Data Policy
Last updated: September 2026
This Data Policy explains what data Zolvio collects, how we process it, and how we protect it. This supplements our Privacy Policy with technical details.
Data Collection Methods
Session Recording Script
When the Zolvio Recording app embed is on in your theme, a script on your storefront records shoppers whose cookie consent allows analytics. It:
- Captures DOM changes and user interactions
- Records mouse movements and click positions
- Tracks scroll behavior
- Collects device and browser metadata
- Uses batching and compression to reduce network overhead
Heatmap Data
Click and scroll events are aggregated into heatmaps showing:
- Click density by page area
- Scroll depth percentages
- Element interaction frequency
A/B Testing Script
When A/B testing is enabled, a script on your storefront may:
- Assign a visitor to a variant (sticky assignment). Assignment runs for every visitor so each one sees a consistent version; it uses a random ID and a 30-day cookie and never records the session.
- Apply a visual modification (text/style/visibility, etc.)
- Track exposures and goal events for attribution
Audit Data
During audits, we analyze:
- Page HTML structure
- Performance metrics
- Content and copy
- Visual screenshots, on paid plans with AI in audits and fixes turned on (reviewed by our AI provider, Anthropic, together with short parts of your theme code)
Data Masking
We automatically hide sensitive information in recordings:
- Typing: everything shoppers type is hidden
- Page text: other page text shows as ***. Product names, prices, headings, menus, buttons, breadcrumbs and size/colour options stay readable so recordings make sense
- Pages: checkout, account, order and login pages are never recorded
- Custom hiding: in Settings → Recording privacy you can hide chat, review, loyalty and email/SMS pop-up widgets, or any element by CSS selector
We also apply server-side redaction as a safety net to reduce the risk of sensitive information being stored if it slips past client-side masking.
URL and Metadata Privacy
- Path-only URLs: for analytics and experimentation data, we minimize URL storage by using path-only URLs (we avoid storing query strings, which can contain sensitive information).
- Sensitive routes: checkout, account, order and login pages are never recorded, and A/B tests and surveys don’t run on them.
- Approximate location: we may derive a country-level code from network headers (when available) to support segmentation and reporting.
Browser Storage
Zolvio may use browser storage to improve reliability and consistency (for example: localStorage, sessionStorage, and IndexedDB). Typical uses include:
- Persisting a pseudonymous visitor ID
- Maintaining session continuity across page loads
- Retrying event delivery if the network is unavailable
- Keeping A/B test assignment consistent
Data Storage
Location
Data is stored in the United States, on DigitalOcean servers, database and file storage.
Encryption
- In transit: TLS
- At rest: encryption (where supported by our infrastructure)
Retention Periods
| Plan | Retention |
|---|---|
| Free | 7 days |
| Starter | 30 days |
| Growth | 60 days |
| Pro | 180 days |
After the retention period, data is scheduled for deletion. For details by data type (including screenshots and aggregated analytics), see our Data Retention Policy.
Data Access
Access to your data is restricted to:
- Authorized users on your Shopify store
- Zolvio engineering team (for support and maintenance)
- Automated systems for processing
Third-Party Services
We use third-party services (“subprocessors”) to operate Zolvio: Shopify (platform and billing), DigitalOcean (servers, database and file storage), Cloudflare (network), Anthropic (AI analysis, with emails and phone numbers removed from text first), Resend (email) and Sentry (error monitoring). The current list, with what each one processes, is in our Privacy Policy.
Data Export
You can export certain data from within the app (where supported):
- Survey responses can be exported (CSV/JSON)
- A/B test results and events can be exported (CSV/JSON)
For other requests (including DSAR-related access/export), contact privacy@zolvio.io.
Data Deletion
Request complete data deletion by:
- Using in-app deletion controls (where available)
- Uninstalling the Zolvio app
- Contacting us at privacy@zolvio.io
Deletion timing can vary depending on data category, retention windows, and legal/security obligations.
Compliance
Zolvio is designed to help you comply with:
- GDPR (EU General Data Protection Regulation)
- CCPA (California Consumer Privacy Act)
- Shopify's app requirements
Contact
For data-related questions, contact us at privacy@zolvio.io