Skip to main content
Cambium Group
LibraryCase studiesApply
Apply
HomeLibraryCase studies

Privacy policy

Last updated September 24, 2026

Effective date: September 24, 2026

This Privacy Policy explains how Cambium Group LLC, an Ohio limited liability company (“Cambium Group”, “we”, “us”), collects, uses, discloses, and protects personal information when you visit our websites, use the Cambium platform, or when a business that uses the Cambium platform installs the Cambium app on its Shopify store or connects its other accounts. By using our website or services, you acknowledge this policy.

1. Our two roles

Controller. For people who visit our website, contact us, or sign in to the Cambium platform, we decide how their information is used. Sections 2 to 4 describe that information.

Processor (service provider). For the data our business customers (“Merchants”) connect to the Cambium platform, including personal information about their own customers (“Shoppers”), we act only on the Merchant’s behalf and on its instructions, under our agreement with the Merchant and our Data Processing Agreement. Section 5 describes that data. The Merchant is responsible for its own privacy notice to Shoppers and for the lawful basis for sharing their data with us. A Shopper who wants to exercise privacy rights should contact the Merchant; we assist the Merchant as our agreement requires.

2. Information we collect as a controller

  • Contact and business information you give us when you apply, book a call, or work with us: name, role, company, work email, phone, website, revenue range, paid media spend, what you tell us about your business, your preferred timing, and what you send us in an engagement.
  • Account information: your name, email, and profile image from Google when you sign in with Google, your workspace, and your role.
  • Usage and security data: IP address, device and browser type, pages and features used, dates and times, and the actions you take in the platform. We record platform requests for security, audit, and support.
  • Communications with us, including support messages.

We do not collect sensitive personal information about website visitors or platform users.

3. How we use controller information

To provide, secure, and support our website and services; to evaluate applications, schedule calls, and respond to inquiries; to manage our business relationships; to create and manage accounts; to send service and transactional messages; to detect, prevent, and investigate fraud, abuse, and security incidents; to improve our services; to meet legal obligations; and to enforce our terms and protect our rights.

4. Cookies and similar technologies

Our website does not use advertising or analytics cookies. The Cambium platform uses only the cookies it needs to work: a session cookie that keeps you signed in and short-lived cookies that protect sign-in and account connections. Our hosting providers keep standard request logs. We honor the Global Privacy Control signal. Because there is no common standard for “Do Not Track” signals, we treat Global Privacy Control as the opt-out signal.

5. Merchant data we process as a processor

When a Merchant connects its accounts, and only on its instruction, we process:

  • Commerce data from Shopify: orders, products, inventory, fulfillment, returns, discounts, gift cards, store credit, subscriptions, and customer records. Customer and order records include the Shopper’s name, email address, phone number, and billing and shipping addresses.
  • Advertising and analytics data from the Merchant’s accounts, such as Meta, Google Ads, TikTok, and Google Analytics: campaign, spend, and performance data, and the identifiers those platforms report.
  • Storefront events from the Cambium pixel on the Merchant’s store: page views, clicks, and checkout events, with pseudonymous identifiers. The pixel checks the Shopper’s analytics consent through the store’s consent settings, and the browser’s Global Privacy Control signal, before it sends anything. If consent is not given, it sends nothing.

We do not collect payment card numbers, bank account numbers, government identifiers, health data, or biometric data.

Purpose limitation. We use Merchant data only to provide our services to that Merchant: to combine its sources, measure its marketing and sales performance, match its orders to its customers, produce its reports, monitoring, and recommendations, and, when the Merchant turns it on, send conversion data to the Merchant’s own advertising accounts (below). Our access to the Merchant’s systems is read-only; we do not change orders, products, or customers in the Merchant’s store.

Personal fields. We keep Shoppers’ names, contact details, street addresses, and device and network identifiers in a restricted zone of the Merchant’s own warehouse. General analytics and reporting do not use them; they use pseudonymous identifiers and locations no more precise than city and postal code.

Conversion matching with advertising platforms. When a Merchant turns on conversion matching, we send, on the Merchant’s instruction, the Merchant’s conversion, profit, and predicted customer-value data to the Merchant’s own accounts at advertising platforms such as Meta, Google, and TikTok, so those platforms can match conversions to the Merchant’s ads. The data can include the Shopper’s name, email address, phone number, and address, which we hash before sending wherever the platform requires it; the order’s details; and device and network identifiers such as IP address, browser user agent, cookie and click identifiers, and the page where the visit started, which the platforms take unhashed. We send a Shopper’s data only when the consent and opt-out state we receive for that Shopper permits it, and we honor opt-out signals such as Global Privacy Control. Each platform’s use of the data is governed by its own terms with the Merchant.

