At a glance
| Who runs LetsMetrix? | Cyber Software Joint Stock Company, Vietnam. |
| Do you sell my data? | No. We never sell personal data, and never share it for cross-context behavioural advertising. |
| What do you do with my Google Analytics and Shopify Partner data? | We display it back to you inside your own workspace. Nothing else, unless you separately opt in to the Estimate Calibration Programme (Section 4.4). |
| Do you train AI on my data? | No. Your data is never used to train or fine-tune any model, and is never included in an AI prompt. |
| Where are my API keys stored? | Encrypted, in a store separate from our main database, never logged, never shown back in full. See Section 5. |
| Can I disconnect? | Yes, any time, from your workspace. We delete the credential within 24 hours. |
| Breach notice? | Within 72 hours of us becoming aware. |
| Contact | [email protected] |
1. Who we are and what this covers
LetsMetrix is a market-research and analytics platform for the Shopify app ecosystem, operated by Cyber Software Joint Stock Company ("LetsMetrix", "we", "us"). This Policy explains how we handle information when you use letsmetrix.com and its subdomains, our platform and APIs, our free tools, or when you contact us (together, the "Services").
LetsMetrix is an independent provider. We are not affiliated with, endorsed by, or operated by Shopify Inc. or Google LLC.
Our processing of personal data on your behalf is additionally governed by our Data Processing Agreement (DPA) at letsmetrix.com/data-processing-agreement, which forms part of your agreement with us. Where the DPA and this Policy conflict on a data-protection matter, the DPA prevails.
If you do not agree with this Policy, please do not create an account.
2. Data categories and our role
We handle five distinct categories of data, and the legal role we play differs by category. This distinction governs the rest of this Policy.
| Category | What it is | Our role |
|---|---|---|
| Account Data | Name, work email, password hash, company, role, country, plan, invoices, support messages | Controller |
| Service Usage Data | Pages and dashboards viewed, features used, searches, exports, IP address, device and browser data, session identifiers, application and audit logs | Controller |
| Public Market Data | Information we collect from publicly accessible sources, principally the Shopify App Store: listings, pricing, categories, publicly displayed reviews and reviewer display names, ranking positions, and their history. Also Derived Insights - the estimates, scores and benchmarks we compute from it | Controller |
| Connection Credentials | The secrets needed to run an integration you authorise: Google OAuth access and refresh tokens (google_token), Shopify Partner organisation ID (partner_id), Partner API access token (partner_key), and related identifiers (gid_id) | Processor |
| Connected Data | What we retrieve from a third-party platform on your instruction: GA4 metrics and dimensions from properties you select; Shopify Partner install/uninstall events, charges, payouts, earnings, and associated merchant shop domains | Processor |
"Controller" means we decide why and how the data is processed. "Processor" means we act only on your instruction and have no independent purpose of our own. Customer Data means all of the above that relates to you.
3. What we collect, why, and on what legal basis
| Data | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|
| Name, email, password hash, company, role, country | Account creation, authentication, service and legal notices | Contract |
| Plan, invoices, payment history | Billing, tax and accounting records | Contract; Legal obligation |
| Support messages | Resolving your request | Contract; Legitimate interests |
| Marketing preferences | Sending updates you asked for | Consent |
| Features used, searches, exports, dashboards viewed | Operating the Services, enforcing plan limits, prioritising the roadmap | Contract; Legitimate interests |
| IP address, device and browser data, session ID | Authentication, session security, fraud and abuse prevention, country-level localisation | Legitimate interests |
| Application, access and audit logs | Security monitoring, incident investigation | Legitimate interests; Legal obligation |
| Product analytics events | Understanding aggregate feature adoption and UX friction | Consent where required; otherwise legitimate interests |
| Connection Credentials and Connected Data | Operating the integrations you authorise (Section 4) | Contract; your documented instruction as controller |
| Public Market Data, including reviewer display names, store names and countries shown publicly | Operating a market-research service | Legitimate interests, balanced against the limited impact of processing data the individual chose to publish on a public marketplace |
We do not store your payment card details. Cards are handled by our payment processor; we receive only a token, the last four digits, the brand and the billing country.
