Effective date: May 8, 2026
/CRO ("the App") is a conversion-rate analytics service for Shopify stores, operated by Taurist Technologies Inc. ("we", "us"). This policy describes what data the App collects when a merchant installs it, how that data is used, and the choices merchants and their customers have.
When a merchant enables tracking, the App's Shopify-sandboxed Web Pixel records behavioral events on the storefront: page views, product views, collection views, searches, cart actions, and checkout steps. Each event includes the event type, a timestamp, the page URL, product/cart/checkout metadata (IDs, quantities, prices), and Shopify's rotating anonymous visitor identifier.
We do not store personal information about storefront visitors. Identifying fields that Shopify includes in checkout events — email address, phone number, first and last name, and billing/shipping addresses — are stripped by our servers before any event is written to storage. We do not use cookies or any tracking technology of our own on the storefront; the pixel runs entirely inside Shopify's sandboxed pixel runtime.
With the merchant's OAuth consent, the App reads: store profile (name, currency, timezone, contact email), product catalog, and order records (totals, discounts, line items, and an opaque customer ID used only to count distinct customers). This data is used solely to produce analytics for that store's owner — funnels, conversion rates, average order value, and improvement recommendations.
Account email address (for sign-in and notifications), and any content the merchant submits in the App (questions, uploaded documents, connected Google Analytics 4 data if the merchant links a GA4 property).
The App's dashboard uses strictly necessary cookies only: a session cookie and short-lived OAuth state cookies. No advertising or cross-site tracking cookies.
We do not sell data, use it for advertising, combine it across merchants, or use one store's data to benefit another.
We use the following providers to run the service, each receiving only what the function requires: Render (application hosting), Supabase (database and file storage), Anthropic and OpenAI (automated analysis of store metrics and content; no visitor personal data is included), Qdrant (search index), Resend (transactional email to merchants), Google (only if the merchant connects GA4).
Store data is retained while the store remains connected. When a merchant uninstalls the App, the store is marked inactive and its data is deleted within 30 days of a deletion request to rich@taurist.com. Merchants may request export or deletion of their store's data at any time.
The App implements Shopify's mandatory privacy webhooks:
customers/data_request — because the App stores no customer personal information, there is no customer data to return.customers/redact — no customer personal information is stored, so no action is required; requests are acknowledged and logged.shop/redact — the store's data is deleted per the retention terms above.
All traffic is encrypted in transit (TLS). Store access tokens are encrypted at rest. Webhook and pixel payloads are authenticated with HMAC signatures. Access to production systems is restricted to authorized personnel.
Questions or requests: rich@taurist.com Taurist Technologies Inc., 1585 Springfield Ave, Maplewood, NJ 07040
We may update this policy; material changes will be noted at this URL with a revised effective date.