The Difference
Marketing was built on the page view.
The funnel now pays for the consented login.
Consent Mode v2, the decay of third-party cookies, first-party identity — the last two years quietly moved the funnel's unit of value from the anonymous page view to the consented, logged-in identity. A page view depreciates: cookie-fragile, anonymous, disposable. A consented login appreciates: durable, addressable, worth money — and the only thing an AI agent or an AI answer engine can act on. Most marketing apps still pivot on the page view. We build on the login.
We bridge data with AI security.
Define your CRM with AI builds.
A weekend build gets you a table and a webhook. It does not get you the tail that actually carries the risk — and that tail is the moat:
We already built it — including all of the above. You get the outcome without becoming the maintenance team.
Build the funnel on the consented login
— not the page view.
Use Everywhere CRM
Your data is yours. CRMs can't say that.
CRMs: Salesforce · Klaviyo · HubSpot · Attio — vendor-locked
CRMs weren't built to include consent in real time. You will need to update or migrate — CRM Sync does both. Every org pays for Salesforce — and the people who actually need the data can't reach it. It's gated behind admins, IT, and a monthly fee. CRM Sync is a consent-governed data plane for Shopify that you run and own — open to a business analyst, not locked away from them. And it isn't only the elephant: most Shopify stores run Klaviyo beside it, and Klaviyo's profiles and flows have to resolve to consent too. The consent gate lives in the data plane, not the ESP — Klaviyo becomes one more consumer of it, not the place the record lives.
| Salesforce | Klaviyo | CRM Sync (this one) | |
|---|---|---|---|
| Your data | Locked in Salesforce — you pay, but can't reach it | Profiles live in Klaviyo — billed per profile to keep your own customers | Stays yours — your Shopify + BigQuery, export anytime |
| Who can access it | Admins + IT gatekeepers | Marketing logins — flows and lists, not the record | A business analyst — just sign in, no gatekeepers |
| Access needed | Admin, IT approval, keys | Account seats + API keys | No Google Console, no keys |
| Consent & entitlement | Bolt-on, if any | A flag: accepts marketing, yes/no — no timestamp, no method, no provenance | Built in — Consent Mode v2 signals with timestamp, method, and audit trail; reset plane, least-privilege |
| Evidence ledger — Omnibus pricing · firmware/SBOM · consent | No | No | One ledger — Omnibus price evidence, firmware/SBOM records, Consent Mode v2. No martech tool offers this. |
| Agent-addressable (UCP) | No | No | Yes — publishes agent-eligible offers to the Universal Commerce Protocol |
| Pricing | Monthly fee — and you lose the data if you stop paying | Per profile — the list grows, the bill grows | One fixed fee — your data stays yours; an agency spreads it across every client |
Use AI to mirror and migrate.
Need what's in Salesforce — or Klaviyo — anyway? Pull either in with a no-code connector — no pipeline, no admin battle.
Logging on change is the difference. Every change — price, consent, campaign — lands in a ledger the business stakeholder owns: their own business notebook, exportable as a CSV, visible only to them. That does two things at once: it adds security (a private, tamper-evident record nobody else can rewrite) and it adds utility to AI-managed data (the AI works against a ledger the human can always read, check, and keep).
The build
Your data is yours. AI helps you keep it secure.
We generate a Worker — AI customizes it for you — and you use it where you need it. The deliverable is an edge Worker on Cloudflare Workers — AI-secure by construction: scoped credentials, ledgered agent actions, masked secrets — and the Verified Trust network (published keys, signed certificates, offline-verifiable records) reinforces the system you already have rather than replacing it. Built to enterprise standards with flexibility in mind: run it beside your standard CRM, or mirror the CRM through it and migrate off to a build you own.
That is what makes AI-paired system development front-end agnostic here: none of the security lives in the page. Every read and write goes through surgical, row-based AI functions at the edge — each call scoped to the row it touches and the mandate it carries, consent checked at that row, and the result ledgered. Swap the front end and nothing security-relevant moves.
Bring your own interface. Managed CMS — Webflow, Em Dash, WordPress, Drupal, AEM, Salesforce Experience Cloud — or file-system frameworks — Astro, Next, Nuxt, Svelte. The data plane doesn't care what renders it, so the presentation layer is your choice and replaceable without touching the data.
The Worker that secures the configurator is shared infrastructure — included. The $90 configurator runs against the shared function/security brain: consent gates, entitlements, ledgers, the Verified Trust network, operated for every tenant at once. Want your own brain — a dedicated Worker on your zone, your own keys, your own ledgers, your own trust network? That is the Enterprise engagement, priced by scope — the same shape as WordPress on shared hosting versus your own private VM: identical software, different isolation, and you graduate when the stakes say so.
