Legal
Privacy Policy
Effective date: June 24, 2026
This policy explains what Casa Signals processes when a store owner connects a WordPress or Shopify store, uses the dashboard, sends messages, or invites users to manage a domain.
1. What Casa Signals Does
Casa Signals helps WordPress, WooCommerce, and Shopify store owners understand site activity, customer journeys, orders, checkout behavior, product performance, and messaging automation.
A connected WordPress site sends event data to Casa Signals only after the site administrator adds an API key and enables event tracking in the Casa Signals Connector plugin. A connected Shopify store sends event data only after the merchant installs the Casa Signals Shopify app and grants the requested permissions via the standard OAuth consent screen.
2. Account and Store Data
We process account details such as name, email address, authentication identifiers, invited users, connected domains, store names, domain email addresses, billing configuration, credit balances, and sender ID requests.
We also process settings created in the dashboard, including API keys, flows, broadcasts, templates, segments, suppression rules, and unsubscribe status.
3. Event and Customer Data
When tracking is enabled, the connector may send event type, event time, page URL, page path, title, referrer, visitor ID, session ID, attribution parameters, WordPress user profile fields, WooCommerce customer fields, billing and shipping fields, cart details, product details, order values, order status, failure reasons, coupons, checkout progress, form metadata, and site health metadata.
When a Shopify store is connected, Casa Signals also receives the order, customer, and checkout webhook payloads that Shopify forwards on the merchant's behalf, including customer name, email, phone, billing and shipping address, order line items, totals, currency, financial status, and the Shopify customer and order identifiers. This data is used to show analytics, build customer timelines, group site activity, power flow and broadcast audiences, prevent duplicate messages, respect unsubscribes, measure recovery, and troubleshoot delivery or tracking issues.
4. Cookies
The WordPress connector can set first-party visitor, session, and attribution cookies on the connected store after tracking is enabled by the site administrator.
These cookies help connect events into a customer journey and understand the source of site activity.
5. Messaging
If a store owner configures SMS or email flows or broadcasts, Casa Signals may process message content, recipient email addresses, recipient phone numbers, delivery status, provider responses, unsubscribe tokens, and suppression decisions.
Marketing and automated messages should only be sent where the store owner has a valid basis and has configured appropriate unsubscribe handling.
6. Payments and Providers
Payments and saved payment methods may be processed by Stripe. Casa Signals does not store full card numbers.
Casa Signals may use service providers for hosting, database storage, email delivery, SMS delivery, URL shortening, payments, analytics, logging, and security. These providers process data only as needed to provide the service.
7. Retention and Security
We keep data for as long as needed to provide Casa Signals, meet legal obligations, prevent abuse, resolve disputes, and maintain accurate analytics, unless deletion is requested or required sooner. For Shopify-connected stores, Casa Signals honors the standard Shopify GDPR webhooks: a customers/data_request webhook causes us to surface the data we hold for that customer to the merchant for fulfillment; a customers/redact webhook causes us to delete that customer's records from our database; a shop/redact webhook causes us to delete all records associated with the store. Each request is audit-logged.
We use technical and organizational safeguards designed to protect account, event, customer, billing, and messaging data, including TLS for all in-transit data, AES-256-GCM application-layer encryption for stored access tokens, single-tenant database access for the operations team, and access logging on customer-data-touching endpoints. No system can be guaranteed to be completely secure.
8. Your Choices
Store owners can disable tracking in the WordPress connector, rotate or remove API keys, hide or clear site data, remove invited users, update domain settings, manage SMS or email unsubscribes, and uninstall the Shopify app from their Shopify admin to revoke the access token and trigger redaction of stored data within forty-eight hours.
Customers receiving messages can use unsubscribe links where provided. Store owners are responsible for responding to privacy requests from their own customers; for Shopify customers, those requests should be initiated through the merchant's Shopify admin so the standard customers/data_request and customers/redact webhooks reach us.
9. Contact
For privacy questions or requests, contact hello@codecasastudios.com.