Security and data

Plain answers about your store's data.

If a question here matters to your legal team, ask and we will put it in writing.

What we collect
Session events, product views, cart and order values, and the widget a session saw.
What we do not collect
Payment details, passwords, or customer records beyond the identifiers Shopify already exposes.
Encryption
TLS in transit, encryption at rest on all stored session data.
Access
Role-based access internally, with audit logging on every export.
Retention
Session-level data for 13 months, aggregates indefinitely unless you ask otherwise.
Deletion
Uninstall removes widgets immediately; a written request deletes stored data within 30 days.
Sub-processors
Cloud hosting and error monitoring only. The list is available on request.

Need a security review before you install?

Send your questionnaire over and we will complete it.