The key strategy works because there is no “store your data somewhere else” fee. Identity and records live in your own Shopify, Xano, and BigQuery under your own keys — the price buys the build, never a place to keep what was already yours.
Fixed prices, live on the store: App $90 · Verified Transactions $90 · Firmware SBOM $250 · Firmware Security $1,900 · CRA Readiness $900 · SBOM Registry $49/mo. Private customization — ERP, RMA lifecycle, fraud linkage, cross-border rails, add-ons — is scoped on the same substrate. The full comparison →
The migration rail
CRM → Shopify → GA4 / UCP.
The same connectors that let you coexist are a data-harvesting rail for leaving: mirror the CRM into Shopify and your own identity spine; flow events server-side into GA4 and the BigQuery you own; publish agent-eligible offers over UCP. Three stages, no big-bang — the CRM keeps running while its monopoly on the record ends.
Direct-to-user data with consent is the real-time benefit. A CRM's copy of the customer is a replica — captured elsewhere, synced later, consent checked after the fact. Here the record is written at the moment of the event, from the user themselves, consent evaluated in the same request. The first copy is already yours, already consented.
Why you want it
Keep your tools. Gain the proof.
You keep the tools you love. Design in Webflow, sell on Shopify, publish anywhere — nothing is replaced, nothing migrates, no IT ticket stands between you and shipping. Adoption is a tag; removal is a deletion.
Your work gets smarter on its own. Audiences build themselves from customers who actually said yes, and your ad spend follows the buyers who really convert — no exports, no list uploads, no waiting on another team.
Every promise you make is provable later. A price, a discount, a consent choice, a design change — each lands in a record the company holds. When leadership, a client, or an auditor asks, you answer from your own records, that moment.
And your name is on the direction. The record shows what you built, what it ran, and what it produced — the difference between saying you brought AI into the business and being able to show it.
Go deeper: Xano · Salesforce → Xano (connected app + credentialing ▸) · Webflow AEO Checklist · Universal Commerce Protocol (UCP)
The dates do the selling.
The same timeline, as a machine reads it
{
"name": "commerce-api-migration-timeline",
"updated": "2026-08-19",
"events": [
{
"date": "2024-03-06",
"authority": "Google",
"event": "Consent Mode v2 becomes mandatory for EEA/UK ads measurement and audiences"
},
{
"date": "2024-04",
"authority": "Shopify",
"event": "GraphQL product APIs raise the variant ceiling from 100 to 2,048 - GraphQL only, and REST stays capped at 100 with no error explaining why"
},
{
"date": "2024-10-01",
"authority": "Shopify",
"event": "REST Admin API declared legacy"
},
{
"date": "2024-12-10",
"authority": "EU",
"event": "Cyber Resilience Act enters into force - the clock starts, obligations phase in across the following three years"
},
{
"date": "2025-02-01",
"authority": "Shopify",
"event": "Public apps forced onto the new GraphQL product APIs - anything on the older GraphQL or REST product APIs had to migrate"
},
{
"date": "2025-04",
"authority": "Shopify",
"event": "New apps must use the GraphQL Admin API"
},
{
"date": "2025-05",
"authority": "Google",
"event": "The channel field is deprecated on data sources and products - anything keying on channel in reporting or reconciliation is reading a field with an end date"
},
{
"date": "2025-11",
"authority": "YouTube",
"event": "Affiliate analytics arrive - creator, content and product-level data becomes retrievable"
},
{
"date": "2025-12-10",
"authority": "Shopify",
"event": "Web pixel payloads null email, phone, name and address for apps without approved protected-customer-data access"
},
{
"date": "2026-01",
"authority": "Google",
"event": "Affiliate performance reporting lands in Reports v1alpha - parity with the Merchant Center reports, through the API"
},
{
"date": "2026-01-13",
"authority": "Shopify",
"event": "Marketing app pixels default to Optimized - Shopify may pause some or all of a pixel's data sharing on its own judgement"
},
{
"date": "2026-02-28",
"authority": "Google",
"event": "Merchant API v1beta retired - integrations must be on v1"
},
{
"date": "2026-04-14",
"authority": "Google",
"event": "Merchant Center begins warning on images below the updated minimum resolution - warnings only, enforcement follows in 2027"
},
{
"date": "2026-05",
"authority": "Google",
"event": "Merchant API MCP Access Service ships in alpha - fourteen tools, read-only and low-risk writes, making Merchant Center data agent-readable"
},
{
"date": "2026-06-11",
"authority": "EU",
"event": "Cyber Resilience Act Chapter IV applies - notification of conformity assessment bodies, and the assessment market opens"
},
{
"date": "2026-06-15",
"authority": "Google",
"event": "Consent Mode ad_storage becomes the sole control of the GA4 to Google Ads flow; the Signals toggle is retired"
},
{
"date": "2026-08-18",
"authority": "Google",
