Chính sách riêng tư

Ads Dashboard (ads.dcomcy.com) và tiện ích Chrome “Shopify Token Grabber” / “Dcomcy Token Tool” · Cập nhật 19/09/2026

Ads Dashboard là công cụ báo cáo quảng cáo: nó ghép số liệu chi tiêu từ Facebook Ads với doanh thu thật từ Shopify để bạn biết mỗi chiến dịch lãi lỗ ra sao. Trang này nói rõ dữ liệu nào được giữ, giữ ở đâu, và dùng làm gì.

Tiện ích Chrome — phần Shopify

Áp dụng cho “Shopify Token Grabber” trên Chrome Web Store và cho tab Shopify của “Dcomcy Token Tool” (bản tải từ dashboard). Phần này làm đúng một việc: thay bạn bấm qua các bước trên Shopify Dev Dashboard để lấy Admin API access token cho một store mà chính bạn chỉ định.

Token chỉ rời tiện ích theo đúng một đường: vào trang ads.dcomcy.com mà bạn đang mở, khi chính bạn bấm lấy token từ trang đó. Trang đó lưu token vào tài khoản Ads Dashboard của bạn. Dùng tiện ích một mình thì token chỉ hiện trong cửa sổ tiện ích, không đi đâu cả.

Ngoài các tên miền của Shopify và Facebook, tiện ích còn gọi tới máy chủ của chúng tôi (ads.dcomcy.com) cho đúng hai việc, không bao giờ kèm token:

Tiện ích giữ gì trong máy bạn

Tiện ích không làm gì

Token đi đâu

Token đi thẳng từ tiện ích vào trang ads.dcomcy.com đang mở trên máy bạn — đúng chỗ mà nếu không có tiện ích thì bạn sẽ tự dán vào. Chỉ đúng tên miền này gọi được tiện ích; mọi trang khác bị Chrome chặn từ trước khi tới mã của chúng tôi.

Khi lượt lấy token do dashboard yêu cầu, tiện ích chỉ xin các quyền chỉ đọc: đơn hàng, sản phẩm, khách hàng, báo cáo — và nếu Shopify trả về quyền rộng hơn quyền đã xin thì tiện ích từ chối token đó thay vì đưa cho dashboard. Dùng tiện ích một mình, cửa sổ tiện ích còn một lựa chọn “Toàn quyền” xin thêm quyền ghi; token đó chỉ hiện trong cửa sổ tiện ích cho bạn tự dùng, dashboard không nhận.

Tiện ích Chrome “Dcomcy Token Tool” — phần Facebook

Bản tải từ dashboard (không có trên Chrome Web Store) có thêm tab Facebook: tự tạo một app Facebook developer trong tài khoản Facebook của chính bạn, rồi lấy token Meta Ads 60 ngày (quyền ads_management, ads_read, business_management) để bạn dán vào dashboard.

Ads Dashboard

Dữ liệu được giữ

Giữ trong bao lâu

Dùng để làm gì

Chỉ để dựng báo cáo cho chính bạn xem, và để chạy những việc bạn bật: nhắc đổi creative, tự tăng ngân sách theo ngưỡng bạn đặt, gửi thông báo Telegram. Không dùng cho mục đích nào khác, không bán, không chia sẻ với bên thứ ba, không dùng để huấn luyện mô hình.

Khi bạn hỏi AI hỗ trợ (nút góc dưới màn hình), câu hỏi và bản tóm tắt số liệu đang hiện trên màn hình (tên campaign, chi phí, doanh thu, ROAS — không có token hay thông tin người mua) được gửi tới nhà cung cấp AI để soạn câu trả lời. Câu hỏi và câu trả lời được lưu 30 ngày để cải thiện hỗ trợ. Không muốn gửi thì đừng dùng nút này.

Dữ liệu của mỗi tài khoản tách riêng. Người dùng này không xem được dữ liệu của người dùng khác.

