Privacy Policy
Last updated
Pluto Profit ("Pluto," "we," "us," or "our") provides a profit analytics platform for ecommerce merchants. This Privacy Policy describes how we collect, use, store, and disclose personal data when you visit our websites (including plutoprofit.com and app.plutoprofit.com), create an account, or use our products and services (together, the "Services").
Please read this policy carefully. If you do not agree with it, do not use the Services or provide us with personal data. You are not legally required to provide personal data, but without it we may not be able to provide the Services.
The Services are designed for businesses, not for personal or household use. We treat personal data covered by this policy as relating to individuals acting as business representatives (for example store owners, finance, or marketing operators), not as consumers shopping on a merchant's storefront.
More detail on technical controls is available on our Security page. This Privacy Policy is the governing privacy notice; the Security page is informational and does not replace this policy.
1. Roles: controller and processor
Privacy laws such as the GDPR and similar frameworks distinguish between a controller (who decides why and how personal data is processed) and a processor(who processes data on a controller's instructions).
- Account and prospect data. Pluto is the controller of personal data about people who sign up for Pluto, manage a workspace, visit our marketing sites, or contact us (for example name, work email, and authentication identifiers).
- Merchant store and channel data. When a merchant connects Shopify, Meta, or other platforms, we process order, product, cost, ad spend, and related analytics data on behalf of that merchant to provide the Services. For that merchant data, the merchant is typically the controller and Pluto is the processor(or "service provider" under US state privacy laws), acting under the merchant's instructions and our agreement with them.
Merchants are responsible for providing appropriate notices and obtaining any required consents for shoppers and other individuals whose data appears in the systems they connect to Pluto.
2. Categories of data we process
2.1 Account and user data
When you create or use a Pluto account, we may process:
- Identity and contact details (for example name, work email, company or workspace name)
- Authentication data via our identity provider (passwordless email codes / magic links; we do not store user passwords)
- Workspace membership, roles, invites, and product settings
- Billing and subscription metadata (processed with our payment provider; we do not store full card numbers)
- Support communications and feedback you send us
2.2 Merchant data from connected platforms
When you connect integrations, we receive data needed to compute profit and related analytics. Depending on what you connect, this may include:
- Shopify: orders, refunds, products, inventory signals, payment/payout and dispute metadata, fulfillments, and related store configuration. We design order ingestion to minimize shopper PII: we do not rely on customer name, email, phone, or street address for core profit analytics. We may store a stable customer identifier (for example Shopify customer id) for cohort and LTV features where permitted. We honor Shopify mandatory compliance webhooks (including
customers/data_request,customers/redact, andshop/redact). - Meta and other ad platforms: ad account structure and performance metrics (spend, impressions, clicks, and related insights) via official APIs and OAuth. We request only the permissions needed for read-only analytics unless a feature explicitly requires more.
- Other channels you choose to connect (for example additional ad or email platforms): metrics and entity metadata as required for profit and performance views.
- Costs and configuration you enter in Pluto (COGS, custom costs, goals, and similar).
2.3 Technical and usage data
We automatically collect limited technical data such as IP address, browser and device type, approximate location derived from IP, pages or product areas used, and diagnostic logs. We use this to operate, secure, and improve the Services.
3. How we use data
We use personal and merchant data to:
- Provide, operate, maintain, and improve the Services
- Authenticate users, manage workspaces, and protect accounts
- Sync and process store and ad data into profit, LTV, and related analytics
- Send service, security, billing, and (where appropriate) product communications
- Monitor reliability, prevent abuse, and debug production issues
- Comply with law and enforce our Terms of Service
We do not sellpersonal information. We do not use merchant store or ad data to build competing advertising products for other merchants, and we do not use connected Meta or Shopify data to contact a merchant's end customers on our own behalf.
4. Legal bases (EEA/UK where applicable)
Where GDPR or UK GDPR applies, we rely on:
- Contract — to provide the Services you request
- Legitimate interests — to secure, improve, and market the Services in a proportionate way
- Legal obligation — where we must retain or disclose data under law
- Consent — where required (for example certain cookies or marketing), which you may withdraw
5. Sharing and subprocessors
We share data only as needed to run the Services, with vendors under contractual confidentiality and data-protection terms, or when required by law. Categories of subprocessors and infrastructure include:
- Hosting and application delivery: Google Cloud (backend services in the United States) and Vercel (web application delivery)
- Operational database: Neon (Postgres), primary region AWS us-east-1 (Northern Virginia, USA)
- Analytics warehouse: ClickHouse Cloud, primary region AWS us-east-1 (Northern Virginia, USA)
- Identity: WorkOS (authentication and organization management)
- Coordination: Redis (locks, queues, and related operational state)
- Payments: Stripe (subscriptions and billing)
- Email delivery: transactional email providers used for magic codes and product email
- Observability: error monitoring and log analytics providers used to operate production systems
Connected platforms (Shopify, Meta, Google Ads, and others) process data under their own terms when you authorize an integration. We do not control those platforms' independent practices.
We may disclose data if required by law, regulation, legal process, or governmental request, or to protect the rights, safety, and security of Pluto, our users, or the public.
6. International transfers and storage location
Pluto's primary production systems for application backends, operational data, and analytics are hosted in the United States (including Northern Virginia / us-east-1 for core databases). If you access the Services from outside the United States, your data may be transferred to and processed in the United States and other countries where our providers operate.
Where required, we use appropriate safeguards for cross-border transfers (for example standard contractual clauses or equivalent mechanisms offered by our providers).
7. Retention
We retain account and merchant data while your account and integrations remain active and as needed to provide the Services, resolve disputes, enforce agreements, and meet legal, tax, and accounting requirements. When you disconnect an integration or we receive a valid shop-level deletion/redaction request, we delete or de-identify related merchant data in line with our product flows and legal obligations (subject to residual backups that expire on a limited schedule).
8. Security
We implement technical and organizational measures appropriate to the risk, including HTTPS/TLS in transit, encryption of OAuth tokens at rest (AES-256-GCM), workspace-scoped access controls, verified webhooks, and operational monitoring. No method of transmission or storage is perfectly secure. Details of current controls are described on our Security page. We have not completed a SOC 2 examination or ISO 27001 certification as of the date above and do not claim those certifications.
9. Cookies and similar technologies
We use cookies and similar technologies that are necessary to run the Services (for example session and authentication cookies) and, where used, limited analytics to understand product usage. You can control cookies through your browser settings; disabling certain cookies may affect sign-in or product functionality.
10. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or export personal data, to object to or restrict certain processing, or to lodge a complaint with a supervisory authority. You can:
- Update profile and workspace settings in the product
- Disconnect integrations at any time
- Request account or personal data deletion by contacting us at the email below
For merchant store data we process as a processor, we may need to redirect end-customer requests to the relevant merchant, or act on the merchant's documented instructions (including platform compliance webhooks).
We do not knowingly sell or share personal information of individuals under 16 for cross-context behavioral advertising.
11. Children
The Services are not directed to children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will take appropriate steps.
12. Changes
We may update this Privacy Policy from time to time. We will change the "Last updated" date when we do. Material changes may also be communicated in-product or by email where appropriate. Continued use of the Services after an update means you accept the revised policy.
13. Contact
Questions about this Privacy Policy or privacy requests:
Pluto Profit
Email: legal@plutoprofit.com
Product: app.plutoprofit.com
Security overview: plutoprofit.com/security