Privacy policy · Feed & Pixel for ChatGPT Ads
Last updated: 8 October 2026
This policy explains which data the Feed & Pixel for ChatGPT Ads app for Shopify (the “app”) processes. The app sends the merchant’s product catalog to their ChatGPT ads account and measures store activity through OpenAI’s Conversions API. It is an independent integration built by Línea Gráfica; it is not made by or affiliated with OpenAI.
1. Who we are
LÍNEA GRÁFICA ESPECIALISTAS EN COMERCIO ELECTRÓNICO S.L. (Línea Gráfica)
VAT number: B91794685
C/ Astronomía 1, Torre 1, Planta 10, Módulos 8-11, 41015 Sevilla (España)
Email: contacto@lineagrafica.es
App support: appsupport@lineagrafica.es
Data protection officer: dpo@lbo-abogados.com
Company register: Registro Mercantil de Sevilla, folio 208, tomo 5072, sección General, hoja SE-82.558, inscripción 1ª
For the data of the store’s visitors and customers, the merchant is the data controller and we act as their data processor, following the merchant’s instructions (the app’s settings).
2. Data about the store’s visitors and customers
The app’s web pixel runs in the storefront only when the visitor has accepted marketing and analytics cookies, through the store’s Shopify cookie banner. When it runs, it sends to our server these events: page viewed, product viewed, product added to cart, checkout started and checkout completed. For each event we receive:
- the page URL, the event time, the product or cart contents (product IDs, names, quantities and prices) and the order total;
- the visitor’s IP address and browser user agent;
- the ChatGPT ad click reference (
oppref), if the visitor came from a ChatGPT ad; - on checkout completion: the order ID and the customer’s email, phone, first and last name (sent to OpenAI only as SHA-256 hashes), country, city, region and postal code.
These events are forwarded to the Conversions API of the merchant’s own OpenAI ads account, so the merchant can measure the sales that come from their ChatGPT ads. When a consenting visitor’s order is created, Shopify also notifies the app (orders/create) and the same purchase is sent from the server as a backup, with the same ID so it is not counted twice. Orders from visitors who did not give consent are not sent.
We store only what is needed to run the service:
- the checkout token and click reference, for 30 days, to link an order to its ad click;
- the IDs, amounts and currency of the orders already sent, so they are not sent twice;
- daily totals (events sent, orders, revenue, ad spend) for the app’s dashboard.
Events are queued in memory for a few seconds and are not stored. We do not store emails, phone numbers, names, addresses or IP addresses.
3. Data about the merchant
- The store’s domain and the Shopify access session needed to run the app.
- The product catalog read from Shopify (titles, descriptions, images, prices, stock, barcodes), used to build the feed file. The latest feed file is kept so it can be uploaded to OpenAI or downloaded through the private link.
- The settings the merchant saves: Pixel ID, Conversions API key and Ads API key (stored encrypted), feed delivery method and SFTP access, countries and feed rules.
- The ads account name and currency, and the ad spend reported by OpenAI.
- The plan and the state of the subscription, as reported by Shopify.
4. Purpose, legal basis and retention
This data is used solely to provide the app, on the basis of the contract with the merchant. Sending visitor events relies on the visitor’s consent, collected by the store. Click references are deleted after 30 days. When the app is uninstalled, Shopify notifies us and all the store’s data, including the feed file, is deleted (shop/redact). On a customers/redact request we delete the records of that customer’s orders; on a customers/data_request there is no other personal data to return.
5. Hosting and recipients
The app and its data are hosted in the European Union. Recipients: Shopify, the platform the store runs on, and OpenAI, which receives the catalog and the events in the merchant’s own ads account, under the merchant’s agreement with OpenAI. Data is never sold, shared for other commercial purposes or used by us to train artificial intelligence models.
6. Your rights
Store customers should first contact the store, which is the data controller. You may exercise your rights of access, rectification, erasure, restriction, portability and objection by writing to appsupport@lineagrafica.es or to the data protection officer at dpo@lbo-abogados.com. You may also lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) or your local supervisory authority.
7. Changes
If the processing changes, this page will be updated and the date at the top amended.