Privacy Policy
Last updated: 11.06.2026
1. Introduction
Headless Analytics ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our analytics service for Shopify stores.
2. Information We Collect
2.1 Behavioral Data
We collect behavioral data from store visitors. This data is used to provide
analytics to the merchant and, when enabled, to transmit conversion events to Meta.
The data we collect includes:
• Page view events
• Conversion events
• Technical metadata (browser type, device type, screen resolution)
• Geographic location (country/region level)
• Referrer sources and UTM parameters
• Product interaction events (which products were viewed/added to cart)
• A persistent visitor identifier used to recognise the same visitor across
pages and visits on a single store (stored as a long-lived cookie and in
the browser's local storage; cleared when the visitor clears cookies or
local storage for the site)
Data Handling:
• Visitor identifiers are scoped to a single store. We do not share visitor
identifiers across different stores.
• Email, phone, name, postal code, city, region, and country values that reach
our servers are cryptographically hashed using SHA-256 before any further
processing.
• IP addresses are processed in readable form where required by the third-party
platforms we integrate with (notably Meta Conversions API, which requires
the visitor's IP and user agent in order to accept conversion events).
IP addresses are not stored as part of your analytics history.
• When Meta Conversions API is enabled, we send a hashed form of the visitor
identifier to Meta so that Meta can recognise the same visitor across
devices. This means that, once Meta is in the loop, identity matching is
performed by Meta on Meta's systems, and is by Meta's design both
cross-device and cross-site.
What This Means:
Because identity matching for advertising is ultimately performed by Meta, we
cannot on our own fulfill data access or deletion requests for store visitors
that relate to Meta's matching of their identifier. For data that lives only in
our analytics store, deletion happens automatically at the end of the retention
period, and can be requested earlier by the merchant.
2.2 Store Information
We collect your Shopify store domain, subscription tier, and the operational
status of your subscription (active / trial / cancelled). We do not collect or
store payment or billing information on our servers — all billing is handled
by Shopify, and we receive only a subscription identifier and a status flag
back from Shopify.
2.3 Meta CAPI Data Processing (Available on All Plans)
When you enable Meta Conversions API integration, we process conversion events
to send to Meta's servers on your behalf. Meta CAPI is available on every plan,
including the free plan.
Technical Implementation:
• Email addresses and other PII fields are hashed using SHA-256 before
transmission to Meta.
• IP addresses and user agent strings are transmitted to Meta in readable
form because Meta's Conversions API requires them in order to accept an
event and to match it to a click. We do not retain the IP address in your
analytics history.
• A hashed form of the visitor identifier is also transmitted to Meta, which
allows Meta to match the same visitor across devices.
• Meta receives the event and decides how to store, match, and use it on
Meta's side. We have no control over Meta's retention or processing of
data once it has been delivered to Meta.
Your Responsibilities:
• You must obtain explicit consent from users before enabling Meta CAPI
• You represent that you have proper legal basis for this data transmission
• You are responsible for compliance with GDPR, CCPA, and Meta's Terms
• We act solely as a technical processor and are not responsible for your
consent practices or Meta's data handling
GDPR Note: Transmission to Meta constitutes an international data transfer
and third-party data sharing requiring explicit consent (GDPR Article 49).
3. How We Use Your Information
We use the collected information to:
Provide analytics and insights about your store's performance
Process billing and manage subscriptions
Send server-side conversion events to Meta (if enabled)
Improve our service and develop new features
Provide customer support
Comply with legal obligations
4. Data Retention
Free Plan: Analytics data is retained for up to 90 days
Growth Plan: Analytics data is retained for up to 720 days
Pro Plan: Analytics data is retained without time limit
After the retention period, data is automatically and permanently deleted from our systems. We do not retain ClickHouse data beyond the active plan's retention period, and we do not keep parallel backups that outlive the retention window. We cannot recover deleted data. You can request immediate deletion at any time by contacting support@headless.life.
5. Data Sharing and Disclosure
We do not sell your data. We may share your information with:
Meta Platforms: Only if you enable Meta CAPI integration (available on all plans)
Legal Requirements: When required by law or to protect our rights
6. Data Subject Rights
6.1 Rights for Merchants (Our Customers)
If you are a Shopify store owner using our service, you have the following rights
under GDPR:
• Access: Request a copy of your account data and analytics
• Rectification: Correct inaccurate account information
• Erasure: Request deletion of your account and all associated data
• Portability: Export your analytics data in portable format
• Restriction: Limit how we process your account data
• Objection: Object to certain types of processing
To exercise these rights, contact support@headless.life
6.2 Rights for Store Visitors (End Users)
If you are a visitor to a store using our analytics:
We do collect a persistent visitor identifier (a cookie and a local storage
entry scoped to the store you are visiting) and behavioral events associated
with it. The visitor identifier is scoped to a single store, is not shared
across stores, and is used to recognise repeat visits and to support Meta's
cross-device matching when Meta CAPI is enabled.
