Refract
ProductPricing
Log inGet started

Privacy

Last updated August 16, 2026. Refract is the product at refractreports.com.

What this covers

This page explains what we collect when you use Refract, why we collect it, and how to get it deleted. It applies to the website, the signed-in app, and emails we send you (verification, password reset, billing).

Account data

When you sign up we store your name, email, and a hashed password. We send a verification link to that email and, if you forget your password, a reset link. Those messages come from our business Gmail. We keep a session cookie so you stay signed in. We do not store your card number. Stripe does, and we only keep the Stripe customer / subscription ids we need to show plan status and open the billing portal.

Store data you connect

You choose what to connect. Depending on that, we store:

  • Shopify: shop domain, API credentials (encrypted), orders, products, refunds, and related sales data needed for the profit report.
  • Meta / Google Ads: account ids and tokens (encrypted), and spend so ads show on the P&L.
  • ShipStation: shipment fees you import or connect, used as shipping cost.
  • Costs you type in: SKU COGS, rent, and other fixed costs.
  • Optional support inbox: Gmail credentials or OAuth tokens (encrypted) if you turn on the support bot, plus the threads it handled.

Each store lives in its own warehouse. We do not mix one merchant’s orders with another’s. Credentials are encrypted at rest. We do not sell your data, and we do not use your store data to train public models.

How we use it

To run the product: sign you in, sync the sources you connected, build your profit report, bill the plan you pick, send auth and (when billing is live) receipt-related email, and keep the service working. Nightly jobs refresh connected stores. We look at logs (errors, health, sign-in) to fix outages, not to read your P&L.

Who else sees it

Hosting is on DigitalOcean (app + Postgres). Auth and contact mail send from our business Gmail. Card payments are Stripe. Shopify, Meta, Google, ShipStation, and Gmail only see what you already have with them. We call their APIs with the credentials you pasted. We don’t sell lists to advertisers. We may share data if required by law, or with a contractor bound to keep it confidential (for example a host or email provider).

Cookies

We use a session cookie to know you’re signed in. That’s it for the app. The marketing pages don’t run an ad pixel. Stripe’s checkout and customer portal are on Stripe’s domain and follow Stripe’s cookies.

Retention and deletion

We keep account and warehouse data while the account is open. If you cancel, access lasts through the period you already paid; after that we can delete the warehouse and account. Ask from the contact form using the same email you signed up with. We will remove the warehouse, encrypted credentials, and login, except records we must keep for taxes or dispute (for example Stripe invoices, which Stripe retains).

Security

Passwords are hashed. API tokens are encrypted. The dashboard is only served to the signed-in organization. No method is perfect. If we learn of a breach that affects you, we will email the account address.

Children

Refract is for business operators. It is not directed at children under 16.

Contact

We don’t publish an inbox on this site (scrapers harvest those). Use the contact form, or reply to a Refract message if you already have an account.

Refract  Shopify profit, without the spreadsheet.
Log inSign upPricingContactPrivacyTerms
© 2026 Refract