Privacy Policy
Last updated: 16 September 2026
Parable (“we”, “us”) helps Shopify merchants decide how much to spend on ads by projecting profit. This policy explains what we collect, why, and your choices. It is operated by GREGORY, LUKE AARON, an Australian sole trader based in Western Australia (ABN 66 890 208 665), who operates Parable.
What we collect
- Account: when you sign in with Google, Parable collects your name, email address, stable Google account identifier, and profile image to create, identify, and display your Parable account. Sign-in requests only
openid,email, andprofile. Parable does not retain a Google refresh token for sign-in. - Shopify store data: orders, products, inventory, and aggregate sales metrics from stores you connect. Order records can include customer information returned by Shopify; we use it only to compute sales and attribution and never to contact customers.
- Advertising & analytics data: spend and conversion figures from ad platforms you connect (e.g. Meta Ads, Google Ads) and channel revenue from analytics you connect (e.g. Google Analytics 4).
- Connection credentials: access/refresh tokens for the services you connect, stored encrypted.
- Feedback: when you send an issue or feature suggestion, we receive your message, its category, your account email and identifier, and the page path without query strings or store identifiers. We do not automatically attach screenshots, logs, or connected store data.
How we use it
We use connected store and platform data to compute your profit, ad-spend, and projection figures and keep your connected data in sync. We do not sell your data or send connected store records to advertisers. Optional website measurement and subscription outcome reporting are described under Website privacy choices below.
We use feedback you send to investigate issues, improve Parable, and reply to you. Feedback is delivered to our support inbox.
Google API Services data
When you connect Google Ads, Parable uses the adwords scope to list the Google Ads accounts available to you. We read customer identifiers, account names, currencies, and manager-account relationships so you can select the account associated with your store. For the selected account, we read reporting date, campaign identifier, cost, conversions, conversion value, and all-conversions value. Campaign-level responses are processed during import. Parable retains account-level daily totals for cost, conversions, and all-conversions value, but does not retain campaign identifiers, campaign-level rows, campaign names, ads, creatives, audiences, or search terms.
When you connect Google Analytics 4, Parable uses the analytics.readonly scope to list property identifiers and names. For the selected property, we read Google Analytics’ aggregated daily report by default channel group: date, channel group, sessions, ecommerce purchases, and purchase revenue. Parable does not request individual users or event-level Analytics records.
Parable uses these API responses for account or property selection, synchronization, attribution context, profit calculations, and recommendations shown to the merchant. Authorized administrators may also use the restricted review tool described below to review aggregated, derived dashboard charts and figures for support, troubleshooting, and product improvement. Parable performs read, list, and reporting operations only. It does not create or modify campaigns, ads, budgets, Google Analytics properties, or Google Analytics settings. Stored reporting totals remain associated with the connected store; Parable does not create a separate anonymized Google dataset.
Parable and the hosting and database service providers that operate the service process raw Google API responses and stored Google identity, connection metadata, encrypted credentials, and reporting totals. We do not otherwise disclose Google user data except when required by law or when directed or consented to by the user. We do not sell Google user data, transfer it to advertisers or data brokers, or use it for advertising, retargeting, lending, or other unrelated purposes. We do not use Google user data to train generalized artificial-intelligence or machine-learning models, or transfer it to third-party model providers for training. Parable’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How we protect Google data
Google API requests use HTTPS. Short-lived Google access tokens are used only on Parable’s servers and are not retained. Google Ads and Google Analytics refresh tokens are encrypted with AES-256-GCM before database storage. Imported reporting data and other records are stored in managed database storage encrypted at rest. Stored Google data is associated with the connected Shopify store, and product access is restricted to the authenticated Parable account that owns that store or the Shopify-authenticated installation. Administrative dashboard review is available only through the restricted, read-only review tool described below.
Meta Ads data
When you connect Meta Ads, Parable requests the ads_read permission. It stores the identifier, name, and currency of the Meta ad accounts returned during connection so the user can select the account for their store. For the selected active account, Parable imports daily date, spend, impressions, clicks, reported purchase count, and reported purchase value. It also stores the encrypted OAuth token, expiry, configured permission scope, and connection status needed to keep the account connected. Parable does not request Meta profile fields in its API calls or retain a Facebook profile.
Parable uses that information to synchronise the merchant-selected account and combine its advertising history with the merchant’s Shopify sales data for dashboard figures, attribution context, profit calculations, and ad-spend recommendations. Parable does not create, edit, pause, publish, or change ads, campaigns, or budgets through Meta.
Meta API requests use HTTPS. Meta OAuth tokens are exchanged on Parable’s servers, are not returned to the browser, and are encrypted with AES-256-GCM before database storage. Vercel Inc. provides the hosted server-side runtime and Neon, LLC provides the managed PostgreSQL database. Parable’s production server functions are configured in Washington, D.C., United States, and its production Neon database is configured on Amazon Web Services in US East 1 (Northern Virginia), United States. Vercel’s edge network and authorised subprocessors may process data in other locations under Vercel’s data-processing terms.
Revoking Parable in Meta stops future Meta API access but does not itself delete information already imported into Parable. To delete stored Meta connection credentials, reporting, and derived dashboard data, follow the data deletion instructions.
