Privacy Policy
Last updated: 2026-08-03
This Privacy Policy explains what data Darwiny ("Darwiny", "we") collects about you and, when you separately enable Darwiny experimentation services, about visitors to your storefront. The public Shopify app is a narrower account-connection and Shopify-billing surface; its app-specific limits are described in section 10.
Data controller
The data controller for the purposes of GDPR is Darwiny, Flæsketorvet 68, 1. sal, 1711 Copenhagen, Denmark. Contact: support@darwiny.ai.
1. Data we collect
From merchants (you)
- Account info: email, authentication tokens, profile data.
- Billing state: Shopify handles plan approval and charges for merchants who use the public Shopify app. We retain the plan, billing-cycle dates, subscription status, and aggregate capacity-usage state needed to operate and reconcile that billing. Customers who do not install the public Shopify app may be billed separately by Stripe. We do not receive or store card data from either provider.
- Store metadata for services you separately enable: domain, product URLs, product titles, and images.
- Usage data: pages visited in the dashboard, feature interactions, error reports.
From storefront visitors, only when you separately enable Darwiny experimentation
- A consent-gated first-party cookie (
_dg_vid) containing a random visitor UUID. - Which variation was shown, and anonymous counters: impressions, add-to-cart, checkout, purchase.
- For separately configured Shopify revenue-attribution integrations outside the public app connector: the Shopify order ID, gross order total, currency, and Darwiny experiment and variation IDs needed to deduplicate and attribute orders. Shopify classifies order data as protected customer data.
- Short-lived security metadata used to prevent fraudulent traffic reports: the storefront origin and an opaque one-way request-network binding. The raw network address is not included in Shopify billing events.
2. Data we do not collect
For a separately configured order-attribution integration, we retain only the minimal fields listed above, not customer names, email addresses, shipping or billing addresses, line items, or payment details. We do not fingerprint devices or share storefront visitor data with advertising networks. The public Shopify app connector does not request order access, subscribe to order events, or create order attribution records.
3. How we use data
- Operate and improve the Service.
- Manage paid Darwiny services, verify Shopify App Pricing entitlements, report aggregate capacity usage to Shopify, and prevent duplicate or conflicting billing.
- Send transactional emails (OTP codes, install instructions, billing receipts).
- Debug and monitor the system (error reports via Sentry).
- Aggregated product analytics (PostHog) with inputs masked by default.
4. Subprocessors
- Supabase — auth and database hosting (EU region)
- Shopify — app-plan approval, subscription billing, and aggregate usage billing for merchants who install the public Shopify app
- Stripe — subscription billing for customers who do not use the public Shopify app
- Resend — transactional email
- Vercel — application hosting
- Azure — worker hosting
- Sentry — error monitoring
- PostHog — product analytics (EU region)
5. Data retention
Experiment, store, and account data are retained for the life of your account. Minimal order-attribution records from a separately configured integration are retained for up to 90 days; aggregate experiment counters no longer identify an order. For the public Shopify connector, we retain installation, lifecycle, and account-binding metadata, subscription snapshots, billing-cycle usage ledgers, and idempotent billing-event audit records while needed to operate the connection and meet legal accounting obligations. Payload-free traffic-event idempotency receipts are retained for no more than 90 days. Short-lived storefront authorization tokens expire after 10 minutes, and network rate-limit keys are retained only for their configured abuse-prevention windows. Disconnecting removes the account binding. Shopify privacy requests are processed through Shopify's mandatory compliance webhooks, payload-free webhook receipt metadata is retained for up to 90 days, and connector identity records are purged when Shopify sends a verified shop-redaction request. When you delete your account by emailing support@darwiny.ai we remove your data within 30 days, except where retention is required by law (e.g. invoicing records).
6. Cookies
If you separately enable storefront experimentation, then with analytics consent the Darwiny loader sets one first-party experimentation cookie on your storefront (_dg_vid) to keep a visitor on the same variation across visits and measure that variation. It is not used for cross-site tracking. The dashboard uses functional cookies for authentication and session state. We respect Shopify's Customer Privacy API: if analytics processing is not allowed, the loader does not set the cookie or send experiment analytics. The public Shopify connector does not install that loader, set storefront cookies, or track storefront visitors.
7. Your rights
Depending on where you live you may have rights to access, correct, port, or delete your personal data, object to processing, and withdraw consent. EU/UK residents have additional rights under GDPR/UK-GDPR. California residents have rights under the CCPA. To exercise any right, email support@darwiny.ai.
