Last Updated: October 2026
Ardor Digital (“Ardor,” “we,” “our,” or “us”) is a sole proprietorship registered in Nova Scotia, Canada. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information through our website, marketing and consulting services, and software products, including Ardor Reporting Dashboard, Ardor Creative Operations, and related client review tools.
We provide services to businesses internationally. The information we process depends on the service you use, the permissions you grant, and the instructions of the business whose information we handle. This policy does not replace any applicable data processing agreement with a client.
We provide services to businesses internationally. The information we process depends on the service you use, the permissions you grant, and the instructions of the business whose information we handle. This policy does not replace any applicable data processing agreement with a client.
We may collect personal information when you interact with our website, contact us, or engage with our services.
This may include:
When providing services or operating connected software, we may receive business and marketing information from clients, their authorized users, and platforms they authorize us to access. This can include store and advertising account identifiers, campaign settings, creative content, marketing performance metrics, and review or approval records.
Product-specific sections below describe the information used by particular integrations. Connecting a platform does not give us unrestricted access to everything in that platform; access depends on the permissions granted and the functions enabled.
When visiting our website, we may automatically collect certain technical information, including:
This information helps us understand how visitors use our site and improve the website experience.
When providing services or operating connected software, we may receive business and marketing information from clients, their authorized users, and platforms they authorize us to access. This can include store and advertising account identifiers, campaign settings, creative content, marketing performance metrics, and review or approval records.
If you are located in the European Economic Area (EEA) or the United Kingdom, we process personal data under the following lawful bases:
Product-specific sections below describe the information used by particular integrations. Connecting a platform does not give us unrestricted access to everything in that platform; access depends on the permissions granted and the functions enabled.
Consent
When you voluntarily submit information through forms or subscribe to communications.
Legitimate Interests
When processing is necessary for legitimate business purposes, such as responding to inquiries, improving our services, or maintaining relationships with prospective clients.
Contractual Necessity
When processing data required to provide services to clients.
We use information for the purposes appropriate to the relationship and service, including the following:
We limit the collection and use of personal information to what is reasonably necessary for these purposes. We do not use information obtained from a connected client platform to send unrelated marketing communications.
When we handle customer or campaign information on a client’s documented instructions, we act as a processor or service provider for that client, as applicable. The client is responsible for its purposes for processing and for having the necessary authority to provide or connect the information.
We are responsible for our own processing of business contact information, account administration, service security, and other purposes we determine. Where an agency uses our software for its own clients, the applicable agreements define the parties’ roles and responsibilities, including any subprocessor relationship.
We use client platform information to provide the authorized service, support the account, and protect the service. Permission to connect an account does not authorize unrelated marketing use of the information.
Ardor Digital operates Ardor Reporting Dashboard, a private reporting tool that produces read-only performance reports for the Shopify stores we manage on behalf of our clients. For each connected store, the merchant is the data controller and Ardor Digital acts as a data processor.
Data we access. Through the Shopify Admin API, and only after the store grants access, the app reads: order data (including orders older than 60 days), customer records, and product and inventory data. This data is used solely to calculate aggregate performance metrics — total revenue, order counts, average order value, new-vs-returning customer split, repeat-purchase rate, cohort retention, and customer lifetime value.
Data minimization. The app does not request, access, or store protected customer personal fields — no customer name, email address, phone number, or postal address. Order and customer records are aggregated into the metrics above and then discarded; we do not retain individual orders or customers as personal data. Only non-personal, aggregated figures are stored.
Purpose limitation. This data is used only to generate the merchant's own performance report. We never sell, rent, or share it, and never use it for advertising or automated decisions affecting individuals.
Storage and security. Aggregated data is held in an access-controlled datastore that is encrypted at rest, and all data is transmitted over TLS. Stored access
credentials are additionally encrypted using AES-256-GCM. Reports are accessible only via a private per-client link, and administrative access is restricted to authorized Ardor Digital personnel.
Sub-processors. We use the following sub-processors to operate the app: Vercel (application hosting and compute) and Upstash (encrypted data storage). This list may be updated as our infrastructure changes.
Retention and deletion. Aggregated metrics are retained only for as long as needed to provide reporting for the engagement. The app implements Shopify's mandatory data-protection webhooks: on a customer redaction request we confirm that no customer personal data is held; and when a store uninstalls the app or requests shop redaction, all of that store's data is permanently deleted (within 48 hours of Shopify's shop-redaction request). Merchants may also request deletion at any time by contacting hello@ardordigital.com.
When we handle customer or campaign information on a client’s documented instructions, we act as a processor or service provider for that client, as applicable. The client is responsible for its purposes for processing and for having the necessary authority to provide or connect the information.
Ardor Creative Operations supports advertising reporting, creative analysis, review and approval, and authorized deployment of ads for connected Meta advertising accounts. Functionality depends on the version of the service available to your organization and the access it grants.
Depending on the permissions granted and functions enabled, the service processes:
This describes account, creative, and reporting information; it does not mean we receive the identities of everyone who sees or clicks an ad. Our initial Meta integration is not intended to collect individual lead-form submissions or upload customer lists to create audiences.
We use connected information to import and display ads, calculate reports, compare creative performance within relevant campaign contexts, support review and approval, and carry out deployment actions authorized through the service. We also use necessary operational information to investigate failures, provide support, maintain security, and record who authorized changes.
Creative analysis and recommendations concern advertising performance. They do not guarantee results or establish that a creative caused a particular outcome.
Information is available to authorized users within the relevant client or agency workspace and to Ardor personnel or contractors who need access to deliver, support, or secure the service. We also use contracted infrastructure providers for hosting, storage, authentication, and related operations.
