Skip to main content

Privacy Policy

Last Updated: May 22, 2026

Trellis is a product of Trellis Ads LLC, a Utah limited liability company. This Privacy Policy describes how we collect, use, store, and protect your information when you use the Trellis advertising analytics platform at trellisads.com.


1. Introduction

Trellis is an advertising audit and analytics platform for e-commerce businesses. We connect to your advertising platforms (Google Ads, Microsoft Advertising, Meta Ads) and e-commerce platforms (Shopify) to generate performance reports and optimization recommendations.

This policy applies to all users of trellisads.com, our APIs, and related services. By creating an account, you agree to these practices.


2. Information We Collect

a. Account Information

When you create a Trellis account, we collect:

b. Business Profile Data

To calibrate our analysis, we collect business targets you provide:

This data is entered by you and used exclusively to calibrate our analysis to your business goals.

c. Platform Credentials

When you connect your advertising or e-commerce accounts, we store:

All credentials are encrypted at rest using industry-standard symmetric encryption and decrypted only at the moment of use for API calls on your behalf.

d. Advertising Platform Data

Once connected, we pull the following data from your advertising accounts:

e. Order & Revenue Data

If you connect your Shopify store, we access:

We never store raw customer email addresses, only irreversible hashes used solely to match ad conversions to orders.

f. Usage Data

We collect standard usage data to maintain and improve the service:

g. Communications

We retain records of transactional emails we send you, including:


3. How We Use Your Information

We use your information to:

We do not use your information to:

We may use cookies and similar technologies on our marketing website to measure advertising effectiveness and reach prospective customers through platforms such as Google and LinkedIn. These activities do not involve data you store within the Trellis product.

De-Identified and Aggregate Data

We may create de-identified, aggregated data derived from your use of the Service. This data does not identify you or any individual end user. We may use aggregate data for any lawful business purpose, including product improvement, benchmarking, and research. Aggregate data is not subject to deletion or portability obligations under this policy.


4. Google API Services User Data Disclosure

As required by Google's API Services User Data Policy, this section addresses our use of Google API data.

Scope requested: https://www.googleapis.com/auth/adwords

Data accessed from Google Ads:

How this data is used: Trellis accesses your Google Ads data in a read-only capacity for the sole purpose of generating audit reports and performance analysis. Trellis does not make changes to your Google Ads account: no bid adjustments, no budget changes, no campaign modifications, no keyword additions or removals.

Storage: Google Ads data is encrypted at rest and stored in PostgreSQL on DigitalOcean infrastructure.

Sharing: Your Google Ads data is never shared with, sold to, or transferred to any third party. The only exception is that aggregated campaign metrics are sent to our AI sub-processors for analysis (see Section 7).

Human access: Access is limited to authorized personnel for support, debugging, and security investigations under appropriate safeguards. Trellis processes Google user data as a data processor on behalf of the account owner.

Limited Use Disclosure:

Trellis's use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.


5. Microsoft Advertising Data Disclosure

Scope requested: msads.manage

Data accessed from Microsoft Advertising:

How this data is used: Trellis accesses your Microsoft Advertising data in a read-only capacity for audit reports and performance analysis. Trellis does not make changes to your Microsoft Advertising account.

Storage, sharing, and human access: The commitments described in Section 4 for Google Ads data apply equally to your Microsoft Advertising data.


5.5 Meta Advertising Data Disclosure

Scopes requested: ads_read, business_management

Data accessed from Meta:

How this data is used: Trellis accesses your Meta Ads data in a read-only capacity for generating audit reports and performance analysis. Trellis does not create, edit, pause, or delete campaigns, ad sets, ads, audiences, pixels, or any other asset in your Meta Ads account.

Storage, sharing, and human access: The commitments described in Section 4 apply equally to your Meta Advertising data.

Data deletion callback: Meta requires apps to support user-initiated data deletion. Requests received at our deletion callback endpoint are honored within the timeframes Meta specifies. You may also initiate deletion via the methods in Section 12.


6. Shopify Data Disclosure

Scopes requested: read_orders, read_products, read_inventory

Data accessed from Shopify:

How this data is used: Trellis accesses your Shopify data in a read-only capacity to (a) reconcile advertising platform conversions against real orders, (b) calculate COGS-adjusted ROAS and profitability, and (c) generate audit recommendations grounded in actual revenue. Trellis does not write to, modify, or delete any data in your Shopify store.

Raw customer email addresses are never stored. Only the SHA-256 hash is persisted, and only for the purpose of matching ad conversions to orders.

Storage, sharing, and human access: The commitments described in Section 4 apply equally to your Shopify data.

Shopify GDPR webhooks: When you connect your Shopify store, we honor Shopify's mandatory data-request and data-deletion webhooks within the timelines Shopify specifies:

The current Shopify-specified response window for customers/data_request and customers/redact is 30 days; the shop/redact purge follows app uninstall.


7. AI Processing Disclosure

Trellis uses third-party artificial intelligence services to analyze your advertising data and generate audit reports. Our current AI sub-processors are Anthropic, OpenAI, and Google, accessed exclusively via their paid commercial API tiers.


