Legal
Privacy Policy
Last updated: August 1, 2026
1. Who we are
Helm (“Helm,” “we,” “us”) is an ecommerce operations product operated at gohelm.co. Merchants connect Shopify and Meta Ads (read-only), then use dashboards, live activity, and automations that send alerts to Slack or append rows to Google Sheets.
Questions about this policy or your data: admin@gohelm.co.
2. Account and workspace data
When you create or join a Helm workspace, we process:
- Account identifiers — email address and authentication session data (via Supabase Auth, including email/password or Google sign-in).
- Workspace membership — workspace name, roles, permissions, team invites (invitee email), and seat/access status.
- Billing identifiers — subscription and customer IDs from our payment provider (Paddle), plan, trial dates, and related status fields needed to enforce access.
- Support content — messages and optional attachments you send through in-app support.
- Automation configuration — prompts, conversation history used to build automations, automation specs, and run history (triggers and results).
We use this data to operate your account, authenticate you, bill the workspace, invite teammates, provide support, and run the product you configured.
3. Shopify store data
When you connect Shopify, Helm requests read-only Admin API scopes that match features we ship. We do not request write access to mutate your store. Scopes fall into these groups:
- Orders, checkouts, customers, products, inventory, fulfillments, returns, and draft orders — Shopify dashboard, live activity, and event automations (including derived alerts such as abandoned checkout or unfulfilled-order follow-ups).
- Discounts, locations, and shipping-related reads — live activity context and order-related event detail.
- Themes, markets, locales, content, product listings, publications, purchase options, and related catalog reads — so we can register and automate on the Admin webhook topics merchants use in plain English (for example when a theme is published).
- Reports — store analytics charts that use ShopifyQL (for example sessions and sales).
We receive and may store:
- Store events and related payloads via webhooks, plus normalized records (orders, checkouts, products, inventory, fulfillments, returns, draft orders, and similar) used to power the features above.
- Customer-related fields that appear on those records when Shopify provides them (for example name or email on an order or checkout), used only for those ops features and merchant-chosen Slack or Sheets templates — not for advertising or resale.
- Encrypted OAuth tokens so Helm can sync and receive webhooks.
Where a customer has opted out of data use or sale through Shopify, we honor that choice and do not use their data inconsistent with it. Helm does not sell customer data.
4. Meta Ads data
When you connect Meta, Helm uses read-only Marketing API access (notably ads_read). We pull ad account structure and campaign-level insights such as spend, impressions, clicks, reach, and purchase-related actions.
What this powers: the Meta dashboard and automations that watch ad metrics (for example spend, ROAS, or CAC thresholds), typically refreshed on a roughly 15-minute cadence.
Meta data deletion requests submitted through Facebook’s Apps and Websites flow are handled by our Data Deletion Request callback at /api/meta/data-deletion, which clears matched Meta connection tokens and provides a status URL. You can also email admin@gohelm.co to request deletion of Meta-related data in Helm.
5. Google Sheets data
When you connect Google Sheets, Helm requests: spreadsheet access to append rows (and optionally create a new tab after you confirm in chat); limited Drive file access (drive.file) so you can choose spreadsheets through Google’s file picker (only files you select, or that Helm creates, become accessible); and your Google account email (userinfo.email) so we can identify and display the connected Google account on your workspace connection. Helm does not request access to list all files in your Google Drive.
What this powers: automation exports and digests that write rows into your sheets, and the Sheets dashboard in Helm. We do not use your spreadsheets for unrelated purposes.
Helm’s use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to serve ads. We do not allow humans to read Google user data except (a) with your explicit consent, (b) for security purposes, or (c) as required to comply with applicable law. Our AI provider processes automation chat and configuration — including spreadsheet names and IDs you attach — to help build automations; it does not read the contents of your Google Sheets cells.
6. Slack data
When you connect Slack, Helm can post messages to channels you authorize, list channels, and read channel history and user profiles as needed for the Slack dashboard and delivery of alerts.
What this powers: automation alerts and manual messages into your Slack workspace. Outbound text may include store or ad fields you put in a template (for example order number or customer email). That content is delivered to your Slack workspace under your control.
7. AI processing
Automation builder chat (your prompts, connected-context summaries, and proposed automation specs) is processed by our LLM provider (Anthropic) so Helm can draft and refine automations. We use this solely to operate that feature. We do not sell conversation content. Processing is also subject to the provider’s own terms and privacy practices.
8. How we share data (and what we do not do)
We do not sell your data. We do not share merchant or customer data with third parties for their own independent marketing.
We use service providers (“processors”) that help us run Helm. They process data only to provide their service to us, for example:
- Supabase — authentication, database, and support file storage
- Paddle — subscription billing and payments
- Resend — transactional email (invites, support replies)
- Anthropic — automation chat processing
- Hosting — application and worker hosting (for example Vercel and Railway)
- Connected platforms — Shopify, Meta, Slack, and Google, as you authorize, to read inputs or deliver outputs
We may disclose information if required by law, to protect Helm or users, or in connection with a merger or sale of assets (with notice where appropriate).
9. Retention
We keep workspace and connected data while your workspace remains active and as needed to provide the service, comply with law, or resolve disputes.
- Some short-lived metric snapshots used for threshold checks are pruned on a rolling basis (approximately 45 days).
- Disconnecting a platform — or uninstalling Helm from Shopify Admin — clears OAuth tokens so Helm can no longer access that account. Historical synced records may remain in your workspace until Shopify sends shop/redact, the workspace is removed, or you ask us to delete them.
- Shopify’s mandatory compliance webhooks (
customers/data_request,customers/redact,shop/redact) are received at our HMAC-verified webhook endpoint. We fulfill them in-product: data requests are compiled from records we hold and emailed to our compliance contact; customer redaction clears personal fields we stored for that customer; shop redaction deletes the store connection and cascaded Shopify data for that shop. - Meta data deletion requests are handled via our Data Deletion Request callback (
/api/meta/data-deletion) and status page at /meta/data-deletion, or by emailing admin@gohelm.co.
To request deletion of your Helm workspace or personal account data outside those platform flows, email admin@gohelm.co.
10. Security
We use industry-standard measures appropriate to the sensitivity of the data. Data in transit is protected with HTTPS/TLS. Data at rest in our primary database is encrypted by our infrastructure provider (Supabase). Platform OAuth tokens are additionally encrypted at the application layer before storage. Where our provider maintains database backups, those backups are encrypted under the provider’s controls.
We maintain a security incident response process. If we become aware of a security incident affecting personal data we hold, we will investigate promptly and notify affected customers and authorities as required by applicable law. Access to production systems is limited to authorized personnel. No method of transmission or storage is 100% secure.
11. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or export personal data, or to object to certain processing. You can disconnect integrations in Helm settings, leave a workspace if invited, and contact us at admin@gohelm.co to exercise applicable rights. We may need to verify your request.
Helm’s automations notify you or log data on your behalf; they do not make automated decisions about your customers that have legal or similarly significant effects.
12. Children
Helm is built for business users. We do not knowingly collect personal information from children under 13. If you believe a child has provided us data, contact us and we will take appropriate steps.
13. Changes
We may update this Privacy Policy from time to time. We will change the “Last updated” date above and, when changes are material, take additional steps such as a notice in the product or by email where appropriate. Continued use of Helm after an update means you accept the revised policy.
14. Contact
Helm — privacy and data requests: admin@gohelm.co.
Website: https://gohelm.co