Last updated: August 26, 2026
Privacy Policy
1. Identity and Services of the Responsible Party
Entropy Global, Inc. ("Entropy," "Epyc App," "we," "us," or "our"), operating under the brand name Epyc App, is responsible for the collection, use, disclosure, and storage of personal data of users ("you," "user," or "data subject") through our website and platform at epyc.app (the "Service").
Epyc App is a smart budget management platform that helps digital marketers monitor, control, and optimize advertising spend across Google Ads, Meta (Facebook), TikTok, and Display & Video 360 (DV360) platforms through intelligent alerts, real-time insights, and advanced Marketing Mix Modeling experiments.
2. Precedence Over Other Agreements
If this Privacy Policy conflicts with any other agreement between you (or the organization you represent) and Entropy Global, Inc. or any of its affiliates — including agreements relating to models, algorithms, datasets, deliverables, or data access — this Privacy Policy and the Terms of Service shall control with respect to personal data processed through the Platform. Data processed under a separate engagement with Entropy Global, Inc. is governed exclusively by that engagement and does not constitute rights in the Platform or its data.
3. Personal Data We Collect
To provide our services, we collect and process the following categories of personal data:
Account Information:
- Name and email address
- Company/organization details
- Account credentials and authentication data
Advertising Platform Data:
- OAuth tokens and authorization credentials for Google Ads, Meta, TikTok, Display & Video 360 (DV360), Google Analytics 4, and Shopify
- Campaign performance metrics (spend, impressions, clicks, conversions)
- Budget and bid information
- Ad account and campaign identifiers
Connected Store Data (Shopify):
When a merchant connects a Shopify store, we read the following through Shopify's
Admin API using the read_orders and read_products scopes,
and nothing else:
- Orders: order number, creation date, payment and fulfillment status, currency, order totals, discounts, and line items (product title, SKU, quantity, price)
- Products: title, status, vendor, product type, inventory levels, and variant SKUs and prices
- The store's
.myshopify.comdomain, name and currency
We do not read your customers' personal data. Our order query never requests customer names, email addresses, phone numbers, or billing or shipping addresses. Shopify's API returns only the fields a query asks for, so that data never reaches our servers at all — it is not collected and then filtered out.
Store data is read on demand to answer a question you ask inside
Epyc App. We do not run background syncs and we do not build a copy of your catalog
or order history. We do not request the read_all_orders scope, so only
roughly the last 60 days of orders are available to us.
What is stored: the answers you receive are part of a conversation, so the data returned for a question is saved with that conversation in our database as part of its history — the same way the question and answer themselves are. This lets you reopen a past conversation and see what it was based on. It is retained under the schedule in section 9 and is deleted when you delete the conversation.
Disconnecting the store in Epyc App deletes the stored authorization credentials for
that store. Uninstalling the app from Shopify does the same, through Shopify's
shop/redact notification.
Usage Data:
- IP address and browser information
- Device characteristics and operating system
- Usage patterns and feature interactions
- Log files and analytics data
Important: We do not collect sensitive personal data such as financial account numbers, social security numbers, or health information. All advertising platform connections use secure OAuth protocols and we never store your platform passwords.
3a. Commitments to Merchants Connecting a Store
Where we process data from a connected e-commerce store, the following commitments apply.
Purpose limitation
Store data is used only to answer the merchant's own questions about their business inside Epyc App — sales and revenue reporting, product performance, and comparison against connected advertising channels. We do not use it to train machine-learning models, to build profiles, or for any purpose the merchant has not asked for.
We do not sell personal data
We do not sell, rent or share personal data for cross-context behavioural advertising, and we never sell store or customer data to third parties. There is accordingly no sale to opt out of.
Customer consent decisions
We do not read the personal data of a merchant's customers, and we do not track, profile or market to them. Marketing-consent choices a customer makes with the merchant are therefore unaffected by this integration.
Automated decision-making
Epyc App uses automated analysis to summarise a merchant's own data and to suggest budget or campaign changes. These are recommendations shown to the merchant, who decides whether to act on them. No automated decision is made about an individual customer, and none produces a legal or similarly significant effect on any individual. Merchants can ask us to review or explain any recommendation using the contact details in section 12.
4. How We Use Your Data
We process your personal data for the following purposes:
Core Services:
- Create and manage your account
- Connect to advertising platforms via OAuth
- Monitor campaign spending and performance
- Send budget alerts and notifications
- Generate MMM experiments and insights
- Provide customer support
Platform Improvements:
- Analyze usage patterns to improve features
- Conduct security monitoring
- Maintain and optimize platform performance
- Develop new features and capabilities
- Ensure compliance with platform policies
5. Data Sharing and Transfers
We may share your personal data in the following limited circumstances:
Service Providers:
With third-party service providers who help us operate our platform (cloud hosting, analytics, customer support) under strict data processing agreements.
Legal Requirements:
When required by law, court order, or to protect our rights and safety or that of our users.
Business Transfers:
In connection with a merger, acquisition, or sale of assets, with appropriate data protection measures.
6. Your Rights and Controls
You have the following rights regarding your personal data:
Access & Portability
Request a copy of your personal data in a portable format
Rectification
Correct inaccurate or incomplete personal data
Deletion
Request deletion of your personal data (with certain limitations)
Withdraw Consent
Revoke consent for data processing at any time
How to Exercise Your Rights:
To exercise any of these rights, please contact us at:
- Email: [email protected]
- Response Time: We will respond within 30 days
- Verification: We may need to verify your identity before processing requests
7. Data Security
We implement comprehensive security measures to protect your personal data:
Encryption
Data encrypted in transit and at rest using industry-standard protocols
OAuth Security
Secure OAuth 2.0 authentication with automatic token refresh
Access Controls
Role-based access controls and regular security audits
8. Cookies and Tracking
We use cookies and similar technologies to improve your experience on our platform. These help us remember your preferences, analyze usage patterns, and provide personalized features.
Cookie Control: You can manage cookie preferences through your browser settings. However, disabling certain cookies may limit platform functionality.
9. Data Retention
We retain your personal data only as long as necessary to:
- Provide our services to you
- Comply with legal obligations
- Resolve disputes and enforce agreements
- Maintain security and fraud prevention
When you delete your account, we will delete or anonymize your personal data within 30 days, except where retention is required by law.
10. International Data Transfers
Your data may be processed in countries other than your country of residence. We ensure appropriate safeguards are in place for all international transfers, including standard contractual clauses approved by relevant authorities.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. For significant changes, we may also send you an email notification.
12. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
Email: [email protected]
Support: [email protected]
Response Time: We will respond to privacy inquiries within 30 days