← Home

Privacy policy

Last updated: September 2026

quickByte digital ("we", "us") operates this website and works with clients under contract. This policy covers information collected through the site, routine business contact, and data processed through our platform integrations, our reporting pipeline, the quickByte Marketing Dashboard app for Shopify, and the qB Hub app for Shopify.

Information we collect

How we use information

Retention

We keep information only as long as needed for the purposes above or as required by law. To request deletion, email hello@quickbyte.digital or see Data deletion.

Platform and client account data

When clients authorise integrations with our reporting pipeline, we process marketing performance data from connected platforms including Google (Google Ads, GA4, Search Console), Meta, Klaviyo, and Shopify. This data is used only to deliver contracted reporting and related operations for that client, and not for unrelated advertising, profiling, or resale.

Processed data is stored in agency-controlled cloud infrastructure (Google Cloud / BigQuery), in logically isolated datasets per client brand.

Retention: marketing performance data is retained for the duration of the client engagement, so that historical and year-on-year comparisons remain available, and is deleted on request or on termination of the engagement. Retention periods are set per client contract.

Google

Use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising targeting, profiling, or any purpose beyond contracted client reporting. We do not sell Google user data.

Meta

Meta Platform Data is processed in accordance with the Meta Platform Terms. We do not use Meta Platform Data for advertising outside of agreed client reporting, and we do not sell or license it to third parties.

Deletion of platform data

To request deletion of data we hold from platform API connections, email hello@quickbyte.digital or see Data deletion. We will process verified requests within 30 days.

quickByte Marketing Dashboard app for Shopify

The quickByte Marketing Dashboard app connects a Shopify store to the reporting service used by that store's marketing team or agency. The marketing team or agency links the store to their dashboard from their side; the app cannot do this itself.

What the app reads. Order and product totals, through Shopify's Admin API: daily revenue, order counts, discounts, refunds, shipping, taxes, payment fees and product costs. These are combined into daily figures for the brand.

What the app does not read. The app does not read customers' names, email addresses, phone numbers or postal addresses. It holds Shopify's Protected Customer Data access at Level 1 with no customer fields, so that information is not available to it. To report new and returning customers, it reads whether each order is a first or a repeat purchase, as Shopify records it on the order, without reading who the customer is.

Where it is stored. In the agency-controlled Google Cloud infrastructure described above, in a dataset isolated to that brand. The app stores no customer personal data.

When a store uninstalls the app. Syncing stops immediately. Shopify then asks us to erase that store's data, and we delete the data we received from that store through Shopify within 30 days of the request.

Customer data requests. When Shopify forwards a customer's request to see or erase their data, we acknowledge it. Because the app holds no customer personal data, there is nothing to return or erase.

qB Hub app for Shopify

The qB Hub app adds a loyalty and customer hub to a Shopify store: a points program, a rewards drawer, a wishlist, and an AI concierge that answers shoppers' questions. The store installs it; each store's data is processed by a separate instance of our service, isolated from every other store's.

What the app reads from Shopify. Orders (items, prices, discounts, refunds and fulfilment), products (prices, costs, tags and stock) and the store's markets and currencies, to work out the points each order earns. For customers, the app reads only their customer ID, email address and total spend at the store. It holds Shopify's Protected Customer Data access for email only: it does not read names, phone numbers or postal addresses from Shopify.

Why it reads a customer's email. To confirm that a shopper who opens the rewards drawer is the signed-in customer they say they are, and, when the store connects Klaviyo, to keep that customer's loyalty details up to date on the store's Klaviyo profile for them. When the store turns on Meta or Google reporting, the email is sent to those accounts hashed, never readable. When a signed-in customer asks for a person, their email goes with the request to the store's own helpdesk or inbox, so the store can reply.

What the app stores. For each store:

The concierge. When a shopper asks the concierge a question, we send the question, the conversation so far and the store's own information (its products, policies and help articles) to Anthropic, which provides the AI model, and return its answer. For a signed-in customer we also send their first name as the store shows it and their loyalty standing (points, tier), so it can answer questions about their rewards. Anything a shopper types is sent as typed, so shoppers should not share information they do not want processed. We use Anthropic's commercial API, under terms that do not allow Anthropic to train its models on the data we send, and we do not use it to train AI models either. When a shopper asks for a person, the conversation goes to the store: to its Gorgias helpdesk when connected, otherwise to the store owner by email. When the store uses Klaviyo, a signed-in customer's request is also recorded on their own Klaviyo profile. The address a signed-out shopper types is passed on for the store to reply to, and is marked as unconfirmed.

What the app does not do. It does not sell personal data, use it for advertising outside the store's own accounts, or combine one store's customers with another's.

How long we keep it. Drawer activity for 180 days; the link between a browser and a customer for up to 400 days after the browser was last seen on the store; an unrecognised browser's ad-click identifiers for 90 days after it was last seen; wishlist share records for 400 days (they limit how often one address can be sent a list); concierge conversations for 12 months after their last message. The loyalty ledger and wishlists are kept while the store uses the app, because points and rewards must stay honourable.

When a store uninstalls the app. The service stops using the store's Shopify access and its Klaviyo key at once. Shopify then asks us to erase that store's data, and we delete everything we hold for that store: the ledger, wishlists, conversations, browser links, activity and settings.

Customer data requests. When Shopify forwards a customer's request to see their data, we send the store everything we hold about that customer, including the browser links and ad-click identifiers tied to them, their conversations (with the store's replies) and wishlists shared with them. When it forwards a request to erase it, we erase that customer from every part of the service, including those conversations, wishlists shared with them and the link between their browser and their account. We keep only a record that the request was received and completed (the customer's ID and the order numbers the request named), as evidence that it was honoured.

AI analyst

Our reporting dashboards include an optional AI analyst that answers questions about a brand's own reporting. When a user asks a question, we send the question and the relevant figures from that brand's reporting to Anthropic, which provides the AI model, and return its answer to the user. It is used only to answer the requesting user's questions about their own reporting.

We send aggregated reporting figures only, never customers' names, email addresses or other customer personal data. These figures can include performance data from any connected platform, including Google Ads, Google Analytics and Search Console. We use Anthropic's commercial API, under terms that do not allow Anthropic to train its models on the data we send, and we do not use it to train AI models either.

Service providers

We use the following providers to run our services. Each processes data only to provide its service to us.