"event": "Content API for Shopping shuts down - product feeds ride the Merchant API only"
},
{
"date": "2026-09-11",
"authority": "EU",
"event": "Cyber Resilience Act reporting obligations begin - actively exploited vulnerabilities need an early warning within 24 hours, full notification within 72, final report within 14 days"
},
{
"date": "2026-10",
"authority": "Shopify",
"event": "Customer Account API removes Customer.lastIncompleteCheckout and the Checkout Classic types"
},
{
"date": "2026-H2 (TBA)",
"authority": "Google",
"event": "Second consolidation wave - ads personalization moves out of GA4 into Google Ads under ad_personalization, and tag-collected IP addresses are encrypted and flow to the linked Ads account"
},
{
"date": "2026-H2 (TBA)",
"authority": "Shopify",
"event": "Final sunset date for legacy customer accounts to be announced - deprecation already in force"
},
{
"date": "2027-01",
"authority": "Shopify",
"event": "Fields deprecated in the 2026-10 release are removed"
},
{
"date": "2027-01-31",
"authority": "Google",
"event": "Minimum image resolution is enforced in Merchant Center - offers below it stop being eligible, having been warned since April 2026"
},
{
"date": "2027-02-01",
"authority": "YouTube",
"event": "Partner Programme thresholds roughly double - 1,000 subscribers plus 8,000 watch hours in 365 days or 20 million Shorts views in 90; Shopping affiliate needs YPP, so the gate in front of it rises"
},
{
"date": "2027-02-18",
"authority": "EU",
"event": "Battery Digital Product Passport becomes mandatory - relevant batteries must carry a passport reachable by QR code, and this is the first hard QR mandate"
},
{
"date": "2027",
"authority": "EU",
"event": "Aluminium, textiles and tyres join the Digital Product Passport scope, alongside measures on secondary materials, product lifespan and recyclability"
},
{
"date": "2027-12-11",
"authority": "EU",
"event": "Cyber Resilience Act main obligations apply - essential requirements, conformity assessment, technical documentation, CE marking and SBOM"
},
{
"date": "2027-12-31",
"authority": "GS1",
"event": "Sunrise 2027 - retail point-of-sale expected to scan 2D barcodes (GS1 Digital Link)"
},
{
"date": "2028-2029",
"authority": "EU",
"event": "Packaging Digital Product Passport delegated acts expected - specifying the exact data requirements and formats per packaging category"
},
{
"date": "2030",
"authority": "EU",
"event": "Packaging and Packaging Waste Regulation - QR codes on all packaging carrying recycling and material composition data"
}
]
}
Humans read the calendar. Machines read the JSON. Same record.
Migration questions, answered
Do I need to do anything before August 18?
If your Shopify store syncs products through the Google & YouTube app: no — your provider handles the API migration. But be explicit about what that covers: the app connects ONE store, on ONE primary domain, to ONE Merchant Center — single tenant, single border, standard Shopify DNS. If your brand runs multiple URLs — country TLDs, brand domains, regional storefronts — the app path does not carry them. Plugins were made for single-border applications — this one is simply honest about it, and the same assumption sits silently inside most consent banners, review widgets, and email tools on multi-domain estates. Multi-domain estates need Cloudflare namespace and wildcard rules at the edge, so every domain resolves, verifies, and feeds as one estate instead of five half-verified ones. And if you run a custom Content API integration (agency scripts, in-house feed jobs): migrate to the Merchant API now, or file Google’s extension form immediately — it has no stated deadline, which means the practical deadline is today. An extension buys time; it does not remove the migration.
What is the Merchant API?
Google’s replacement for the Content API for Shopping: new resource names, new enums, new versioning, split into sub-APIs. It is a reshape, not a rename — prices move from value strings to amountMicros, identifiers consolidate, and Google increasingly reads product truth from your site’s own structured data.
What does GraphQL-only mean for my Shopify apps?
Shopify declared the REST Admin API legacy in October 2024, and new apps must use GraphQL since April 2025. Apps and plugins still speaking REST run on borrowed time — every schema addition lands GraphQL-first, and REST-era integrations quietly fall behind the data they think they see.
What happens if my feed misses the deadline?
The old pipe stops. Products stop updating in Merchant Center, listings go stale and expire, and your presence on Google’s shopping surfaces degrades — not with an error page, but with silence. Fulfillment of the migration is invisible when it works and expensive when it doesn’t.
Where does CRM Sync fit?
Our Merchant API projection is computed in-worker from the record, already in v1 shapes — GTIN and MPN from the identity spine, ISO currency, language, and country throughout. When Google reshapes again, only the mapping changes: absorbed where the code lives, same day, no refeed, no migration invoice. The Shopify side is GraphQL-first by construction.