🎁 Founding-merchant program — 100% free right now, every feature included · 24-hour support replies · tailored onboardingLearn more →

Privacy Policy

Last updated: June 18, 2026

This Privacy Policy explains how Lightning Quest Inc., doing business as EcomWizzard ("EcomWizzard", "we", "us"), collects, uses, stores, and protects information when a merchant connects their store and uses our application and website at ecomwizzard.com (the "Service"). When you connect a store or support channel, you are the controller of your customers' personal data and EcomWizzard acts as a processor handling that data on your behalf.

Information we collect

Store data. When you connect a WooCommerce or Shopify store, we access and store data from that store through its API, including orders, products, inventory, and customer records. Customer records may include names, email addresses, phone numbers, and shipping and billing addresses. We request only the data needed to provide the features you use.

Account data. When you create a workspace, we collect your name, email address, and authentication credentials.

Connected-channel data. If you connect a support channel (Gmail, Facebook, Instagram, WhatsApp, live chat, phone, or contact forms), we process the messages and related metadata in that channel so your team and AI assistant can read and respond to them. See the Google and Meta sections below for the specifics.

Advertising & analytics data. If you connect Google Ads, Google Analytics, or a Meta advertising account, we access campaign, spend, performance, and traffic/funnel metrics from those accounts to produce your advertising and profit analytics. See the Google and Meta sections below for the specific scopes and uses.

Usage data. We collect standard log and device information (such as IP address, browser type, and pages viewed) and use a session cookie to keep you signed in.

Google user data

EcomWizzard offers several optional Google integrations — a Gmail mailbox for support, your Google Ads account, your Google Analytics property, and your Google Business Profile. You choose which (if any) to connect, and each is authorized separately through Google's OAuth consent screen. This section describes exactly what we access for each and why, and is provided to satisfy the Google API Services User Data Policy. In every case we access only the Google account you connect — which must be one you own or are authorized to manage — and we never sell Google data, never use it for our own advertising, and never use it to train generalized or third-party AI/ML models.

Gmail (support inbox). If you connect a Gmail or Google Workspace mailbox as a support channel, we request:

  • gmail.readonly — read your incoming support emails so they appear in your inbox. Read-only: EcomWizzard never modifies, labels, deletes, or moves anything in your Gmail.
  • gmail.send — send the replies your team (or AI assistant, with your approval) composes, from your own address.
  • gmail.settings.basic — read your "send-as" aliases so replies can go out from the correct support address.
  • openid · email · profile — identify the connected mailbox (the email address and account name).

Used solely to bring your support emails into one inbox, match them to the customer's orders, and draft and send replies in your voice. Ticket state (read / archived) is tracked in EcomWizzard, not written back to your Gmail.

Google Ads. If you connect your Google Ads account, we request:

  • adwords — access to your campaign names, status, spend, and performance metrics, so we can show ad-spend, ROAS, and blended-profit (MER) analytics next to your store revenue, and — only when an authorized user of your workspace explicitly initiates it from the dashboard — campaign-management actions on your behalf: pausing or enabling a campaign, changing a campaign budget, creating a new campaign (always created paused), and adding creative assets. We never make changes you did not initiate, every change is recorded in your workspace audit log, and we access only Google Ads accounts you own or are authorized to manage.
  • userinfo.email — identify the connected Google account.

Google Analytics (GA4). If you connect a Google Analytics 4 property, we request:

  • analytics.readonly — read-only access to your traffic and funnel metrics (sessions, page and product views, add-to-cart, checkout, purchases, and traffic sources) so we can show storefront and per-product conversion analytics. We never modify your Analytics configuration.
  • userinfo.email — identify the connected Google account.

Google Business Profile. If you connect your Google Business Profile to monitor reviews, we request:

  • business.manage — read your business locations and customer reviews so they surface in EcomWizzard for monitoring and response. We access only the locations on the account you connect.
  • userinfo.email — identify the connected Google account.

How Google data is stored. Data we sync (support messages, ad and analytics metrics, reviews) is stored in our encrypted Postgres database so the app can render it; email attachments are stored on access-controlled storage. Your Google OAuth tokens are encrypted at rest with AES-256-GCM, and all data is encrypted in transit with TLS. Data is hosted on our cloud infrastructure provider (Railway).

