Privacy Policy
Last updated: 30 August 2026 · Versión en español
EmilIA by Milimetrix ("EmilIA", "we") is an e-commerce analytics platform. It connects to the services a merchant already uses — including Shopify — reads the metrics those services expose, and presents them back as reporting. This policy describes exactly what we read, why, how long we keep it, and how to have it removed.
Our role
For data that belongs to a merchant's store, the merchant is the data controller and EmilIA is a processor: we process that data only to provide the reporting the merchant asked for, and only on their instructions. For the account you use to sign in to EmilIA itself, we are the controller.
What we read from a Shopify store
Only what the reporting needs. Concretely, and exhaustively:
- Orders: order id and number, dates, financial and fulfilment status, totals (subtotal, shipping, tax, discounts, refunds), currency, and the marketing attribution parameters (UTM) Shopify records for the visit.
- Order line items: product and variant identifiers, SKU, title, quantity, prices, product type, vendor and tags.
- Product catalogue: title, type, price and — only if the merchant separately grants the optional
read_inventorypermission — stock levels. - Store profile: store name, time zone and currency. The time zone is what every daily boundary in the reporting is computed in.
What we do NOT read
This is the part worth being precise about, because it is what keeps the app outside Shopify's protected customer fields:
- No customer names, email addresses, phone numbers or postal addresses. Our order query does not request the customer object at all, so those fields never reach our systems — not in plain text, not hashed, not in logs.
- No payment details. We never see card numbers or any payment instrument.
- No storefront visitor tracking. EmilIA installs no script on the storefront and sets no cookies on it.
We ask Shopify for read_orders, read_all_orders and read_products. read_all_orders is what allows reporting on more than the last 60 days of history, which is the point of a trend. read_inventory is optional and requested only when the merchant chooses to see stock.
What we do with it
We aggregate it into reporting: revenue, order counts, average order value, trends over time, and product performance. We also generate written summaries of those figures using Google's Gemini API — the summaries are built from aggregated totals only (for example "revenue this week vs last"); individual orders are never sent to any AI service.
We do not sell this data, we do not share it with advertisers, and we do not use one merchant's data to serve another. We do not make automated decisions that produce legal or similarly significant effects for anyone.
How long we keep it
While the app is installed, order history is retained for as long as the merchant keeps using EmilIA. That is inherent to the product: a year-over-year comparison cannot exist without last year's data, and deleting it on a fixed schedule would silently break the reporting the merchant installed the app for.
Deletion happens on these events, not on a timer:
- On uninstall: we immediately destroy the access tokens for the store and stop all synchronisation. No further data is read.
- On Shopify's
shop/redactrequest — which Shopify sends 48 hours after an uninstall — we delete the store's order and line-item data permanently. - On direct request: a merchant can ask us to delete their data at any time, installed or not. See data deletion.
Where it goes
EmilIA runs on infrastructure operated by these providers, which process data on our behalf under their own agreements:
- Vercel — application hosting and delivery.
- Supabase — the PostgreSQL database where the reporting data is stored.
- Upstash — ephemeral cache and rate limiting.
- Inngest — scheduling of the background jobs that fetch data.
- Google (Gemini API) — narrative summaries, from aggregated figures only.
Shopify order data is not exported to any data warehouse or analytics product of ours beyond the database above.
How it is protected
- All traffic is encrypted in transit over TLS, and data is encrypted at rest by our database provider.
- The access tokens that let us read a store are encrypted with AES-256-GCM before being written, with keys held outside the database.
- Every request from the embedded app is authenticated with a signed Shopify session token, and every query is scoped to the store that token names — never to a store named by the request.
Cookies on this website
This site sets no advertising or tracking cookies. Loaded logged out — which is how this page is normally read — it sets no cookies at all. The only cookie ever stored is the session cookie that keeps you signed in to EmilIA, and it only exists once you sign in.
- Performance measurement (page load and responsiveness) runs on every visit. It records timings and the route, carries no identifier for you, and uses no cookies.
- Usage analytics — anonymous and also cookieless — load only if you accept them in the banner. Choosing "Essential only" means the analytics script is never loaded, not merely that it is asked not to record.
Your choice is stored in your own browser and you can change it at any time by clearing this site's data, which brings the banner back.
Rights and choices
Merchants can ask us at any time to tell them what data we hold for their store, to correct it, to export it, or to delete it. Where a store's customer exercises a right against the merchant, the merchant can relay it to us and we will act on it — Shopify also forwards such requests to us automatically through its compliance webhooks, and we respond to those.
Because we hold no customer names, emails, phone numbers or addresses, a request about an individual shopper is answered from the merchant's own Shopify data rather than ours; we can confirm what order-level records exist and delete them.
Agreements with merchants
The terms above — processing only on the merchant's instructions, only for the stated purposes, with the deletion routes described here — are the terms on which we process a store's data, and they apply whether or not anything further is signed. A merchant who needs a separate written data processing agreement, or whose own compliance programme requires one on their paper, can request it at privacy@milimetrix.com.
Contact
Write to privacy@milimetrix.com. We aim to acknowledge privacy requests within 5 business days and to complete them within 30 days.
Changes
If we change what we process or why, we update this page and the date at the top before the change takes effect. The Spanish version is updated in the same commit.