LLM Pixels
Privacy Policy
Last updated 27 August 2026
How LLM Pixels handles personal data. This policy covers the Shopify app only.
Who processes your data
LLM Pixels is operated by ARS PROGRAMMATICA. For data about a merchant's customers, the merchant is the data controller and LLM Pixels acts as a processor on their instructions.
What the app does
LLM Pixels measures which purchases in a Shopify store followed a ChatGPT advertisement, and reports those conversions to OpenAI so the merchant can see whether their advertising works.
Storefront events
A Shopify web pixel sends events such as page views, add-to-cart and checkout directly from the shopper's browser to OpenAI. These events do not pass through our servers and contain no names, email addresses or phone numbers.
The pixel runs only when the shopper has granted analytics and marketing consent. Shopify enforces this; the app cannot override it.
Order data
If a merchant enables server-side tracking, our server receives a webhook when an order is paid and forwards a conversion event to OpenAI. That event contains:
- Name, email address and phone number, which are hashed with SHA-256 before transmission and never sent or stored in readable form.
- Shopify customer ID, hashed with SHA-256 and used only as a pseudonymous match key.
- City, region, postal code and country, sent as provided.
- IP address and browser user agent, sent as provided.
- Order value, currency, and the products purchased.
What we store
No customer personal data is stored. Identifiers are hashed in memory, included in the conversion event, and discarded when the request ends.
We store only the merchant's Shopify session, their OpenAI Pixel ID, their event preferences, an encrypted OpenAI API key, and the status of the most recent conversion event.
One short-lived exception: when a shopper checks out through an express button that bypasses the cart, the advertising click identifier is held for up to seven days alongside a one-way hash of the checkout reference, so the resulting order can be matched to the advertisement. Neither value identifies a person, the checkout reference itself is never stored, and the record is deleted automatically.
Consent
Where a shopper declines analytics or marketing consent, no storefront events are sent and no conversion event is sent for their order.
Where a shopper permits measurement but opts out of their data being sold, the conversion event is marked so that OpenAI excludes it from user-level personalisation.
Who we share data with
- OpenAI, which receives the conversion events described above and is the reason the app exists.
- Railway, which hosts the application and its database.
- Shopify, which is the source of the data and the platform the app runs on.
Retention
Customer personal data is not retained, because it is not stored. Merchant settings, including the encrypted API key, are deleted when the app is uninstalled, and again on Shopify's shop redaction webhook 48 hours later.
Application logs record the shop domain and whether an event succeeded. They contain no personal data.
Security
All data is transmitted over TLS. The OpenAI API key is encrypted at rest with AES-256-GCM under a key held only in the server environment. Automated tests assert that no raw email address, phone number, name, order identifier or checkout token appears in any outgoing request.
Your rights and contact
Shoppers should contact the merchant whose store they purchased from, as the merchant is the controller. Merchants and others can reach us at info@arsprogrammatica.com.
Because no customer personal data is stored, requests to access or erase such data will be answered with confirmation that none is held.
Data Processing Agreement · Chrome Extension Privacy Policy · Security and Data Protection