Now connecting Shopify, Meta Ads, Google Ads, PayPal and StripeRequest early access

Privacy policy

Last updated: 2026-09-15

This policy explains what personal data Firstview ("the platform") processes, why, and what your rights are. The platform is operated by LOGOS ECOM LLC, 175 SW 7th Street, STE 1517-1000, Ste R, Miami, FL 33130, United States ("we"), the data controller for your account data. Contact for privacy matters: support@firstview.io.

1. Who uses the platform

The platform is a financial tool for Shopify stores. Accounts are created by invitation; there is no public sign-up. Some accounts belong to a coaching programme run with a partner: those accounts have a coach who follows their stores inside the platform and use additional coaching features. An account outside a programme has no coach, and nobody other than the account holder and the people they invite sees its data.

2. Data we process

CategoryExamplesSource
Account dataName, email, password hash, role (store owner, coach, admin), optional Discord handleYou, or whoever invited you
Store dataStore name, currency, supplier, daily sales, refunds, costs of goods, ad spend, fees, notesEntered by you, or read from Shopify
Shopify dataOrders and refunds (amounts, dates, currency, shipping country, products), products, Shopify Payments disputes and, only when you build a dispute defence, the disputed order's customer details (name, email, addresses, IP, fulfilment and tracking)Read from the Shopify Admin API with the custom app token you create
Advertising dataAd accounts (name, ID, currency), campaigns and daily metrics (spend, clicks, CPC, add-to-carts, purchases, attributed revenue); the email of the Google or Meta login you authoriseRead from Meta Ads and Google Ads after you authorise access
Payment disputesDisputes and chargebacks (status, reason, amount, deadlines, linked order) from Shopify Payments, Stripe and PayPal; the evidence you attachRead from the processors' APIs with the credentials you provide; files uploaded by you
Coaching data (programme accounts only)Coaching calls and reports, creative reviews, launch sheets, resources, onboarding, notifications; for coaches, the Google account email and the calendar events the platform createsYou and your coach; Google Calendar, if the coach connects it
Technical dataServer logs (IP address, user agent, timestamps) for security and troubleshootingAutomatically, on use

3. Why we process it and on what basis

  • To provide the service — computing your Profit Sheet, Daily ROAS, refund and dispute analytics, and, for programme accounts, letting your coach follow them (performance of the agreement between you and us).
  • Integrations — reading data from Shopify, Meta, Google, PayPal and Stripe only after you connect the account, and only with the permissions listed in section 4 (your consent, which you withdraw by disconnecting).
  • Dispute defence — assembling the evidence package and, on your explicit confirmation, submitting it to the processor (performance of the agreement; legitimate interest in defending the store against chargebacks).
  • Security and legal — protecting accounts, preventing abuse, keeping records we are required to keep (legitimate interest; legal obligation).

4. Integrations and the exact permissions we request

Every integration is connected by you, with your own credentials, one store at a time. We request the minimum permissions needed to read the numbers, and we never create, edit or pause anything in your accounts. The only write we ever perform is submitting dispute evidence, and only after you review it and click submit.

  • Shopify — a custom app you create in your store admin, with these access scopes: read_orders, read_all_orders, read_customers, read_products, read_inventory, read_shopify_payments_payouts, read_shopify_payments_disputes, read_reports, read_shopify_payments_dispute_evidences, write_shopify_payments_dispute_evidences, write_shopify_payments_dispute_file_uploads, write_products, write_orders, write_discounts, read_merchant_managed_fulfillment_orders, read_third_party_fulfillment_orders, read_store_credit_accounts, write_store_credit_account_transactions. Read scopes bring in orders, refunds, products, inventory, payouts and Shopify Payments disputes; the two write scopes exist only to submit the evidence of a dispute you confirmed.
  • Meta Ads — authorised through Facebook Login for Business with the ads_read permission, to read the ad accounts you choose, their campaigns and daily insights. No ads_management: we cannot change your ads.
  • Google Ads — authorised through Google OAuth with the https://www.googleapis.com/auth/adwords scope, used in read-only mode to list the ad accounts you have access to and to read their daily cost, click and conversion metrics. We also request openid and email to show which Google account is connected.
  • Google Calendar (coaches only) — coaches may connect their Google account with https://www.googleapis.com/auth/calendar.events and https://www.googleapis.com/auth/calendar.events.freebusy, so the platform can create, update and delete the calendar events of the coaching calls it schedules and check whether a time slot is free. We do not read the content of other events.
  • PayPal — API credentials you create in your PayPal developer dashboard, used to read disputes (status, deadlines, reason, amount, linked order) and, only on your explicit confirmation, to send messages and evidence in a dispute.
  • Stripe — a restricted API key you create in your Stripe dashboard with read access to disputes and charges. Nothing is ever written to Stripe.

