for Shopify

Effective August 19, 2026

Privacy policy

cbsplit is operated by Supercharged Entertainment Ltd (British Columbia, Canada). This page says what we collect, why, and for how long. The short version comes first because it is the part that matters: we never sell your data, never mine it, never use it for advertising, never train anything on it, and never look at one store's data to benefit another. Data exists here for exactly one purpose - running your experiments and showing you, and only you, the results.

What we collect, and why

From the merchant's store (via Shopify, with the permissions shown at install): the store domain, a Shopify access token, a cached copy of the product catalog (titles, variants, prices, images) so pickers and offers work, the store's currency, and everything the merchant creates in the app - funnels, tests, targeting rules, offer designs, notes.

About the store's visitors, collected on the merchant's behalf to run their experiments: a random visitor identifier (a first-party cookie containing no personal information), which page was visited and which test version was assigned, device type, country, referrer and UTM parameters, and the technical request details (IP address, browser user agent) that come with any web request.

About orders (via Shopify's order webhooks): order number, amounts, taxes and shipping, the products purchased, the buyer's email address and country, and which test version or offer the order is attributed to. We retain the order records Shopify sends us so that reports can be recomputed accurately. We never see or store payment card details - Shopify processes all payments.

For billing: the monthly gross-sales total used to compute the fee tier. A total, not a customer list.

What we do with it

Assign visitors to test versions and keep those assignments consistent; attribute orders and upsells to the experiments that produced them; render reports to the merchant who owns the store; compute the monthly fee; and alert our own operators when the system detects a fault (such alerts carry an order number and a diagnostic reason, not customer details). That is the complete list.

Each store's data is isolated. Access control is enforced server-side on every query; no report, export, or feature aggregates one store's data with another's.

What we will never do

We do not sell, rent, or trade data. We do not share it with advertisers or data brokers. We do not build profiles of shoppers across stores. We do not use merchant or shopper data to train machine-learning models. We do not use it for our own marketing. If a future feature would need something this page rules out, the feature changes, not the commitment.

Cookies on merchant storefronts

Two first-party cookies, both set only when the merchant has enabled the storefront embed: a random visitor identifier (so a returning visitor sees the same test version - it contains no personal information), and a signed marker of which test version the visitor was assigned (so their order can be attributed to it). No third-party advertising cookies, no fingerprinting, no session recording.

Retention and deletion

Diagnostic records are pruned automatically on short clocks: checkout attribution hints after about two days, request logs and offer-call markers after about thirty days. Experiment and order records are kept while the merchant uses the app, because deleting them would silently corrupt the merchant's own reports.

We honor Shopify's privacy webhooks in full: when a customer asks their store for their data, we supply what we hold; when a customer requests erasure, we erase their personal fields; when a store uninstalls, Shopify instructs us about 48 hours later and we erase the store's data. You can also reach us directly at [email protected] for any data request.

Security

All data moves over TLS, everywhere - browser to us, Shopify to us, our extensions to us. Sensitive stored fields, including access tokens and buyer contact details, are encrypted at rest with authenticated encryption (AES-256-GCM). Signing secrets fail closed: if a signing key is missing, the affected feature refuses to run rather than running unsigned.

Who touches the data

Shopify (the platform the data comes from and returns to), Cloudflare (network transport in front of our servers), Resend (delivery of our own operational alert emails), and the infrastructure our servers run on. Each processes data only as needed to provide their service to us. No other third parties receive it.

The boring but true parts

This service is directed at merchants, not children, and we do not knowingly collect data from children. If this policy changes, the change and its date appear on this page; material changes are announced inside the app. Questions, requests, complaints: [email protected]. This policy is governed by the laws of British Columbia, Canada.