Legal
Privacy Policy
Last updated: July 13, 2026
1. Our approach
ShopLens provides website and store analytics. The ShopLens tracker is designed not to set analytics cookies, build cross-site visitor profiles, or sell visitor analytics data. This policy explains the information the service processes and the choices available to account holders.
2. Account and service information
When you create or operate an account, we process information needed to provide and secure the service, including your email address, password hash, email-verification and password-reset state, site names and domains, plan and usage information, settings, support messages, and timestamps associated with the account.
For a connected Shopify store, we may also process the shop domain, store details returned during authorization, installation state, granted permissions, authorization credentials, and identifiers needed to connect the store to its ShopLens site. You should revoke access by uninstalling the app or contacting us when the connection is no longer needed.
3. Website analytics information
Depending on your configuration and platform, ShopLens can process page paths, referrer domains, campaign parameters, event types, timestamps, device and browser categories, country when available, and conversion information. Direct-site integrations may send a merchant-provided order reference, currency, and reported order value for deduplication and aggregate reporting. The Shopify Web Pixel sends an opaque Shopify analytics event identifier with supported page, cart, checkout, and purchase events so exact event deliveries can be deduplicated. ShopLens does not retain a raw Shopify order number or customer contact fields from that event.
ShopLens does not store raw IP addresses or full user-agent strings as analytics fields. It derives a one-way identifier from limited request context, a secret salt, the customer site, and the current date. Including the date causes the derived identifier to change daily, so it is not designed to recognize a visitor across days or customer websites. Internet requests still pass through network and infrastructure providers that may process technical request data to deliver and protect the service.
4. Cookies and local storage
The ShopLens analytics tracker does not set analytics cookies. On Shopify, the ShopLens Web Pixel runs through Shopify Customer Events, declares its privacy purposes, and receives events according to Shopify Customer Privacy settings and consent state. The ShopLens account application may use strictly necessary authentication storage to keep an account holder signed in and secure the dashboard. A customer website may use cookies or similar technology through its commerce platform, theme, advertising, video, chat, or other applications; those technologies are outside this policy.
5. Payments and service providers
We use service providers for hosting, databases, transactional email, error and security operations, and payment processing. Direct subscription payments are processed by Stripe; ShopLens does not receive full card numbers. For Shopify-installed subscriptions, Shopify presents and processes app charges under the merchant's Shopify agreement. Providers process information under their agreements with us and their own legal obligations.
6. How information is used
We use information to operate analytics reports, authenticate accounts, connect authorized sites, calculate usage, process subscriptions, prevent abuse, troubleshoot errors, respond to support requests, communicate service or security information, comply with law, and improve the reliability of ShopLens. We do not sell visitor analytics data or use it to build advertising profiles across customer websites.
7. Retention and deletion
We retain information for as long as reasonably needed to provide the service, secure it, meet contractual and legal obligations, resolve disputes, and maintain legitimate business records. Direct account holders can use available dashboard controls to export or delete supported data. For Shopify installations, operational analytics remains available while the app is installed and store data is deleted when Shopify sends the applicable redaction request after uninstall. Backups and legally required records may take additional time to expire.
When Shopify sends an authenticated privacy request, ShopLens may create a minimized encrypted work item and response artifact so the request can be processed outside Shopify's webhook response window. It contains only the Shopify order references needed to locate legacy records while queued and, for an access response, the matching analytics-event fields ShopLens actually retained: event type and name, page path and referrer, device, browser, country, campaign fields, reported value and currency, the matched order or source-event reference, daily visitor hash, and timestamp. It does not add the shopper's name, email address, phone number, or Shopify customer ID. These fields are encrypted with a dedicated key and are not stored in database plaintext. Correlated records are removed if a later authenticated deletion request arrives. The workflow receives a retention review after 30 days. If the legal request is still unresolved, its sole minimized locator/response remains encrypted under the legal-obligation exception, is escalated for manual action, and is deleted immediately when verified fulfillment or redaction is recorded. Operator-exported copies must be securely deleted before completion.
8. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal information. Direct account holders should contact us from the account email. Shopify merchants should identify their shop domain and may be asked to verify store ownership through Shopify Admin. We may need to retain limited information when required by law or necessary to protect the service and others.
9. Consent and legal responsibility
Cookie-free measurement can reduce analytics-cookie complexity, but it does not guarantee that a website needs no consent banner or other disclosure. Requirements depend on the business, jurisdiction, purpose, configuration, and every technology on the site. Customers are responsible for their own notices, consent choices, legal bases, and agreements. This policy is product information, not legal advice.
10. Security and international processing
We use reasonable technical and organizational safeguards, but no internet service can guarantee absolute security. Our providers may process information in countries other than yours, subject to the safeguards and transfer mechanisms applicable to their services.
11. Changes and contact
We may update this policy as ShopLens changes. The date above shows the latest revision. Material changes may be communicated through the service or account email when appropriate.
Privacy questions or requests: oasystems01@gmail.com.