We do not sell connected Meta information or disclose it to unrelated customers for their own marketing. We do not use it for cross-client benchmarking, training general-purpose AI models, or unrelated advertising. Any future use outside the purposes described here would require a separate assessment of applicable platform rules, legal requirements, and notices or permissions.
We apply access controls and safeguards appropriate to the information processed. Access credentials must be protected and restricted to the systems and personnel that need them. Our general Data Security section applies.
We retain connected advertising information while needed to provide the authorized service. When an integration is disconnected, we stop further collection through that connection. Disconnecting access and deleting previously stored information are separate actions.
You can request deletion by following our Data Deletion Instructions or contacting hello@ardordigital.com. We verify the request and the requester’s authority before deleting information from a shared client workspace.
Where retention is required by applicable law, we retain only the necessary information for the required period, restrict its use, and explain the exception where permitted. This does not create a general right to retain Meta data contrary to applicable platform requirements.
Deleting information from Ardor’s systems does not itself delete ads, campaigns, Pages, Instagram content, or other records held by Meta. Those records remain subject to Meta’s controls and policies.
You may decline or revoke platform permissions, although this can prevent affected features from working. You may also request access, correction, or deletion of information held by Ardor, subject to applicable rights and verification of your authority. Requests concerning information controlled by one of our clients may need to be handled with that client.
Data Deletion Instructions: https://ardordigital.com/data-deletion.
Our website may use cookies or similar technologies to:
We are responsible for our own processing of business contact information, account administration, service security, and other purposes we determine. Where an agency uses our software for its own clients, the applicable agreements define the parties’ roles and responsibilities, including any subprocessor relationship.
These may include services such as analytics platforms or marketing tools.
We use client platform information to provide the authorized service, support the account, and protect the service. Permission to connect an account does not authorize unrelated marketing use of the information.
You can manage or disable cookies through your browser settings.
Where required by applicable law (such as in the EU or UK), cookie consent may be requested before certain tracking technologies are activated.
We use service providers to operate our business and deliver our services; product-specific provider information appears above where applicable. These providers may include:
These services may process limited personal information on our behalf and are required to protect that information in accordance with applicable privacy laws.
Because Ardor Digital operates internationally and uses global software platforms, personal information may be transferred to or processed in countries outside your own jurisdiction.
Where personal data is transferred internationally, we take reasonable steps to ensure appropriate safeguards are in place to protect that data in accordance with applicable privacy laws, including GDPR where applicable.
We retain personal information only for as long as necessary to:
Ardor Creative Operations supports advertising reporting, creative analysis, review and approval, and authorized deployment of ads for connected Meta advertising accounts. Functionality depends on the version of the service available to your organization and the access it grants.
When information is no longer required, we take reasonable steps to securely delete or anonymize it.
Depending on your jurisdiction, you may have certain rights regarding your personal information.
For individuals in the European Economic Area and the United Kingdom, these rights may include:
Depending on the permissions granted and functions enabled, the service processes:
You may also have the right to lodge a complaint with a data protection authority.
To exercise any of these rights, please contact us using the contact details below.
This describes account, creative, and reporting information; it does not mean we receive the identities of everyone who sees or clicks an ad. Our initial Meta integration is not intended to collect individual lead-form submissions or upload customer lists to create audiences.
We implement reasonable administrative, technical, and organizational safeguards to protect personal information against unauthorized access, loss, misuse, or disclosure.
However, no internet transmission or electronic storage method can be guaranteed to be completely secure.
We may update this Privacy Policy periodically to reflect changes in legal requirements or our practices.
We use connected information to import and display ads, calculate reports, compare creative performance within relevant campaign contexts, support review and approval, and carry out deployment actions authorized through the service. We also use necessary operational information to investigate failures, provide support, maintain security, and record who authorized changes.
Any updates will be posted on this page with an updated revision date.
Creative analysis and recommendations concern advertising performance. They do not guarantee results or establish that a creative caused a particular outcome.
If you have questions about this Privacy Policy or how your data is handled, you may contact us at:
Ardor Digital
99 Wyse Road, Suite 1100
Dartmouth, Nova Scotia,
B3A 4S5, Canada
Website: https://www.ardordigital.com
Email: hello@ardordigital.com
Information is available to authorized users within the relevant client or agency workspace and to Ardor personnel or contractors who need access to deliver, support, or secure the service. We also use contracted infrastructure providers for hosting, storage, authentication, and related operations.
Data Deletion Instructions: [insert published URL].
We do not sell connected Meta information or disclose it to unrelated customers for their own marketing. We do not use it for cross-client benchmarking, training general-purpose AI models, or unrelated advertising. Any future use outside the purposes described here would require a separate assessment of applicable platform rules, legal requirements, and notices or permissions.
You may decline or revoke platform permissions, although this can prevent affected features from working. You may also request access, correction, or deletion of information held by Ardor, subject to applicable rights and verification of your authority. Requests concerning information controlled by one of our clients may need to be handled with that client.
Deleting information from Ardor’s systems does not itself delete ads, campaigns, Pages, Instagram content, or other records held by Meta. Those records remain subject to Meta’s controls and policies.
Where retention is required by applicable law, we retain only the necessary information for the required period, restrict its use, and explain the exception where permitted. This does not create a general right to retain Meta data contrary to applicable platform requirements.
We apply access controls and safeguards appropriate to the information processed. Access credentials must be protected and restricted to the systems and personnel that need them. Our general Data Security section applies.
[
You can request deletion by following our Data Deletion Instructions or contacting hello@ardordigital.com. We verify the request and the requester’s authority before deleting information from a shared client workspace.
We retain connected advertising information while needed to provide the authorized service. When an integration is disconnected, we stop further collection through that connection. Disconnecting access and deleting previously stored information are separate actions.