This Privacy Policy explains how CRO-Conversion Rate Optimizer (the "App", "we", "us")
collects, uses, and protects information when a Shopify merchant installs and
uses the App, and when their customers interact with features the App provides
on the merchant's online store. By installing the App you agree to this policy.
1. Information we collect
We collect only the data needed to provide the App's features:
Store information: your store domain, store name, contact email, currency, country, and timezone, obtained from Shopify when you install the App.
Access token: a Shopify access token that lets the App read the data you approve. It is encrypted at rest and never shared.
Product and inventory data: read from your store to display wishlist items, upsells, availability, and shoppable video product tags.
Customer wishlist data: for logged in customers, the products they save to their wishlist, linked to the customer identifier that Shopify provides through its signed App Proxy.
Back in stock requests: the email address a shopper submits to be notified when a product returns to stock, together with the related product.
Subscription and billing records: your plan, status, and any discount code applied, used to manage your subscription to the App.
We do not collect payment card details, and we do not request
access to your orders or to your full customer list. The App uses least
privilege access scopes limited to reading products, inventory, and themes.
2. How we use information
To provide and operate the App's storefront features (wishlist, side cart, trust badges, offers, countdown timers, payment icons, and shoppable reels).
To sync a logged in customer's wishlist across their devices.
To send back in stock notifications that a shopper explicitly requested.
To create and manage your subscription and apply any discount code.
To secure the service, prevent abuse, and troubleshoot problems.
3. How information is shared
We do not sell your data or your customers' data. Information is processed only
to run the App. Data is stored on our hosting provider and transmitted to and
from Shopify over encrypted connections. If you connect an email provider for
back in stock notifications, the shopper's email is shared with that provider
solely to deliver the message you requested.
4. Data retention and deletion
We keep data only as long as the App is installed and needed to provide the
service. The App fully supports Shopify's mandatory privacy webhooks:
Customer data request: when a shopper asks what data you hold, we compile the wishlist and back in stock records associated with that customer.
Customer redact: when Shopify requests deletion of a customer's data, we remove that customer's wishlist and back in stock records.
Shop redact: when you uninstall the App, Shopify sends a shop redact request 48 hours later and we permanently delete all data associated with your store.
Uninstalling the App immediately revokes the App's access token and deactivates your store record.
5. Security
Access tokens are encrypted at rest using authenticated encryption with a per
store derived key. All requests between the App, Shopify, and your storefront
are verified using Shopify's HMAC signatures, session tokens, and App Proxy
signatures, and are served over HTTPS. Access to stored data is restricted.
6. Your rights
Depending on your location, you or your customers may have rights to access,
correct, or delete personal data. You can exercise deletion at any time by
uninstalling the App, or by contacting us using the details below. We respond
to Shopify's automated privacy requests as described in section 4.
7. Changes to this policy
We may update this policy from time to time. Material changes will be reflected
by updating the date at the top of this page.