One segment 2 activations

How it works

How-The same Shopify segment drives your email and your Google Smart Bidding.

The same Shopify segment drives your email and your Google Smart Bidding.

Shopify Customer Segments are native, free, and GA4-linked. CRM Sync reads the same segment live (customerSegmentMembers), consent-gates it against Consent Mode v2, weights it by real revenue, and hands Google a tagged, immediately-flagged conversion. Klaviyo's segments are trapped in Klaviyo and never touch your Google bidding.

Source · Shopify

Customer Segment
(native, free, GA4-linked)

Activation 1 · Shopify Email

Sends to the segment — free, built in.

Activation 2 · CRM Sync

Consent gate → revenue value → Google Smart Bidding (Customer Match + conversion value).

Result

Smart Bidding on the tagged, consented, immediately-flagged conversion — the bid optimizes on truth, not a latent anonymous page view.

Security · questions, answered

Sealed rows. Unrewritable history.

Every sensitive record is encrypted on its own row, and the history is append-only — nothing is quietly rewritten, by anyone. That design is what makes the answers below possible.

Are you SOC 2 or ISO certified?

Our foundation is. We build on SOC 2 and ISO certified partners — the platforms that run and store the data hold those certificates, and we hand you their reports as part of your evidence package. That attestation is the building block; what we add on top is the part a certificate can’t give you: records you can check today, not a report about last year.

Isn’t a certificate enough?

A certificate means an auditor visited once and the paperwork looked right that week. It says nothing about the data itself. A company can frame a certificate on the wall and still run on messy, unprovable data underneath — the certificate protects the frame, not you.

What is the difference between an attestation and a verified record?

An attestation is a professional opinion: someone examined a description of a system and signed a statement that it looked right during a window that has already closed. A verified record is the data itself: every action written down as it happened, signed, and checkable by anyone at any time — you don’t have to trust the checker; you can be the checker. Attestation was written for auditors who visit. Today’s rules are written for questions that arrive. And AI is finishing the shift, because a software agent can’t read an opinion letter under NDA — but it can verify a signed record in the moment it acts. The same pivot already happened to commerce APIs when machines became the main consumers, and it arrived by mandate, not by preference. Verification is repivoting from opinion to record. We built the record.

So what do you do instead?

We write everything down as it happens. Every consent, with the time and how it was given. Every permission granted or removed. Every price, with its history. Every key we rotate. When an auditor, a regulator, or your own security team asks a question, the answer is pulled from the record in minutes — not reconstructed from memory over weeks.

What happens when a customer asks to be deleted?

We delete what identifies them. The anonymous facts the law requires us to keep — like price history — stay, but nothing can connect them to a person anymore. And our data export returns the history, not just today’s row — because “we logged it” only counts if you can show it. Start a request anytime at Your Data Rights — no account or password needed.

What if a purchase isn’t working?

Everything in the store is digital and unlocks instantly — so instead of a returns counter, we offer a live review session: we walk your install, verify your entitlements, and tour the features you bought until it works. Book one at Returns & review sessions.

Where does the data live?

In a region you choose — fifteen available, including the EU, UK, Korea, and Japan. European data can stay in Europe.

What about AI agents?

Before an AI agent can touch anything here, every single request must carry three things: proof the customer consented, a session identity that says exactly who the agent is acting for, and a one-time key so the same action can never accidentally run twice. Missing any one of the three, the request is refused. No exceptions, no special paths. This is the first thing an AI security review checks.

What if something goes wrong?

There’s a written plan: who finds out, who decides, and notification within 72 hours. There’s also a written list of our own known weak spots, each with a date to fix it. We name them before anyone asks — that’s what real security looks like.

A certificate answers for one week in the past. A record answers for right now.

AI as your partner

Nothing ripped out. Answered in real time.

The regulator's question is asked in real time: what did the servers do? A multi-year platform rebuild is the wrong-size answer — one public ERP migration failure walked from scoping failure to material weakness to shareholder suits to delisting. The Wrong-Size Tool walks the whole ladder.

An AI middleware partner inverts it. Your systems stay; the AI sits beside them — consent recorded at the moment of the event, evidence written as the order moves, answers while it happens instead of next quarter's remediation program.

AI as your middleware partner →The ERP failure ladder →

The permission baseline

Shopify ID, paired with Google — the Segment Authorization Funnel.

Every permission in the system stands on one identity spine: the Shopify customer ID paired with a verified Google sign-in. From that pairing, authorization flows one way — identity → consent → entitlement → segments — so nothing reaches an audience that the person didn't consent to and the account isn't entitled to.

