App
privacy.
This notice covers Profit Maximizer: A/B Testing. The website privacy notice (German) also applies when you visit this page.
Operator and contact
VISIONS STUDIO, Samuel Marques Lucio, Sperlingweg 4, 80937 Munich, Germany. Email: contact@marqueslucio.com. For storefront visitor data, the merchant is generally responsible for its store privacy information and any required consent; we process data to provide the app to that merchant.
Data processed
For merchants, we store the shop domain, Shopify session and access token, plan and billing status, experiment settings and results. A Shopify session may contain an admin user's name, email address and ID. We process support messages to answer the request.
For A/B tests, the browser creates a random visitor ID in local storage. Our server stores a hash of it, along with the assigned variant, assignment and event times, page path and, where relevant, device category or campaign parameters. Shopify pixel events can include page, product and cart activity, checkout start and checkout completion. To attribute orders, we process a SHA-256 hash of a checkout token, order and line-item IDs, quantities, currency, net merchandise revenue, refunds and product costs where Shopify provides them. The pixel does not transmit the raw checkout token to our server. Hashes remain pseudonymous, linkable data.
The browser stores the visitor ID and signed assignment for delivery; an assignment can also be held in a private cart attribute. The app does not request buyer names, buyer email addresses, phone numbers, postal addresses or payment details for experiment reports.
Purpose, legal basis and consent
We use these data for secure Shopify sign-in, test delivery, visitor and order attribution, reporting, billing and support. Contract performance is relevant to merchant data and support (GDPR Art. 6(1)(b)); legitimate interests may apply to security and misuse prevention (Art. 6(1)(f)). The merchant's privacy framework determines the legal basis for visitor tracking. The app checks Shopify's analytics-processing permission; without it, no new A/B assignments or pixel events are sent for measurement. When consent is withdrawn, the storefront script removes its local IDs and assignments and initiates removal of the cart attributes it created. Previously stored server-side measurements are not retroactively erased by this action; deletion requests and the retention rules below apply.
Recipients, location and transfers
The app and database run on an IONOS VPS in Spain (EU). Shopify supplies the Admin API, storefront, Web Pixel, webhooks and app billing. VISIONS STUDIO operates the app and provides support. A support email also involves the email service used to send it. Processing by Shopify or communications services outside the European Economic Area cannot be excluded; the relevant contractual privacy safeguards apply. We do not sell visitor data or use app data for our own advertising.
Retention and deletion
Experiment settings remain while the shop uses the app. Pseudonymous event and order data are deleted 365 days after the event; visitor assignments are deleted 365 days after their last activity once the attribution window has expired. Reports are calculated from these data and therefore lose older measurements. Stored privacy exports are deleted 30 days after creation. The random browser ID has no fixed expiry and remains until consent withdrawal, browser-data deletion or relevant browser settings remove it. On uninstall, we remove Shopify sessions and pause running tests. The remaining shop data are deleted from the active app database when Shopify sends shop/redact. Shopify customer deletion requests remove linked assignments, events, conversions and stored exports. Local database backups on the same VPS are rotated out after 14 days. Statutory retention duties for business and billing records remain unaffected.
Access and rights
The app processes Shopify privacy requests for access and deletion; the merchant can export a copy of linked data from the app admin. Storefront visitors can first exercise their rights with the merchant. You may also contact us. Subject to legal conditions, rights include access, rectification, erasure, restriction, portability and objection, as well as a complaint to a data protection supervisory authority.
Last updated: 23 September 2026