Security and data
Plain answers about your store's data.
If a question here matters to your legal team, ask and we will put it in writing.
- What we collect
- Session events, product views, cart and order values, and the widget a session saw.
- What we do not collect
- Payment details, passwords, or customer records beyond the identifiers Shopify already exposes.
- Encryption
- TLS in transit, encryption at rest on all stored session data.
- Access
- Role-based access internally, with audit logging on every export.
- Retention
- Session-level data for 13 months, aggregates indefinitely unless you ask otherwise.
- Deletion
- Uninstall removes widgets immediately; a written request deletes stored data within 30 days.
- Sub-processors
- Cloud hosting and error monitoring only. The list is available on request.
Need a security review before you install?
Send your questionnaire over and we will complete it.