Privacy policy
Draft — to be reviewed by counsel. This text describes how the app is built today and is not yet a final legal document. Company name, contact address, governing law and sub-processor list are placeholders to be completed.
PageStax (“PageStax”, “we”) is an app for Shopify merchants. This policy explains what information PageStax collects when a merchant installs it, and when shoppers visit pages a merchant has published with it.
Information we collect from merchants
- Store information provided by Shopify when you install the app: your shop domain, and an access token that lets PageStax act on your store within the permissions you approved.
- Catalog and store data read through Shopify’s APIs to build and publish pages: products, variants, prices, inventory, images, shipping and delivery settings, and theme files where you publish to your home page.
- Content you create: page drafts, published pages, saved sections, offers, journeys, experiments and settings.
- Agent tokens you create for the command-line tool. We store only a one-way hash of each token, its label and when it was created and last used.
- Billing status of your PageStax plan, as reported by Shopify’s Billing API. We do not receive or store payment card details.
Information we collect about shoppers
On pages published with PageStax, and in the PageStax cart when a merchant has turned it on, we record analytics events so the merchant can measure pages, offers and experiments:
- An anonymous visitor identifier, generated at random and stored in the shopper’s browser.
- Events such as page views, add-to-cart, offer accepted or declined, which experiment variant was shown, and the page, section, product and variant involved.
- Purchases, received from Shopify’s checkout through a Shopify web pixel: order value and the PageStax attributes attached to the cart. We do not collect shoppers’ names, email addresses, postal addresses or payment details through analytics.
- Reviews a shopper chooses to submit through a review form: the review text, rating and the name or other details the form asks for.
How we use information
- To provide the app: render and publish pages, apply offers and discounts the merchant set up, and show the merchant their analytics and experiment results.
- To enforce plan limits and keep the service secure and working.
- We do not sell personal information, and we do not use shopper data for advertising or share it across merchants.
Retention
Raw analytics events are kept for up to 180 days, after which only aggregated daily summaries remain. Merchant content is kept while the app is installed. When a merchant uninstalls, agent tokens are deleted immediately; when Shopify sends its shop-data deletion request (48 hours after uninstall), we delete the shop’s published pages, offers, journeys and analytics.
Shopper privacy requests
PageStax responds to Shopify’s mandatory privacy webhooks for customer data requests, customer deletion and shop deletion. Shoppers who want to exercise their rights should contact the merchant whose store they visited; the merchant can reach us to fulfil the request.
Where data is processed
PageStax runs on cloud infrastructure provided by third-party hosting providers, and on Shopify’s platform. A list of sub-processors will be published here. [Placeholder]
Security
Requests from Shopify are verified by signature, access tokens are held server-side, and agent tokens are stored only as hashes. No method of transmission or storage is completely secure, but we work to protect the information we hold.
Changes
We will update this page when our practices change and revise the date above.
Contact
Questions about this policy: [contact email — placeholder].