Legal
Privacy
What we read, what we refuse to read, and what you can make us delete.
Effective 28 July 2026
The short version
We read advertising, analytics and order data from the tools you already pay for, so we can check what each of them claims against evidence from the others. That is the entire purpose. We do not sell your data, we do not pool it with any other brand’s, and we never ask the platforms for your customers’ names, email addresses, phone numbers or postal addresses.
Everything below is the specific version of that paragraph. If the two ever disagree, the specific version governs.
Who we are
Incremental.ai LLC (“Incremental.ai”, “we”) operates the service at getincremental.ai. When you connect a platform to us, you are the controller of that data and we process it on your instructions.
What we collect about you
Your account. Your name, work email address, the brand or company you represent, and any teammates you invite. If you subscribe, Shopify bills you directly — the charge appears on your Shopify invoice, and we never see or store a card number.
Your onboarding answers. A short questionnaire covering things the data cannot tell us on its own — your brand name and brand search terms, which channels you run, and how you account for spend. We use these to interpret your data correctly.
Ordinary service logs. Which accounts were accessed and when, so we can answer questions about a report later. We log access to your data. We do not log the data itself, and we never put personal or platform data in a URL.
What we read from the platforms you connect
Nothing here is collected until you explicitly connect that platform, and disconnecting it stops the reading immediately. We request the narrowest permission each platform offers — read-only in every case. We ask Meta for ads_read, not ads_management: we can see your advertising results and cannot change your campaigns, your budgets or your creative.
| Platform | What we read |
|---|---|
| Meta Ads | Ad account, campaign, ad set and ad structure; spend, impressions and clicks; and the conversions and revenue Meta itself claims |
| Google Ads | Campaign and search-term performance, spend, and Google’s claimed conversions |
| Google Analytics 4 | Sessions and revenue by channel grouping |
| Google Search Console | Query-level impressions and clicks, to separate branded from unbranded demand |
| Shopify | Order-level revenue, refunds, discounts, currency, order source and referral path, and a pseudonymous customer identifier |
| Klaviyo | Campaign and flow revenue attributed to the Placed Order metric |
| TikTok Ads and Pinterest Ads | Campaign performance, spend, and each platform’s claimed conversions |
| Awin and Impact | Affiliate transaction records, their approval status, commission owed, and the partner name |
What we deliberately never ask for
This is a design decision in the code, not a policy promise laid over it. Our Shopify query requests a customer’s identifier and nothing else, because all we need to know is whether an order was that person’s first. We never request, receive or store:
- Customer names
- Customer email addresses or phone numbers
- Shipping or billing addresses
- Payment card numbers or bank details
We do receive the referring website and landing page for an order where you have granted access to it, linked to that pseudonymous identifier. Under GDPR that combination is personal data, so we treat it as personal data, and it is covered by everything below.
Where your platform credentials live
We do not hold your access tokens. Authorisation runs through Nango, a managed OAuth provider, and the tokens stay in their vault. Our database stores a reference to the connection, not the credential behind it. This is deliberate: a compromise of our systems does not hand anyone the keys to your ad accounts.
What we do with it
We use it to produce your reports, and for nothing else. Each platform’s claim about what it caused is compared against independent evidence from the others, and the result is an estimate of what your advertising actually drove, together with the reasoning behind it. We keep a record of which inputs and which version of our software produced every number, so that any figure you question months later is traceable.
What we never do
- Sell your data, or share it with data brokers
- Use it to advertise to your customers, or to build audiences of any kind
- Pool it with another brand’s. Every brand’s data is stored separately and enforced at the database layer, and the calibration that improves your estimates over time is built only from your own results — never from a shared model trained across our customers
- Let one brand see, or be inferred from, another brand’s data
- Give any platform data about a competitor who also uses us
Who else touches it
We use a small number of vendors to run the service: Nango for platform authorisation and Supabase for database hosting. Each is bound to use your data only to provide their service to us. We do not add vendors that would take your data outside this list without updating this page.
Subscriptions are billed by Shopify, through their Billing API, so your payment details stay with Shopify and never reach us or any processor of ours.
How long we keep it, and how to make us delete it
We keep your connected platform data for as long as your account is active, because the history is what makes each new month’s estimate better than the last.
You can disconnect any platform at any time, which stops all further reading from it immediately. You can ask us to delete everything at any time, whether or not you close your account. We complete deletion within 30 days and confirm when it is done.
Full instructions, and what survives deletion and why, are on Deleting your data.
Your rights
Wherever you are, you can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. If you are in the EEA or UK you additionally have the right to object to or restrict processing, the right to portability, and the right to complain to your data protection authority. If you are in California you have the rights granted by the CCPA, including the right to know and the right to delete — and note that we do not sell personal information, so there is nothing to opt out of.
Write to support@getincremental.ai and we will respond within 30 days. We do not charge for this and we will not make you justify the request.
Security
Data is encrypted in transit and at rest. Access between brands is isolated at the database layer rather than only in application code, so a mistake in our software cannot quietly cross that boundary. Access to production data is limited to those who need it and is logged.
Our service is for businesses. It is not directed at children and we do not knowingly collect data from anyone under 16.
Changes
If we change how we handle your data in a way that matters, we will email you before it takes effect rather than quietly changing the date at the top of this page.
Contact
Incremental.ai LLC is a New York limited liability company, registered with the New York State Department of State under DOS ID 7976997.
Incremental.ai LLC
New York, United States
Everything reaches us at support@getincremental.ai — including privacy, data access and deletion requests.
See also Privacy, Terms and Deleting your data.