Privacy Policy
Last updated: September 9, 2026. This describes what Tutti actually collects, how it's used, and who it's shared with — written to match what the product really does, not generic boilerplate.
Who operates Tutti
Tutti is operated by Profox Pty Ltd (trading as Tutti), 1/22 Westpool Drive, Hallam, VIC 3803, Australia ("Tutti," "we," "us"). This policy applies to tutti.haus, app.tutti.haus, and any successor domain Tutti operates the service from.
Two different groups of people this policy covers
Tutti serves Shopify store owners directly — you sign up, connect your own tools, and use the dashboard. But some of the data Tutti processes belongs to your customers, not you: the Tutti Pixel installed on your storefront (see below) captures browsing and click data from the people who shop at your store.
For that second category, you (the merchant) are the data controller and Tutti is a data processor acting on your instructions — the same relationship you already have with Shopify, Google Analytics, or any other tool installed on your storefront. Tutti processes your end customers' data only to power the attribution features you've enabled, and you remain responsible for your own store's privacy notice to your shoppers.
What data we collect
Account data
Your Tutti account signs in with Google exclusively — your login has no password of its own. We receive your name, email address, profile picture, and Google account identifier from Google, and store enough to keep you signed in and to identify your workspace.
Data from the tools you connect
Tutti is read-only against every third-party platform it connects to — it fetches data to power your dashboard and never writes back to Shopify, Meta, or Google, with the one explicit exception described in "Sending data to Meta" below. When you connect a platform, we access (via OAuth) roughly:
- Shopify — your orders, order line items, customer names/emails/phone numbers on those orders, products, and store details like currency and timezone.
- Facebook Ads (Meta) — your ad account's campaigns, ad sets, ads, spend, and performance metrics.
- Google Ads — the same, for your Google Ads account.
- Google Analytics 4 (GA4) — session and channel-level traffic data from your property.
- Google Search Console — clicks, impressions and search queries for your own verified site.
The OAuth access and refresh tokens that grant this access are encrypted at the application layer (AES-256-GCM) before they're ever written to our database — even direct database access doesn't expose a usable token.
The Tutti Pixel — data from your storefront visitors
Once Shopify is connected, a first-party tracking pixel is installed on your storefront (a Shopify Web Pixel Extension). It captures, from your shoppers' own browsers: pages and products viewed, searches, cart activity, checkout steps, the completed order, and whatever brought the shopper there — ad click identifiers (Meta's fbclid, Google's gclid), UTM parameters, referring page, and browser/device details. It sets a first-party cookie on your store's own domain to recognize a returning visitor within one browsing session. This never uses fingerprinting or any technique designed to identify a visitor without a real, first-party cookie or identifier.
Data we derive
From the data above, Tutti computes attribution matches (which channel likely earned a sale, with a confidence score and a plain-language reason), health-check findings, dashboard metrics, and activity logs. This derived data is stored so your dashboard doesn't need to recompute it on every page load.
Ask Tutti conversations
Messages you send to the "Ask Tutti" chat assistant, and the assistant's replies, are stored so your conversation persists across sessions. Answering a question may involve Tutti sending relevant workspace data (e.g. recent orders, campaign performance) to Anthropic's Claude API to generate a response — see "Third parties we share data with" below.
Google user data (Google Sign-In, Google Ads, Google Analytics)
This section applies specifically to data Tutti receives from Google through Google's APIs. Tutti requests access to Google user data in three places, each with its own consent screen:
What we access, and why
- Google Sign-In (scopes: openid, email, profile) — your name, email address, profile picture, and Google account identifier. Used only to create your Tutti account, sign you in, and identify which workspace is yours. Google Sign-In is the only way customers sign in to Tutti.
- Google Ads (scope: https://www.googleapis.com/auth/adwords, read-only in practice) — the list of Google Ads accounts you can access, and for the account you choose: campaign names, status, budgets, spend, clicks, impressions, conversions and conversion value. Used to show your Google Ads performance beside your Shopify sales and to work out which ads produced which sales. Tutti never creates, edits, or pauses campaigns or ads; the one exception — adding a tracking parameter to your account's final URL suffix — happens only when you click a clearly labelled button in Settings, never automatically.
