Effective date: July 22, 2026
Profenor (the “Service”) is operated by RJ-DCF LLC (“Company,” “we,” “us,” or “our”), a Texas limited liability company. This policy explains what personal information we collect, how we use and share it, how long we keep it, and your rights. For data we process on behalf of a merchant, we generally act as a processor / service provider, and the merchant is the controller. Where we process personal information on behalf of a merchant, such processing is governed by the Data Processing & Service-Provider Terms in Article 17 of our Terms of Service.
Geographic scope. The Service is offered only to businesses based in the United States. It is not directed to, intended for, or made available to anyone located outside the United States — including, without limitation, the European Union, the United Kingdom, Canada, and every other jurisdiction. We do not knowingly offer the Service to, or process the personal information of, anyone outside the United States; if you are outside the U.S., please do not use the Service. This policy is written for U.S. law (including California’s CPRA); if we expand outside the United States, we will update it accordingly.
We use information to: provide the Service (per-order profit, IRS-referenced categorization, P&L, nexus tracking); authenticate and support you; communicate with you regarding your account, including transactional notices, security alerts, service updates, and, if you choose to enable them, optional recurring account summaries and performance reports; secure and troubleshoot the platform; comply with legal obligations; and improve the Service using aggregated or de-identified data only, understand which marketing channels are effective, and evaluate the effectiveness of our own promotional campaigns. We may also use contact information voluntarily submitted through our public marketing website to respond to inquiries, provide requested resources or free tools, administer waitlists, send product updates and educational content, and market our products and services. You may unsubscribe from marketing emails at any time by using the unsubscribe link included in each email. Optional recurring summary emails may be disabled at any time through your account settings or by using the unsubscribe link included in those emails. We do not sell or share the personal information in your Profenor account, your connected store and financial data, or Shopify Protected Customer Data — including for cross-context behavioral advertising — and we do not use your financial data to train generalized or third-party machine-learning models. This absolute commitment covers the logged-in application and all bookkeeping, financial, and Shopify-sourced data. Any product improvement uses aggregated or de-identified data that does not identify you or any individual. We do not attempt to re-identify de-identified information, and we contractually prohibit any recipient from attempting to re-identify it. Separately, on our public marketing website (for example, our homepage/landing pages, profit-calculator, nexus-checker, demo, and thank-you pages), we use third-party advertising cookies and pixels to measure and target our advertising; this activity is described in §9.1 (Advertising and Third-Party Cookies) and may constitute a “sale” or “share” of personal information under California law and “targeted advertising” under other state laws — but it involves only marketing-site browsing data and never your account, financial, bookkeeping, or Shopify data. Our own first-party website measurement uses Cloudflare Web Analytics, which is cookieless (see §9).
Advertising and conversion technologies used on our public marketing website operate independently from the Profenor application and are not used to collect, access, disclose, or analyze customer bookkeeping data, financial records, Shopify Protected Customer Data, or information processed within authenticated customer accounts.
We share data only with vendors that help us operate the Service, under contract and data-protection terms:
| Subprocessor | Purpose | Data region |
|---|---|---|
| Shopify | Source of store data (you authorize via OAuth) | US |
| Render (application hosting + Postgres database) | Application hosting and managed Postgres database | US |
| Cloudflare | Content delivery / edge security and cookieless, first-party Web Analytics (aggregate page metrics only; no tracking cookies, no cross-site profiling, no advertising) | US |
| Stripe | Payment processing | US |
| Google Workspace (Google LLC) | Transactional / service email delivery | US |
| Meta (Meta Pixel) | Advertising measurement and retargeting on our marketing website only — never the logged-in app or your financial data (see §9.1) | US |
| Google (GA4 + Google Ads) | Marketing-website analytics and advertising conversion measurement on our marketing website only — never the logged-in app or your financial data (see §9.1) | US |
| Reddit (Reddit Pixel) | Advertising measurement and retargeting on our marketing website only — never the logged-in app or your financial data (see §9.1) | US |
The advertising subprocessors above (Meta, Google, Reddit) act as independent controllers of the marketing-site data they collect through their own pixels/tags, under their own privacy policies; they operate only on our public marketing website and never receive your account, bookkeeping, financial, or Shopify Protected Customer Data. We keep this list current and provide advance notice of new subprocessors that materially affect the processing of personal information. We may also disclose information if required by law, to enforce our terms, or to protect the rights, property, or safety of any person. In a merger or asset sale, information may transfer subject to this policy.
