Privacy policy

Last updated: 2026-08-22

This Privacy Policy describes how the Uptest Shopify app ("the App", "we", "us") collects, uses, and stores data when a merchant installs it on a Shopify store. Our goal is to run A/B tests on storefront content while collecting the minimum data required and storing no personally identifiable information (PII) about end customers.


1. What we collect

When the App is installed on a store and an A/B test is active, we collect:

2. What we do not collect

We never collect or store:

3. Where data is stored

4. Who has access

5. Cookies

The App writes the following first-party cookies on the storefront's domain:

Cookie namePurposeLifetime
_uptest_vidSticky anonymous visitor ID for variant pinning365 days
_uptest_<testId>Records the visitor's variant for one test365 days
_uptest_activeComma-separated list of active test IDs (helper)365 days
_uptest_themeTheme tests only: which theme variant this visitor sees1 day

These cookies are strictly necessary for the A/B test to function (without them, the same visitor would see different variants on different page loads, which would invalidate the test). They contain no personal information.

The App also keeps a few keys in the browser's localStorage / sessionStorage under the same _uptest_ prefix: a cached copy of the test configuration, the cached consent verdict, the landing-page snapshot for the current visit and small de-duplication markers. They exist only so the page can render the right variant quickly; they never leave the device and are not sent to our servers.

6. GDPR and CCPA

We support Shopify's mandatory privacy webhooks:

Retention. We retain raw, event-level analytics data (the anonymous visitor identifier, the pages visited, and the resulting order id and order value) for 12 months after the A/B test that produced it has finished, plus the running time of the test itself. A scheduled hourly job deletes it automatically after that, together with the record of which variant each anonymous visitor was shown. What we keep beyond that point is a whole-day statistical rollup (DailyStat) — visitor, add-to-cart, checkout and order counts and revenue totals, per test variant per day — which contains no visitor, customer, or order identifiers and cannot be traced back to an individual; it is retained for the lifetime of the test so historical results stay readable.

Right to access / deletion. Merchants can request a full export or deletion of their shop's data at any time by emailing the address below. We respond within 30 days.

California residents (CCPA). The categories of information collected are listed in section 1 above. We do not sell personal information.

7. Security

8. Children

The App is not directed at children under 13, and we do not knowingly collect data from them. If you believe we have inadvertently collected such data, please contact us so we can delete it.

9. Changes to this policy

We may update this Policy from time to time. Material changes will be reflected by an updated "Last updated" date at the top of this document and, where appropriate, by a notice in the App admin.

10. Contact

For privacy questions, data export, or deletion requests:

Email: support@uptest.app

We respond to privacy requests within 30 days.