Privacy Policy

Last updated: 2026-09-30

This Privacy Policy explains what data Darwiny ("Darwiny", "we") collects about you and, when you separately enable Darwiny experimentation services, about visitors to your storefront. What the public Shopify app accesses, and how it runs those services on a storefront, is described in section 10.

Data controller

The data controller for the purposes of GDPR is Darwiny, Flæsketorvet 68, 1. sal, 1711 Copenhagen, Denmark. Contact: support@darwiny.ai.

1. Data we collect

From merchants (you)

From storefront visitors, only when you separately enable Darwiny experimentation

2. Data we do not collect

For a separately configured order-attribution integration, we retain only the minimal fields listed above, not customer names, email addresses, shipping or billing addresses, line items, or payment details. We do not fingerprint devices or share storefront visitor data with advertising networks. For the public Shopify app, read-only order access is requested for that one purpose, as described in section 10.

3. How we use data

4. Subprocessors

5. Data retention

Experiment, store, and account data are retained for the life of your account. Minimal order-attribution records from a separately configured integration are retained for up to 90 days; aggregate experiment counters no longer identify an order. For the public Shopify connector, we retain installation, lifecycle, and account-binding metadata, subscription snapshots, billing-cycle usage ledgers, and idempotent billing-event audit records while needed to operate the connection and meet legal accounting obligations. Payload-free traffic-event idempotency receipts are retained for no more than 90 days. Short-lived storefront authorization tokens expire after 10 minutes, and network rate-limit keys are retained only for their configured abuse-prevention windows. Disconnecting removes the account binding. Shopify privacy requests are processed through Shopify's mandatory compliance webhooks, payload-free webhook receipt metadata is retained for up to 90 days, and connector identity records are purged when Shopify sends a verified shop-redaction request. When you delete your account by emailing support@darwiny.ai we remove your data within 30 days, except where retention is required by law (e.g. invoicing records).

6. Cookies

If you separately enable storefront experimentation, then with analytics consent the Darwiny loader sets one first-party experimentation cookie on your storefront (_dg_vid) to keep a visitor on the same variation across visits and measure that variation. It is not used for cross-site tracking. The dashboard uses functional cookies for authentication and session state. We respect Shopify's Customer Privacy API: if analytics processing is not allowed, the loader does not set the cookie or send experiment analytics. The public Shopify app loads that loader only while the merchant has switched on its app embed in their theme (section 10).

7. Your rights

Depending on where you live you may have rights to access, correct, port, or delete your personal data, object to processing, and withdraw consent. EU/UK residents have additional rights under GDPR/UK-GDPR. California residents have rights under the CCPA. To exercise any right, email support@darwiny.ai.

8. International transfers

We primarily host data in the EU. Some subprocessors (Stripe, Resend, Sentry) may process data outside the EU under Standard Contractual Clauses or equivalent safeguards.

9. Security

We use industry-standard controls: TLS for data in transit, encrypted storage at rest, row-level security for per-account data isolation, and scoped access tokens. Despite these measures no system is perfectly secure; you use the Service at your own risk.

10. Shopify app access

The Darwiny public Shopify app lets a merchant have new versions of a product page designed, approve a Shopify-billed Darwiny plan, and test those versions on their own storefront. It requests two read-only Shopify scopes. The read-products scope lets the embedded app display products from the currently authenticated shop so the merchant can choose which product to design pages for. The read-orders scope is used for one purpose: receiving Shopify's order-created webhook, limited to four fields (the order identifier, its total, its currency, and its cart attributes), so that a purchase can be credited to the page version the shopper saw. The app does not use Shopify Admin APIs to read customers, checkouts, or payment data, and it does not write to the shop's products, orders, or theme files. It writes only its own app-data metafields: the linked Darwiny store identifier, a connected flag, a random verification value, a revision number, and the addresses its theme app embed loads from. The embedded app screens do not load advertising or product-analytics trackers.

A storefront is changed only through the app's theme app embed, which the merchant switches on and off in the Shopify theme editor; the app cannot switch it on. While it is on, it loads the Darwiny loader described in sections 1 and 6. On a product page that has a running test, the loader shows either the store's own page or a Darwiny-designed version of it. With the visitor's analytics consent under Shopify's Customer Privacy API, it sets the first-party cookie described in section 6, counts page views and add-to-cart actions per version without identifying the visitor, and adds the Darwiny experiment, version, and random visitor identifiers to the cart's attributes so that a resulting order can be matched to the version. Without that consent it sets no cookie, sends no analytics, and adds nothing to the cart. It does nothing in the theme editor's preview. Switching the embed off, disconnecting the account, or uninstalling the app stops all of it.

