Data Policy

Last updated: September 2026

This Data Policy explains what data Zolvio collects, how we process it, and how we protect it. This supplements our Privacy Policy with technical details.

Data Collection Methods

Session Recording Script

When the Zolvio Recording app embed is on in your theme, a script on your storefront records shoppers whose cookie consent allows analytics. It:

  • Captures DOM changes and user interactions
  • Records mouse movements and click positions
  • Tracks scroll behavior
  • Collects device and browser metadata
  • Uses batching and compression to reduce network overhead

Heatmap Data

Click and scroll events are aggregated into heatmaps showing:

  • Click density by page area
  • Scroll depth percentages
  • Element interaction frequency

A/B Testing Script

When A/B testing is enabled, a script on your storefront may:

  • Assign a visitor to a variant (sticky assignment). Assignment runs for every visitor so each one sees a consistent version; it uses a random ID and a 30-day cookie and never records the session.
  • Apply a visual modification (text/style/visibility, etc.)
  • Track exposures and goal events for attribution

Audit Data

During audits, we analyze:

  • Page HTML structure
  • Performance metrics
  • Content and copy
  • Visual screenshots, on paid plans with AI in audits and fixes turned on (reviewed by our AI provider, Anthropic, together with short parts of your theme code)

Data Masking

We automatically hide sensitive information in recordings:

  • Typing: everything shoppers type is hidden
  • Page text: other page text shows as ***. Product names, prices, headings, menus, buttons, breadcrumbs and size/colour options stay readable so recordings make sense
  • Pages: checkout, account, order and login pages are never recorded
  • Custom hiding: in Settings → Recording privacy you can hide chat, review, loyalty and email/SMS pop-up widgets, or any element by CSS selector

We also apply server-side redaction as a safety net to reduce the risk of sensitive information being stored if it slips past client-side masking.

URL and Metadata Privacy

  • Path-only URLs: for analytics and experimentation data, we minimize URL storage by using path-only URLs (we avoid storing query strings, which can contain sensitive information).
  • Sensitive routes: checkout, account, order and login pages are never recorded, and A/B tests and surveys don’t run on them.
  • Approximate location: we may derive a country-level code from network headers (when available) to support segmentation and reporting.

Browser Storage

Zolvio may use browser storage to improve reliability and consistency (for example: localStorage, sessionStorage, and IndexedDB). Typical uses include:

  • Persisting a pseudonymous visitor ID
  • Maintaining session continuity across page loads
  • Retrying event delivery if the network is unavailable
  • Keeping A/B test assignment consistent

Data Storage

Location

Data is stored in the United States, on DigitalOcean servers, database and file storage.

Encryption

  • In transit: TLS
  • At rest: encryption (where supported by our infrastructure)

Retention Periods

PlanRetention
Free7 days
Starter30 days
Growth60 days
Pro180 days

After the retention period, data is scheduled for deletion. For details by data type (including screenshots and aggregated analytics), see our Data Retention Policy.

Data Access

Access to your data is restricted to:

  • Authorized users on your Shopify store
  • Zolvio engineering team (for support and maintenance)
  • Automated systems for processing

Third-Party Services

We use third-party services (“subprocessors”) to operate Zolvio: Shopify (platform and billing), DigitalOcean (servers, database and file storage), Cloudflare (network), Anthropic (AI analysis, with emails and phone numbers removed from text first), Resend (email) and Sentry (error monitoring). The current list, with what each one processes, is in our Privacy Policy.

Data Export

You can export certain data from within the app (where supported):

  • Survey responses can be exported (CSV/JSON)
  • A/B test results and events can be exported (CSV/JSON)

For other requests (including DSAR-related access/export), contact privacy@zolvio.io.

Data Deletion

Request complete data deletion by:

  1. Using in-app deletion controls (where available)
  2. Uninstalling the Zolvio app
  3. Contacting us at privacy@zolvio.io

Deletion timing can vary depending on data category, retention windows, and legal/security obligations.

Compliance

Zolvio is designed to help you comply with:

  • GDPR (EU General Data Protection Regulation)
  • CCPA (California Consumer Privacy Act)
  • Shopify's app requirements

Contact

For data-related questions, contact us at privacy@zolvio.io