token, token expiration, consent and safety settings, and incident action history.
  • Google Ads: accessible Google Ads customer IDs, campaign ID/name/status, your selected customer and campaign allowlist, an encrypted refresh token, consent and safety settings, and incident action history.

BlindSpot does not need or intentionally collect ad creative, audience membership, lead data, click-level data, conversion records, budgets, bids, keywords, targeting, Google profile data, or advertising end-user personal data to provide Ads Guardrails.

3. How we use information

  • Provide, secure, support, and improve the service.
  • Authenticate users, enforce account boundaries, and administer subscriptions.
  • Run requested monitoring checks, open and recover incidents, deliver alerts, and preserve operational evidence.
  • Connect accounts and display eligible resources for configuration.
  • For Ads Guardrails, read basic campaign status and pause or resume only campaigns you explicitly allowlist, only under the mode, monitor, and safety controls you configure.
  • Detect abuse, troubleshoot failures, meet legal obligations, and communicate service or policy changes.

BlindSpot does not sell provider data, use it to build advertising profiles, use it to target advertising, share it with data brokers, or create cross-merchant advertising benchmarks.

4. Advertising automation controls

Ads Guardrails begins in non-mutating Shadow mode. Armed mode requires explicit consent. BlindSpot acts only on campaigns and trigger monitors you select, deduplicates actions for one continuous incident, and resumes only campaigns its records show it paused for that incident. You can disable the automation, activate its merchant kill switch, or disconnect the provider. If BlindSpot has campaigns recorded as paused, the product requires recovery before disconnect to avoid leaving them stranded.

5. How we disclose information

We disclose information only as reasonably necessary:

  • to infrastructure, communications, security, and support vendors acting for us under appropriate obligations;
  • to services you direct us to connect, such as Shopify, Meta, Google, Slack, or a webhook destination;
  • to comply with law, legal process, or valid government requests;
  • to protect users, BlindSpot, or others from fraud, abuse, or security threats; or
  • in connection with a business transaction, subject to applicable notice and safeguards.

We do not sell personal information.

6. Security

We use administrative, technical, and organizational safeguards designed to protect information. Provider tokens are handled server-side and encrypted at rest with AWS Key Management Service before storage. They are not intentionally returned to the browser after connection. No security program can eliminate every risk, and we cannot guarantee absolute security.

7. Retention, disconnect, and deletion

We retain account, configuration, and operational evidence for as long as needed to provide the service, meet contractual or legal obligations, resolve disputes, and protect the service. After any BlindSpot-paused campaigns are recovered, disconnecting Meta or Google requests provider-side token revocation and removes the active integration record, including its encrypted provider token and selected account/campaign configuration. Limited action metadata may be retained where required for security, support, legal compliance, or proof of prior authorized activity; it does not include provider credentials.

Manual disconnect can remove the local connection and direct you to provider settings if revocation cannot be confirmed. A complete deletion request retries temporary provider failures before destroying the local credential needed to finish cleanup. You can always revoke BlindSpot directly in your provider account. See our data deletion instructions for disconnect, revocation, uninstall, verified request, and status-receipt steps.

8. Google API Services User Data Policy

BlindSpot's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

9. Your choices and rights

Depending on your location, you may have rights to access, correct, delete, restrict, or receive a copy of personal information, or to object to certain processing. You can change product configuration in the app, disconnect integrations, revoke provider access, or contact us. We may need to verify your identity and authority over the relevant shop before completing a request.

10. Changes to this policy

We may update this policy as the service or applicable requirements change. We will update the date above and provide additional notice when required.

11. Contact us

For privacy questions or requests, email support@blindspotapps.com. Include your Shopify shop domain and the service involved, but never send us a password, access token, refresh token, or recovery code.