Who can access it. Only (a) the authorized team members of your own EcomWizzard workspace; (b) our personnel, strictly as needed to operate, secure, or support the Service; and (c) for the support inbox only, our AI subprocessor (Anthropic), which receives the minimum message context needed to return a requested reply draft and is contractually barred from using it for any other purpose or for model training. We do not share Google user data with any other third party.

Limited Use. EcomWizzard's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We only allow humans to read your Google data when (i) you give explicit consent for a specific item, (ii) it is necessary for security purposes (such as investigating abuse), (iii) it is required to comply with applicable law, or (iv) the data is aggregated and anonymized.

How to disconnect a Google integration. You can disconnect any Google connection at any time from inside EcomWizzard — Gmail at CS Hub → Settings → Channels → Email, and Google Ads, Google Analytics, and Google Business Profile at Settings → Integrations. Disconnecting immediately stops all syncing and revokes our stored tokens. You can also revoke EcomWizzard's access directly from your Google Account at myaccount.google.com/permissions.

How to delete Google data. Disconnecting stops further access; to also delete the Google data already stored (emails, ad and analytics metrics, or reviews), email privacy@ecomwizzard.com (or follow the Data Deletion instructions). We delete it within 30 days, except where retention is required by law.

Meta data (Facebook & Instagram & WhatsApp)

If you connect a Facebook Page, Instagram account, or WhatsApp Business number, we receive the messages customers send to those accounts — the message content, the sender's platform-scoped id and display name, and any attached media — so they appear in your inbox and you can reply. Access is granted through Meta's OAuth / Embedded Signup and is used only to operate the messaging features. Tokens are encrypted at rest; message content is stored in our encrypted database to render the inbox. Disconnect any Meta channel at CS Hub → Settings → Channels; to delete stored Meta data, see the Data Deletion instructions (also reachable as our Data Deletion callback for Meta).

How we use information

We use the information above to provide and operate the Service: to sync and display your orders, products, and analytics; to route orders to suppliers and track fulfillment; to power the customer-support inbox; to secure and maintain the Service; and to communicate with you about your account. We do not sell personal information, and we do not use your customers' data to train general-purpose AI models.

AI processing

To draft and suggest replies in the support inbox, the content of customer messages and related store context may be sent to our AI subprocessor (Anthropic) acting on our behalf under contract. It processes the data only to return the requested output and is not permitted to use it for its own purposes or for model training.

How we share information / subprocessors

We share information only with service providers (subprocessors) that help us run the Service, each bound by contract to protect it:

  • Railway — cloud hosting + database infrastructure.
  • Anthropic — AI reply drafting/assistance.
  • Google — the Google integrations you connect (Gmail, Google Ads, Google Analytics, Google Business Profile).
  • Meta — the messaging channels you connect (Facebook, Instagram, WhatsApp).
  • Connected commerce, payment, and fulfillment providers you enable (e.g. WooCommerce, Shopify, Stripe, PayPal, ShipHero, ParcelWill) and email delivery providers.

We may also disclose information if required by law or to protect our rights, and in connection with a merger or acquisition. We never sell your data or your customers' data.

Data retention and deletion

We retain store, account, and channel data for as long as your workspace is active. We honor platform-mandated data-protection requests (for example, Shopify's customer data-request, customer-redact, and shop-redact webhooks). You may request deletion of any connected channel or of your entire workspace at any time — see the Data Deletion instructions — and we will delete the data within 30 days except where retention is required by law.

Security

We protect data in transit with TLS and encrypt credentials and access tokens at rest with AES-256-GCM. Access to production data is limited to personnel who need it to operate the Service. No method of transmission or storage is completely secure, but we use industry-standard safeguards.

International transfers

EcomWizzard is operated from the United States and may process and store information in the U.S. and other countries. Where we transfer personal data across borders, we use appropriate safeguards consistent with applicable law.

Your rights

Depending on where you live, you may have rights to access, correct, delete, or restrict the processing of your personal data, and to object to certain processing (including under the GDPR and CCPA). A store's customers should direct such requests to the merchant, who can fulfill them through the Service; we will assist merchants in responding. To exercise your own rights, contact us using the details below.

Children

The Service is intended for businesses and is not directed to children under 16. We do not knowingly collect personal data from children.

Changes to this policy

We may update this policy from time to time. When we do, we will revise the "Last updated" date above, and material changes will be communicated through the Service.

Contact us

Lightning Quest Inc. (DBA EcomWizzard), Wyoming, USA. For privacy or data-deletion requests, email privacy@ecomwizzard.com; for general support, support@ecomwizzard.com. See also our Contact page.