Skip to content

Privacy Policy

Last updated: October 8, 2026

Who operates AdParity

AdParity is the name of this service. It verifies ecommerce advertising infrastructure for merchants. A legal entity name is not configured on this service yet.

What AdParity does

AdParity compares Shopify, the storefront, Google Merchant Center, and browser-side tracking so a merchant can see whether those systems agree before spending more on ads.

Information from accounts

When you create an account, AdParity stores the Firebase user id, email address, display name, and profile image URL if the sign-in provider supplies one. It also stores workspace name and membership role. If you turn on monitoring alerts, AdParity stores the notification email address you enter.

Shopify

The current Shopify app requests these read scopes: read_products, read_inventory, read_locations. With that access, AdParity reads products, variants, SKUs, barcodes, prices, inventory, locations, and store metadata such as name, domain, currency, and timezone. Shopify credentials are stored on the server and are not readable by the browser. The current scopes do not include customer lists, order history, or payment details, and AdParity does not use the Admin API to ingest orders.

Google Merchant Center

If you connect Merchant Center, AdParity requests the scope https://www.googleapis.com/auth/content. That Google scope is broader than read-only. AdParity's Merchant integration uses it to read account metadata, processed products, identifiers, prices, availability, and diagnostics, and to compare that state with Shopify and the storefront. AdParity does not write Merchant Center data. The refresh credential is stored on the server so scheduled checks can run after you connect. You can disconnect in AdParity, which deletes the stored credential and asks Google to revoke it.

Google user data is used to provide the Merchant checks you can see in AdParity. AdParity does not use it to advertise, retarget, sell data, broker data, or make credit decisions. This page describes that behavior. It is not a certification under the Google API Services User Data Policy.

Storefront checks

AdParity can open an automated browser on the storefront of a Shopify store you connected. A check may load a product page, select a variant, add an item to the cart, and begin checkout. Daily monitoring does not complete a paid order. The worker accepts a scan for a connected store. It does not accept an arbitrary URL from the browser.

Meta Pixel observations

AdParity does not connect to a Meta account or the Meta API for the current browser check. During a storefront journey it observes Meta Pixel requests the storefront sends. Stored results can include Pixel ids, event names, values, currency, and finding summaries. AdParity does not store storefront cookies, the raw Pixel request, or a browser session.

Monitoring email

Monitoring is off until you turn it on. When it is on, AdParity runs the same preflight about once a day and can email you when an important result changes. Those messages are transactional alerts, not marketing. Resend delivers them. AdParity stores the recipient address, delivery status, and provider message id. The send request does not ask for open or click tracking.

Cookies and local storage

AdParity uses an HttpOnly session cookie named adparity_session and a short-lived HttpOnly cookie named adparity_csrf to sign you in and check the session request. Firebase Authentication in the browser is kept in memory for the sign-in step and is not the lasting session. AdParity does not set marketing or analytics cookies and does not load a third-party analytics script. A cookie banner is not shown because these cookies are the sign-in mechanism.

Service providers and connected platforms

Vercel hosts the web application. Google Firebase and Google Cloud store accounts and application data. Microsoft Azure runs the automated browser. Resend sends alert email. Shopify and Google Merchant Center are platforms you authorize. They are not listed here as subprocessors. Names and purposes are also on the Providers page.

Retention

Account, catalog, scan, preflight, finding, and monitoring records stay while the workspace and store connection remain, including after you disconnect a platform, until you delete the AdParity account or a Shopify shop redaction deletes that store's records. Disconnecting Shopify or Google removes that platform's server credential and stops later calls. It does not by itself erase earlier preflight history. OAuth attempt records are valid for 10 minutes. Webhook delivery ids are treated as duplicates for 48 hours. AdParity does not promise a fixed number of days after which history disappears, and it does not control how long Resend keeps a sent message.

Deletion

A workspace owner can disconnect Shopify or Google Merchant Center from Connections. Disconnecting in AdParity removes AdParity's stored credential. It does not uninstall the Shopify app from Shopify Admin. Deleting the AdParity account, after a fresh sign-in and explicit confirmation, removes the sole owner's workspace data and the Firebase user when that workspace has no other member. Shopify shop redaction deletes the data for that store only, including credentials, catalog, scans, preflights, findings, Merchant data, and monitoring. Customer data request and customer redaction webhooks are accepted. The current scopes do not give AdParity Shopify customer records to return or erase. Deletion of a workspace with more than one member is not automatic.

Security

The site is served over HTTPS. OAuth credentials are stored in server-only Firestore documents. Workspace membership is checked on the server. Firestore rules deny browser access to credentials. The scan worker authenticates server to server and runs only for a connected store. Logs are written to avoid tokens and raw payloads. None of this makes the service immune to compromise.

Where processing happens

Firestore for this project is in the United States multi-region named nam5. The browser worker runs on Azure Container Apps. Resend delivers alert email. Vercel may process web requests outside a single region. AdParity does not claim that every copy of data stays in one country.

Children

AdParity is business software for merchants. It is not directed at children, and it does not ask a merchant to verify the age of shoppers.

Privacy requests

Depending on where you live, applicable law may give you rights to access, correct, or delete personal information, or to object to certain processing. AdParity does not decide in this policy which statute applies to you. Signed-in owners can disconnect integrations and delete a sole-owner account from the account page. A public privacy contact address is not configured yet.

Changes

When this policy changes, the date above and the policy version change. A signed-in user who has not accepted the current version is asked once. The rest of the product stays available.

Contact

No public privacy contact address is configured. Use the signed-in account page for disconnect and account deletion.

No legal entity name or postal address is configured.