Legal
Privacy Policy
Last updated: August 20, 2026
Friction Observatory / Checkout Friction Observatory (“we”, “our”, “the app”) provides synthetic checkout monitoring for Shopify merchants and agencies. This policy explains what data we process when you install or use the app, how we use it, and how you can request deletion.
Who this applies to
This policy covers merchants and agencies who install the app on a Shopify store, and visitors who submit contact details on our marketing waitlist or lead forms. It does not cover shoppers on your storefront — we do not run their checkouts or store their personal data from live orders.
Data we process
- Store identity & configuration: shop domain, storefront URL, product page URLs you choose to test, markets/regions and devices to monitor, schedule settings, and optional staging storefront URL.
- Shopify authentication: offline access tokens and related OAuth session data needed to keep the embedded app connected (encrypted at rest in production).
- Optional secrets you provide: storefront password for password-protected or staging shops, Slack incoming webhook URLs, and alert email addresses (encrypted at rest).
- Business estimates you enter: monthly traffic and average order value used only to estimate revenue-at-risk figures (not payment data).
- Billing status: plan type (trial / Pro / Agency), Shopify subscription status (including whether a charge is a test charge and when a billing trial window ends), and how many synthetic checkout tests you have used so we can enforce trial limits. We do not receive or store card numbers — Shopify handles payment.
- Agency brand settings (Agency plan): display name, optional contact line, and logo file used on white-label client PDFs / share views.
- Audit results & artifacts: health scores, failure codes, reports, console/network signals from the synthetic run, failure screenshots, and session videos of the bot journey.
- Share links: signed tokens that let someone you choose open a report without logging into Shopify Admin.
- Marketing contacts: name/email and related fields submitted via waitlist or lead forms.
Trial usage we count
Checkout tests are synthetic bot runs you start in the app (each market × device × product URL counts as one test). We keep a count of those runs so we can apply published limits: five lifetime tests on the free Trial plan, and 30 tests total during Shopify’s 14-day Pro/Agency billing trial (not 30 per day). Automatic schedules stay off until Shopify begins charging the shop. After a live subscription starts billing, paid shops are not limited by that 30-test cap. Test charges that Shopify never invoices stay on the 30-test cap.
What we do not collect
We do not process real customer checkout payments, card data, or shopper PII from live orders. Audits use automated bot journeys that stop at checkout presentation and do not complete purchases. We do not sell personal data.
How we use data
- Run and schedule synthetic checkout tests you configure
- Show health history, market comparisons, reports, PDFs, and share links in the app
- Send optional Slack and email alerts when issues are confirmed
- Provide Agency portfolio views across stores you link under your account
- Operate billing entitlements through Shopify, including counting synthetic checkout tests against the free Trial (5 lifetime tests) and the Shopify billing trial (30 tests total over 14 days, not per day)
- Secure, debug, and improve the service (including abuse prevention)
- Respond to support and privacy requests
Processors & third parties
- Shopify: app install, OAuth, embedded admin, Billing, and mandatory privacy webhooks.
- Hosting & infrastructure: servers, database, and job queue used to run the app and store configuration/audit data.
- Network proxies (when used): may route test traffic through third-party proxies so market checks can originate closer to a buyer region. Proxies see storefront requests made by our bots, not your customers’ accounts.
- Slack / email: if you connect a webhook or alert email, payloads are delivered to your workspace or inbox under those providers’ terms.
- Optional AI assistance: if enabled in our environment, limited page-control text may be sent to an AI provider solely to help discover Add to cart / checkout selectors when standard heuristics fail. We do not send customer order data.
Retention
Configuration and audit history are kept while the app remains installed and needed to provide the service. Session videos and screenshots are retained for a limited period and may be deleted by automated cleanup. After uninstall or a Shopify shop-redact request, we deactivate the store, revoke the Shopify session, clear stored secrets (such as storefront password, Slack webhook, and alert email), and scrub or remove associated audit artifacts as described below.
Shopify privacy webhooks
We implement Shopify’s mandatory GDPR webhooks (customers/data_request, customers/redact, shop/redact). Because we do not store shopper PII from live checkouts, customer data-request and customer-redact events typically require no customer records to export or erase. Shop redact removes the merchant’s connection data and redacts storefront URLs / artifact paths tied to that shop.
Your choices & deletion
- Uninstall the app from Shopify Admin to disconnect the store and trigger cleanup flows.
- Email privacy@frictionobservatory.com to request deletion of remaining audit artifacts, brand assets, or marketing contacts.
- You can clear optional secrets (storefront password, Slack webhook, alert email) from the app settings.
- You can stop sharing by not distributing share links; links are signed and time-limited.
Security
We use HTTPS in production, restrict artifact access with signed URLs, and encrypt sensitive merchant-provided secrets at rest where configured. No method of transmission or storage is 100% secure; please use strong Shopify account controls and rotate credentials if you suspect misuse.
Children
The app is intended for business users operating Shopify stores, not for children under 16.
Changes
We may update this policy as the product changes. The “Last updated” date at the top will change when we do. Continued use of the app after an update means you accept the revised policy.
Contact
Privacy: privacy@frictionobservatory.com
Support: support@frictionobservatory.com