5. Google API Services

Firstview's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google Ads data is used only to display and compute your own advertising metrics on the platform, and Google Calendar data only to manage the events of the calls the platform schedules. Google user data is never used for advertising, never sold, never used to train models, and never read by humans except with your consent, for security, or as required by law.

6. Meta Platform data

Data received through Meta's Marketing API (ad accounts, campaigns and insights) is used solely to display your own advertising performance on the platform. We do not use it to build profiles, to advertise, to train models, or to share with third parties. We keep it only while your account and the connection exist. You can revoke access at any time in your Meta Business settings or by disconnecting the integration on the platform; when Meta notifies us of a removal, we delete the stored credential and the imported metrics within 30 days. See the data deletion page.

7. Your customers' data (Shopify)

Information about the customers of your store (their name, email, addresses, IP address, fulfilment and tracking details) is only read when you build a dispute defence, and only for the disputed order. We process it on your behalf and on your instructions, as your processor, for the sole purpose of assembling and submitting the evidence you confirm. It is not used for any other purpose, not combined across stores, and is deleted together with the dispute, the store or the account. Our daily sales figures use order amounts, dates, currency, shipping country and products, never customer identities.

8. Who we share data with

  • For programme accounts: your coach and the programme staff, who see the accounts in their portfolio. An account outside a programme has no coach, and nobody else sees it.
  • Service providers that host and run the platform under contract: Supabase (database, authentication, file storage), Vercel (hosting), Resend (transactional email). They process data on our instructions only.
  • The services you connect (Shopify, Meta, Google, PayPal, Stripe) receive only what you explicitly submit (for example, dispute evidence).
  • Authorities, when required by law.

We do not sell personal data, we do not share it with advertisers or data brokers, and we do not use it to train artificial intelligence models.

9. Retention

Account and store data are kept while the account is active and for up to 30 days after a deletion request. Integration credentials are deleted immediately when you disconnect. Data imported from an integration stays with the store until the store or the account is deleted. Server logs are kept for 30 days. Records we must keep by law (for example, billing) are kept for the legally required period.

10. Security

Integration credentials are encrypted at rest with a key held only by the server and are never sent to the browser. Access to data is enforced in the database, row by row, so that each account can only read its own stores. Traffic is encrypted in transit. Access by staff is limited to what their role needs and is logged.

11. Cookies

The platform uses only strictly necessary cookies: the session cookies that keep you signed in, and a preference for the light or dark theme. We do not use advertising or third-party analytics cookies, and we do not track you across other sites.

12. Your rights

You can ask for access to your data, correction, deletion, restriction, portability, and object to processing; you can also withdraw consent for an integration at any time by disconnecting it. If you are in the European Economic Area or the United Kingdom, these rights are granted by the GDPR and you may complain to your local supervisory authority. If you are a resident of California or another US state with a privacy law, you have the right to know, delete and correct your data and to not be discriminated against for exercising those rights; we do not sell or share personal data as those laws define it. To exercise any right, write to support@firstview.io. To delete your data, follow the data deletion instructions.

13. Children

The platform is a business tool for adults. We do not knowingly collect data from anyone under 18; if we learn we have, we delete it.

14. International transfers

We are established in the United States, and our providers may process data in the United States and in the European Economic Area. Where data of EEA or UK residents is transferred outside those areas, the transfer relies on the European Commission's standard contractual clauses, the UK addendum, or an adequacy decision.

15. Changes

We will post any change to this policy on this page and update the date above. Material changes are announced inside the platform.