Privacy Policy
Effective 28 August 2026 · Applies to milbaagency.com and to the Milba Connect Shopify app.
1. Who we are
Milba is a performance marketing agency. We run advertising campaigns for e-commerce brands and report the results back to them in the Milba client dashboard at milbaagency.com.
Milba Connect is our Shopify app. Its single job is to read a merchant’s order totals so that the merchant can see, in their own dashboard, how much revenue each advertising campaign produced.
2. Our role
For data we read from a merchant’s Shopify store, the merchant is the data controller and Milba acts as a data processor. We process that data only on the merchant’s instructions, under the agency agreement signed with them, and for the purpose described in section 4.
For the accounts our own clients and staff use to sign in to the Milba dashboard, Milba is the data controller. See section 10.
3. What Milba Connect reads
The app requests exactly one Shopify access scope: read_orders. It requests no other scope, and it deliberately does not request read_all_orders. On connection it reads the previous 60 days of orders, and from then on receives order updates by webhook.
For each order, we store only:
- Order identifier, name, and Shopify store domain
- Total price, currency, and financial status
- Processed, cancelled, and refunded dates, and refunded total
- The landing page URL and referring URL that Shopify's customer journey exposes, which is what lets us attribute an order to an advertising campaign
We also store the store’s domain, currency, and timezone, plus an encrypted access token so the app can keep reading orders.
4. Why we process it
Solely to calculate advertising performance — attributing revenue to the campaign, channel, or ad that produced it — and to display those totals to the merchant in their own dashboard. Nothing else.
We do not use this data to build profiles of individual shoppers, to make automated decisions about any individual, to target or message shoppers, or for any purpose of our own beyond serving the merchant whose store it came from. We never sell data to anyone, in any form.
5. What we never access
Milba Connect does not read, receive, or store customer names, email addresses, phone numbers, shipping or billing addresses, or payment details. It also does not read products, inventory, fulfilment, or customer records.
Our Shopify data access is approved at Level 1 protected customer data, which by definition excludes name, address, phone, and email fields.
6. Retention and deletion
Order data is kept only while the merchant’s store remains connected, because it is what the merchant’s own revenue reporting is built from. It is deleted when:
- the merchant uninstalls the app — Shopify sends shop/redact 48 hours later and we erase the store record and every order stored for it;
- an administrator removes the store from the Milba dashboard, which deletes the same data immediately.
Because we hold no customer personal data, a customers/redact or customers/data_request request from Shopify has nothing to erase or return; we log the request and acknowledge it.
7. Security
All data is encrypted in transit over TLS and encrypted at rest by our database provider. Shopify access tokens receive a second layer of AES-256-GCM encryption before they are written to the database. Access tokens are short-lived and refreshed automatically.
Every webhook we receive from Shopify is verified with an HMAC signature before it is processed; unverified requests are rejected. Store data is visible only to the merchant’s own account and to authorised Milba staff who need it to run that merchant’s campaigns.
8. Sub-processors
We rely on a small number of providers:
- Vercel — application hosting (EU and US regions)
- Neon — the PostgreSQL database where order and account data is stored
- Resend — transactional email to dashboard users only; no shopper data is ever sent by email
Each is bound by its own data processing terms. We do not share merchant or shopper data with advertising networks, data brokers, or any other third party.
9. International transfers
Data may be processed in the European Union and the United States by the providers listed above, under Standard Contractual Clauses or an equivalent transfer mechanism.
10. Dashboard account data
For people who sign in to the Milba dashboard — our clients, their coaches, and our own staff — we store a name, an email address, and a hashed password, together with the invoices, support tickets, and reports belonging to that account. This data exists to operate the service and is kept for the life of the account plus any period we are required by law to retain billing records.
11. Your rights
Under the GDPR you may request access to, correction of, or deletion of your personal data, and may object to or ask us to restrict its processing. Shoppers on a merchant’s store should direct such requests to that merchant, who is the controller of their data; the merchant can pass the request to us and we will act on it. You also have the right to complain to your supervisory authority — in Portugal, the CNPD.
12. Changes and contact
We will update this page if our processing changes, and the effective date above will change with it.
Questions, or any data protection request: privacidade@milbaagency.com