Information we process
When you install the app, we process your Shopify store domain, installation credentials, granted access scopes, and technical request metadata required to authenticate and operate the service.
The app queries aggregate Shopify Analytics metrics such as sessions, funnel stages, traffic source, device, country, landing-page type, and web-performance measurements. Diagnostic report results are calculated on request and are not used to build advertising profiles.
The app also reads theme metadata and file checksums, plus Shopify change notifications for themes, products, stock status, discounts, domains, customer-account settings, and store settings. It does not read theme-file contents or modify any of these resources.
When service-status monitoring is enabled, the app reads public incident data from the selected providers' official status pages. Store, customer, and analytics data are not sent to those providers. Each store can turn individual status integrations on or off.
The public FunnelSleuth website uses Google Analytics only after a visitor allows anonymous analytics. Google may receive website usage details such as page views, browser type, and approximate location. Shopify store analytics, store identifiers, customer information, and app report data are not sent to Google.
Customer data
FunnelSleuth does not store customer names, email addresses, postal addresses, payment details, or individual browsing histories. If a merchant enables privacy-safe store visit tracking, Shopify loads it only when the visitor's analytics consent permits. Standard shopping events are converted immediately into anonymous daily totals; visitor identifiers are not retained.
Shopify classifies aggregate ShopifyQL reporting as protected customer data access and requires Level 2 field declarations. FunnelSleuth uses that approval only to request aggregate analytics and does not directly retrieve or retain customer-level name, email, phone, or address values.
How information is used
- Authenticate your store and maintain the app session.
- Generate the conversion diagnosis you request.
- Measure consented visits to the public marketing website.
- Secure, monitor, troubleshoot, and improve the service.
- Respond to support and legal requests.
Legal bases
Where the GDPR applies, we process installation and service data to perform our contract with the merchant, protect the service and our legitimate interests, and comply with legal obligations. We do not sell personal information or share it for cross-context behavioral advertising as those terms are used by the CCPA and CPRA.
Service providers
We use Shopify to provide commerce analytics and retain a bounded change-event history in app-owned installation data, Vercel to host the application, and Supabase to store encrypted app-session records. If a merchant optionally connects a GitHub theme repository, FunnelSleuth reads commit timestamps, changed filenames, commit identifiers, and the editor identity supplied by Shopify or GitHub. Theme file contents, GitHub access tokens, and complete commit messages are not retained. These providers process data under their own security and privacy commitments.
Retention and deletion
App-session records, up to 100 summarized store-change events, and the latest live-theme checksum baseline are retained while the app is installed and deleted following uninstall or a verified shop-redaction request. Schema-event summaries retain resource identifiers and changed field paths, not complete metaobject values or raw event payloads. Security and operational logs are retained for up to 30 days unless a longer period is required to investigate abuse, preserve evidence, or comply with law. We do not retain aggregate diagnostic results as a merchant data warehouse.
Security
Data is transmitted over HTTPS. Access is restricted to the minimum systems and credentials required to operate the app. No system can be guaranteed perfectly secure, but we apply reasonable administrative and technical safeguards.
Your rights
Depending on your location, including under the GDPR, UK GDPR, CCPA, or CPRA, you may request access, correction, deletion, portability, or restriction of personal information and may object to certain processing. Because most app data belongs to the Shopify merchant account, requests should identify the relevant .myshopify.com domain. We will not discriminate against you for exercising applicable privacy rights.
International processing
Our service providers may process information in Canada, the United States, and other locations where they operate. Where required, transfers are protected through contractual and legal safeguards supplied by those providers.
Policy changes
We may update this policy as the service or applicable law changes. The effective date at the top identifies the current version, and material changes will be communicated through the app or merchant contact information when appropriate.
Contact
Email tuttonlara@gmail.com with privacy questions or requests.