The short version
- No shopper names, emails, phone numbers or addresses from Shopify.
- App server and database in London, encrypted in transit and at rest. Emails go out through Resend in Ireland.
- Read-only access, except redirects you approve one by one and our checkout pixel.
- Uninstall, and your store’s data is deleted automatically.
Our role
Stillsold is a Shopify app run by Catchlead Ltd, 124 City Road, London EC1V 2NX. For your store’s data we are your processor: we handle it only to provide Stillsold to your store, on your instructions. We sign a data processing agreement with every store before install.
What we collect
Your catalogue
Product titles, handles, types, tags, prices, images and stock status, to suggest in-stock alternatives.
- From
- Shopify Admin API
- Kept
- While installed
Dead-end visits
Page path, dead-end type, product and variant, click source (channel, click-ID name, UTM source and campaign, referrer domain), market, currency, language, random visitor and visit IDs, and test group. Used to measure dead ends and the hold-back comparison.
- From
- Stillsold’s storefront embed
- Kept
- While installed
Session counts
Daily counts by channel and country, with no IDs, for the dead-end share of sessions. A random sample of sessions (10% by default) sends one count from its first page, with or without consent, and says whether consent was given.
- From
- Storefront embed
- Kept
- Daily totals, while installed
Orders after a dead end
Order number and ID, total, currency, first item’s title and date, to measure the revenue difference between the groups.
- From
- Shopify order webhook
- Kept
- While installed; removed if the order is cancelled
Checkout matching
Checkout token, order ID and visitor ID from the order confirmation page, so Shop Pay and Buy it now orders count too. Other online orders are held briefly in case a matching report arrives.
- From
- Stillsold web pixel and order webhook
- Kept
- Unmatched: 3 days. Matched: IDs only, 30 days
Back-in-stock sign-ups
The email a shopper types in, the product, language and the consent text shown, to send one restock email.
- From
- The shopper, on your store
- Kept
- 30 days after sending; 90 days if never sent
Your settings
Your report email address, app settings and the Shopify access token for your store.
- From
- You and Shopify
- Kept
- Until uninstall
What we never collect
- Customer names, emails, phone numbers or postal addresses from Shopify. We request only Shopify’s protected customer data level 1.
- Payment details, full landing URLs or click-ID values.
- IP addresses. They are used in memory for rate limiting and never stored.
Outside dead-end pages and the order confirmation page, the only thing a shopper’s browser sends is the sampled, anonymous session count. Order webhooks are read for the fields above and the rest is discarded at once.
Shopper consent
The embed follows Shopify’s Customer Privacy API. Without analytics consent, a dead-end visit is still recorded, with the details above and a random ID that lasts only for that browser session. It isn’t linked to the cart or to any order, and it’s left out of the hold-back comparison, but it counts towards your dead-end totals. With analytics consent, the visitor ID is kept for up to a year in a first-party cookie. The web pixel runs only with analytics consent and is never used for marketing.
The sampled session count is sent with or without consent. It carries no ID and is stored only as daily totals.
Browser storage
First-party, set by the embed on your storefront.
- Cookie
- _ss_vid: 1 year, only with analytics consent
- Session storage
- _ss_sid, _ss_land, _ss_s, _ss_seen, _ss_closed: this browser session only, with or without consent
- Cart attributes
- _ss_v, _ss_b: only with analytics consent
Deletion
48 hours after you uninstall, Shopify sends a deletion request and we delete all your store’s data automatically. Shopper deletion and access requests are handled automatically for back-in-stock sign-ups, the only data we hold that contains a shopper’s contact details. Deleted data leaves the database’s restore history within 7 days.
Sub-processors
Fly.io, Inc.
Runs the app server.
- Where
- London, UK
Neon, on Amazon Web Services
Database, encrypted at rest (AES-256) and in transit (TLS 1.2+).
- Where
- London, UK
Resend, Inc.
Sends the weekly report and back-in-stock emails.
- Where
- Sent from Ireland (EU); account data in the US
We’ll tell you before adding or replacing a sub-processor. Pilot invoices go through Stripe, which sees only your billing contact, never store or shopper data.
How it’s protected
- Encryption: HTTPS only between browsers, Shopify and the app; TLS to the database; data encrypted at rest.
- Verified requests: webhooks by HMAC signature, storefront calls through Shopify’s signed app proxy, the admin by Shopify session tokens. Web pixel reports aren’t signed, so they’re treated as untrusted and count only once Shopify’s signed order webhook for the same checkout arrives. Revenue figures always come from Shopify, never from the browser.
- Least privilege: read-only Shopify access, except redirects (created only when you approve each one) and the pixel.
- Access: production access is limited to the founder, with two-factor authentication on every provider account. Secrets live in the host’s encrypted secret store, never in code.
- Isolation: each pilot store runs on its own server and database.
- Backups and rollback: point-in-time database restore, one-command rollback.
- Storefront safety: no theme code edits. The script never blocks your page and switches off from the theme editor in one click.
Incidents and contact
If we become aware of a security incident affecting your store’s data, we’ll tell you without undue delay, aiming for within 48 hours, with what happened, what data was involved and what we’re doing about it.
Security contact: security@stillsold.io. For personal data, see the privacy notice.