Last updated: August 26, 2026

Privacy Policy

1. Identity and Services of the Responsible Party

Entropy Global, Inc. ("Entropy," "Epyc App," "we," "us," or "our"), operating under the brand name Epyc App, is responsible for the collection, use, disclosure, and storage of personal data of users ("you," "user," or "data subject") through our website and platform at epyc.app (the "Service").

Epyc App is a smart budget management platform that helps digital marketers monitor, control, and optimize advertising spend across Google Ads, Meta (Facebook), TikTok, and Display & Video 360 (DV360) platforms through intelligent alerts, real-time insights, and advanced Marketing Mix Modeling experiments.

2. Precedence Over Other Agreements

If this Privacy Policy conflicts with any other agreement between you (or the organization you represent) and Entropy Global, Inc. or any of its affiliates — including agreements relating to models, algorithms, datasets, deliverables, or data access — this Privacy Policy and the Terms of Service shall control with respect to personal data processed through the Platform. Data processed under a separate engagement with Entropy Global, Inc. is governed exclusively by that engagement and does not constitute rights in the Platform or its data.

3. Personal Data We Collect

To provide our services, we collect and process the following categories of personal data:

Account Information:

  • Name and email address
  • Company/organization details
  • Account credentials and authentication data

Advertising Platform Data:

  • OAuth tokens and authorization credentials for Google Ads, Meta, TikTok, Display & Video 360 (DV360), Google Analytics 4, and Shopify
  • Campaign performance metrics (spend, impressions, clicks, conversions)
  • Budget and bid information
  • Ad account and campaign identifiers

Connected Store Data (Shopify):

When a merchant connects a Shopify store, we read the following through Shopify's Admin API using the read_orders and read_products scopes, and nothing else:

  • Orders: order number, creation date, payment and fulfillment status, currency, order totals, discounts, and line items (product title, SKU, quantity, price)
  • Products: title, status, vendor, product type, inventory levels, and variant SKUs and prices
  • The store's .myshopify.com domain, name and currency

We do not read your customers' personal data. Our order query never requests customer names, email addresses, phone numbers, or billing or shipping addresses. Shopify's API returns only the fields a query asks for, so that data never reaches our servers at all — it is not collected and then filtered out.

Store data is read on demand to answer a question you ask inside Epyc App. We do not run background syncs and we do not build a copy of your catalog or order history. We do not request the read_all_orders scope, so only roughly the last 60 days of orders are available to us.

What is stored: the answers you receive are part of a conversation, so the data returned for a question is saved with that conversation in our database as part of its history — the same way the question and answer themselves are. This lets you reopen a past conversation and see what it was based on. It is retained under the schedule in section 9 and is deleted when you delete the conversation.

Disconnecting the store in Epyc App deletes the stored authorization credentials for that store. Uninstalling the app from Shopify does the same, through Shopify's shop/redact notification.

Usage Data:

  • IP address and browser information
  • Device characteristics and operating system
  • Usage patterns and feature interactions
  • Log files and analytics data

Important: We do not collect sensitive personal data such as financial account numbers, social security numbers, or health information. All advertising platform connections use secure OAuth protocols and we never store your platform passwords.

3a. Commitments to Merchants Connecting a Store

Where we process data from a connected e-commerce store, the following commitments apply.

Purpose limitation

Store data is used only to answer the merchant's own questions about their business inside Epyc App — sales and revenue reporting, product performance, and comparison against connected advertising channels. We do not use it to train machine-learning models, to build profiles, or for any purpose the merchant has not asked for.

We do not sell personal data

We do not sell, rent or share personal data for cross-context behavioural advertising, and we never sell store or customer data to third parties. There is accordingly no sale to opt out of.

Customer consent decisions

We do not read the personal data of a merchant's customers, and we do not track, profile or market to them. Marketing-consent choices a customer makes with the merchant are therefore unaffected by this integration.

Automated decision-making

Epyc App uses automated analysis to summarise a merchant's own data and to suggest budget or campaign changes. These are recommendations shown to the merchant, who decides whether to act on them. No automated decision is made about an individual customer, and none produces a legal or similarly significant effect on any individual. Merchants can ask us to review or explain any recommendation using the contact details in section 12.

4. How We Use Your Data

We process your personal data for the following purposes:

Core Services:

  • Create and manage your account
  • Connect to advertising platforms via OAuth
  • Monitor campaign spending and performance
  • Send budget alerts and notifications
  • Generate MMM experiments and insights
  • Provide customer support

Platform Improvements:

  • Analyze usage patterns to improve features
  • Conduct security monitoring
  • Maintain and optimize platform performance
  • Develop new features and capabilities
  • Ensure compliance with platform policies

5. Data Sharing and Transfers

We may share your personal data in the following limited circumstances:

Service Providers:

With third-party service providers who help us operate our platform (cloud hosting, analytics, customer support) under strict data processing agreements.

Legal Requirements:

When required by law, court order, or to protect our rights and safety or that of our users.

Business Transfers:

In connection with a merger, acquisition, or sale of assets, with appropriate data protection measures.

6. Your Rights and Controls

You have the following rights regarding your personal data:

Access & Portability

Request a copy of your personal data in a portable format

Rectification

Correct inaccurate or incomplete personal data

Deletion

Request deletion of your personal data (with certain limitations)

Withdraw Consent

Revoke consent for data processing at any time

How to Exercise Your Rights:

To exercise any of these rights, please contact us at:

  • Email: [email protected]
  • Response Time: We will respond within 30 days
  • Verification: We may need to verify your identity before processing requests

7. Data Security

We implement comprehensive security measures to protect your personal data:

Encryption

Data encrypted in transit and at rest using industry-standard protocols

OAuth Security

Secure OAuth 2.0 authentication with automatic token refresh

Access Controls

Role-based access controls and regular security audits

8. Cookies and Tracking

We use cookies and similar technologies to improve your experience on our platform. These help us remember your preferences, analyze usage patterns, and provide personalized features.

Cookie Control: You can manage cookie preferences through your browser settings. However, disabling certain cookies may limit platform functionality.

9. Data Retention

We retain your personal data only as long as necessary to:

  • Provide our services to you
  • Comply with legal obligations
  • Resolve disputes and enforce agreements
  • Maintain security and fraud prevention

When you delete your account, we will delete or anonymize your personal data within 30 days, except where retention is required by law.

10. International Data Transfers

Your data may be processed in countries other than your country of residence. We ensure appropriate safeguards are in place for all international transfers, including standard contractual clauses approved by relevant authorities.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. For significant changes, we may also send you an email notification.

12. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Email: [email protected]

Support: [email protected]

Response Time: We will respond to privacy inquiries within 30 days