- Google Analytics 4 (scope: https://www.googleapis.com/auth/analytics.readonly) — the list of GA4 properties you can access, and for the property you choose: aggregated session, traffic-channel, landing-page, device, engagement and conversion data, plus advertising cost when your property is linked to Google Ads. Used as a second, independent view of where your store's visitors came from.
- Google Search Console (scope: https://www.googleapis.com/auth/webmasters.readonly) — the list of Search Console properties you can access, and for the property you choose: clicks, impressions, click-through rate, average position and search appearance, broken down by date, page and search query. Used to show the organic search demand reaching your storefront pages beside the traffic you pay for. Tutti only reads: it never submits a sitemap, requests indexing, or changes anything in Search Console.
Connecting Google Ads, GA4 or Search Console is optional — you can use Tutti with only Shopify connected. Each is connected separately, from Settings, through Google's own consent screen.
How we use it
Google user data is used only to provide and improve the Tutti features you can see and use yourself: the dashboard and metric tiles, the attribution matching that credits each sale to a channel, background health checks that flag changes worth your attention, and the Ask Tutti assistant when you ask it a question about your own numbers. We do not use Google user data for advertising of any kind (including targeted, personalised, or retargeted advertising), we do not sell it or share it with data brokers, we do not use it to assess creditworthiness or for lending, we do not use it to train artificial-intelligence or machine-learning models, and we do not use it to build databases or profiles unrelated to the Tutti features you use.
How we share it
We do not transfer Google user data to anyone except the service providers listed in "Third parties we share data with" below, and only as needed to run Tutti: it is stored in our database hosted by Neon, processed by our application hosted on Vercel, and — only when you ask the Ask Tutti assistant a question that needs it — the relevant figures (for example, last week's Google Ads spend) are sent to Anthropic's API to generate your answer. Anthropic does not use that data to train its models. Google user data is never sent to Meta or any other advertising platform; the opt-in Meta Conversions API feature described below sends only Shopify order data. Team members you invite to your workspace see the same connected data you do.
How we protect it
The OAuth access and refresh tokens Google issues are encrypted with AES-256-GCM at the application layer before they are written to our database, and are decrypted only in memory when Tutti calls Google's APIs on your behalf. All traffic between your browser, Tutti, and Google uses HTTPS. Access to production systems is restricted to the people who operate Tutti and limited to what is needed to run it. See "How we protect your data" and our Security page for the full set of measures.
How long we keep it, and how to delete it
- Google Ads, GA4 and Search Console data is retained for as long as that account stays connected to your workspace. On each sync Tutti ingests roughly the last two weeks of campaign, session and search-performance data for attribution matching, and keeps what it has ingested — plus the matches, insights, and dashboard snapshots derived from it — so your history stays consistent while the account is connected.
- Disconnecting Google Ads, GA4 or Search Console from Settings deletes the stored tokens and every piece of data Tutti ingested or derived from that account, immediately and permanently.
- Revoking Tutti's access from your Google Account (myaccount.google.com/permissions) makes the stored tokens unusable at once; Tutti will stop syncing and show the connection as needing attention. To also remove what was already stored, disconnect the account in Tutti or delete your Tutti account.
- Deleting your Tutti account (Settings → Delete account) removes your Google sign-in data, every connected account, and everything derived from them, immediately and permanently.
- Encrypted database backups kept by our database host (Neon) roll off automatically on its short point-in-time-restore window and are never used to restore data a customer has deleted.
Limited Use disclosure
How we use this data
- To run your dashboard — blended revenue, spend, ROAS, and per-channel breakdowns.
- To match each sale to the channel that most likely earned it, and show you how confident that match is.
- To run background health checks and propose Tasks worth your attention.
- To power the Ask Tutti chat assistant, which can query your own connected data to answer questions.
- To keep your integrations working — refreshing tokens, syncing new orders, registering webhooks.
- To operate, secure, and improve the product, and to communicate with you about your account.
Sending data to Meta (opt-in, off by default)
Tutti has one feature that sends data to a third party rather than only reading from it: if you explicitly turn on Conversions API (CAPI) sync in Settings and provide a Meta Pixel ID, Tutti automatically reports purchases it has already matched to a real Meta ad click back to Meta's advertising system, so Meta's algorithm can learn from real, confirmed sales.
Third parties we share data with
Tutti doesn't sell your data. We share data with the following categories of third parties, each strictly to provide the service:
- Google — for sign-in (OAuth), and for Google Ads/GA4/Search Console data if you connect those. See "Google user data" above for exactly what is accessed and how it's used.
