B2B Gold

Privacy policy

Last updated

This website collects nothing. The apps and extensions are a different question, and each one answers it differently — so the second half of this page takes them one at a time.

What this policy covers

This page covers b2bgold.app, the website you are reading. It is not the policy for any app or extension.

Each product runs somewhere else — inside your Shopify store, or inside your browser — handles different data, and publishes its own policy. Those policies govern. The summaries further down exist so you can compare the products without opening five documents, and each one carries the date printed on the document it came from. Where a summary and a product’s own policy disagree, the product’s policy is the one that counts.

What this website collects

Nothing. Not as a policy position — there is no mechanism.

  • No cookies. The site sets none, of any kind, for any purpose. There is no consent banner because there is nothing to consent to.
  • No analytics. No page-view counter, no session recorder, no tag manager, no pixel. Not a cookieless one either.
  • No third-party requests. Every font, image and stylesheet is served from this domain. The site’s Content-Security-Policy allows scripts, styles, images, fonts and network connections from b2bgold.app and nowhere else, so a third-party request could not be made even by accident.
  • No JavaScript. The pages ship none. The only <script>tag on any page holds application/ld+json structured data for search engines, which browsers do not execute. A build check fails if an executable one ever appears.
  • Nothing to submit. There are no accounts, no sign-up, no forms, no checkout and no search box.

The pages are static files served from Cloudflare’s network. No application code of ours runs when you request one, so there is nothing on our side that could record your visit — no server-side logging we operate, and no database for a visit to land in. Cloudflare handles the request itself, as the network delivering the file.

If you email the studio, we keep the conversation, and we use it to answer you. Nothing else.

What is true of every product

Five things hold across the products, each of them stated in the products’ own policies. Everything else — where data is stored, for how long, and who else touches it — differs enough per product that a studio-wide answer would be wrong for at least one of them, which is what the next section is for.

  • Nothing is sold. X Shield and UpBar both say so in their policies. All Pixel Helper sends nothing off your device at all. cPixel transmits only to the advertising platforms you connect, at your direction.
  • Your store’s data is yours. For the Shopify apps you are the controller and B2B Gold is the processor: the apps act on your instructions, which are the settings you choose. Telling your own customers what you have installed, and collecting any consent your jurisdiction requires, is your responsibility rather than ours — all three Shopify products say so in writing.
  • Shopify’s mandatory privacy webhooks are implemented by all three Shopify apps: customer data request, customer redaction and shop redaction. When a customer asks you for their data or asks to be erased, and when you uninstall, Shopify notifies the app and the app acts on it.
  • Data is encrypted in transit with TLS and encrypted at rest. X Shield and cPixel both add that production access requires hardware-backed passkeys rather than passwords.
  • Nothing here is aimed at children. X Shield and All Pixel Helper both say under 13 explicitly; UpBar states its service is directed at merchants. These are tools for merchants and for the people who debug their tracking.

What each app and extension does

One entry per product currently published, in the order the site lists them. Each summary is taken from that product’s own policy and dated to it.

All Pixel Helper

All Pixel Helper - Tag & dataLayer Debugger on the Chrome Web Store · summary as published May 2026

The extension collects, transmits and sells nothing. It runs entirely on your device, and it has no network code that contacts any backend.

What it handles

  • Outbound requests are observed through Chrome’s read-only webRequest API. Only requests matching a built-in list of advertising and analytics endpoints are decoded; everything else is ignored. Nothing is blocked, modified or redirected.
  • Page-side JavaScript globals such as window.fbq, window.gtag, window.dataLayer and window.ttq are read to detect which pixels are installed.
  • Performance timing entries are read for known pixel script URLs, to flag scripts that load after the page completes.
  • Access to all URLs is requested because pixels can fire on any domain and the extension cannot know in advance which sites you will debug. It is read-only.

How long it keeps it

  • Captured events live in chrome.storage.session, which Chrome wipes when you close the browser.
  • A bounded buffer of at most 500 events per tab. Nothing is written to disk-persistent storage.
  • No cookies, no localStorage, no IndexedDB.

Shared with. Nobody. No third-party SDK or service is embedded or called at runtime, and no telemetry, crash report or usage analytic is sent anywhere.

Core Web Vitals (iframes)

Core Web Vitals (iframes) on the Chrome Web Store

No summary is published here yet. Its Chrome Web Store listing is the authoritative source for what this extension does with your data.

HTTP Header Modifier

HTTP Header Modifier on the Chrome Web Store

No summary is published here yet. Its Chrome Web Store listing is the authoritative source for what this extension does with your data.

cPixel

cPixel: Meta & OpenAI Ads CAPI on the Shopify App Store · summary as published August 2026

You are the controller, B2B Gold is the processor, and your instructions are the platforms you connect and the settings you choose. The advertising platforms themselves are independent controllers or your own processors under your agreement with them — not sub-processors of ours.