We access and process Shopify Protected Customer Data (“PCD”) only as needed to provide the Service’s bookkeeping functions, and we maintain the elevated (Level 2) Protected Customer Data protections required by Shopify for the categories of PCD we process. We commit to: (a) data minimization — requesting and retaining only the PCD fields necessary for per-order profit, P&L, and nexus calculations; (b) using PCD solely for the merchant-authorized purpose and not for advertising or model training; (c) applying the encryption and access controls in this section; and (d) honoring deletion and access obligations. Protected Customer Data is used solely to provide merchant-requested bookkeeping, profitability, reporting, and tax-related informational services and is not used for advertising, marketing profiling, cross-customer analytics, or generalized artificial-intelligence model training.
We access Shopify merchant and customer information only through Shopify-authorized APIs after authorization by the merchant and only to the extent reasonably necessary to provide the bookkeeping, profitability, reporting, and tax-related informational services requested by that merchant.
We use industry-standard encryption in transit (TLS) and at rest, encrypt third-party access tokens using industry-standard encryption, enforce access controls, and apply strict multi-tenant isolation (every record is scoped to its owner; no customer can access another’s data). Backups are encrypted. No method of transmission or storage is 100% secure. No security safeguards can eliminate all risk. Customer acknowledges that use of any internet-connected service involves inherent risks and that the Company does not guarantee that unauthorized access, cyberattacks, or security incidents will never occur.
Breach notification. If we become aware of a personal-data breach, we will: notify affected merchants (as their processor) without undue delay and, where feasible, within seventy-two (72) hours of confirming a reportable security incident, consistent with Article 17.10 of our Terms of Service; provide notices required by applicable U.S. state law; and, where Profenor acts as the controller of the affected personal information (for example, account data of our own users), provide direct notice to affected individuals as required by applicable state breach-notification law (including Texas Bus. & Com. Code §521.053). Because the Service is US-only, GDPR supervisory-authority notification is not currently applicable; we will add it if we expand to the EU/UK.
We retain personal information only as long as necessary for the purposes above:
| Category | Retention |
|---|---|
| Account Data | Duration of account plus ninety (90) days after closure |
| Connected Store and Financial Data | Duration of account plus thirty (30) days after termination to permit export, then deleted or anonymized |
| Billing Records | Seven (7) years |
| Usage and Security Logs | Twelve (12) months |
| Backups | Deleted through normal rotation procedures within ninety (90) days |
| Prospect / Lead Contact Information | Until you unsubscribe, request deletion, or the Company determines the information is no longer reasonably necessary for marketing or business purposes |
We keep data longer only where law requires. Where deletion requests relate to financial or bookkeeping records that we or our merchant customers are legally required to retain for accounting, tax, audit, fraud-prevention, or legal-compliance purposes, we may delete or anonymize personal identifiers while retaining the underlying transactional and financial information to the extent required or permitted by applicable law. You can request export or deletion (see §8).
Security audit logs. To meet our security and Shopify Protected Customer Data obligations, we keep tamper-resistant access-log records — metadata showing who accessed protected data and when, not the underlying customer data — for twelve (12) months. For security and legal-compliance reasons these audit records may be retained after account closure and may include limited identifiers such as the store domain; this is a limited exception to deletion. When you close your account we delete or anonymize your data as described above, except for these audit records, which are retained for the period stated.
Depending on your location, you may have rights to access, correct, delete, port, and object to or restrict certain processing, and to non-discrimination for exercising those rights. To exercise rights, contact info@profenor.com or use in-app data tools. We will verify your request and respond within the timelines below; where we act as a processor for a merchant, we will route your request to that merchant.
Scope of the deletion right (one carve-out). When you delete your account, we delete or anonymize your data as described in §7, except for limited tamper-resistant security audit-log metadata (such as the store domain) that we retain for approximately twelve (12) months after closure for security and fraud-prevention purposes, as described in §7 (“Security audit logs”). This is a narrow, legally-recognized exception to deletion; it does not include your store, financial, or account contents. Deletion is also propagated to backups through normal rotation (see §7) rather than instantaneously. Where applicable law permits or requires retention of certain bookkeeping, accounting, tax, fraud-prevention, audit, or legal-compliance records, we may retain those records after removing or anonymizing personal identifiers to the extent reasonably practicable.
