SETROASFLOW — DATA FLOW & PROCESSING DESCRIPTION
Version: Draft — 25 August 2026
SOURCE 1 — MERCHANT BROWSER
Events may include PageView, AddToCart, Purchase and other configured events.
SOURCE 2 — WORDPRESS / WOOCOMMERCE
Plugin-based event collection.
SOURCE 3 — SHOPIFY
Web Pixel and order webhooks. Shopify privacy webhooks include customers/data_request, customers/redact and shop/redact, with HMAC verification.
EDGE
Cloudflare Workers receive the request and apply geo-aware consent handling. For EU users without affirmative consent, personal data may technically reach the first-party edge before being discarded or anonymized.
PROCESSING
Permitted events may be normalized, enriched with country/region and device type, associated with attribution data and sent to storage and configured destinations.
STORAGE
Cloudflare D1 / Durable Objects: CDP profiles and related identity information, including clear email where collected with consent.
Supabase Postgres: Merchant accounts, destination configurations, events and usage. The events table does not contain PII in clear text but may contain pseudonymous/linkable information.
KV: audience-cookie/server-side audience state.
OPERATOR ACCESS
Authorized SetRoasFlow personnel may technically access production data stores when necessary for operations, debugging or support. This access is organizationally and contractually restricted and is not routine.
DESTINATIONS
Advertising platforms, analytics, CRM providers, AI providers and Merchant-controlled warehouse endpoints.
AI
On-demand functions include segment creation from merchant text, segment naming, delivery-error explanation and aggregate weekly digests. AI is designed not to receive end-user PII as structured customer fields. Merchant-provided free text is forwarded as typed and may contain personal data.
META SPEND
Where authorized, SetRoasFlow reads aggregated daily spend from the Merchant's Meta ad account for ROAS calculations.
DELETION
Project deletion triggers deletion of applicable live project data within 24 hours. Provider disaster-recovery copies may persist for limited periods before automatic expiration. Third-party destinations retain copies according to their own systems and policies.