StorePilot App Privacy Policy
Last updated
Plain-English summary: the StorePilot app records how shoppers move through your store — clicks, scrolls, and funnel steps — as de-identified events keyed to rotating random IDs. It never captures names, emails, IP addresses, page URLs, or anything a shopper types. Tracking runs only where Shopify's consent rules allow it, and raw events are deleted after the retention window you choose.
What this policy covers
This page describes the StorePilot AI Shopify app — what it processes on a store where it's installed, and about that store's shoppers. Visits to this marketing website are covered separately by the website privacy policy.
Who we are
The app is operated by the team behind StorePilot AI (built by EVDEV). For any privacy question, email hello@usestorepilot.com. [Legal entity name and registered address to be added.]
What the app collects on your storefront
Behavior events come from two collectors: a Shopify Web Pixel (which runs inside Shopify's own sandbox) and an app-embed block you can switch off with one toggle in the theme editor. Both are gated by consent (next section).
- What an event contains: the event type (e.g. product viewed, added to cart, checkout started, checkout completed), a coarse page type ("product page", "cart" — never the URL), a device class (mobile / tablet / desktop), a traffic-source category (e.g. organic, social, direct), a coarse region bucket derived from the store's own locale settings (never from a shopper's IP address), an A/B-test arm tag when an experiment is running (which variant the session was shown — "A" or "B", nothing more), and an opaque, rotating session ID. Clicks are recorded by element role, scrolls by depth. When a checkout completes, the order total (amount and currency) is recorded so revenue impact can be measured.
- What is never captured: no names, no emails, no IP addresses (never collected in the first place), no page URLs, no user agents, no customer IDs, and never the contents of anything a shopper types — search terms and form values are not recorded.
- Not session replay: the app extracts behavioral features; it does not record video or replay a shopper's screen.
Consent
Both collectors are gated by Shopify's Customer Privacy API. Events are recorded only where that API says analytics processing is allowed for the visitor. In opt-in regions such as the EU and UK, nothing is collected until the shopper consents; if a shopper withdraws consent mid-session, collection stops and unsent events are discarded.
Store context (optional)
To ground its recommendations, the app can read anonymized aggregates about your catalog, pricing, and the last 60 days of sales through Shopify's Admin API — totals and product-type tallies. This runs only when you trigger it from the app's Settings. No customer details and no order-level records are retained: no order IDs, no addresses, no customer IDs, no individual order rows.
How long we keep data
Raw behavior events, session journeys, and the daily de-identified aggregates built from them are all deleted on the same retention window you choose in the app's Settings — 30, 90, or 180 days (90 by default). What persists beyond that window is your experiment history and results — the tests you ran and what they concluded — which contain no visitor-level data.
Sub-processors
- Anthropic — drafts the wording of recommendations and experiments. It receives only de-identified numeric aggregates and generation instructions — never customer text, never order rows, never personal details.
- Fly.io — hosts the app and its Postgres database.
- Shopify — the pixel runs in Shopify's sandbox, and storefront events and admin data flow over Shopify's own infrastructure.
Your rights, and your customers' rights
GDPR and CCPA requests — access, deletion, correction — are handled through the data-request page. The app also honors Shopify's mandatory privacy webhooks: customer data request, customer redact, and shop redact. When Shopify sends one, we run the corresponding lookup or deletion. When you uninstall the app, Shopify sends a shop-redact request and we delete the store's data on receipt.
Changes
We'll update this page when the app's practices change and revise the date above. Questions? hello@usestorepilot.com.
This page is provided for transparency and is not legal advice. Final wording should be reviewed by counsel before relying on it.