Utmio

Privacy Policy

Last updated September 28, 2026

Utmio is a private ad-attribution and profit dashboard. An online store owner uses it to see which Meta (Facebook and Instagram) ads lead to sales in their WooCommerce store. It runs at utmio.com. This page explains what data Utmio handles, why, and how to have it deleted.

Utmio is not open to the public. Only people the owner has added can sign in, and the reports contain only the owner's own store and ad data.

Data we collect

Sign-in

Your email address and password. Sign-in is handled by Supabase Auth, and a session cookie keeps you signed in. Figures you enter yourself, such as product costs, fees and expenses, are stored with your account data.

Facebook data you connect

When you choose Continue with Facebook, Utmio receives only what you grant through Facebook Login for Business:

Utmio does not read or store your Facebook profile details, friends, posts, messages or photos.

Store orders (WooCommerce)

Utmio receives orders from your store through the WooCommerce REST API and webhooks. It stores the order number, date, status, total and currency, the products bought (product ID, name, quantity, line total), and the IP address and browser user agent WooCommerce recorded for the order.

The customer's email, phone number, first and last name, city, state, postcode and country are turned into one-way SHA-256 hashes when the order arrives, and only the hashes are stored. Utmio does not store readable names, email addresses, phone numbers or street addresses. The hashes let it recognize repeat customers and match an order to an earlier visit. Other details in the order, such as street addresses, are not kept. Your WooCommerce API key and secret are stored encrypted (Supabase Vault).

Website visits (tracking script)

If the store has the Utmio tracking script installed, each visit records:

Purchase events sent to Meta (Conversions API)

If the store owner turns this on, Utmio sends a Purchase event to Meta for paid orders that no other tool reported. The event contains the order value, currency, order ID, product IDs, the time, and the store address. For matching, it includes the hashed email, phone, first name, last name, city, state, ZIP and country, and the fbc and fbp values. The IP address and browser user agent are sent as they are, because Meta requires them in that form.

How we use it

Only to show the account owner their own reporting: which ads led to which orders, what was spent, and what it earned. When the Conversions API is on, we also use the data above to send purchase events to Meta. We do not use it for advertising, profiling or any other purpose.

Facebook and Meta data

Who we share data with

We do not sell personal data. Data goes only to:

Storage and security

Data is stored in a Supabase database in the United States. It is accessed over HTTPS, and dashboard data can be read only by signed-in people the owner has added. Facebook tokens and WooCommerce keys are encrypted at rest. Customer identifiers are stored as hashes. Our server and hosting providers may keep short-lived technical logs, such as IP address and requested page, for security and debugging.

We keep data until you disconnect and ask us to delete it, or until the owner removes it. Disconnecting Facebook removes the stored token straight away but leaves already-imported spend data in place.

Cookies

utmio.com sets only what it needs to work: the sign-in session cookies, and two short-lived cookies used while connecting Facebook. It uses no advertising or analytics cookies. The tracking script on a store's website is installed by the store owner.

Your choices

You can disconnect Facebook, remove Utmio from your Facebook settings, or ask us to delete everything tied to you. Shoppers at a connected store can ask us to delete their data too. Instructions are on the data deletion page.

Changes

If this policy changes, we will update the date at the top of this page.

Contact

Questions or requests: medkormat@gmail.com