We do not seek special categories of data (Art. 9 GDPR), government identifiers, health data, or end-consumer order contents. If you send us such data, for example inside a support ticket, we delete it once your request is resolved.
Public Market Data objection. If you are named in Public Market Data and object to our processing, or you are a developer who believes our figures about your app are wrong, write to [email protected]. We review within 10 business days, correct verified errors, and label disputed estimates. We do not attempt to identify, contact, profile, or re-identify individual reviewers.
What we never do
- We never sell personal data or share it for cross-context behavioural advertising.
- We never use Google user data for advertising, credit assessment, or AI/ML training.
- We never let a third party use your data for that third party's own purposes.
- We never give one customer access to another customer's workspace data.
- Except under Section 4.4, we never use your Connected Data to build, calibrate, validate, or benchmark the estimates shown to any other user.
4. Integrations you authorise
Integrations are opt-in. None is enabled by default, and the Platform remains usable, with reduced functionality, without connecting anything. By connecting, you instruct us to access that platform on your behalf and to retrieve, store and display the resulting data in your workspace. We act on that instruction and no other.
4.1 Google Analytics 4
What we request. You are redirected to Google's own consent screen, where the exact permissions are shown before you approve. We request read-only analytics scopes only. We do not request write, delete or account-management scopes, and we request no access to Gmail, Drive, Contacts, or any other Google product.
What we store. An OAuth access token and refresh token, the Google account email used to authorise, and the account, property and data-stream identifiers you select.
What we retrieve. Aggregate GA4 report data - metrics and dimensions - from the properties you select, for the date ranges needed to populate your dashboards, scheduled reports and exports, plus caching so the Platform stays within Google's API quotas.
Limited Use. LetsMetrix's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, information received from Google APIs is not: (1) used for anything other than providing or improving user-facing features prominent in the LetsMetrix interface; (2) used or transferred for advertising of any kind; (3) sold or transferred to data brokers or information resellers, or used for creditworthiness or lending decisions; (4) used to train, fine-tune or improve generalised or third-party AI/ML models; or (5) read by any human, except with your explicit consent for specific data, where necessary for a security or abuse investigation, to comply with law, or where the data is aggregated and anonymised for internal operations.
Revocation. Disconnect any time in Workspace Settings -> Integrations, or independently at myaccount.google.com/permissions. We revoke the token with Google and delete it within 24 hours.
Change of use. If we ever wish to access a category of Google user data not disclosed here, we will update this Policy and prompt you to consent again before doing so.
4.2 Shopify Partner API
What we store. Your Partner organisation ID, the Partner API access token you generate and provide, and the global identifiers of the apps and objects you select.
What we retrieve. App install and uninstall events, subscription and one-time charges, payouts and earnings, relationship and event history, and the shop domains associated with those events - for apps within your Partner organisation only.
This may include your merchants' data. Shop domains and related records can be personal data of, or confidential information belonging to, merchants who installed your apps. By connecting, you confirm you are authorised to disclose it to us and have a valid legal basis for doing so. In respect of that data we act as your processor or sub-processor under the DPA.
Revocation. Disconnect in the Platform, and also revoke the token in your Shopify Partner Dashboard. We delete the stored credential within 24 hours.
Third-party terms. Your use of the Partner API remains governed by your agreement with Shopify, including the Shopify Partner Program Agreement. You are responsible for compliance with it.
4.3 Rules that apply to every integration
Least privilege: we request the narrowest scope that supports the feature. Purpose limitation: Connected Data is used only for the features in your workspace. Tenant isolation: Connected Data is logically segregated per workspace and enforced at the data-access layer. No onward sale: it is never sold, licensed or disclosed to anyone other than the sub-processors in Section 7, and never for their own purposes. No unilateral expansion: we will not begin retrieving a materially new category of Connected Data without notifying you and, where required, obtaining fresh consent.
