Skip to content
Invisible OfferMore margin. Less noise.
  • The experiment
  • Field guide
  • Your estimate
Estimate discount spend ↓

Explore Invisible Offer

01The experiment↗02Field guide↗03Your estimate↗Estimate discount spend ↓
Invisible Offer/Legal/Privacy notice

INVISIBLE OFFER / LEGAL

Privacy notice

This draft describes the data flows visible in the current Invisible Offer Shopify app and website code. It needs the operator details and the open privacy operations listed below before it can serve as the final public notice.

PUBLICATION CHECK

Before publication, confirm the legal operator name, registered address, privacy contact email, applicable jurisdiction, provider locations, retention schedule, and the customer privacy request process.

01

Who operates the service

Invisible Offer is a Shopify app that helps a merchant measure whether a discount changes purchasing outcomes. The merchant controls its Shopify store and decides whether to install and use the app. The legal entity operating Invisible Offer and its privacy contact must be added before publication.

02

Information the app processes

When a merchant installs the app, the service processes the shop domain and Shopify identifiers, granted access scopes, and an encrypted Shopify access credential. Storefront telemetry can include an anonymous session identifier, experiment-unit identifier when Shopify reports analytics processing is allowed, event type and time, product and variant identifiers, quantity, price, cart value, currency, and checkout token.

Shopify order and refund notifications are normalized into shop-scoped order and refund records. Depending on the event, these can include Shopify order/refund identifiers, checkout token, product identifiers, quantities, prices, discounts, currency, timestamps, cancellation/refund values, and Invisible Offer experiment attributes. The current event schema and normalized order record do not intentionally store shopper name, email, phone number, or postal address. Shopify may include those fields in the raw webhook delivery; the app normalizes the payload before storing the order record.

03

How information is used

The service uses these records to operate the Shopify integration, maintain pseudonymous shopping sessions, assign eligible experiment units, record authorized decisions, reconcile orders and refunds, protect the service, and present experiment measurements to the merchant. Behavioral summaries may be sent to the configured semantic decision provider to describe observed shopping behavior. Those signals are not treated as proof that a discount caused a purchase.

The Web Pixel is configured for analytics processing and not for marketing, preferences, or sale of data. Shopify's customer privacy controls determine whether analytics processing is allowed in the storefront. The persistent experiment-unit identifier is created only when the pixel receives an explicit affirmative analytics permission.

04

Service providers and storage

The current system uses Shopify for commerce and app platform functions, Railway for application runtime, Neon PostgreSQL for persistent records, Upstash Redis for short-lived session and queue state, and the semantic provider configured for the deployment. Provider regions and any cross-border transfer safeguards depend on account configuration and must be confirmed for the final notice.

Shopify access credentials are encrypted before being stored. Neon is the persistent record store; Redis is used for temporary state and coordination. Security controls and provider terms should be reviewed with the final operating entity before launch.

05

Retention and deletion

A fixed public retention schedule has not yet been established. Shopify uninstall events disable the installation and clear its stored credential. The shop-redaction webhook calls a shop erasure routine, but its current deletion list omits some shop-scoped tables, so complete erasure has not been verified. Per-customer data-request export and customer-redaction deletion are declared in the Shopify app configuration, but the current handlers acknowledge those requests without exporting or deleting records. These operational gaps must be resolved before this draft is used as a final notice or the app is broadly distributed.

06

Your privacy choices

Storefront analytics processing follows the consent signal exposed by Shopify. Merchants and shoppers can also use the privacy controls and request channels made available by Shopify and the merchant. A working privacy contact and a procedure for verifying, answering, and completing requests must be added before publication.

07

Contact and effective date

Privacy contact: [ADD CONFIRMED PRIVACY EMAIL]. Legal operator: [ADD LEGAL ENTITY NAME AND REGISTERED ADDRESS]. Effective date: [ADD APPROVED EFFECTIVE DATE].

Invisible OfferMore margin. Less noise.

Randomize. Observe. Build evidence.

The experimentField guidePrivacyTermsCookies

© 2026 Invisible Offer · Educational material, not a claim about any merchant's results.