Privacy Policy
Last updated: 5 September 2026
Avery ("we", "us", "our") is a conversion rate optimisation tool for Shopify merchants. This policy describes what data we collect, why, and who can see it.
1. What we collect
From your Shopify store (via OAuth)
- Store metadata - your store domain, owner email address, and the OAuth scopes you granted.
- Product catalogue - titles, handles, status, images, variants, prices, and description metadata. Used to identify conversion issues in your catalogue.
- Theme files - Liquid templates and CSS from your live theme. Read when you ask us to suggest a code change. We read; we never write without your explicit approval.
- Order aggregates - daily order count, revenue, and average order value. Used to measure whether a change helped. We do not collect individual order details, customer names, or shipping addresses.
From Google PageSpeed Insights
We send your store’s public URLs (home, product, collection, and cart pages) to the Google PageSpeed Insights API to measure loading speed. Google processes these requests under their own privacy policy. We store the resulting scores and diagnostic data.
From the free website scan
If you use the free scan on our home page, we record the website address you entered, what we read from its public pages, the findings we produced, and the internet address (IP) your request came from. The IP address is used only to limit how many scans one visitor can run and is never linked to an account. Scan records are deleted after 90 days. We read only pages the website already serves to any visitor; we do not sign in to it or change anything on it.
From our web pixel (when installed)
If you install the Avery web pixel, it collects anonymous browsing data from your store’s visitors:
- A browser-scoped visitor identifier (Shopify’s
clientId, not a cookie we set) - Page URLs visited and referrer
- Viewport dimensions and device type
- Whether the visitor completed a purchase and the order value
- Consent status as reported by Shopify’s consent API
We do not collect names, email addresses, payment details, or any data that identifies an individual visitor. Pixel events are retained for 90 days, then automatically deleted. Aggregated daily summaries (counts by device and traffic source, with no individual data) are kept indefinitely.
Session cookie
We set one signed, httpOnly session cookie to keep you logged in. It lasts 90 days from when you log in, or until you log out, and it contains your store domain and an OAuth state nonce. We do not use analytics cookies, advertising cookies, or any third-party tracking.
2. How we use your data
- Analysis - we inspect your storefront, catalogue, and page speed to identify conversion issues backed by experimental evidence.
- AI-generated code suggestions - when you click "Suggest a fix", we send a summary of the finding and the relevant theme file contents to an AI model, which proposes a code change. You review and approve before anything touches your store.
- Impact measurement - after a change is published, we compare order metrics against the pre-change baseline.
3. Who processes your data
Your data is processed by the following subprocessors:
| Subprocessor | Purpose | Data shared |
|---|---|---|
| Neon (neon.tech) | Database hosting | All stored data, encrypted at rest |
| Fly.io | Application hosting | All data in transit; secrets in Fly’s vault |
| Anthropic (Claude API) | AI analysis and code generation | Store domain, PageSpeed scores, product metadata (titles, prices, image counts), storefront structural observations, finding summaries, and theme file contents when generating code edits. No access tokens, no shopper data, no order details. |
| Google (PageSpeed Insights API) | Page speed measurement | Public storefront URLs |
| Stripe | Subscription billing | Store owner email, an account identifier, and payment details you enter on Stripe’s own checkout page. Avery never sees card numbers. |
| Resend | Email delivery | Store owner email, store domain, and the contents of each email (weekly summary counts, change summaries, billing notices) |
| Sentry | Error monitoring | Error reports: stack traces, store domain and internal record identifiers. Any report containing a Shopify access token is dropped before sending. |
We do not sell your data. We do not share it with anyone other than the subprocessors listed above.
4. Data security
- Shopify OAuth access tokens are encrypted at rest using AES-256-GCM with key rotation support.
- All connections use TLS.
- Database access is restricted to the application. No shared credentials.
- Theme edits pass through mechanical guardrails before they can be previewed or published: file allowlists, maximum diff sizes, Liquid syntax validation, and bans on scripts, iframes, and checkout modifications.
5. Data retention
- Pixel events and sessions - 90 days, then automatically pruned.
- Aggregated daily metrics - kept indefinitely (no individual visitor data).
- Store data, findings, and change history - kept while your store is connected. Deleted when Shopify sends a shop erasure request (typically within 48 hours of uninstalling).
6. Your rights
- Export - you can export all data we hold about your store from the Settings page at any time.
- Disconnect - you can disconnect your store, which revokes the OAuth token immediately. History is kept until the Shopify erasure webhook arrives.
- Delete - you can delete all your data from Settings. This is immediate and irreversible.
- Shopper data requests - Shopify forwards customer data requests and erasure requests to us via mandatory webhooks. We hold no customer-identifiable data (the pixel uses Shopify’s browser-scoped
clientId, not names or emails), so there is nothing to disclose or erase.
7. GDPR
Where GDPR applies, we are a processor of your store’s data and you are the controller. Our Data Processing Agreement is available at /legal/dpa. For shopper data collected by the web pixel, you are responsible for obtaining consent under your own privacy policy; the pixel respects Shopify’s consent API signals.
8. Changes
We will update this page when our data practices change. Material changes will be communicated to connected merchants via email.
Questions? Email us at privacy@useavery.ai