Layla for Shopify — Privacy Policy

Last updated: 22 August 2026

1. Who we are

Layla is a marketing-operations platform built and operated by Business Khana. Marketing agencies use it to run their clients' work in one place: campaigns, content, meetings, invoices and performance reporting.

The Layla Shopify app exists for one purpose: to bring a store's daily sales totals into the agency's performance reports, so ad spend can be compared against revenue that actually landed.

2. What the app requests

The app requests exactly one scope:

  • read_orders — read access to orders and refunds

It requests no other scope. It does not request customer, product, inventory, theme, discount, or price-rule access, and it never writes to the store.

3. What we store — and what we do not

The app reads orders, aggregates them by day, and stores only the totals. One row per store per day:

  • number of orders placed, and how many of those were cancelled
  • number of items sold
  • gross revenue, refunds, and net revenue
  • the store's currency

We do not store any of the following, at any point:

  • customer names, email addresses, phone numbers or postal addresses
  • individual orders, order numbers, or line-item detail
  • payment details of any kind
  • the raw API response — order payloads are aggregated in memory and discarded

In other words, the app holds no personal data. What remains after a sync is a set of daily numbers that cannot identify a person.

4. How the data is used

  • Shown to the agency and, where the agency enables it, to the merchant in their client portal
  • Combined with advertising data (e.g. Meta) to calculate cost per order and return on ad spend

The data is never sold, rented, shared for advertising, used to train machine-learning models, or shared with any third party for their own purposes.

5. Sub-processors

Layla runs on a small, fixed set of providers:

  • Supabase — database and file storage (EU region)
  • Vercel — application hosting
  • Brevo — transactional email

Each processes data only to provide its service to us, under its own data-processing terms.

6. Security

  • All traffic is encrypted in transit (HTTPS/TLS)
  • Access tokens are stored server-side, never exposed to a browser, and never logged
  • Every table is protected by row-level security, so one agency cannot read another's data
  • Both public endpoints the app exposes — the OAuth callback and the webhook receiver — verify Shopify's HMAC signature with a constant-time comparison before any other processing, and the install flow is protected by a single-use CSRF nonce

7. Retention and deletion

Uninstalling the app ends our access immediately: the token stops working. When Shopify sends us the shop/redact notification 48 hours after uninstall, we erase the store's access token, the app credentials, and the store domain — everything that could identify or reach the store.

The daily aggregate numbers are retained as the agency's own record of the campaigns it ran. They contain no personal data and cannot be linked back to a customer or an order. A merchant who wants those numbers deleted as well can ask us and we will delete them — see section 9.

8. GDPR / CCPA compliance requests

We implement all three mandatory Shopify compliance webhooks:

  • customers/data_request — we hold no personal data about any customer, so there is nothing to disclose. The request is recorded and answered on that basis.
  • customers/redact — we hold no personal data about any customer, so there is nothing to erase. The request is recorded.
  • shop/redact — we erase the store's credentials and domain as described in section 7. The request is recorded.

Every compliance request we receive is logged with its outcome, so we can account for how it was handled.

9. Your rights, and how to reach us

You may ask us what data we hold about your store, ask for it to be corrected, or ask for it to be deleted. We answer within 30 days.

10. Changes to this policy

If we change what the app accesses or stores, we will update this page and change the date at the top before the change takes effect.