Restricted dashboard review
Our team may use a restricted review tool to view aggregated dashboard charts and figures generated from connected data for support, troubleshooting, and improving user-facing features. The tool hides the store name, account, and connected-account details. Access is limited to authorized administrators, the view is read-only, and the start of each review session is logged. The review tool is not used to view individual customer records, and we stop these reviews if you ask us to.
Sharing
We share service data only with providers that operate the service on our behalf, and only what each needs: Vercel Inc. for hosting, the server-side runtime and, with your permission, cookieless page-view analytics. Google provides website analytics with cookies when you allow analytics, and receives the App Store listing and installation reports described below when enabled. Neon, LLC provides the managed PostgreSQL database. Resend, Inc. delivers the weekly report and account emails, including feedback to our support inbox. It receives the email addresses and message contents needed for delivery. We use Stripe, Inc. for payment processing where a subscription is not billed through Shopify, which receives billing details and never your store data. Platforms you explicitly connect receive only what is needed to retrieve your data. We do not sell your data. We disclose data if required by law.
Website privacy choices
Website analytics is optional and stays off until you choose Allow analytics. Google Analytics uses cookies to measure visits. Vercel measures page views without analytics cookies. Both are limited to public pages and exclude account, dashboard, admin, report and connection pages. Public page visits can be counted whether or not you are signed in. We remove arbitrary query strings and fragments from page addresses. If you also allow Advertising, bounded ad click identifiers may remain so Google can identify the original ad visit. Google receives a fixed public page title and no referring URL. We do not send account details or connected store data. We do not enable advertising personalization or automatic form tracking. Change or withdraw your choice at any time using Privacy preferences in the footer. Rejecting analytics stops collection and clears our Google Analytics cookies in this browser. We store your preference in this browser so we can respect it on later visits. This choice does not affect the separate Google Analytics account you may connect to use Parable.
Advertising is a separate optional choice. When available, Meta Pixel and Google Ads use cookies and browser storage to measure visits to public pages and clicks to Parable’s Shopify listing, only after you enable Advertising and save your preferences. Allowing analytics never allows advertising. If advertising is unavailable, preferences show it as Not active. We do not send contact details, connected store sales, customer records or form entries to these services. Google advertising personalization and enhanced conversions are disabled. Browser advertising measurement is limited to signed-out public pages. With your permission, Google and Meta can use their ad click identifiers and numeric campaign identifiers to connect an ad visit with a later listing click. The demo’s fixed example-store and walkthrough choices may remain in page addresses. Campaign labels are removed, and unknown query values, fragments and potentially private referring addresses are excluded. Browser advertising tags report listing clicks. If you allow both Analytics and Advertising, we also keep a signed browser identifier for up to 60 days and associate it with a verified new installation. Our server can report the completed installation, a setup with usable store and advertising data, and your first confirmed Parable subscription payment to Google Analytics and our linked Google Ads account. Payment reporting includes the amount excluding tax, currency and an opaque transaction identifier. Free plans, test stores and subscription approvals are not reported as payments. Withdrawing either choice stops future server outcome reports and removes the stored association. Reports already received by Google are subject to Google’s retention controls. Withdrawing Advertising removes the running advertising tags by reloading the page and clears the Meta and Google advertising cookies and click storage set by this website in your browser. Your analytics choice stays separate.
Shopify App Store reporting
When enabled for our App Store listing, Shopify sends listing activity and completed installation events to Parable’s Google Analytics property. Installation events include our app identifier and your shop’s identifier, name and website address. We use these reports to understand how merchants find and install Parable. An installation is not recorded as a paid purchase. These reports do not include the orders, customer records or advertising performance that you connect to use Parable.
Shopify sends these events from its App Store and installation process. They are separate from the tracking on Parable’s website and from the Google Analytics property you may connect for your store. The website privacy controls above apply to tracking on this website.
Retention & deletion
Parable retains Google sign-in identity while the Parable account remains open. Google Ads, Google Analytics, and Meta account or property metadata, encrypted connection credentials, imported daily reporting totals, and derived dashboard data are retained while the connected store remains active. Revoking Parable through Google or Meta stops future API access but does not itself delete data already imported into Parable.
Removing a store inside Parable deletes that store’s connection credentials, Google account or property metadata, imported reporting totals, and derived dashboard data. If Parable is uninstalled from Shopify, Shopify normally sends a shop/redact request approximately 48 hours later, when Parable deletes that store-scoped data. To delete the separate Parable login account or request deletion at any time, contact support@parablepm.com or follow our data deletion instructions.
Limited security, operational, compliance, billing, or support records, such as webhook delivery receipts or audit events, may retain a store or connected-account identifier where necessary to protect the service, comply with legal or platform obligations, prevent abuse, or resolve a support or billing matter. These records are not used for advertising.
Your rights
Depending on your location, you may have rights to access, correct, or delete your data. We honour Shopify’s customer data request and redaction webhooks, and you can exercise your rights directly by contacting us at support@parablepm.com.
Contact
Questions or requests: support@parablepm.com.

