Privacy Policy
Snapshot CRO · Effective date: August 23, 2026
Snapshot CRO ("the App", "we", "us", "our") provides conversion analytics and A/B testing tools ("the Service") to merchants who use Shopify to power their stores. This Privacy Policy describes how personal information is collected, used, and shared when you install or use the App in connection with your Shopify-supported store.
1. Information We Collect
Information about you (the merchant)
When you install the App, we receive certain information from your Shopify account through Shopify's APIs:
- Your store's Shopify domain (myshopify.com address);
- Information about your store's products, content, themes, and reports, as authorized by the access scopes you approve during installation;
- Order information limited to what is needed for conversion measurement (order totals, currency, product identifiers, and order timestamps);
- Authentication tokens issued by Shopify that allow the App to operate;
- Your billing plan and subscription status (billing itself is processed by Shopify — we never see or store your payment details);
- If you contact us for support, the contents of your message and your contact details.
Information about your store's visitors
Once installed and enabled, the App collects analytics data about how visitors browse your storefront so we can provide you with conversion insights. This includes:
- A randomly generated session identifier, stored in a first-party cookie on your storefront (expires after 7 days);
- Pages viewed, page titles, referring URLs, exit links, and on-site search terms and filters used;
- Campaign parameters (UTM tags) present in the URL;
- Engagement measurements such as time on page, scroll depth, and counts of clicks, taps, and interactions with buttons and links;
- Device and browser information (user-agent string and device type);
- IP address, which we use to derive approximate location (country, region, city) and to filter out bot and datacenter traffic;
- Shopping activity such as add-to-cart events, checkout progress, and whether a session resulted in an order, together with the order total and currency;
- A/B test variant assignments for sessions included in tests you run.
What we do not collect or store
- We do not record visitor sessions, capture screen contents, or log the contents of keystrokes or form fields. Interaction data is limited to counts and aggregate measurements.
- We do not store customer names, email addresses, phone numbers, shipping or billing addresses, or payment information. Any customer identifiers that may be present in Shopify event data are discarded and are not saved to our database.
- We do not use fingerprinting techniques to identify visitors across sites or devices.
2. How We Use Information
We use the information we collect to:
- Provide and operate the Service, including analytics dashboards, store snapshots, conversion reports, and A/B tests;
- Attribute orders to visits so you can measure conversion;
- Detect and exclude bot, automated, and datacenter traffic from your analytics;
- Provide customer support and respond to your requests;
- Maintain, secure, and improve the App;
- Comply with applicable laws and Shopify's requirements for apps.
We do not sell or rent personal information, and we do not use visitor data for advertising or share it with data brokers.
3. How We Share Information
We share information only with the service providers we need to operate the App:
- Hosting and infrastructure providers that run the App and store its database;
- An IP geolocation service, which receives visitor IP addresses solely to resolve approximate location;
- Shopify, through the APIs, webhooks, and web pixel infrastructure that the App is built on.
We may also disclose information if required to do so by law, regulation, or valid legal process, or to protect our rights, our users, or the security of the Service.
4. Data Retention and Deletion
- Analytics data is retained while the App is installed so that you can view historical reports.
- When you uninstall the App, Shopify automatically revokes our access to your store's data, and we delete your authentication and billing records. Following Shopify's shop/redact request (sent 48 hours after uninstall), we delete the store's remaining data, including visitor analytics records.
- You may request deletion of your store's data at any time by contacting us at the address below.
5. Privacy Rights and Compliance Webhooks
The App implements Shopify's mandatory compliance webhooks and honors them for all stores, regardless of where a data subject is located:
- customers/data_request — if one of your customers requests their data, we respond with any personal data we hold that can be associated with that customer.
- customers/redact — if one of your customers requests deletion, we delete any personal data we hold that can be associated with that customer.
- shop/redact — after uninstallation, we delete the store's data as described in Section 4.
Because the App does not store customer names, email addresses, or Shopify customer IDs, in most cases we hold no data that can be linked to an individual customer; where that is the case, there is nothing to return or erase, and we confirm completion of the request.
For the purposes of the EU/UK General Data Protection Regulation (GDPR) and similar laws, the merchant is the data controller of their storefront visitors' personal data, and we act as a data processor on the merchant's behalf, processing visitor data only to provide the Service. For information we hold about you as a merchant, we act as a controller. Data subjects may exercise rights of access, correction, deletion, and objection by contacting us at the address below; we respond within the timelines required by applicable law.
6. Your Responsibilities as a Merchant
Because you are the data controller for your store's visitors, you are responsible for:
- Ensuring your store's own privacy policy discloses your use of analytics tools such as the App;
- Obtaining any consent from your visitors that is required by the laws that apply to your store (for example, cookie or tracking consent under the EU ePrivacy rules), including configuring any consent banner your store uses;
- Responding to privacy requests from your customers and forwarding to us any request that concerns data processed by the App.
7. Security
We use reasonable administrative and technical safeguards to protect the information we process, including access controls and encrypted connections to the App and its database. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Children's Privacy
The Service is intended for business use by merchants and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe we have collected such information, contact us and we will delete it.
9. International Transfers
The App is hosted in the European Union. Information may be processed in other countries by our service providers; where required, we rely on appropriate safeguards for such transfers.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to our practices or for operational, legal, or regulatory reasons. The current version will always be posted at this page with its effective date. Your continued use of the App after an update constitutes acceptance of the revised policy.
11. Contact Us
For questions about this Privacy Policy or to make a privacy request, contact us by e-mail at shep@therealheroesofecommerce.com.