Privacy Policy

Last updated:July 8,2026

1. Introduction

Verve ("we","our","the app") is a Shopify application that provides merchants with a customizable cart experience including upsells,bundles,promotions,A/B testing,and full design control. This policy explains what data we access,why we access it,and how we handle it.

For questions or concerns,please use our contact form.

2. Data We Access

Verve requests the following Shopify API scopes. Each scope is used for a specific,limited purpose:

3. A/B Testing

Verve includes an optional A/B testing feature. Here is exactly how it works:

Variant Assignment

Visitors are assigned a test variant using random weighted assignment. The assignment is stored in the visitor's browser localStorage. We do not fingerprint visitors or use an IP address to assign a variant.

Cart Attributes

The assigned variant is stored as a Shopify cart attribute (e.g. _v1_ab_{experimentId}) so it becomes part of the Shopify order data upon checkout. This allows merchants to analyze which variant a customer saw.

UTM Parameters

Optionally,variant information can be appended to checkout URLs as utm_term / utm_content parameters for integration with Shopify Analytics.

No Visitor IDs

We do not perform cross-device or cross-browser tracking. We do not generate unique visitor IDs for this feature. Aggregate cart and purchase events may be processed to report experiment performance to the merchant.

Results Analysis

Conversion data is aggregated from Shopify Orders using custom cart attributes and order totals. Experiment reporting does not require storing a customer's name,address,or email.

4. Data We Store

Our database stores Shopify session data needed for authentication,aggregate subscription and billing state,and a minimal installation/configuration usage footprint. The account row stores the shop's contact email address and shop name so we can reach the responsible merchant for support and essential service communications;both are business contact details of the merchant (never shopper data) and are removed when the app is uninstalled or a shop-redaction request is received. We additionally store the email address of the merchant admin who installs and operates the app,in cleartext,so we can reach the responsible person for support and essential service communications;this operator email is removed when a shop-redaction request is received. Billing state in our database includes a per-order idempotency ledger — the Shopify order id and its timestamp,so each order is counted once — plus aggregate cycle counters;it retains no shopper name,email,address,or other contact details.

Cart configuration is stored in Shopify app-owned metaobjects within the merchant's Shopify store. Features that require an audit trail may also store data there:submitted form values and selected context when a form is used. These records are used only to provide the enabled feature,support audit needs,and answer or execute data-subject requests. New form and quiz configurations default to no Verve submission history;merchants can enable history for analytics or recovery while submissions still reach their configured destinations when history is disabled.

If a merchant sends feedback or a support request through the app,we store the submitted message,an optional reply email,and limited store-configuration context needed to investigate it. We do not retain a browser user-agent for new feedback records.

5. Data Minimisation

On the storefront (shopper-facing),the cart and all components run with:

More broadly:

Customer contact details are processed only when supplied through a merchant-enabled feature that needs them,such as a form or quiz destination. The embedded admin interface uses a session-analytics tool (Microsoft Clarity — see §8) that may set first-party cookies within the Shopify admin;this is separate from the storefront and never runs on your customers.

6. Browser Storage

The storefront extension uses browser localStorage solely for A/B test variant assignment persistence. This data contains no personal information and cannot be used for cross-site tracking. It is cleared when the visitor clears their browser storage.

7. Order Data Handling

For billing and aggregate experiment reporting,order identifiers,custom cart attributes (_v1_*),and order totals are processed in memory as required for those purposes. Billing retains a per-order ledger in our database — the Shopify order id and timestamp — so usage is counted exactly once without order-write access;it stores no shopper contact details. In normal operation the app writes no Shopify Order metafield (the only such write it ever attempts is blanking the customer reference on a legacy loyalty Order metafield during a customer-erasure request,on shops that ran the discontinued program).

8. Third-Party Services & Sub-Processors

Verve relies on a small set of sub-processors to operate. Where customer personal data is involved,it is shared only as described below:

In addition,when a merchant explicitly configures a form destination,the form submission — which may include the customer's email,name,and phone — is sent to the third party the merchant selected:

These third-party transfers occur only for destinations the merchant enables,are limited to the fields the merchant maps,and respect the email- and SMS-marketing consent the customer gives on the form (explicit single opt-in). For data sent to a merchant-selected destination,the merchant is the data controller and is responsible for their own agreement with the chosen provider.

9. Data Retention

Session data in our database is removed through Shopify uninstall and shop-redaction webhook handling. On uninstall we submit deletion of app-owned Shopify metaobjects and installation metafields while Shopify authentication remains available;operational metafields attached to Shopify Orders and Customers remain inside the merchant's Shopify store and are removed or disconnected for applicable customer-erasure requests. A minimal installation/configuration footprint and billing records may be retained for accounting,fraud-prevention,and service administration purposes;those billing records include the Shopify order id and timestamp for idempotent counting but no shopper identity or contact details,and retained usage records contain no merchant contact name or email. BrowserlocalStorage data persists until cleared by the visitor.

Shopify customer data-request webhooks produce a purpose-limited merchant-readable export in Shopify without logging its contents;those exports are scanned and deleted in Shopify after 30 days without a customer-specific database queue. Shopify customer-redaction webhooks delete matching stored form submissions and the merchant-readable export,and erase the customer's residual data from the discontinued loyalty/gift-card program (aggregate progress and app-owned reward records). On shops that ran that program before its removal,a customer reference on a legacy loyalty Order metafield may persist — the app no longer has order-write access to blank it — but it points to a customer Shopify has already anonymised.

10. Contact

If you have questions about this privacy policy or our data practices,please use the contact form at the bottom of our homepage.

Get in Touch

Questions or feedback? We'd love to hear from you.