What we do not do with Merchant data. We do not sell personal information. We do not use it for our own advertising, and we do not use one Merchant’s personal data for another Merchant. We do not use personal data to make automated decisions that have legal or similarly significant effects on Shoppers. Conversion matching is a disclosure the Merchant directs to its own advertising accounts. Under some state laws it is the Merchant’s “sharing” for cross-context behavioral advertising, and the Merchant gives the notices and opt-out choices that those laws require. We may create de-identified, aggregated statistics that cannot identify any person or Merchant, and use them to operate and improve our services.

6. How we disclose information

We disclose personal information only:

  • to service providers (subprocessors) that help us run the services, under written contracts that restrict their use of it (section 7);
  • to the Merchant whose data it is, and to users the Merchant authorizes;
  • to the Merchant’s advertising accounts, at the Merchant’s direction, for conversion matching (section 5);
  • when law, a court order, or a government request requires it, or to protect the rights, property, or safety of Cambium Group, our customers, or others;
  • in connection with a merger, financing, acquisition, reorganization, or sale of all or part of our business, subject to this policy; and
  • with your consent or at your direction.

We do not sell personal information, and we have not sold it in the past 12 months.

7. Service providers (subprocessors)

We use cloud infrastructure providers that host and operate the platform: hosting, data storage, and workflow scheduling, in the United States. For our website, we use providers for website hosting, call scheduling, spreadsheet storage, and customer relationship management. They process data only to provide those services to us, under written contracts that restrict its use. A Merchant may ask us for the current list, and we notify Merchants before a new provider processes their personal data.

8. Retention and deletion

  • We keep a Merchant’s data, including the personal fields in its restricted zone, for the term of our agreement with that Merchant, and delete it when the agreement ends, unless law requires us to keep it longer. Data already sent to an advertising platform is held under that platform’s terms with the Merchant.
  • When Shopify sends us a Shopper data request, a Shopper redaction request, or a shop redaction request, we record it and complete it within 30 days.
  • We keep controller information only as long as needed for the purposes in section 3, to meet legal obligations, to resolve disputes, and to enforce our agreements.

9. Security

We use administrative, technical, and physical safeguards that fit the sensitivity of the data. They include:

  • encryption in transit (TLS) and at rest, including backups;
  • a separate, isolated data store for each Merchant;
  • access limited by role, with single sign-on and enforced 2-step verification for staff;
  • credentials kept only in a secret manager;
  • access logging; and
  • a written security incident response policy.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If an incident affects a Merchant’s data, we notify that Merchant without undue delay.

10. Your privacy rights

Depending on where you live, you may have the right to:

  • know or access the personal information we hold about you;
  • correct it;
  • delete it;
  • receive a portable copy of it;
  • opt out of its sale or sharing, or of targeted advertising (we do neither);
  • limit the use of sensitive personal information (we collect none as a controller); and
  • appeal our decision on your request.

We will not discriminate against you for using these rights.

To make a request, email contact@cambiumgroup.co. We verify requests before we act on them. You may use an authorized agent where the law allows; we may ask for proof of the agent’s authority. If we deny your request, you may appeal by replying to our decision, and you may contact your state attorney general or data protection authority.

If your information is Merchant data (section 5), contact the Merchant. We will help the Merchant respond.

California residents. In the past 12 months we collected, as a controller, these categories: identifiers, commercial information about business engagements, internet or other electronic network activity, and professional information. We collected them from you, your devices, and Google sign-in, for the purposes in section 3. We disclosed them to service providers for business purposes. We do not sell or share personal information, and we do not use sensitive personal information to infer characteristics.

People in the European Economic Area, United Kingdom, or Switzerland. Our legal bases are contract (providing the services), legitimate interests (securing and improving the services, and business communications), legal obligation, and consent where we ask for it. We process data in the United States. Where the law requires it, we use appropriate safeguards for international transfers, such as standard contractual clauses. You may complain to your local data protection authority.

11. Children

Our services are for businesses. They are not directed to anyone under 18, and we do not knowingly collect personal information from them. If you believe a child has given us personal information, contact us and we will delete it.

12. Changes to this policy

We may update this policy. We will post the new version with a new effective date. For material changes, we will notify Merchants by email or in the platform before the changes take effect.

13. Contact

Cambium Group LLC, an Ohio limited liability company. Email: contact@cambiumgroup.co.

Cambium Group© 2026TermsPrivacy