4.4 Estimate Calibration Programme - optional, off by default
Our public estimates are modelled from public signals, so they can differ from reality. Customers who connect real data can help us close that gap. Participation is entirely voluntary.
By default, your Connected Data is used only inside your own workspace. It is not used to build, calibrate, validate or benchmark the Public Market Data or Derived Insights shown to any other user.
If you separately opt in to the Estimate Calibration Programme, we will use your Connected Data to improve the accuracy of our public estimation models, subject to all of the following safeguards:
- Opt-in only. The programme is off by default, is enabled by a separate control with its own consent screen, and is never a condition of using any other feature. Declining has no effect on your plan, price, or support.
- Coefficients leave, data does not. Only aggregate correction coefficients derived from many contributors are applied to our models. Your raw Connected Data, and any figure attributable to you, never leaves your workspace.
- Cohort threshold. A coefficient is applied to a category or cohort only where it is derived from at least twenty (20) contributing applications. Cohorts below that threshold receive no calibration at all.
- No self-calibration. We never use your data to adjust the public estimate we display for your own applications, so that your actual figures cannot be inferred from our estimates of you.
- Published methodology. We publish a plain-language description of how calibration works and which cohorts are calibrated.
- Withdrawal at any time. Your contribution is removed at the next model rebuild and no subsequent coefficient will incorporate it.
We may offer a commercial incentive for participation. Participation is never required.
5. How we protect Connection Credentials
We treat Connection Credentials as the most sensitive asset on the Platform.
- Credentials are stored encrypted at rest using AES-256, in a store separate from the main application database, with encryption keys held outside that database. Keys are rotated whenever we have reason to believe one may have been exposed.
- All traffic to and from the Platform, and all outbound API calls, use TLS 1.2 or higher. Credentials are never sent over an unencrypted channel and never placed in a URL.
- Credentials are never displayed back to you in full after entry; the interface shows a masked value only.
- Credentials are never written to application logs, error traces, analytics events, or support tickets. Redaction is enforced at the logging layer, not left to individual developers.
- No LetsMetrix employee has routine access to credentials in plaintext. Decryption happens in the service at request time, and every decryption event is recorded with the actor, the workspace, and the timestamp.
- Human access to your Connected Data is limited to least-privilege support access, and only where you have raised a support request, or where required for a security investigation or by law.
- Credentials are held per workspace. There is no shared or global credential store.
- On disconnection, plan change that removes the integration, or account closure, we revoke the credential upstream where the provider supports it and delete it from our store within 24 hours, including from hot backups at the next rotation.
- We will never ask you for a password by email, chat, or phone, and never ask for any credential outside the official OAuth flow or the Shopify Partner Dashboard token flow. Report anything that does to [email protected].
6. AI features
Some features use artificial intelligence, including large language models, for tasks such as review sentiment analysis and feature-gap reports.
- Input scope. These features run on Public Market Data - principally publicly displayed app reviews - and on content you deliberately submit to an AI feature. Your Connected Data is never included in an AI prompt.
- No training on your data. Your Customer Data and Connected Data are never used to train, fine-tune or improve any LetsMetrix or third-party model, whether raw or in aggregated or derived form.
- Model providers. Where a third-party model provider processes content for us, we use their business API tier under terms that prohibit training on our submissions, and we do not enable any data-sharing or training option. Providers are named in Section 7.
- Output is not advice, and may be wrong. AI output consists of estimates and suggestions. It is not legal, financial, investment or professional advice, and no automated decision producing legal or similarly significant effects is made about you.
7. Sharing, sub-processors, and international transfers
We disclose personal data only as follows:
| Recipient | Why |
|---|---|
| Sub-processors (below) | To host, secure, support, bill and operate the Services, under contract, on our instruction only |
| Your own workspace members | Because you invited them; you control seats and roles |
| Platforms you connect | To execute the API requests you instructed |
| Professional advisers | Legal, audit, accounting and insurance, under confidentiality |
| Authorities | Only in response to a valid, binding legal request. We assess each request, resist over-broad ones, and notify you unless legally prohibited |
| An acquirer | In a merger, acquisition or asset sale, under confidentiality and protection no less than this Policy. We will notify you |
We do not disclose personal data to advertisers, data brokers, or information resellers.