Nơi lưu

Máy chủ đặt tại Railway. Kết nối luôn qua HTTPS. Token, đơn hàng Shopify đã lưu và báo cáo lưu tạm đều được mã hoá trước khi ghi xuống; khoá giải mã nằm ngoài cơ sở dữ liệu.

Cookie

Trang web chỉ dùng cookie cần thiết để chạy, không dùng cookie quảng cáo hay theo dõi, và không có mã của mạng quảng cáo nào: cookie phiên đăng nhập; cookie “tin cậy máy này 30 ngày” nếu bạn chọn khi nhập mã 2FA; và vài cookie tạm sống vài phút trong lúc đăng nhập Google hoặc cài app Shopify. Bạn xoá cookie thì chỉ bị đăng xuất, không mất dữ liệu.

Bên thứ ba

Ngoài các bên trên, không ai nhận dữ liệu của bạn.

Quyền của bạn

Liên hệ

Dịch vụ do Nguyễn Duy — Dcomcy phát triển và vận hành.

Thắc mắc về dữ liệu, hoặc muốn xoá tài khoản: nguyenduy661992@gmail.com, hoặc Zalo 0968666692.

English summary

Chrome extension “Shopify Token Grabber”

The token leaves the extension by exactly one route: into the ads.dcomcy.com page you have open, when you ask for it from that page, which then saves it to your Ads Dashboard account. Used on its own, the extension only shows the token in its popup and sends it nowhere.

Besides Shopify and Facebook domains, the extension calls our server (ads.dcomcy.com) for two things, never with a token attached: it fetches configuration (/ext/config.json — button texts, scope sets, timeouts, so a UI change on their side is fixed server-side) and reports a stuck automation step (/ext/report — the failing step, the page language, up to 25 button labels visible on that page, and a random per-install id used only to group reports from the same installation; it is not tied to your identity, email or store).

The points above describe the Shopify part: “Shopify Token Grabber” on the Chrome Web Store and the Shopify tab of “Dcomcy Token Tool”.

Chrome extension “Dcomcy Token Tool” — Facebook part

The build downloaded from the dashboard (not on the Chrome Web Store) adds a Facebook tab: it creates a Facebook developer app in your own Facebook account and obtains a 60-day Meta Ads token (ads_management, ads_read, business_management) for you to paste into the dashboard.

Ads Dashboard

Ads Dashboard joins Facebook Ads spend with real Shopify revenue so an advertiser can see which campaigns make money. It holds the account's email and hashed password, encrypted Facebook and Shopify access tokens, ad metrics, and Shopify order records (order number, value, status, risk level, UTM parameters). For stores connected with a pasted token it also keeps the shipping country — only the country; the rest of the address is dropped the moment orders are fetched. Stores installed through the AdsDcomcy app on the Shopify App Store are fetched without any address. It does not store shoppers' names, emails, phone numbers or payment details.

Retention: orders are kept while the store is connected. Deleting the store in settings deletes its token and the orders cached through that connection at once. Uninstalling the app revokes the token immediately, and the store and its orders are deleted when Shopify's shop/redact request arrives 48 hours later. A customers/redact request deletes the named orders.

That data is used only to build reports for the account that owns it, and to run features the user switches on: creative reminders, budget rules, Telegram notifications. It is never sold, never shared with third parties beyond the services listed above, and never used to train models. When a user asks the in-app AI support chat, the question and a summary of the numbers on screen (campaign names, spend, revenue, ROAS; no tokens, no buyer data) are sent to the AI provider to write the answer; questions and answers are kept 30 days. Each account's data is isolated from every other account's.

Servers run on Railway and all traffic goes over HTTPS. Tokens, stored Shopify orders and cached reports are encrypted at rest, with the key kept outside the database.

To disconnect a store, delete it in settings — its token goes with it — or uninstall the app in Shopify Admin to revoke the token immediately. To delete everything, write to nguyenduy661992@gmail.com or message Zalo +84 968 666 692.