From each order-created webhook we keep only the order identifier, the gross order total, the currency, and the Darwiny experiment and version identifiers from the cart attributes, for up to 90 days; aggregate experiment counters no longer identify an order. The webhook subscription asks Shopify to leave out everything else, so we do not receive the customer's name, email address, shipping or billing address, line items, or payment details. An order without Darwiny cart attributes leaves only a payload-free receipt.

A merchant who is new to Darwiny gets an account made from the email address Shopify has verified for their staff login; a merchant with an existing Darwiny account connects it with the account email and a verification code. We retain the Shopify shop ID, canonical myshopify.com domain, primary domain when available, app installation ID, connection and lifecycle status, the state of the theme app embed, the linked Darwiny account/store identifiers, and one-way security hashes used for verification. The shop name is fetched to display in the embedded screen and is not stored in the connection record. Product catalog pages are returned directly to the embedded app with no-store cache controls. For a linked account, we retain one tenant-scoped snapshot containing at most the 200 most recently updated active products so the same synchronized catalog can be used in Darwiny. Each refresh replaces that snapshot, which remains bound to the exact Shopify connection and Darwiny store. Raw verification credentials are not stored.

App Bridge session tokens and request-scoped Shopify Admin tokens are used temporarily to verify the installation and shop identity, read that shop's product catalog, and write the app-data metafields above. They are not stored in our database, cookies, local storage, or browser storage. Besides the order-created webhook, the app receives only the uninstall webhook and Shopify's mandatory privacy webhooks. A mandatory privacy request may contain a request identifier and order identifiers; we use those only to locate and fulfill an access or deletion request, which removes the matching order-attribution records. We do not retain raw webhook payloads and keep only limited receipt metadata for authentication, deduplication, and compliance auditing.

Shopify hosts plan selection and approval. The disclosed capacity levels per Shopify billing cycle are: USD 39 for 1 active Darwiny product and 5,000 Darwiny-tested page visits; USD 79 for up to 5 products and 15,000 visits; USD 119 for up to 10 products and 30,000 visits; USD 199 for up to 20 products and 75,000 visits; USD 399 for up to 50 products and 200,000 visits; USD 649 for up to 100 products and 500,000 visits; and USD 1,099 for up to 200 products with no tested-visit cap (traffic above 500,000 visits uses this level). More than 200 active products requires an enterprise arrangement and is not automatically billed through these levels.

If greater capacity is used by Darwiny services that the merchant has separately enabled, we report a Shopify shop ID, capacity event handle, event timestamp, permanent idempotency key, and aggregate capacity-level increment to Shopify's App Events API. The level is determined by whichever is higher—active-product capacity or tested-traffic capacity—so those dimensions are not added together. The highest capacity level reached during a billing cycle remains the cycle total even if usage later decreases. We do not send buyer or merchant contact data in billing events.

Before the one-way platform-wide Shopify billing cutover is activated, eligible customers who have not installed the public Shopify app may use standalone Stripe billing. Once activated, Darwiny creates no new Stripe checkout, portal, payment link, trial, subscription, or upgrade route. Existing standalone billing records remain available only for required lifecycle actions such as cancellation, refund, dispute, and payment reconciliation. An active Shopify App Pricing subscription is required before a merchant can connect an account through the public app, and an unresolved standalone entitlement must be closed before connection to prevent overlapping charges. Once connected, Shopify is the sole billing authority for the app-related subscription. Optional storefront experimentation and revenue attribution remain subject to the disclosures elsewhere in this policy.

Disconnecting the Darwiny account removes the account binding only. It does not cancel the Shopify plan, reverse capacity charges already reached in the current billing cycle, or change the plan's scheduled cancellation date. Plan changes are managed through Shopify. To stop future recurring app charges, uninstall Darwiny from Shopify Admin; Shopify may still bill charges from the current cycle.

11. Changes

We may update this policy. Material changes will be announced by email at least 14 days before they take effect.

12. Contact

Privacy questions: support@darwiny.ai.