Chính sách riêng tư

Ads Dashboard (ads.dcomcy.com) và tiện ích Chrome “Shopify Token Grabber” / “Dcomcy Token Tool” · Cập nhật 19/09/2026

Ads Dashboard là công cụ báo cáo quảng cáo: nó ghép số liệu chi tiêu từ Facebook Ads với doanh thu thật từ Shopify để bạn biết mỗi chiến dịch lãi lỗ ra sao. Trang này nói rõ dữ liệu nào được giữ, giữ ở đâu, và dùng làm gì.

Tiện ích Chrome — phần Shopify

Áp dụng cho “Shopify Token Grabber” trên Chrome Web Store và cho tab Shopify của “Dcomcy Token Tool” (bản tải từ dashboard). Phần này làm đúng một việc: thay bạn bấm qua các bước trên Shopify Dev Dashboard để lấy Admin API access token cho một store mà chính bạn chỉ định.

Tiện ích không có máy chủ riêng, và mọi kết nối mạng của nó chỉ đi tới các tên miền của Shopify. Token chỉ rời tiện ích theo đúng một đường: vào trang ads.dcomcy.com mà bạn đang mở, khi chính bạn bấm lấy token từ trang đó. Trang đó lưu token vào tài khoản Ads Dashboard của bạn. Dùng tiện ích một mình thì token chỉ hiện trong cửa sổ tiện ích, không đi đâu cả.

Tiện ích giữ gì trong máy bạn

Tiện ích không làm gì

Token đi đâu

Token đi thẳng từ tiện ích vào trang ads.dcomcy.com đang mở trên máy bạn — đúng chỗ mà nếu không có tiện ích thì bạn sẽ tự dán vào. Chỉ đúng tên miền này gọi được tiện ích; mọi trang khác bị Chrome chặn từ trước khi tới mã của chúng tôi.

Token mà tiện ích xin chỉ gồm các quyền chỉ đọc: đơn hàng, sản phẩm, khách hàng, báo cáo. Nếu Shopify trả về quyền rộng hơn quyền đã xin, tiện ích từ chối token đó thay vì đưa cho dashboard.

Tiện ích Chrome “Dcomcy Token Tool” — phần Facebook

Bản tải từ dashboard (không có trên Chrome Web Store) có thêm tab Facebook: tự tạo một app Facebook developer trong tài khoản Facebook của chính bạn, rồi lấy token Meta Ads 60 ngày (quyền ads_management, ads_read, business_management) để bạn dán vào dashboard.

Ads Dashboard

Dữ liệu được giữ

Giữ trong bao lâu

Dùng để làm gì

Chỉ để dựng báo cáo cho chính bạn xem, và để chạy những việc bạn bật: nhắc đổi creative, tự tăng ngân sách theo ngưỡng bạn đặt, gửi thông báo Telegram. Không dùng cho mục đích nào khác, không bán, không chia sẻ với bên thứ ba, không dùng để huấn luyện mô hình.

Khi bạn hỏi AI hỗ trợ (nút góc dưới màn hình), câu hỏi và bản tóm tắt số liệu đang hiện trên màn hình (tên campaign, chi phí, doanh thu, ROAS — không có token hay thông tin người mua) được gửi tới nhà cung cấp AI để soạn câu trả lời. Câu hỏi và câu trả lời được lưu 30 ngày để cải thiện hỗ trợ. Không muốn gửi thì đừng dùng nút này.

Dữ liệu của mỗi tài khoản tách riêng. Người dùng này không xem được dữ liệu của người dùng khác.

Nơi lưu

Máy chủ đặt tại Railway. Kết nối luôn qua HTTPS. Token, đơn hàng Shopify đã lưu và báo cáo lưu tạm đều được mã hoá trước khi ghi xuống; khoá giải mã nằm ngoài cơ sở dữ liệu.

Bên thứ ba

Ngoài các bên trên, không ai nhận dữ liệu của bạn.

Quyền của bạn

Liên hệ

Thắc mắc về dữ liệu, hoặc muốn xoá tài khoản: [email protected].

English summary

Chrome extension “Shopify Token Grabber”

The extension has no server of its own, and its only network traffic goes to Shopify domains. The token leaves the extension by exactly one route: into the ads.dcomcy.com page you have open, when you ask for it from that page, which then saves it to your Ads Dashboard account. Used on its own, the extension only shows the token in its popup and sends it nowhere.

The points above describe the Shopify part: “Shopify Token Grabber” on the Chrome Web Store and the Shopify tab of “Dcomcy Token Tool”.

Chrome extension “Dcomcy Token Tool” — Facebook part

The build downloaded from the dashboard (not on the Chrome Web Store) adds a Facebook tab: it creates a Facebook developer app in your own Facebook account and obtains a 60-day Meta Ads token (ads_management, ads_read, business_management) for you to paste into the dashboard.

Ads Dashboard

Ads Dashboard joins Facebook Ads spend with real Shopify revenue so an advertiser can see which campaigns make money. It holds the account's email and hashed password, encrypted Facebook and Shopify access tokens, ad metrics, and Shopify order records (order number, value, status, risk level, UTM parameters). For stores connected with a pasted token it also keeps the shipping country — only the country; the rest of the address is dropped the moment orders are fetched. Stores installed through the AdsDcomcy app on the Shopify App Store are fetched without any address. It does not store shoppers' names, emails, phone numbers or payment details.

Retention: orders are kept while the store is connected. Deleting the store in settings deletes its token and the orders cached through that connection at once. Uninstalling the app revokes the token immediately, and the store and its orders are deleted when Shopify's shop/redact request arrives 48 hours later. A customers/redact request deletes the named orders.

That data is used only to build reports for the account that owns it, and to run features the user switches on: creative reminders, budget rules, Telegram notifications. It is never sold, never shared with third parties beyond the services listed above, and never used to train models. When a user asks the in-app AI support chat, the question and a summary of the numbers on screen (campaign names, spend, revenue, ROAS; no tokens, no buyer data) are sent to the AI provider to write the answer; questions and answers are kept 30 days. Each account's data is isolated from every other account's.

Servers run on Railway and all traffic goes over HTTPS. Tokens, stored Shopify orders and cached reports are encrypted at rest, with the key kept outside the database.

To disconnect a store, delete it in settings — its token goes with it — or uninstall the app in Shopify Admin to revoke the token immediately. To delete everything, write to [email protected].