8. International transfers
We primarily host data in the EU. Some subprocessors (Stripe, Resend, Sentry) may process data outside the EU under Standard Contractual Clauses or equivalent safeguards.
9. Security
We use industry-standard controls: TLS for data in transit, encrypted storage at rest, row-level security for per-account data isolation, and scoped access tokens. Despite these measures no system is perfectly secure; you use the Service at your own risk.
10. Shopify app access
The Darwiny public Shopify app lets a merchant approve a Shopify-billed Darwiny plan and connect the installed shop to an existing Darwiny account. It requests no Shopify resource scopes and does not use Shopify Admin APIs to read products, customers, orders, checkout, or payment data. It does not subscribe to commerce events, install a theme or app extension, modify storefront code, set storefront cookies, or track storefront visitors. The embedded account-connection screen does not load advertising or product-analytics trackers.
To authenticate and display the connection, the connector processes the account email you enter and Shopify's authenticated shop identity. We retain the Shopify shop ID, canonical myshopify.com domain, primary domain when available, app installation ID, connection and lifecycle status, the linked Darwiny account/store identifiers, and one-way security hashes used for the verification challenge. The shop name is fetched to display in the embedded screen and is not stored in the connector record. Raw verification credentials are not stored.
After connection, the embedded app may also display aggregate experiment status and results that are already stored in the linked Darwiny account, including experiment counts, tested visits, and aggregate conversions recorded by Darwiny. Displaying that existing Darwiny account data does not require additional Shopify resource scopes, install a storefront tracker, or add an embedded-app analytics tracker. All-time experiment results shown in the activity summary are separate from the peak capacity measured for the current Shopify billing cycle.
App Bridge session tokens and request-scoped Shopify Admin tokens are used temporarily to verify the installation and shop identity. They are not stored in our database, cookies, local storage, or browser storage. The app receives only the uninstall webhook and Shopify's mandatory privacy webhooks. A mandatory privacy request may contain a request identifier and order identifiers; we process those only to locate and fulfill an access or deletion request. The connector does not create order records from them. We do not retain raw webhook payloads and keep only limited receipt metadata for authentication, deduplication, and compliance auditing.
Shopify hosts plan selection and approval. The disclosed capacity levels per Shopify billing cycle are: USD 39 for up to 3 active Darwiny products and 15,000 Darwiny-tested page visits; USD 79 for up to 3 products and 30,000 visits; USD 119 for up to 5 products and 75,000 visits; USD 199 for up to 10 products and 200,000 visits; USD 399 for up to 25 products and 500,000 visits; and USD 649 for up to 50 products with no tested-visit cap (traffic above 500,000 visits uses this level). More than 50 active products requires an enterprise arrangement and is not automatically billed through these levels.
If greater capacity is used by Darwiny services that the merchant has separately enabled, we report a Shopify shop ID, capacity event handle, event timestamp, permanent idempotency key, and aggregate capacity-level increment to Shopify's App Events API. The level is determined by whichever is higher—active-product capacity or tested-traffic capacity—so those dimensions are not added together. The highest capacity level reached during a billing cycle remains the cycle total even if usage later decreases. We do not send buyer or merchant contact data in billing events.
Customers who never install the public Shopify app may continue to use Stripe billing. An active Shopify App Pricing subscription is required before a merchant can connect an account through the public app. An existing Stripe customer cannot connect while the standalone Stripe entitlement remains active. Selecting the Shopify plan does not automatically cancel or refund that standalone subscription, so the customer must coordinate the provider migration with Darwiny support to avoid overlapping charges. Once connected through the public Shopify app, Shopify is the sole billing authority for that app-related subscription; the embedded app provides no Stripe checkout, Stripe billing link, or external payment route. Optional storefront experimentation and revenue attribution remain subject to the disclosures elsewhere in this policy.
Disconnecting the Darwiny account removes the account binding only. It does not cancel the Shopify plan, reverse capacity charges already reached in the current billing cycle, or change the plan's scheduled cancellation date. Plan changes are managed through Shopify. To stop future recurring app charges, uninstall Darwiny from Shopify Admin; Shopify may still bill charges from the current cycle.
11. Changes
We may update this policy. Material changes will be announced by email at least 14 days before they take effect.
12. Contact
Privacy questions: support@darwiny.ai.