Privacy Policy

Last updated: 22 July 2026

Parable (“we”, “us”) helps Shopify merchants decide how much to spend on ads by projecting profit. This policy explains what we collect, why, and your choices. It is operated by GREGORY, LUKE AARON, an Australian sole trader based in Western Australia (ABN 66 890 208 665), who operates Parable.

What we collect

  • Account: when you sign in with Google, Parable collects your name, email address, stable Google account identifier, and profile image to create, identify, and display your Parable account. Sign-in requests only openid, email, and profile. Parable does not retain a Google refresh token for sign-in.
  • Shopify store data: orders, products, inventory, and aggregate sales metrics from stores you connect. Order records can include customer information returned by Shopify; we use it only to compute sales and attribution and never to contact customers.
  • Advertising & analytics data: spend and conversion figures from ad platforms you connect (e.g. Meta Ads, Google Ads) and channel revenue from analytics you connect (e.g. Google Analytics 4, Triple Whale).
  • Connection credentials: access/refresh tokens for the services you connect, stored encrypted.

How we use it

Solely to provide the product: computing your profit, ad-spend, and projection figures, and keeping your connected data in sync. We do not sell your data or use it for advertising.

Google API Services data

When you connect Google Ads, Parable uses the adwords scope to list the Google Ads accounts available to you. We read customer identifiers, account names, currencies, and manager-account relationships so you can select the account associated with your store. For the selected account, we read reporting date, campaign identifier, cost, conversions, conversion value, and all-conversions value. Campaign-level responses are processed during import. Parable retains account-level daily totals for cost, conversions, and all-conversions value, but does not retain campaign identifiers, campaign-level rows, campaign names, ads, creatives, audiences, or search terms.

When you connect Google Analytics 4, Parable uses the analytics.readonly scope to list property identifiers and names. For the selected property, we read Google Analytics’ aggregated daily report by default channel group: date, channel group, sessions, ecommerce purchases, and purchase revenue. Parable does not request individual users or event-level Analytics records.

Parable uses these API responses for account or property selection, synchronization, attribution context, profit calculations, and recommendations shown to the merchant. Authorized administrators may also use the restricted review tool described below to review aggregated, derived dashboard charts and figures for support, troubleshooting, and product improvement. Parable performs read, list, and reporting operations only. It does not create or modify campaigns, ads, budgets, Google Analytics properties, or Google Analytics settings. Stored reporting totals remain associated with the connected store; Parable does not create a separate anonymized Google dataset.

Parable and the hosting and database service providers that operate the service process raw Google API responses and stored Google identity, connection metadata, encrypted credentials, and reporting totals. We do not otherwise disclose Google user data except when required by law or when directed or consented to by the user. We do not sell Google user data, transfer it to advertisers or data brokers, or use it for advertising, retargeting, lending, or other unrelated purposes. We do not use Google user data to train generalized artificial-intelligence or machine-learning models, or transfer it to third-party model providers for training. Parable’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How we protect Google data

Google API requests use HTTPS. Short-lived Google access tokens are used only on Parable’s servers and are not retained. Google Ads and Google Analytics refresh tokens are encrypted with AES-256-GCM before database storage. Imported reporting data and other records are stored in managed database storage encrypted at rest. Stored Google data is associated with the connected Shopify store, and product access is restricted to the authenticated Parable account that owns that store or the Shopify-authenticated installation. Administrative dashboard review is available only through the restricted, read-only review tool described below.

Meta Ads data

When you connect Meta Ads, Parable requests the ads_read permission. It stores the identifier, name, and currency of the Meta ad accounts returned during connection so the user can select the account for their store. For the selected active account, Parable imports daily date, spend, impressions, clicks, reported purchase count, and reported purchase value. It also stores the encrypted OAuth token, expiry, configured permission scope, and connection status needed to keep the account connected. Parable does not request Meta profile fields in its API calls or retain a Facebook profile.

Parable uses that information to synchronise the merchant-selected account and combine its advertising history with the merchant’s Shopify sales data for dashboard figures, attribution context, profit calculations, and ad-spend recommendations. Parable does not create, edit, pause, publish, or change ads, campaigns, or budgets through Meta.

Meta API requests use HTTPS. Meta OAuth tokens are exchanged on Parable’s servers, are not returned to the browser, and are encrypted with AES-256-GCM before database storage. Vercel Inc. provides the hosted server-side runtime and Neon, LLC provides the managed PostgreSQL database. Parable’s production server functions are configured in Washington, D.C., United States, and its production Neon database is configured on Amazon Web Services in US East 1 (Northern Virginia), United States. Vercel’s edge network and authorised subprocessors may process data in other locations under Vercel’s data-processing terms.

Revoking Parable in Meta stops future Meta API access but does not itself delete information already imported into Parable. To delete stored Meta connection credentials, reporting, and derived dashboard data, follow the data deletion instructions.

Restricted dashboard review

Our team may use a restricted review tool to view aggregated dashboard charts and figures generated from connected data for support, troubleshooting, and improving user-facing features. The tool hides the store name, account, and connected-account details. Access is limited to authorized administrators, the view is read-only, and the start of each review session is logged. The review tool is not used to view individual customer records, and we stop these reviews if you ask us to.

Sharing

We share service data only with infrastructure providers that operate the service on our behalf, including Vercel Inc. for hosting and server-side runtime and Neon, LLC for the managed PostgreSQL database, and with platforms you explicitly connect when needed to retrieve your data. We do not sell your data. We disclose data if required by law.

Retention & deletion

Parable retains Google sign-in identity while the Parable account remains open. Google Ads, Google Analytics, and Meta account or property metadata, encrypted connection credentials, imported daily reporting totals, and derived dashboard data are retained while the connected store remains active. Revoking Parable through Google or Meta stops future API access but does not itself delete data already imported into Parable.

Removing a store inside Parable deletes that store’s connection credentials, Google account or property metadata, imported reporting totals, and derived dashboard data. If Parable is uninstalled from Shopify, Shopify normally sends a shop/redact request approximately 48 hours later, when Parable deletes that store-scoped data. To delete the separate Parable login account or request deletion at any time, contact support@parableppm.com or follow our data deletion instructions.

Limited security, operational, compliance, billing, or support records, such as webhook delivery receipts or audit events, may retain a store or connected-account identifier where necessary to protect the service, comply with legal or platform obligations, prevent abuse, or resolve a support or billing matter. These records are not used for advertising.

Your rights

Depending on your location, you may have rights to access, correct, or delete your data. We honour Shopify’s customer data request and redaction webhooks, and you can exercise your rights directly by contacting us at support@parableppm.com.

Contact

Questions or requests: support@parableppm.com.