Privacy Policy
Last updated September 28, 2026
Utmio is a private ad-attribution and profit dashboard. An online store owner uses it to see which Meta (Facebook and Instagram) ads lead to sales in their WooCommerce store. It runs at utmio.com. This page explains what data Utmio handles, why, and how to have it deleted.
Utmio is not open to the public. Only people the owner has added can sign in, and the reports contain only the owner's own store and ad data.
Data we collect
Sign-in
Your email address and password. Sign-in is handled by Supabase Auth, and a session cookie keeps you signed in. Figures you enter yourself, such as product costs, fees and expenses, are stored with your account data.
Facebook data you connect
When you choose Continue with Facebook, Utmio receives only what you grant through Facebook Login for Business:
- The ad accounts you can access (ID, name, currency, time zone, status and business name).
- Campaign, ad set and ad names, IDs, statuses and budgets for the ad accounts you choose to track.
- Daily performance figures for each ad: spend, impressions, clicks, link clicks, landing page views, add to carts, checkout starts, purchases and purchase value as reported by Meta, and 3-second video views.
- The access token Facebook issues. While you pick ad accounts it waits in a short-lived (15 minutes) HttpOnly cookie that page scripts cannot read. It is then stored encrypted on the server (Supabase Vault).
Utmio does not read or store your Facebook profile details, friends, posts, messages or photos.
Store orders (WooCommerce)
Utmio receives orders from your store through the WooCommerce REST API and webhooks. It stores the order number, date, status, total and currency, the products bought (product ID, name, quantity, line total), and the IP address and browser user agent WooCommerce recorded for the order.
The customer's email, phone number, first and last name, city, state, postcode and country are turned into one-way SHA-256 hashes when the order arrives, and only the hashes are stored. Utmio does not store readable names, email addresses, phone numbers or street addresses. The hashes let it recognize repeat customers and match an order to an earlier visit. Other details in the order, such as street addresses, are not kept. Your WooCommerce API key and secret are stored encrypted (Supabase Vault).
Website visits (tracking script)
If the store has the Utmio tracking script installed, each visit records:
- An anonymous visitor ID and session ID supplied by the script.
- The page URL, the referring site, and campaign (UTM) parameters.
- Ad click IDs when present in the URL (Facebook fbclid, Google gclid, gbraid and wbraid, TikTok ttclid) and the Meta browser identifiers fbp and fbc (and TikTok's ttp).
- The visit time, and the IP address and browser user agent of the request.
- Optionally, a SHA-256 hash of an email address, linking that visitor ID to the hash. The tracking endpoint accepts only a hash, never a readable address.
- When the visitor completes an order, the order number is linked to their visitor ID.
Purchase events sent to Meta (Conversions API)
If the store owner turns this on, Utmio sends a Purchase event to Meta for paid orders that no other tool reported. The event contains the order value, currency, order ID, product IDs, the time, and the store address. For matching, it includes the hashed email, phone, first name, last name, city, state, ZIP and country, and the fbc and fbp values. The IP address and browser user agent are sent as they are, because Meta requires them in that form.
How we use it
Only to show the account owner their own reporting: which ads led to which orders, what was spent, and what it earned. When the Conversions API is on, we also use the data above to send purchase events to Meta. We do not use it for advertising, profiling or any other purpose.
Facebook and Meta data
- Access to your ad accounts is read-only. Utmio never posts, and never creates, edits, pauses or deletes ads or campaigns.
- Facebook data is used only to show the account owner their own ad reporting. We never sell it, share it, or use it for any other purpose.
- Utmio follows the Meta Platform Terms. You can revoke access at any time, as described on the data deletion page.
Who we share data with
We do not sell personal data. Data goes only to:
- Meta: Utmio calls Meta's APIs to read your ad data and, if turned on, to send purchase events.
- The services that run Utmio: Supabase (database, hosted in the US), Cloudflare (relays store order notifications at api.utmio.com), and the server that hosts utmio.com. They process data only to operate the service.
- Authorities, if the law requires it.
Storage and security
Data is stored in a Supabase database in the United States. It is accessed over HTTPS, and dashboard data can be read only by signed-in people the owner has added. Facebook tokens and WooCommerce keys are encrypted at rest. Customer identifiers are stored as hashes. Our server and hosting providers may keep short-lived technical logs, such as IP address and requested page, for security and debugging.
We keep data until you disconnect and ask us to delete it, or until the owner removes it. Disconnecting Facebook removes the stored token straight away but leaves already-imported spend data in place.
Cookies
utmio.com sets only what it needs to work: the sign-in session cookies, and two short-lived cookies used while connecting Facebook. It uses no advertising or analytics cookies. The tracking script on a store's website is installed by the store owner.
Your choices
You can disconnect Facebook, remove Utmio from your Facebook settings, or ask us to delete everything tied to you. Shoppers at a connected store can ask us to delete their data too. Instructions are on the data deletion page.
Changes
If this policy changes, we will update the date at the top of this page.
Contact
Questions or requests: medkormat@gmail.com