Privacy Policy
Last updated:July 8,2026
1. Introduction
Verve ("we","our","the app") is a Shopify application that provides merchants with a customizable cart experience including upsells,bundles,promotions,A/B testing,and full design control. This policy explains what data we access,why we access it,and how we handle it.
For questions or concerns,please use our contact form.
2. Data We Access
Verve requests the following Shopify API scopes. Each scope is used for a specific,limited purpose:
read_locales— Read shop languages to display locale-specific cart content and translations.read_discounts— Read discount codes to display and apply them in the cart.read_files— Read shop files for custom images used in cart components.read_markets— Read market configuration for country and locale targeting.read_metaobject_definitions/read_metaobjects— Read app configuration data (templates,zones,component settings) stored as metaobjects.read_orders— Count eligible orders for usage-based billing and aggregated zone analytics. We read order totals and custom cart attributes to attribute revenue. The Shopify order id and timestamp are kept in our database for billing idempotency (so each order is counted once);no shopper contact details are stored.read_products— Read product data to power upsell recommendations and gift wrap product selection.read_publications— Check whether the theme extension is installed in the Online Store sales channel.read_themes— Verify the cart suite is installed in the active theme.read_content— Read Online Store page handles to power custom-content page targeting (the handle whitelist that decides which pages a component may appear on).unauthenticated_read_metaobjects— The storefront extension reads published cart configuration without authentication to render the cart on the storefront.write_discounts— Create automatic discounts for cart promotions such as free shipping thresholds and bundle / tiered discounts.write_files— Upload custom images for cart components.write_metaobject_definitions/write_metaobjects— Save app configuration (templates,zones,component settings) as metaobjects.write_products— Create gift wrap and shipping protection products used as cart add-ons.write_publications— Publish app-created products (gift wrap,shipping protection) to the Online Store sales channel.write_cart_transforms— Register the app's bundle Cart Transform Function so virtual bundles merge their component items into one discounted line at checkout.read_customers/write_customers— Used only when a merchant configures a form or quiz destination that writes to Shopify Customer records:creating or updating a customer,recording email/SMS marketing consent,or writing a customer-owned metafield (also used by the optional customer-segment tagging action). The app processes customer data only when such a destination is actually configured.
3. A/B Testing
Verve includes an optional A/B testing feature. Here is exactly how it works:
Variant Assignment
Visitors are assigned a test variant using random weighted assignment. The assignment is stored in the visitor's browser localStorage. We do not fingerprint visitors or use an IP address to assign a variant.
Cart Attributes
The assigned variant is stored as a Shopify cart attribute (e.g. _v1_ab_{experimentId}) so it becomes part of the Shopify order data upon checkout. This allows merchants to analyze which variant a customer saw.
UTM Parameters
Optionally,variant information can be appended to checkout URLs as utm_term / utm_content parameters for integration with Shopify Analytics.
No Visitor IDs
We do not perform cross-device or cross-browser tracking. We do not generate unique visitor IDs for this feature. Aggregate cart and purchase events may be processed to report experiment performance to the merchant.
Results Analysis
Conversion data is aggregated from Shopify Orders using custom cart attributes and order totals. Experiment reporting does not require storing a customer's name,address,or email.
4. Data We Store
Our database stores Shopify session data needed for authentication,aggregate subscription and billing state,and a minimal installation/configuration usage footprint. The account row stores the shop's contact email address and shop name so we can reach the responsible merchant for support and essential service communications;both are business contact details of the merchant (never shopper data) and are removed when the app is uninstalled or a shop-redaction request is received. We additionally store the email address of the merchant admin who installs and operates the app,in cleartext,so we can reach the responsible person for support and essential service communications;this operator email is removed when a shop-redaction request is received. Billing state in our database includes a per-order idempotency ledger — the Shopify order id and its timestamp,so each order is counted once — plus aggregate cycle counters;it retains no shopper name,email,address,or other contact details.
Cart configuration is stored in Shopify app-owned metaobjects within the merchant's Shopify store. Features that require an audit trail may also store data there:submitted form values and selected context when a form is used. These records are used only to provide the enabled feature,support audit needs,and answer or execute data-subject requests. New form and quiz configurations default to no Verve submission history;merchants can enable history for analytics or recovery while submissions still reach their configured destinations when history is disabled.
If a merchant sends feedback or a support request through the app,we store the submitted message,an optional reply email,and limited store-configuration context needed to investigate it. We do not retain a browser user-agent for new feedback records.
