ProfitStar

Privacy policy · Last updated 13 August 2026

What ProfitStar stores

ProfitStar is a bookkeeping tool for Shopify merchants. It reads financial totals from a store and advertising spend from ad accounts the merchant connects, and shows that merchant their own profit. This page describes exactly what that involves.

Who we are

ProfitStar is operated by Paperwallet. For any question about this policy or to request deletion of your data, write to rbisaidev@gmail.com.

We do not collect data about your customers

This is the most important thing on the page, so it comes first. ProfitStar does not read, receive, or store customer names, email addresses, phone numbers, shipping or billing addresses, or customer IDs. No customer record is requested from Shopify at any point.

Order data is read as financial totals: what an order was worth, what was refunded, how many units moved. Under Shopify’s classification this places the app at protected customer data Level 1, and it is enforced in our codebase by an automated test that fails the build if a customer-identity field is ever introduced.

What we store about your store

  • Your shop: its myshopify.com domain, display name, currency, timezone, install date, and current plan.
  • Orders: Shopify order ID and name, the date placed, whether it was cancelled or was a test order, subtotal, discounts, shipping collected, tax, total units, and a snapshot of cost of goods.
  • Refunds: Shopify refund ID, the date refunded, the amount of product returned, and refunded shipping.
  • Product costs: variant and product IDs, product type, and cost per item as recorded in your Shopify inventory.
  • Advertising spend: daily spend, impressions, clicks and conversions from ad accounts you choose to connect.
  • Your settings: the cost assumptions you enter, any manual costs you record, and manually entered ad spend.
  • Connection credentials: access tokens for Shopify and for any ad platform you connect, along with which ad account you selected.

Why we store it

Solely to calculate and display your own profit and loss (revenue, advertising spend, cost of goods, shipping, fees, margin and marketing efficiency) inside your Shopify admin, to you. Your data is never used to build products for anyone else, never aggregated with other merchants’ data, and never sold, rented or shared for marketing.

Who else sees it

ProfitStar uses a small number of infrastructure providers, each of which processes data only to run the service:

  • Vercel: application hosting.
  • Neon: the database where the data above is stored.
  • Shopify: the source of your order and product data.
  • Meta and Google: the source of advertising spend, for accounts you connect. We only ever read spend and performance figures from these accounts; we never create, change, pause or manage advertising.

How it is protected

  • All traffic travels over HTTPS, and the database connection is encrypted.
  • Access tokens for Shopify, Meta and Google are individually encrypted at rest with AES-256-GCM. They are never written to logs and never sent to a browser.
  • Every request from the app to our servers is authenticated with a short-lived Shopify session token, and all data is scoped to the single shop that request belongs to.

How long we keep it

For as long as the app is installed. When you uninstall, your access tokens are erased immediately and syncing stops. Shopify then sends a shop-redaction request 48 hours later, at which point all data belonging to your shop is permanently deleted. You can also ask us to delete it sooner at the address above.

Your choices

  • Disconnect any ad platform at any time from the app’s settings; its stored credentials are deleted.
  • Uninstall the app at any time from your Shopify admin, which begins the deletion described above.
  • Request a copy of, or the deletion of, your data by writing to us.

Changes

If what the app stores changes, this page changes with it, and the date at the top is updated.