Privacy Policy
Last updated 14 August 2026
The short version
Lemon is an analytics app for Shopify stores. It reads a merchant's order and cart data to work out which marketing channel produced each sale, and shows the result back to that merchant.
We never store IP addresses, we never track anyone across other websites, and we never sell data or use it to target advertising. Our access to Shopify and to connected ad platforms is read-only.
Two kinds of people this covers
Merchants are the people who create a Lemon account and connect a store. For their account data, Lemon Analytics is the data controller.
Shoppers are the customers of those stores. We only ever see shopper data because a merchant connected their store and asked us to analyse it. For that data the merchant is the controller and Lemon Analytics acts as a processor on their instructions.
What we collect, and why
Merchant account
Your name, email address, and either a hashed password or a Google account identifier if you sign in with Google. This is what lets you log in and keeps your store's data separate from every other account.
Store and order data from Shopify
Orders and their totals, currency, line items, refunds and dates; your product catalogue; and the email address and name attached to an order at checkout. This is the basis of every revenue figure the app reports.
Cart and checkout activity
Through Shopify's web pixel we record carts and checkouts as they happen: which items were added, the cart value, whether it was purchased or abandoned, and when it was last touched. Visits are grouped using the first-party identifier Shopify's pixel provides for that store. It does not follow anyone to another website.
Approximate location
City, region and country, so a merchant can see where demand comes from. This is derived from the network address of the request and, once a buyer supplies one at checkout, from their shipping address. The IP address itself is used only in the moment of that lookup and is never written to our database.
How a visit arrived
The referring site, landing page and UTM parameters that Shopify already records alongside a visit. Attributing a sale to a channel is the entire purpose of the product, and this is the data that makes it possible.
Connected ad accounts
If you connect Meta or Google Ads, we read campaign names and their daily spend, impressions, clicks and conversion totals, so spend can sit next to attributed revenue. These are aggregate campaign figures and contain no personal data about individuals. The permission we request is read-only; we cannot create, edit, pause or spend against your campaigns.
What we never do
- Store IP addresses.
- Track people across websites we do not operate.
- Sell, rent or share data with data brokers.
- Use shopper data to target advertising.
- Write to your store or your ad campaigns.
- Use one merchant's data to serve another.
Who else processes this data
We keep the number of subprocessors small. Application hosting is provided by Vercel, and the database is managed PostgreSQL hosted by Neon in the AWS US-West-2 region. Data reaches Shopify, Meta and Google only as requests we make to their APIs on your behalf.
We may disclose data if the law compels us to, and we will tell the affected merchant unless we are legally prohibited from doing so.
Where data is held and moved
Data is stored in the United States. If you or your shoppers are in the European Economic Area or the United Kingdom, that means data is transferred out of your region; those transfers rely on the European Commission's Standard Contractual Clauses with our subprocessors.
How long we keep it
Shopper details: 13 months. Buyer email addresses, names, and city and region are erased automatically 13 months after the order or cart they came from. That is the longest period the app reports on, so nothing a merchant can look at goes missing, and past it those details serve no purpose. The erasure is a scheduled job that runs daily; nobody has to ask for it.
Order totals and counts: while the store is connected. Amounts, dates, channels and product names are not personal data, and historical orders are what year-over-year comparisons are made of, so these stay. Country is kept too — it cannot identify a shopper and the reports break sales down by it.
Everything, on disconnect. Disconnect a store from Settings, or uninstall the app, and the whole of that store's data is deleted. Uninstalling stops all processing at once and revokes our access; Shopify then sends us a shop erasure request, which we act on automatically. If the store was the only one on an account created by an install, the account goes too.
A record that we answered a customer data request is kept for 90 days afterwards, then deleted, because it holds the requester's email. Erasure requests forwarded by Shopify are handled as described below whether or not the store is still connected.
Rights, and how to use them
Shoppers: please contact the store you bought from. Because the merchant is the controller of your data, requests properly begin with them. Lemon implements Shopify's mandatory privacy webhooks, so when a store forwards a request to access or erase your data, we act on it automatically and return everything we hold about you, or delete it.
Merchants: you can reach your data in the app at any time, and Settings has a Disconnect button on each store that deletes everything we hold for it. Uninstalling the app from your Shopify admin does the same. Depending on where you live you may also have rights to access, correct, export, restrict or object to our processing — write to us and we will action it.
Depending on your jurisdiction you may also have the right to complain to a data protection authority.
Security
Connections are encrypted in transit and the database is encrypted at rest. Passwords are stored only as hashes. Access tokens for Shopify and the ad platforms are encrypted a second time by the application before they are written, so a leaked database would not yield a usable credential for any store, and they are held for the sole purpose of making the read-only API calls described above. Every query is scoped to the account that owns the store. No system is perfectly secure, but we would rather hold less data than defend more — which is why there are no IP addresses or payment details here at all.
Children
Lemon is a tool for businesses and is not directed at children. We do not knowingly collect data from anyone under 16.
Changes
If we change this policy we will update the date at the top, and for anything material we will tell connected merchants directly rather than relying on you to notice.
Contact
Questions, requests or complaints about privacy go to wristworld11@gmail.com.