Current sub-processors. Each is bound by written data-protection obligations no less protective than those we owe you, and we remain liable for their performance.
| Function | Provider | Processing location |
|---|---|---|
| Cloud hosting and storage | [provider] | [country] |
| CDN, WAF and DDoS protection | [provider] | Global edge network |
| Transactional email | [provider] | [country] |
| Support ticketing | [provider] | [country] |
| Product analytics and error monitoring | [provider] | [country] |
| Payment processing | [provider] | [country] |
| AI model inference | [provider] | [country] |
We will notify affected customers at least 15 days before adding or replacing a sub-processor that processes Customer Data, by email and in-Platform notice. You may object on reasonable data-protection grounds within that period; if we cannot resolve the objection, you may terminate the affected Service. Where an urgent replacement is needed for security, legal or continuity reasons, we may act first and notify you without undue delay.
International transfers. Our infrastructure is operated independently by us and our sub-processors, and data may be processed in [list countries]. Where personal data subject to the GDPR or UK GDPR is transferred outside the EEA or UK to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with the measures in Section 9. Where Vietnamese law applies, we maintain the records and, where required, the impact-assessment dossiers required by the Law on Personal Data Protection No. 91/2025/QH15 and Decree No. 356/2025/ND-CP. Request a copy of the relevant transfer mechanism at [email protected].
8. How long we keep data
| Category | Retention |
|---|---|
| Account Data | Life of the account, then 90 days, then deleted or anonymised |
| Billing records and invoices | 10 years, as required by Vietnamese tax and accounting law |
| Connection Credentials | Until disconnection or account closure, then deleted within 24 hours |
| Connected Data (cached GA4 / Partner data) | Life of the connection, then deleted within 30 days |
| Service Usage Data | 24 months, then aggregated or deleted |
| Security and audit logs | 12 months, longer only for an active investigation or legal claim |
| Support tickets | 24 months from resolution |
| Marketing contact data | Until you unsubscribe, then suppression list only |
| Public Market Data | For as long as it serves the market-research purpose, including historical series, subject to the objection right in Section 3 |
| Encrypted backups | Rolling 35 days; deleted records are removed at the next rotation and are not restored to active processing meanwhile |
You may request earlier deletion at any time. We action it without undue delay, except where retention is legally required - in which case we tell you which category and why.
9. Security
We maintain an information security programme appropriate to the risk. Measures currently in place:
Technical - AES-256 encryption at rest for databases and backups, and a separate encrypted store for credentials with keys held outside the database; TLS 1.2+ in transit with HSTS on all domains; workspace-scoped authorisation enforced at the data-access layer; mandatory multi-factor authentication for all staff access to production systems; Web Application Firewall, rate limiting and bot protection; automated secret redaction in logging, with an audit record of every credential decryption; automated dependency and vulnerability scanning with defined patching timelines; encrypted backups with documented restoration procedures.
Organisational - least-privilege access, revoked on the day a person leaves; written confidentiality obligations for all personnel and contractors with data access; a documented incident response runbook with defined roles and escalation; peer code review before production deployment; security review of every sub-processor before onboarding.
Breach notification. If we become aware of a personal data breach affecting your data, we notify you without undue delay and within 72 hours, by email to your account contact and by in-Platform notice, describing the nature of the incident, the categories and approximate volume of data affected, the likely consequences, the measures taken, and a contact point. We cooperate fully with any regulatory notification you must make, and we document all incidents whether or not notification is required.
Your part. Use a strong, unique password, enable multi-factor authentication, manage workspace seats carefully, remove departed team members promptly, and treat any LetsMetrix API key as a secret.
Vulnerability reports go to [email protected]. We acknowledge within 3 business days and will not pursue legal action against good-faith researchers who follow our disclosure guidance.
