Explore the policy
Who we are
Synthweave LLC (“we,” “us”) operates the Sutton brand, the website at getsutton.ai, the Sutton Connect Shopify app, and the Sutton campaign-management service, which clients connect to their Google Ads, Google Merchant Center, Google Search Console, and Google Analytics accounts. This policy covers the website, the app, and those Google connections.
Two different roles
We handle personal data in two distinct capacities, and your rights differ depending on which applies:
- The website. When you visit getsutton.ai or contact us, we decide why and how your data is used. We are the controller, and you can exercise your rights with us directly.
- The Shopify app. When a merchant connects their store, we handle their customers’ data strictly on that merchant’s instructions. The merchant is the controller; we are a processor. If you are a shopper who bought from a store that uses Sutton Connect, your request should go to that store, which can instruct us through Shopify. We act on those instructions.
The Sutton Connect Shopify app
What the app accesses
With the merchant’s consent at install, the app requests read-only access to four things: the store’s orders and full order history, its products, and its inventory. It does not request access to the store’s customer list, to Shopify reports, or to any web-pixel or on-site-event data.
Merchants who use our content-publishing service grant one further permission, separately and after install: permission to publish pages and blog posts to their Online Store. It is optional. The app installs and runs without it, and a merchant who does not publish content is never asked for it. Content is published only on the merchant’s instruction, against a recorded approval of the exact document being published. This permission reads and writes no customer data, and it does not change what personal data the app handles, which remains the order’s email address and nothing else.
The only piece of personal data the app reads and keeps is the customer email address carried on an order. We use it as the key that links a customer’s orders together so we can report repeat-purchase rate and lifetime value. We do not store customer names, phone numbers, or shipping/billing addresses; for an app approved to read only the email field, Shopify withholds the other protected fields, and we additionally strip them on our side before anything is written to storage. Product and inventory data is ordinary catalog information and contains no customer personal data.
What we store
- Structured commercial records: orders, payments, and refunds, used to produce the reporting and analysis the merchant hired us for. The only customer personal data these contain is the order’s email address.
- Raw source payloads: we keep an audit copy of the order data Shopify sends, so every figure we report can be traced back to its source. These records are reduced to email-only on arrival by the same field-stripping described above; they do not retain customer names, phone numbers, or addresses.
- Product feed data: product and inventory information used to build and keep current the merchant’s Google Merchant Center product feed. This is catalog data and contains no customer personal data.
- Store credentials: access tokens are held in an encrypted secrets vault (1Password), never in our own database, and never alongside customer data.
Each merchant’s data is stored in a separate, isolated workspace. We do not combine one merchant’s customer data with another’s.
What we do not do
- We do not sell personal data, and we do not share it for advertising.
- We do not use merchant or shopper personal data to train machine-learning models.
- We do not use one merchant’s data to serve another merchant, and we do not build cross-merchant profiles of shoppers.
Google Ads, Merchant Center, Search Console, and Analytics connections
Sutton is a campaign-management service. A client connects their Google Ads account, and optionally their Google Merchant Center, Google Search Console, and Google Analytics accounts, to Sutton through Google’s sign-in and consent screen. Our team then plans, creates, manages, and reports on the client’s advertising on the client’s behalf. Clients grant access; they do not log into or operate the tool themselves. This section explains how we handle information received through Google APIs.
What we access, and why
- Google Ads (the
adwordspermission): the account structure, campaigns, ad groups, ads, keywords, budgets, bids, conversion settings, and performance reporting for the accounts the client authorizes. We use this data to build and manage the client’s campaigns and to report results back to the client. This is the only Google permission that enables campaign management. - Google Merchant Center (the
contentpermission), for clients running Shopping campaigns only: product feed, product status, and Merchant Center account configuration, accessed through the Merchant API. We use it to build and keep the client’s product feed current. Clients without Shopping campaigns can decline this permission, and we only act on the Merchant Center account IDs a client has approved with us in writing. - Google Search Console (the
webmasters.readonlypermission): the list of verified website properties, search performance data (queries, pages, clicks, impressions), index coverage, and sitemap status, read through the Search Console API. We use it to diagnose landing-page issues and to compare paid and organic performance in the reports we prepare for the client. This permission is read-only: we never change Search Console properties, sitemaps, or settings. - Google Analytics (the
analytics.readonlypermission): the client’s Google Analytics 4 property (traffic, conversions, and revenue by channel), read through the Analytics Data API. We use it to report campaign performance against the client’s own analytics rather than platform-reported numbers only. This permission is read-only: we never modify the property, its settings, or its events. Clients choose which property to connect.
We request no other Google permissions. We do not access Gmail, Drive, Calendar, Contacts, or any Google account data beyond the four services above.