What it handles

  • Online identifiers: advertising click identifiers and platform cookies.
  • Technical data: IP address and browser user agent.
  • Transaction data: order value, currency, line items, order and checkout identifiers.
  • Customer email address and phone number, SHA-256 hashed on your store before transmission and never sent in readable form. The Shopify customer id is hashed for Meta and OpenAI Ads, and carried unhashed only in Google Analytics 4’s user_id field, the one form that platform accepts.
  • Those customer identifiers are sent only while Shopify’s Protected Customer Data approval is in force. The restriction is enforced in code: without the approval they are withheld and matching falls back to click identifiers, IP address and user agent.
  • Customer names and postal addresses are not processed at all. They are neither requested from Shopify nor sent to any platform. No special-category data is processed.

How long it keeps it

  • Event data: not stored — transmitted and discarded.
  • Match data (click identifiers, cookies, IP, user agent): 7 days.
  • Queued order identifiers: 7 days.
  • Reconciliation records: 45 days.
  • Live debug sessions: not stored — redacted, streamed to your browser, discarded.
  • Store configuration and credentials: until uninstall, then deleted on shop redaction.

Shared with. Cloudflare, Inc. for all compute, database, storage and email delivery. Notice is given before a sub-processor is added, and you may object.

Where it is processed. Cloudflare’s global network, under Cloudflare’s own processing terms and transfer mechanisms.

UpBar

UpBar: Countdown Timer Bar on the Shopify App Store · summary as published July 2026

UpBar stores no personally identifiable information about your customers or shoppers. It holds shop-level records only.

What it handles

  • Your Shopify shop domain and the Shopify-issued offline access tokens used to keep the app working between sessions.
  • Your app settings — bar content, free-shipping thresholds, per-country display rules. These are stored as a metafield on your shop, inside your Shopify account, not in a separate database here.
  • An approximate visitor country or region, determined at request time to pick which shipping estimate to show. It is not stored and not linked to a person.
  • Permission scopes are limited to reading your theme and reading and writing files. The app does not request access to your customers, orders, Markets or shipping settings.

How long it keeps it

  • Shop records and access tokens: deleted within 48 hours of uninstall.
  • App configuration: removed when you uninstall or delete it, since it lives in your own Shopify metafield.
  • Operational and webhook logs: up to 90 days.
  • Support conversations: up to 2 years.
  • Anonymised or aggregated statistics: may be kept indefinitely.

Shared with. The policy names cloud hosting and infrastructure providers bound by data protection agreements, without listing them individually.

X Shield

X Shield: IP Country Blocker on the Shopify App Store · summary as published August 2026

Two roles at once. Storefront and order data is yours and is processed on your instructions. Your store details, settings and the store owner’s email address are held by B2B Gold as controller, to run the app and support you.

What it handles

  • A security event for each storefront page load: the visitor’s IP address, the country, continent and city derived from it, the network behind it (ASN, provider, threat score), the browser user agent, the page and referring URL, a timestamp, and identifiers the app generates for the visitor and the session.
  • Where a visitor is signed in and your storefront exposes it, the Shopify customer id, display name and email address, so a blocked visit can be traced back to a real account and so access and erasure requests can be answered.
  • Your store domain, plan, install status and every rule you configure. Blocking decisions are made in the visitor’s browser; the app does not read form input or payment details.
  • Sessions on the app’s own admin pages are recorded with Microsoft Clarity. The only identifier sent is your myshopify.com domain, never the owner’s name or email, and it does not run on your storefront.
  • Order data only if you switch order protection on: each new order’s IP address, customer identifiers and Shopify’s fraud signals, written back to the order as an assessment. It never cancels or refunds an order.

How long it keeps it

  • Raw security events: 90 days, dropped automatically day by day.
  • Aggregated dashboard and report counts: 90 days.
  • App configuration and merchant settings: deleted within 48 hours of uninstall.
  • Privacy request records, including anything exported: up to 180 days.
  • Merchant contact details: while you are subscribed, deleted within 30 days of opting out or uninstalling.
  • Support conversations: 2 years.

Shared with. Shopify, Google Cloud (BigQuery), MongoDB, Railway, Cloudflare, Brevo, and Microsoft (Clarity, on the app’s admin pages only) — each under a data-processing agreement.

Where it is processed. The United States, the European Union and Vietnam, under standard contractual clauses and equivalent safeguards.

Making a data request

If you are a shopper and want to know what a store holds about you, ask the store. The merchant is the controller; Shopify has a built-in flow for exactly this, and it reaches every installed app through the mandatory webhooks above.

If you are a merchant, you can raise a request through Shopify or write to us directly to access, correct, export or delete data, or to object to processing. X Shield’s policy is the most explicit about how these are handled: a person reviews each request before anything is exported or erased, and it is completed within the 30-day statutory deadline.

For All Pixel Helper there is nothing to request. Everything it captures sits in session storage on your own machine and Chrome discards it when you close the browser.

Changes to this policy

The date at the top of this page changes whenever this page does. A material change to a product’s own policy is announced inside that product — that is what X Shield and UpBar both commit to — and All Pixel Helper’s policy is versioned alongside the extension itself.

Contact

Privacy questions about this website or about any product go to support@b2bgold.app. A product’s store listing also carries its own support route, which is faster for anything specific to that app.

B2B Gold is established in Ho Chi Minh City, Vietnam. The terms of use cover the rest.