Privacy Policy
Last updated: September 2026
Zolvio ("we", "our", or "us") is a Shopify app that helps merchants understand visitor behavior and improve conversion. This Privacy Policy explains how we collect, use, share, and retain information when merchants use Zolvio and when visitors interact with a merchant’s storefront where Zolvio is installed.
Information We Collect
From Merchants (You)
- Shopify store information (store name, domain, email)
- Billing information (handled by Shopify)
- Usage data within our app
- Optionally, your storefront password if you save it in Settings so Zolvio can audit a password-protected store. It is encrypted at rest, never displayed again, used only to sign in to your own storefront, and deleted with your store data after uninstall
From Your Store Visitors
- Interaction data (mouse movements, clicks, scroll behavior, navigation)
- Device and browser metadata
- Approximate location (for example, country level)
- Pseudonymous identifiers used to keep sessions consistent across pages
What We Do NOT Intend to Collect
- Credit card numbers or payment details
- Passwords or login credentials
- What shoppers type into forms (it is hidden in recordings)
No analytics tool can guarantee that sensitive information is never exposed in all circumstances. Zolvio is designed to reduce risk through masking, exclusions, and server-side redaction, but merchants must configure consent and disclosures appropriately.
Data Minimization and Safety Controls
- Consent: session recordings and surveys respect the store’s cookie consent. A/B test assignment runs for every visitor so each one sees a consistent version; it uses a random ID and a 30-day cookie and never records the session.
- Sensitive pages: checkout, account, order and login pages are never recorded.
- URL privacy: we minimize URL storage by using path-only URLs (we avoid storing query strings in analytics/experimentation data because they can contain sensitive information).
- Masking & redaction: everything shoppers type is hidden, and other page text shows as ***. Product names, prices, headings, menus, buttons, breadcrumbs and size/colour options stay readable so recordings make sense. We also apply server-side redaction as a safety net.
How We Use Information
- To provide session recordings and heatmaps
- To run store audits, including AI review of page screenshots on paid plans
- To enable A/B testing features
- To show on-site surveys and summarize their answers
- To generate guided fix recommendations
- To improve our service
Cookies and Similar Technologies
Zolvio uses browser storage and similar technologies (for example cookies, localStorage, sessionStorage, or IndexedDB) to support features like session continuity, experiment assignment, and reliable event delivery. You should disclose these technologies in your storefront policies where required.
Merchant Responsibilities
Merchants are responsible for configuring any required consent mechanisms and for updating storefront privacy disclosures. See our Privacy & Compliance docs for a checklist.
Data Storage and Security
We use industry-standard security measures to protect your data:
- Data encrypted in transit (TLS)
- Data encrypted at rest (where supported by our infrastructure)
- Access controls and authentication
- Monitoring and incident response practices
Data Retention
We retain session-related data based on your plan retention period. After the retention period, data is scheduled for deletion. For more detail by data category, see our Data Retention Policy.
Data Sharing
We do not sell your data. We may share data with:
- The subprocessors listed below, which help us operate Zolvio
- Law enforcement when required by law
Subprocessors
- Shopify: the platform Zolvio runs on, including billing
- DigitalOcean (United States): servers, database and file storage
- Cloudflare: network
- Anthropic (United States): AI analysis of screenshots, page and theme code, product details and survey answers, with emails and phone numbers removed from text first
- Resend: email
- Sentry: error monitoring
Data is stored in the United States.
Your Rights
You have the right to:
- Access your data
- Request deletion of your data
- Export your data (where supported)
- Opt out of certain data collection
Merchants can request deletion from within the app (where available) and can also contact us at privacy@zolvio.io for help with requests.
EU and UK Users
For EU/UK users, merchants are typically the data controller for storefront interaction data and Zolvio acts as a processor. Processing bases may include consent (where required), contractual necessity, and legitimate interests, depending on the context. Consult counsel for your specific obligations.
Contact Us
For privacy questions or data requests, contact us at privacy@zolvio.io