Back to Home

Pixelcore Privacy Policy

Last updated: August 19, 2026

Pixelcore is a Shopify app that reports ChatGPT Ads conversions using the OpenAI measurement pixel and the server-side Conversions API. This policy explains precisely what the app handles, what it stores, and for how long.

1. What this policy covers

Pixelcore is a Shopify app that reports conversion events from a merchant's store to OpenAI Ads. This policy describes exactly what the app handles, what it stores, and for how long. It sits alongside the general Neural Matrix privacy policy and takes precedence for anything specific to Pixelcore.

2. What the app processes

When a merchant installs Pixelcore, the app receives Shopify customer events (page views, product views, cart actions, checkouts, purchases) and, where enabled, order data from the orders/create webhook. From these it builds conversion events for the OpenAI Ads Conversions API.

The following shopper data passes through the app in memory: email address and Shopify customer ID (used for advertising attribution, transmitted only as SHA-256 hashes); country, city and ZIP from the checkout address; IP address and user agent; the ad click reference (oppref) and OpenAI browser reference (obref); and product IDs, quantities, order value and currency.

Raw email addresses and customer IDs are never transmitted and never stored. They are hashed with SHA-256 in memory during the request that produces the event. Customer ID hashes are salted with the shop domain, so the same shopper on two different stores never produces the same hash.

Pixelcore does not collect shopper names, phone numbers, street addresses, payment details, or browsing behaviour outside the merchant's own store.

3. What the app stores

Shop configuration: the merchant's OpenAI Pixel ID, their Conversions API key (encrypted at rest with AES-256-GCM), and their tracking preferences.

Event metadata: for each delivered event, the event name, timestamp, order value, the response OpenAI returned, and boolean flags recording which matching signals were present. Irreversible SHA-256 hashes may be retained so a failed event can be retried.

IP addresses and user agents are stripped before an event record is written. They are forwarded to OpenAI and then discarded.

Event metadata is deleted after 30 days.

4. Who we share data with

Conversion events are sent to OpenAI (bzr.openai.com) under the merchant's own OpenAI Ads account, using credentials the merchant supplies. OpenAI's handling of that data is governed by OpenAI's own terms with the advertiser.

We do not sell data, and we do not share it with any other third party. We do not combine data across merchants.

5. Consent

The app's web pixel declares the analytics, marketing and sale_of_data consent purposes to Shopify. Where a shopper declines these in the store's cookie banner, or opts out of data sale or sharing, Shopify blocks the pixel automatically and no event is produced.

6. Merchant and shopper rights

Shopper data requests: Pixelcore stores no personally identifiable shopper data, so there is nothing personally identifiable to return. We respond to Shopify's customers/data_request webhook accordingly.

Shopper deletion: on Shopify's customers/redact webhook we delete all records associated with that shopper's orders.

Shop deletion: on shop/redact, 48 hours after uninstall, we erase the shop's configuration, credentials, event history and attribution records.

Merchants can also pause tracking, disable customer-data sharing entirely, or turn off individual events at any time from the app's Settings page.

7. Security

Data is encrypted in transit with TLS 1.2 or higher. Conversions API keys are encrypted at rest with AES-256-GCM and are never displayed again after entry. Access to production systems is limited to the operators who need it, protected by multi-factor authentication. We do not use real shopper data in development or testing.

If we become aware of a breach affecting merchant or shopper data, we notify affected merchants without undue delay and within any legally required period.

8. Children

The app is not directed at children and does not knowingly process data from anyone under 16.

9. International transfers

Our servers are located in the United States. Merchants outside the United States should account for this when assessing their own obligations.

10. Changes

Material changes to this policy will be reflected in the last updated date above and communicated to merchants in the app.

11. Contact

For any privacy question or request, contact [email protected]. We respond within 5 business days. Neural Matrix is based in Texas, United States.