Privacy Policy — Salescape
Last updated: May 23, 2026
This Privacy Policy describes how Salescape (“we”, “us”, or “our”) collects, uses, and shares information when you use our Shopify application (the “App”). By installing or using the App, you agree to the terms of this policy.
1. Who we are
Salescape is a Shopify application that helps merchants design subscription offers, run A/B tests on storefront product pages, and track the resulting revenue. The App is operated by the Salescape team. For any questions about this policy, contact us at support@salescape.co.
2. Information we collect from merchants
When you install the App on your Shopify store, we collect:
- Store identifier: your
myshopify.comdomain and Shopify Shop ID, required to associate data with your store. - OAuth access tokens issued by Shopify, used only to call the Shopify Admin API on your behalf within the scopes you approved during installation.
- Configuration you create in the App: subscription plans, offers, A/B test settings, layout preferences, copy, and styling.
- Product and theme metadata read via the Shopify Admin API: product titles, variant prices, and theme settings — strictly the minimum needed to render the widget and detect whether the app embed is enabled in your active theme.
We do not request, store, or process payment card details. Billing for the App itself is handled entirely by Shopify Billing API; we only receive the resulting subscription status.
3. Information we collect from your storefront visitors
When a visitor loads a product page containing the Salescape widget, the widget sends the following to our servers:
- A randomly generated anonymous visitor identifier (stored in the visitor's browser localStorage). This identifier is not linked to any personally identifiable information.
- The product ID being viewed and the variant ID the visitor selected.
- The store domain that loaded the widget.
- The experiment key and variant assignment if the product is part of an active A/B test, so that the same visitor consistently sees the same variant.
- Widget interaction events: which option the visitor selected (subscription vs. one-time), and whether they reached checkout. These events are forwarded to your store's Web Pixel and to our analytics database.
We do not collect names, email addresses, billing addresses, IP addresses, or any other directly identifying information from storefront visitors.
4. How we use the information
We use the information described above to:
- Operate the App and render the widget on your storefront.
- Persist subscription plans and offers you configure.
- Route A/B test traffic deterministically so visitors get a stable experience.
- Compute the revenue, conversion, and funnel analytics shown to you in the App.
- Respond to support requests you send to us.
- Comply with Shopify Partner Program requirements and applicable law.
We do not sell, rent, or share your data with third parties for advertising or marketing purposes.
5. Where we store data and how long we keep it
All data is stored on encrypted servers operated by Fly.io in the United States. We use managed PostgreSQL for application data and rely on Fly.io's automated backups for disaster recovery.
- Merchant configuration (offers, plans, A/B tests): retained while the App is installed and for 30 days after uninstall, then permanently deleted.
- Storefront analytics events (anonymous): retained for 12 months, then permanently deleted.
- OAuth tokens: invalidated immediately on uninstall via the
app/uninstalledwebhook.
6. GDPR and CCPA compliance
Salescape complies with Shopify's mandatory privacy webhooks. When Shopify forwards us one of the following requests, we act on it within 30 days:
customers/data_request— we return any data we hold associated with the identified customer. Because we do not collect personally identifying information from storefront visitors, this typically returns an empty result.customers/redact— we delete any data we hold for the identified customer.shop/redact— we delete all data associated with a store, 48 hours after the store uninstalls our App.
If you are an EU/EEA/UK or California resident and want to exercise your data rights directly, email support@salescape.co and we will respond within 30 days.
7. Cookies and similar technologies
The App itself uses Shopify's session cookies (set by Shopify, not by us) to authenticate your admin session. The storefront widget uses one localStorage key (salescape_visitor_id) to maintain stable A/B test assignment per visitor. We do not use third-party advertising cookies.
8. Security
We protect data with:
- TLS encryption for all traffic between your browser, the storefront widget, and our servers.
- Encryption at rest for our PostgreSQL database.
- Scoped OAuth access — we only request the minimum Shopify scopes needed to operate the App.
- HMAC verification on every webhook from Shopify.
No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you within 72 hours.
9. Children
The App is intended for use by Shopify merchants and adult shoppers. We do not knowingly collect information about anyone under 13 years of age.
10. Changes to this policy
We may update this policy from time to time. When we do, we will revise the “Last updated” date at the top and, for material changes, notify you within the App.
11. Contact
Questions, data requests, or complaints:
Salescape Support
Email: support@salescape.co
If you are not satisfied with our response, you may also lodge a complaint with your local data protection authority.