01 · IDENTITYSign in onceOne-click Google login, paired to your Shopify customer ID. Identity arrives verified — no new password.
02 · CONSENTConsent recordedEvery event carries the recorded consent state via Shopify's Customer Privacy API — server-side, evidence-grade.
03 · ENTITLEMENTPermissions grantedCapabilities are purchase-granted and scoped; AI agents act only under signed mandates, every call ledgered.
04 · SEGMENTSSegments authorizedOnly consented, entitled profiles enter the revenue-weighted segments pushed to Google for Smart Bidding.

The same baseline decides what you see: access is granted by invitation, one role at a time — separation of duties by design.

Choose your view →

Feature → function

Everything it does, in one table.

The compliance, vault, and distribution plane on this store — each piece, and the job it exists to do.

Google login
Sign in with the account people already have. Consent attaches to a real, verified person from the first event.
Shopify events
Orders, consent, and page signals ride the consent event bus as server-side events — gated by Shopify's Customer Privacy API — so the record exists after the tab closes, and the ad stack keeps working without cookies.
AI Tool Runner
The agent does the chores — search, cart, checkout, returns, reports — as server-side tool calls under a signed mandate. Every call, and every refusal, is ledgered.
CRA checklist
Turns the EU cyber law into ten tickable steps ahead of two deadlines — 11 Sep 2026 and 11 Dec 2027. Open the checklist
SBOM registry
Stores machine-readable ingredient lists (CycloneDX / SPDX) for every app and firmware version. Private by default; served to authorities and customers on request.
Firmware vault
Encrypts each firmware file under its own key. The file never exists at a public URL — possession of the ciphertext yields nothing.
Upload certificate
An Ed25519-signed receipt proving what was uploaded, by whom, when — verifiable by anyone against the published public key. No account, no trust in us required.
Latest pointer
Always names the newest version of a product line. When its fingerprint changes, that IS the update signal — buy once, updates included.
Grant-gated download
Downloads need a purchased capability, not a link: 120-second single-use tokens, every access — and every denial — recorded.
Hash-chained ledger
Every event's record includes the fingerprint of the record before it. History can be broken visibly, never edited quietly.
Key rotation
A suspected leak is healed server-side: previously issued tokens die at once, and the file never needs re-uploading.
QR bridge
Mints your own QR codes and short links that stamp where a customer came from — a video, a box, a game world — into analytics. Open the wizard
Get the app →The firmware service →The CRA checklist →

Explained like you're five

You made a toy, and you want to share it carefully.

You made a toy, and you want to give it to friends — but only friends who traded you a wristband, and you want to always know who took one.

So you put the toy in a magic safe. The safe doesn't have a door people can find — when a friend with a wristband asks nicely, the safe opens for exactly two minutes, just for them, and then forgets it ever opened. If a mean kid steals the safe, it's just a heavy box. The toy inside stays invisible.

Every toy gets a fingerprint — no two toys have the same one — and a shiny sticker you signed with a special pen only you own. Anybody in the whole world can look at the sticker and say “yep, that's really theirs” — they don't even have to know you.

The box has an ingredients list taped on, like a cereal box, so if one ingredient turns out to be yucky someday, everyone can check their box fast.

And there's a diary that writes itself. Every time anyone opens the safe — or even tries and gets told no — the diary writes it down. Each page is glued to the page before it, so nobody can sneak a page out without everyone seeing the rip.

When you make a newer, better toy, friends don't need a new wristband — you just point the sign that says NEWEST TOY at it, and everybody's wristband still works.

Oh — and you put magic doorbells on your videos and boxes and games, so when friends come to your store, you know which doorbell they rang — and each ring is written in the diary the moment it rings, not at bedtime.

Friends don't need a special key for your house, either. The wristband they already wear everywhere — their Google one — opens your door, and now the diary knows exactly who rang.

Then a helper robot moved in. You don't tell it how to do chores — you give it a signed permission slip, and it fetches, wraps, and returns toys itself. It wears its own wristband, so every chore the robot did — and every chore it was told no about — is in the diary too, while it happens.

A toy factory down the street had a messy diary, so they tore down the whole factory to build a new one. The rebuild broke, the grown-ups found out, and the factory closed for good. You never tore anything down — you added a safe, a diary, a robot, and kept making toys.

The best part: grown-ups in Europe are about to require exactly this — the ingredients list, the diary, the stickers — starting September 11, 2026. Most toy-makers haven't heard yet. You already have all of it.