8. Sub-Processors

We engage the following sub-processors to deliver Trellis. Each is bound by contractual obligations to protect your data and receives only the minimum data necessary to perform its function.

We do not share raw advertising data, credentials, or business metrics with any party outside this list. We will update this list when we add or change a sub-processor and provide notice as described in Section 15.


9. Data Retention

We retain your data only as long as needed to provide the service:

When you delete your account, we remove associated data within a commercially reasonable period, except for records retained for legal compliance.


10. Data Security

We protect your data with the following measures:

Security Incident Notification

In the event of a personal data breach, we will notify affected users without undue delay and within the timeframes required by applicable law (including GDPR Article 33 where it applies), via the email address on file. If you believe your account has been compromised, contact us immediately at [email protected].


11. Cookies

a. Essential Cookies

These cookies are required for Trellis to function and cannot be disabled.

Cookie Purpose Duration
sessionid Maintains your login session Until browser closed
csrftoken Protects against cross-site request forgery 1 year
JWT (httpOnly) Authenticates API requests 30 minutes (access) / 7 days (refresh)
theme Remembers your dark/light mode preference 1 year

These cookies do not track you across other websites and are never shared with third parties.

b. Analytics Cookies

We use Google Analytics (GA4) to understand how users interact with Trellis so we can improve the product. IP anonymization is enabled, and analytics data is not used for targeted advertising, behavioral profiling, data sales, or cross-site tracking.

Cookie Purpose Duration
_ga Distinguishes unique users 2 years
ga<ID> Maintains session state 2 years

c. Advertising and Tracking Cookies

We do not use any advertising, retargeting, or social media tracking cookies on the Trellis application. We do not serve ads on Trellis, participate in advertising networks, or embed social media tracking pixels.

d. Managing Cookies

You may opt out of Google Analytics via your browser settings or the Google Analytics Opt-out Browser Add-on. We respect Do Not Track signals; when DNT is detected, analytics cookies are not set. Blocking essential cookies will prevent you from logging in to Trellis.


12. Your Rights

Depending on your jurisdiction, you have the following rights regarding your data:

All Users

Data Deletion Instructions

You can request deletion of your Trellis account and all associated data in any of the following ways:

  1. Self-service (recommended): Log in, go to Settings → Account → Delete Account. We confirm by email and then process the deletion.
  2. By email: Send a deletion request from the email address on your Trellis account to [email protected]. We aim to respond within 5 business days and complete deletion within 30 days.
  3. Through a connected platform: Uninstalling Trellis from Shopify triggers our shop/redact webhook handler (Section 6). Revoking our Google, Microsoft, or Meta OAuth grant invalidates our tokens and triggers the credential-deletion path in Section 9. Where a connected platform provides a data deletion callback (Meta), we honor it within the windows that platform specifies.

Utah Residents (UCPA)

Under the Utah Consumer Privacy Act, you have the right to:

Trellis does not sell personal data and does not engage in targeted advertising, so these rights are inherently satisfied by our business model.

California Residents (CCPA/CPRA)

Under the California Consumer Privacy Act and California Privacy Rights Act, you have the right to:

We do not sell personal information as defined by CCPA/CPRA. We do not share personal information for cross-context behavioral advertising as defined by CPRA. We do not collect "sensitive personal information" as defined by CPRA §1798.140(ae).

European Union Residents (GDPR)

If the General Data Protection Regulation applies to you, you have the rights of:

Our lawful basis for processing is contract performance (providing the service you signed up for) and legitimate interest (product improvement and security).

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

Data Processing Agreement

Customers subject to data protection laws that require a written data processing agreement — including GDPR Article 28 and UK GDPR — may request a Trellis Data Processing Agreement at [email protected]. Trellis serves the United States market at launch; a formal DPA is provided on request to customers in jurisdictions that require one.


13. Children's Privacy

Trellis is a business-to-business advertising analytics platform. It is not directed at individuals under 16 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 16, we will delete that information promptly.


14. International Data Transfers

All Trellis data is stored and processed in the United States (DigitalOcean infrastructure).

Trellis acts as a data processor with respect to advertising platform data you authorize us to access, processing that data on your behalf and at your direction.

If you access Trellis from outside the United States, your data will be transferred to and processed in the United States. By using Trellis, you consent to this transfer.

Trellis is not currently certified under the EU-U.S. Data Privacy Framework. Customers in jurisdictions that require Standard Contractual Clauses or another transfer mechanism should contact us at [email protected] before connecting an account so we can put the appropriate safeguards in place.


15. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes:

Changes required to comply with applicable law or address security concerns may take effect immediately. Non-material changes (formatting, clarifications) may be made without notice. The date at the top always reflects the most recent revision.


16. Contact Us

If you have questions about this Privacy Policy, want to exercise your data rights, or have concerns about how your information is handled:

Trellis (Trellis Ads LLC) Utah, United States [email protected]

We aim to respond to all privacy-related inquiries within a reasonable time, typically 5 business days.