Privacy Policy
Last updated: July 14, 2026
Google API Limited Use Compliance
runNorth's use of information received from Google APIs, including Google Analytics 4, adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used exclusively to display your own analytics data within your runNorth dashboard and is never used to develop, improve, or train AI or machine-learning models, nor transferred to third parties for any such purpose.
1. Who we are
runNorth is an analytics and advertising optimisation dashboard for e-commerce founders, operated by Tamir Levy ("we", "our", "us"). runNorth connects to your Meta Ads account, Shopify store, and Google Analytics 4 property to display performance data in a single dashboard.
Contact: 7tamir@gmail.com
2. What data we access
runNorth accesses the following data on your behalf when you connect each integration:
- Meta Ads: Campaign spend, impressions, clicks, conversions, reach, frequency, creative thumbnails, audience targeting, and ad account structure. We use the Meta Marketing API with your explicit OAuth authorisation.
- Shopify: Order revenue, refunds, customer email addresses (hashed for matching only), product inventory, and fulfilment status. Accessed via Shopify Admin API with your OAuth authorisation.
- Google Analytics 4 (scope:
analytics.readonly): Sessions, users, pageviews, traffic sources (channel grouping, source/medium), bounce rate, conversion events (add_to_cart, begin_checkout, purchase), and funnel step metrics broken down by date and channel. We access data via the Google Analytics Data API (GA4) with your explicit OAuth authorisation. This scope grants read-only access; we never write to or modify your GA4 property. - Account information: Your email address and name as provided during sign-up via Clerk.
3. How we use your data
- Display your own advertising and revenue performance to you in your runNorth dashboard.
- Compute analytics such as true ROAS, funnel conversion rates, and audience breakdowns.
- Generate AI-assisted recommendations using Claude (Anthropic). Only aggregated metrics — never raw customer data — are sent to the AI model.
- Store historical performance data in Google BigQuery so you can view trends over time.
We do not sell your data, share it with third parties for advertising, or use it to train AI models.
4. Storefront tracking (North Pixel)
When you install runNorth on your Shopify store, we install a lightweight JavaScript file (North Pixel) as a Shopify script tag, and register a Web Pixel extension in Shopify Customer Events. These track visitor behaviour on your storefront to power attribution and analytics.
The pixel operates in two modes based on visitor consent:
- Consented visitors (Path A): A persistent visitor ID is stored in
localStorage(_at_id). Events are tracked and forwarded server-side to Meta Conversions API and GA4. A cart attribute links the session to the purchase for attribution. Legal basis: consent (GDPR Art. 6.1.a / ePrivacy Art. 5.3). - Non-consented visitors (Path B): No cookies, no
localStorage— zero device storage. Our server computes a one-way daily session hash from the visitor's IP and browser headers; the raw IP is discarded immediately and the hash expires at UTC midnight. No data is forwarded to Meta or Google. Legal basis: legitimate interest (GDPR Art. 6.1.f) — aggregate funnel analytics with no device footprint and no third-party sharing. - Events tracked (both paths): Page views, product views, add-to-cart, checkout initiation, and purchases. Each event is sent to our server (
/api/track) and stored in our database. - Approximate location (both paths):The country from which a visitor connects is derived from their IP address at our server edge and stored alongside each event (country level only — e.g. "DE", "NL"). The raw IP address is not stored for non-consented visitors. Legal basis: legitimate interest (GDPR Art. 6.1.f) — country-level location is too coarse to identify any individual and is used solely for aggregate geographic analytics.
- Order webhook: runNorth registers an
orders/createwebhook to receive order data (order ID, total, email, UTM source) for purchase attribution. Customer emails are used only for matching and are never shared.
runNorth respects Shopify's native _tracking_consent cookie, Pandectes, Cookiebot, and major consent management platforms. Path B session hash rows are deleted automatically after 90 days.
5. Meta Platform data
Data obtained through the Meta Marketing API is used solely to display your own ad account performance within runNorth. We do not use Meta Platform Data to target advertising, build audience profiles, or share data with other advertisers. Our use complies with Meta's Platform Terms and Developer Policies.
6. Google API data — specific disclosures
The following disclosures apply specifically to data obtained via the Google Analytics Data API:
- Data accessed: Session counts, user counts, pageviews, traffic source dimensions (channel, source, medium, campaign), conversion event counts (add_to_cart, begin_checkout, purchase), and funnel metrics — all aggregated by date and channel group. We do not access individual-level user data, raw event logs, or any Google user profile information.
- Data use: GA4 data is used exclusively to display your own analytics within your private runNorth dashboard. It powers the GA4 tab, funnel conversion rates, and traffic source breakdowns. No other use is made of this data.
- Data transfer: GA4 data is not sold, shared, or transferred to any third party. It is stored in your dedicated partition in Google BigQuery (EU region) and is never accessible to other runNorth users or any external service. Aggregated metrics (not raw data) may be passed to Claude (Anthropic) solely to generate AI summaries displayed within your own dashboard session; Anthropic does not use this data for model training (see Anthropic's privacy policy).
- Data protection: GA4 data is stored in Google BigQuery with row-level user isolation — each account can only query its own data. OAuth tokens are stored encrypted in our database and are never logged or exposed. All data in transit uses TLS 1.2+.
- Data retention and deletion:GA4 data is retained in BigQuery for as long as your runNorth account is active, and up to 3 years for trend analysis. Disconnecting your GA4 integration from the Settings page immediately revokes runNorth's OAuth token. To request full deletion of your stored GA4 data, email 7tamir@gmail.com — we will delete all records within 30 days.
- AI/ML model training: Google user data obtained via the Google Analytics Data API is never used to develop, improve, or train any AI or machine-learning model, and is never transferred to any third-party service for that purpose.
7. Data storage and security
Performance data is stored in Google BigQuery (EU region) and a PostgreSQL database hosted on Neon. Access tokens are stored encrypted in our database and are never logged or exposed to other users. All data is scoped to your account — you can only see your own data.
8. Data retention and deletion
You can disconnect any integration at any time from the Settings page. Upon disconnection, your access tokens are deleted immediately. To request full deletion of all stored data, email us at 7tamir@gmail.com and we will delete your data within 30 days.
9. Your rights
Under GDPR and applicable data protection law, you have the right to access, correct, export, or delete your personal data. To exercise any of these rights, contact us at 7tamir@gmail.com.
10. Changes to this policy
We may update this policy from time to time. The date at the top of this page reflects the most recent revision. Continued use of runNorth after changes constitutes acceptance of the updated policy.
Tamir Levy · 7tamir@gmail.com