How we use and store it
- Advertising, feed, search, and analytics data is used solely to provide the service the client engaged us for: managing, measuring, and reporting on that client’s own marketing. The Search Console and Analytics permissions are read-only.
- Access and refresh tokens are held in an encrypted secrets vault, never in our own database, and never alongside client business data.
- Each client’s advertising data is kept in a separate, isolated workspace. We do not combine one client’s Google data with another’s, and we do not use it to build cross-client profiles.
- Advertising, Search Console, and Analytics data is aggregated and is not personal data about individual users. Where Google Ads or Google Analytics reporting contains user-level or customer-level fields, we do not export or store them.
Sharing
We do not sell information obtained through Google APIs, and we do not share it with third parties except the service providers listed below who process it on our behalf (hosting, our data platform, and our credentials vault), or as the client instructs, or where required by law. We do not use it for advertising other than the client’s own campaigns, and we do not use it to train machine-learning models.
Limited Use disclosure
Sutton’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Retention and revoking access
- You can revoke Sutton’s access at any time from your Google Account at myaccount.google.com/permissions, or by asking us to disconnect. Revocation invalidates our tokens immediately.
- When a client disconnects or ends their engagement, we stop accessing their Google accounts immediately, delete the stored tokens, and erase that client’s advertising data from our systems within 30 days, except where a legal obligation requires longer retention.
- While the engagement is active, we retain advertising data for as long as it is needed to manage and report on the client’s campaigns.
- To request deletion of Google-sourced data at any time, email privacy@getsutton.ai. We act on the request within 30 days.
The getsutton.ai website
When you submit the contact form or book a call, we collect what you provide (name, work email, company, approximate revenue, and your message) and use it to respond, to schedule and prepare for a call, and to keep in touch about our services. We also collect standard usage analytics including pages viewed and general device and location information. You can control cookies through your browser settings.
Contact, reservation, and signup submissions are stored in our restricted Sanity workspace so a delivery problem cannot erase the enquiry. Resend sends the related notifications and welcome emails. Access is limited to the team members who handle those conversations.
To limit automated form abuse, we keep a keyed, shortened fingerprint of the submitting IP address for a ten-minute rate-limit window. We do not use it for marketing.
Service providers
We use a small set of providers, each processing data on our behalf under its own terms:
- Shopify: the source of merchant and order data, at the merchant’s direction.
- Google (Ads API and Merchant API): the source of advertising and product-feed data for clients who connect their accounts, at the client’s direction.
- Synthweave: our data platform, where merchant commercial records and raw source payloads are stored.
- 1Password: encrypted storage for credentials only.
- Cloudflare and Vercel: hosting and network delivery.
- Resend: transactional email.
- Sanity: content management and restricted website enquiry records.
- Slack: internal operational alerts. These carry aggregate figures and status only, not shopper personal data.
- Google (Analytics and Tag Manager), PostHog, and Calendly: website analytics and call scheduling. These apply to the website only and have no access to merchant or shopper data from the app.
Retention and deletion
For app data we act on the merchant’s instructions, including the standard requests Shopify passes to us:
- Data access request. When a merchant requests the personal data we hold about one of their customers, we provide it to the merchant within 30 days.
- Customer erasure. When a merchant requests erasure of a specific customer, we delete that customer’s personal data (from both our structured records and our raw source archive) within 30 days.
- Uninstall. When a merchant uninstalls the app, we stop collecting immediately and revoke the stored credentials. We erase that store’s data within 30 days of Shopify’s store-erasure notification.
While the app is installed, we retain commercial records for as long as they are needed to provide the reporting the merchant engaged us for. Website enquiry data is kept until it is no longer needed for the conversation it relates to.
Security
Connections to Shopify and to Google use OAuth rather than shared passwords or pasted API keys. Access tokens are short-lived, rotated automatically, held in an encrypted vault, and revoked on uninstall or disconnect. All traffic runs over TLS. Data arriving from Shopify is cryptographically verified before we accept it, and requests that fail verification are rejected.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal data, and to object to or restrict certain processing.
- Website data: contact us directly using the address below and we will respond.
- Shopper data from a store using our app: contact that store. As the controller it can instruct us, and we act on its instruction. If you contact us first, we will tell you which store holds the relationship where we are able to.
- Google account connections: revoke access from your Google Account permissions page at any time, or email us to disconnect and delete your data.
International transfers
We are based in the United States and our providers may process data in the United States and elsewhere. Where required, transfers rely on appropriate safeguards such as standard contractual clauses.
Changes
If we make a material change to how we handle personal data, we will update this page and the date above.
Contact
Privacy questions and data requests: privacy@getsutton.ai.