No method of transmission or storage is completely secure. We commit to the standard of care described here, not to a guarantee of impenetrability.
10. Your rights
Depending on where you are, you may have the right to: be informed; access a copy of your data; rectify inaccurate data; erase your data; restrict processing; object to processing based on legitimate interests; data portability; withdraw consent at any time without affecting prior processing; not be subject to solely automated decisions with legal effect (we make none); and complain to a supervisory authority.
If you are in California or another U.S. state with a comprehensive privacy law, you also have rights to know, delete, correct, opt out of sale/sharing and targeted advertising, and to limit use of sensitive personal information. We do not sell or share personal information, so there is nothing to opt out of, but you may still submit a request. We will not discriminate against you for exercising any right.
If you are in Vietnam, your rights under Law No. 91/2025/QH15 on Personal Data Protection - including to know, consent, withdraw consent, access, correct, delete, restrict, object, request provision, and complain - apply through the same channel.
How to exercise. Email [email protected] from the address on your account. We verify by confirming control of that address, and by proportionate additional means for high-risk requests. We respond within 30 days, extendable once by 30 days for complex requests, telling you before the first period expires. Requests are free unless manifestly unfounded or excessive.
Requests from your merchants or end users. Where their data reached us through your integration, you are the controller and we will assist you. If such a person contacts us directly, we will not respond substantively - we refer them to you and notify you without undue delay.
Complaints. Please give us the chance to resolve it first at [email protected]. You may nonetheless complain at any time to your supervisory authority - in Vietnam, the competent authority under the Ministry of Public Security; in the EEA, the authority of your residence or place of work.
11. Cookies, children, links, changes, and contact
Cookies and similar technologies. We use cookies, local storage and session storage in four categories: strictly necessary (authentication, session integrity, security, storing your consent choice - no consent required); functional (language, timezone, saved layouts and filters); analytics (aggregate usage measurement, error and performance monitoring, UX heatmaps); and marketing (campaign measurement on the public website only). The last three are set only with your consent where local law requires it. Manage your choices at any time through the cookie banner or the Cookie Preferences link in the footer, or in your browser. We honour Global Privacy Control signals where applicable law requires. Session-replay and heatmap tools, where used, mask text inputs by default and are not loaded in authenticated areas that display Connected Data.
Marketing email. Sent only with your consent, or to existing customers about closely related services where the law permits. Unsubscribe from any message. This does not stop service, security, billing or legal notices, which are part of the Service.
Children. The Services are business tools, not directed to anyone under 16, and we do not knowingly collect children's data. Contact us and we will delete it.
Third-party sites. We link to sites we do not control, including the Shopify App Store and developer websites. Read their policies before providing data.
Changes. For material changes - those that meaningfully alter what we collect, why, who we disclose to, or your rights - we give at least 30 days' advance notice by email and prominent in-Platform notice, stating the effective date. Clarifications, formatting and typo corrections may be made without advance notice. If a change would involve processing Google user data in a way not previously disclosed, we will obtain your renewed consent first. Continued use after the effective date constitutes acceptance.
Contact us. Privacy, data rights, and legal notices: [email protected] | Security and vulnerability reports: [email protected] | General enquiries: letsmetrix.com/contact-us
Cyber Software Joint Stock Company (Công ty Cổ phần Phần mềm Cyber)
No. 3, Alley 175/55 Lac Long Quan, Tay Ho Ward, Hanoi, Vietnam
Business Registration No. / Tax code: 0109598571
Personal data protection contact: [designated person or function, per Article 33 of Law No. 91/2025/QH15]
Changelog - v2.0 (26 Aug 2026): full rewrite. Added controller/processor split; GA4 and Shopify Partner integration disclosures; Google Limited Use affirmation; credential protection section; opt-in Estimate Calibration Programme; AI and no-training commitment; sub-processor table with 15-day change notice; retention table; expanded rights, transfers and breach notification. v1.0 (27 Aug 2021): initial version.