Other U.S. state privacy rights. If you are a resident of a state with a comprehensive privacy law — for example, Texas (the Texas Data Privacy and Security Act), Virginia, Colorado, Connecticut, and others — you may have rights to access, correct, delete, and obtain a portable copy of your personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. We honor these rights where applicable and respond within 45 days (extendable as the law allows). Universal opt-out mechanism. Where required by your state’s law (for example, the Colorado Privacy Act and the Texas Data Privacy and Security Act), we honor the Global Privacy Control (GPC) as a universal opt-out signal for targeted advertising and the sale of personal data — this is not California-only. On our marketing website, we use third-party advertising pixels (Meta, Reddit, Google) that constitute targeted advertising and a “sale”/“share” of marketing-site personal information (see §9.1); when we detect a valid GPC signal we suppress those advertising pixels so that no such sale/share or targeted advertising occurs for that browser. Your account, bookkeeping, financial, and Shopify data are never used for advertising in the first place, so an opt-out changes nothing there — it only takes effect on the marketing website, where it meaningfully suppresses ad-pixel sharing. Where required by applicable law, you may opt out of the use of advertising cookies and similar technologies used for targeted advertising by using our cookie preferences tool, the “Do Not Sell or Share My Personal Information” link available on our marketing website, or by enabling a recognized Global Privacy Control (GPC) browser signal, which we honor where legally required. Appeals. If we decline your request, you may appeal by contacting us at info@profenor.com; we will respond to your appeal within the time your state’s law requires (for example, 60 days under Virginia and Colorado law). Authorized agents. You may use an authorized agent to submit requests on your behalf; we may require proof of the agent’s authorization and may verify your identity directly.
| Category collected | Purpose |
|---|---|
| Identifiers (name, email, business name) | Account creation, support, security |
| Commercial / financial info (orders, payouts, SKU costs, transactions) | Bookkeeping calculations (profit, P&L, nexus) |
| Internet/usage activity (logs, device, feature usage) | Security, troubleshooting, improvement |
| Prospect / Lead Contact Information (such as name, email address, and business name voluntarily submitted through website forms or tools) | Responding to requests, providing requested resources, administering waitlists, and sending product updates and marketing communications |
Because the Service is offered only in the United States, GDPR/UK GDPR obligations — including EU Standard Contractual Clauses (SCCs), the UK Addendum, and an Art. 27 EU/UK representative — do not currently apply. If we expand to serve EU/UK users, we will update this policy to add the applicable legal bases, transfer mechanisms, and representative details.
Inside the logged-in Service (app), we use only essential cookies required to operate and secure the Service (for example, to keep you signed in), and for our own website measurement we use Cloudflare Web Analytics, a privacy-first, cookieless, first-party analytics service: it reports aggregate page metrics only, does not set tracking cookies, does not fingerprint or build cross-site profiles of you, and does not share data with any third party for advertising. We do not run third-party advertising or behavioral-tracking pixels inside the logged-in app or on your account, financial, bookkeeping, or Shopify data. On our public marketing website, we additionally use third-party advertising cookies and pixels as described in §9.1. You can manage cookies via your browser, and we honor GPC opt-out signals (see §8.1 and §9.1).
Our public marketing website may also use advertising and conversion technologies (such as Meta Pixel, Google Ads, Reddit Pixel, or similar tools) to measure advertising performance, attribute conversions, and deliver or measure personalized advertising. These technologies are used only on our public marketing website, not within the authenticated Profenor application, and are never used to access or process customer bookkeeping, financial, or Shopify Protected Customer Data.
On our public marketing website — for example our homepage/landing pages, profit-calculator, nexus-checker, demo, and thank-you pages — we use third-party advertising cookies, pixels, and tags to measure the performance of our paid advertising and to show relevant ads (including retargeting). We use: - Meta Pixel (Meta Platforms, Inc.) — Meta Privacy Policy - Reddit Pixel (Reddit, Inc.) — Reddit Privacy Policy - Google tags — Google Analytics 4 (GA4) and Google Ads conversion tracking (Google LLC) — Google Privacy Policy
These providers set cookies and other identifiers on the marketing site and collect online identifiers, device and browser information, pages viewed, and ad interactions. The purpose is measuring ad performance and delivering retargeting / cross-context behavioral advertising. This data is shared with those providers as independent controllers, who process it under their own privacy policies (linked above). This activity does not involve — and these pixels never receive — your Profenor account credentials, connected-store data, financial or bookkeeping data, or Shopify Protected Customer Data.
Under California law this activity may constitute a “sale” and/or “share” of personal information, and under Texas (TDPSA), Virginia, Colorado, and Connecticut law it constitutes “targeted advertising.” You have real, functional ways to opt out: - Global Privacy Control (GPC): we honor a valid GPC browser signal by suppressing these advertising pixels on the marketing site, so no sale/share or targeted advertising occurs for that browser. - “Do Not Sell or Share My Personal Information”: use our cookie preferences tool or the “Do Not Sell or Share My Personal Information” link available in the footer of our marketing website to turn these pixels off. - Provider ad settings: Meta ad preferences, Google Ads Settings, and Reddit ad personalization settings. - Industry opt-outs: the DAA WebChoices tool at optout.aboutads.info and the NAI opt-out at optout.networkadvertising.org.
The Service is not directed to anyone under 18, and we do not knowingly collect personal information from them.
We will post updates with a new effective date and notify you of material changes.
RJ-DCF LLC · info@profenor.com · 3707 Cypress Creek Parkway, Ste 310 #2006, Houston, TX 77068