5. Data Minimisation
On the storefront (shopper-facing),the cart and all components run with:
- No cookies
- No tracking pixels
- No third-party analytics scripts
- No visitor fingerprinting
- No browsing history or behavioral profiles
More broadly:
- No shopper identity,contact details,or behavioral profile stored in our database
- A per-order billing ledger (Shopify order id + timestamp) is retained internally to count each order once — no shopper contact details,and no Shopify Order metafield is written for it
- The merchant contact details we retain (shop contact email,shop name,operator email — see §4) are business contact data of the merchant account,never shopper data,and are deleted on uninstall or shop-redaction
- No browser user-agent captured by default with form submissions
Customer contact details are processed only when supplied through a merchant-enabled feature that needs them,such as a form or quiz destination. The embedded admin interface uses a session-analytics tool (Microsoft Clarity — see §8) that may set first-party cookies within the Shopify admin;this is separate from the storefront and never runs on your customers.
6. Browser Storage
The storefront extension uses browser localStorage solely for A/B test variant assignment persistence. This data contains no personal information and cannot be used for cross-site tracking. It is cleared when the visitor clears their browser storage.
7. Order Data Handling
For billing and aggregate experiment reporting,order identifiers,custom cart attributes (_v1_*),and order totals are processed in memory as required for those purposes. Billing retains a per-order ledger in our database — the Shopify order id and timestamp — so usage is counted exactly once without order-write access;it stores no shopper contact details. In normal operation the app writes no Shopify Order metafield (the only such write it ever attempts is blanking the customer reference on a legacy loyalty Order metafield during a customer-erasure request,on shops that ran the discontinued program).
8. Third-Party Services & Sub-Processors
Verve relies on a small set of sub-processors to operate. Where customer personal data is involved,it is shared only as described below:
- Cloudflare (Workers + D1) — our hosting and database infrastructure;processes all app requests as our infrastructure provider.
- Resend — transactional and notification email delivery (for example,a merchant welcome/announcement email,or emailing a form submission to a merchant-chosen address). Processes only the recipient email and the message content needed for delivery.
- Microsoft Clarity — an optional session-analytics tool used only inside the embedded admin interface (never on the storefront) to understand how merchants use the app. It loads a Microsoft script and may set first-party cookies in the admin. It is enabled only when configured for the deployment.
- Anthropic — when a merchant uses the optional in-app AI assistant,the merchant's typed description of the cart experience they want is sent to Anthropic's Claude API to generate a configuration draft. Only merchant-authored text is sent — no shopper personal data. Available only when enabled for the deployment.
In addition,when a merchant explicitly configures a form destination,the form submission — which may include the customer's email,name,and phone — is sent to the third party the merchant selected:
- Klaviyo — email,first and last name,phone,and marketing-consent state,when the merchant adds a Klaviyo destination.
- Mailchimp — email and name,when the merchant adds a Mailchimp destination.
- Gorgias — email and name,sent as a support ticket when the merchant adds a Gorgias help-desk destination.
- Zendesk — email and name,sent as a support request when the merchant adds a Zendesk help-desk destination.
- A merchant-defined webhook URL — the submission payload,when the merchant configures a custom webhook destination.
- Shopify (the merchant's own store) — the Shopify customer / metafield destination writes the submission into the merchant's own Shopify customer records.
These third-party transfers occur only for destinations the merchant enables,are limited to the fields the merchant maps,and respect the email- and SMS-marketing consent the customer gives on the form (explicit single opt-in). For data sent to a merchant-selected destination,the merchant is the data controller and is responsible for their own agreement with the chosen provider.
9. Data Retention
Session data in our database is removed through Shopify uninstall and shop-redaction webhook handling. On uninstall we submit deletion of app-owned Shopify metaobjects and installation metafields while Shopify authentication remains available;operational metafields attached to Shopify Orders and Customers remain inside the merchant's Shopify store and are removed or disconnected for applicable customer-erasure requests. A minimal installation/configuration footprint and billing records may be retained for accounting,fraud-prevention,and service administration purposes;those billing records include the Shopify order id and timestamp for idempotent counting but no shopper identity or contact details,and retained usage records contain no merchant contact name or email. BrowserlocalStorage data persists until cleared by the visitor.
Shopify customer data-request webhooks produce a purpose-limited merchant-readable export in Shopify without logging its contents;those exports are scanned and deleted in Shopify after 30 days without a customer-specific database queue. Shopify customer-redaction webhooks delete matching stored form submissions and the merchant-readable export,and erase the customer's residual data from the discontinued loyalty/gift-card program (aggregate progress and app-owned reward records). On shops that ran that program before its removal,a customer reference on a legacy loyalty Order metafield may persist — the app no longer has order-write access to blank it — but it points to a customer Shopify has already anonymised.
10. Contact
If you have questions about this privacy policy or our data practices,please use the contact form at the bottom of our homepage.