Privacy policy

Last updated: 2026-09-15

This policy explains what personal data Firstview("the platform") processes, why, and what your rights are. The platform is operated by Firstview, Lda., Lisboa, Portugal, Portugal ("we"), the data controller. Contact for privacy matters: support@firstview.io.

1. Who uses the platform

The platform is a financial tool for Shopify stores. Accounts are created by invitation: for customers, and for the students, coaches and staff of the 7Figure Blueprint e-commerce mentoring programme, who use it free of charge with coaching features on top. There is no public sign-up.

2. Data we process

CategoryExamplesSource
Account dataName, email, password hash, role (student, coach, admin), Discord handleYou, or whoever invited you
Store dataStore name, currency, supplier, daily sales, refunds, costs of goods, ad spend, fees, notesEntered by you, or read from Shopify
Shopify dataOrders and refunds (amounts, dates, currency, shipping country, products), products, Shopify Payments disputes and, when you build a defence, the order's customer details (name, email, addresses, IP, fulfilment and tracking)Read from the Shopify Admin API with your custom app token
Advertising dataAd accounts, campaigns and daily metrics (spend, clicks, CPC, add-to-carts, purchases, attributed revenue)Read from Meta Ads and Google Ads with your authorisation
Payment disputesDisputes and chargebacks (status, reason, amount, deadlines, linked order) from Shopify Payments, Stripe and PayPal; the evidence you attachRead from the processors' APIs with your credentials; files uploaded by you
Programme data (7Figure Blueprint students only)Coaching calls and reports, creative reviews, launch sheets, resources, onboarding, notificationsYou and your coach
Technical dataServer logs (IP address, user agent, timestamps) for security and troubleshootingAutomatically, on use

3. Why we process it and on what basis

  • To provide the service — computing your Profit Sheet, Daily ROAS, refund and dispute analytics, and, for programme students, letting your coach follow them (performance of the agreement between you and us).
  • Integrations — reading data from Shopify, Meta, Google, PayPal and Stripe only after you connect the account, and only the scopes listed on our integrations table (your consent, which you can withdraw by disconnecting).
  • Dispute defence — assembling the evidence package and, on your explicit confirmation, submitting it to the processor (performance of the agreement; legitimate interest in defending the store against chargebacks).
  • Security and legal — protecting accounts, preventing abuse, keeping records we are required to keep (legitimate interest; legal obligation).

4. Google API Services

Firstview's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google Ads data is used only to display and compute your own advertising metrics on the platform; it is never used for advertising, never sold, and never read by humans except with your consent, for security, or as required by law.

5. Meta Platform data

Data received through Meta's Marketing API (ad accounts, campaigns and insights) is used solely to display your own advertising performance on the platform. We do not use it to build profiles, to advertise, or to share with third parties. You can revoke access at any time in your Meta Business settings or by disconnecting the integration on the platform; see the data deletion page below.

6. Who we share data with

  • For programme students: your coach and the programme staff, who see the accounts in their portfolio. A customer outside the programme has no coach, and nobody else sees their account.
  • Service providers that host and run the platform under contract: Supabase (database, authentication, file storage), Vercel (hosting), Resend (transactional email). They process data on our instructions only.
  • The processors you connect (Shopify, Meta, Google, PayPal, Stripe) receive only what you explicitly submit (for example, dispute evidence).
  • Authorities, when required by law.

We do not sell personal data and we do not share it with advertisers or data brokers.

7. Retention

Account and store data are kept while the account is active and for up to 30 days after a deletion request. Integration credentials are deleted immediately when you disconnect. Server logs are kept for 30 days. Records we must keep by law (for example, billing) are kept for the legally required period.

8. Security

Integration credentials are encrypted at rest with a key held only by the server. Access to data is enforced in the database, row by row, so that each account can only read its own stores. Traffic is encrypted in transit. Access by staff is limited to what their role needs.

9. Your rights

Under the GDPR you can ask for access, rectification, erasure, restriction, portability, and object to processing. To exercise them, write to support@firstview.io. You can also complain to your supervisory authority; in Portugal, the CNPD (cnpd.pt). To delete your data, follow the data deletion instructions.

10. International transfers

Our providers may process data outside the European Economic Area. Where they do, transfers rely on the European Commission's standard contractual clauses or an adequacy decision.

11. Changes

We will post any change to this policy on this page and update the date above. Material changes are announced inside the platform.