- Shopify, Meta (Facebook/Instagram Ads) — to read the data you've explicitly connected, and to send hashed purchase data back to Meta only if you've turned on CAPI sync.
- Anthropic — the Ask Tutti chat assistant is powered by Anthropic's Claude models; relevant workspace data may be sent to Anthropic's API to generate a response to your questions.
- Vercel — hosts the application and runs its scheduled background jobs.
- Neon — hosts the Postgres database Tutti's data is stored in.
We may also disclose data if required by law — subject to the review, minimisation, and notice commitments in our policy on requests from public authorities — or to protect the rights, property, or safety of Tutti, our customers, or others.
Shared workspaces
If you invite a team member to your workspace, they see the same connected accounts, dashboards, Tasks, attribution data, and Ask Tutti conversation you do — it's one shared workspace, not separate copies per person. Only the workspace owner can connect or remove an integration, or invite/remove team members. See our Team Members documentation for the full model.
Processing your customers' data on your behalf
Where Tutti processes your customers' personal data as your processor (see "Two different groups of people" above), our Data Processing Agreement applies automatically as part of our terms — it covers the categories of data processed, subprocessors, security measures, breach notification, and deletion. Our Security & Incident Response page describes the protective measures and incident process in detail.
Internal access to your data
Tutti staff cannot browse your dashboard. Our internal panel shows technical diagnostics only — integration connection and sync state, when data last arrived, errors, your account email and store domain, and who on your team can sign in. It never shows your sales, spend, results, campaign names, products or shoppers; those values are never sent to it.
If a member of staff needs to see your account — because you asked for help, or we're investigating a bug in it — they file a request with their name and a written reason. You see it in Tutti and only the workspace owner can approve it. Approval opens a read-only window of at most 45 minutes, in which no change, export or Ask Tutti message is possible, and which you can end early at any time. Every request, decision and viewing session is written to your Activity log and to our own internal audit log. There is no override and no way in without your approval.
The full process, including what happens outside the app, is written up in Who can see your data.
How we protect your data
OAuth access and refresh tokens for every connected platform are encrypted at the application layer (AES-256-GCM) before being stored — not stored in plaintext in our database under any circumstance. Data in transit uses HTTPS. Access to production data is limited to what's needed to operate the service. No method of storage or transmission is 100% secure, and we can't guarantee absolute security, but we take reasonable, real technical measures to protect your data.
Data retention and deletion
We retain your data for as long as your account is active and the relevant integration stays connected. Disconnecting an integration from Settings deletes its stored tokens and every piece of data Tutti ingested or derived from it, immediately. If you delete your account (available directly from Settings), the deletion is real and immediate — every connected account, every piece of derived attribution data, every Task and activity log, and your login itself are permanently removed in one operation. This can't be undone, and there's no way for us to restore it afterward. If you leave a workspace as an invited team member instead, only your own login and membership are removed — the workspace owner's data is untouched.
Your rights
Depending on where you're located, you may have rights to access, correct, export, or delete your data. In practice:
- Access & export — your dashboard already shows your real data directly, and several views (Live Orders, the Attribution table) support CSV export.
- Correction — connected-platform data reflects the source platform (e.g. Shopify); update it there and Tutti's next sync will reflect it.
- Deletion — a real, working "Delete account" flow is available in Settings, described above.
- Opt-out of the Meta CAPI sync — turn it off any time in Settings; it's off by default.
To exercise any right not covered by the in-app tools above, contact us using the details below.
Children's privacy
Tutti is a business tool for Shopify store operators and isn't directed at children. We don't knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us and we'll remove it.
International data transfers
Tutti is operated from Australia. The infrastructure providers we rely on for hosting (Vercel) and database storage (Neon) may process and store data in countries other than your own. By using Tutti, you understand your data may be transferred to and processed in other countries, which may have data protection laws different from those in your own country.
Changes to this policy
We may update this policy as Tutti's product changes. We'll update the "Last updated" date above when we do, and for material changes we'll make a reasonable effort to notify you directly (e.g. by email).
Contact us
Questions about this policy or your data can be sent to tsaar@maltandbrew.com, or by mail to Profox Pty Ltd, 1/22 Westpool Drive, Hallam, VIC 3803, Australia.