Because identity matching for advertising is ultimately performed by Meta on
Meta's own systems once Meta CAPI is enabled, we cannot on our own:
• Provide access to "your" data on Meta's side
• Delete "your" data on Meta's side
• Confirm whether Meta matches events about you specifically
We can, on request to the store owner:
• Stop setting our first-party identifier on the store by having the merchant
disable our analytics, which will also stop new Meta CAPI events from being
sent for that store.
For data that lives only in our analytics store, deletion happens automatically
at the end of the plan's retention period.
For questions about data collection on a specific store, contact the store owner
directly. They are the Data Controller.
To prevent tracking: Use browser privacy features, ad blockers, or contact the
store owner to request they disable analytics.
7. Legal Basis for Processing and Consent
7.1 First-Party Analytics (Base Service)
Our base analytics operates on first-party data for the merchant's own store.
Legal basis under GDPR:
• Article 6(1)(f) - Legitimate Interest: Processing of first-party analytics
data for the merchant's business purposes.
• We use a persistent visitor identifier scoped to a single store, used only
to recognise repeat visits and (when Meta CAPI is enabled) to support
Meta's cross-device matching. We do not share that identifier across
different stores, and we do not build a behavioural profile of the visitor
beyond what is needed to provide the analytics.
• Because we set a persistent identifier, you should treat the service as
using cookies and obtain whatever consent your jurisdiction requires
before the pixel loads. The pixel is the merchant's responsibility to
deploy behind their own consent flow.
Merchant Responsibility:
You are responsible for ensuring that your privacy policy and consent
mechanism are appropriate for your jurisdiction, and for listing our
cookies and the Meta CAPI integration (when enabled) in your own privacy
notice.
7.2 Meta CAPI (Optional Feature)
Enabling Meta Conversions API requires explicit consent because:
• It constitutes third-party data sharing (with Meta)
• It's used for advertising purposes, not just statistics
• It involves international data transfer (to Meta's US servers)
Required Legal Basis: Consent (GDPR Article 6(1)(a) and 9(2)(a) if special categories apply)
We strongly recommend implementing a consent management platform (CMP) that:
• Obtains explicit opt-in consent before enabling Meta CAPI
• Allows users to withdraw consent
• Documents consent for compliance purposes
8. Privacy Architecture
Technical Practices:
✓ We use a long-lived first-party visitor identifier (cookie + browser
storage) scoped to a single store, for the sole purpose of recognising
repeat visits on that store.
✓ We do not share visitor identifiers across different stores.
✓ Visitor-facing PII fields (email, phone, name, postal code, city,
region, country) are hashed using SHA-256 before they are stored or
transmitted.
✓ We use lightweight, event-level deduplication on the device. We do not
combine browser and device signals into a long-term device fingerprint
for advertising or cross-site identification purposes.
✓ The merchant dashboard shows aggregated metrics, not individual-level
user journeys.
What This Means in Practice:
✗ We do not sell or rent your data.
✗ We do not share your visitor identifiers with anyone other than Meta,
and only when Meta CAPI is enabled for the store.
✗ We do not show merchants "User X visited N times and bought Product Y."
✗ We do not build cross-site advertising profiles on Meta's behalf
beyond the conversion event Meta CAPI sends for the merchant's own
store.
✗ We do not retain ClickHouse analytics data beyond the active plan's
retention period and we do not keep parallel backups that outlive
that window.
9. Data Security
We implement industry-standard security measures to protect your data, including encryption in transit (HTTPS/TLS), encrypted storage, access controls, and regular security audits.
In the event of a data breach affecting personal data, we will:
Notify relevant supervisory authorities within 72 hours (GDPR Article 33)
Notify affected merchants promptly so you can fulfill your obligations to notify your customers
Provide details necessary for you to assess the risk to your customers
10. International Data Transfers
We ensure appropriate safeguards are in place for international data transfers in compliance with GDPR, including:
Standard Contractual Clauses (SCCs) with third-party processors where applicable
Data Processing Agreements with all service providers where applicable
Your analytics data is stored in a ClickHouse database hosted with a US-based
infrastructure provider. Cloudflare Workers, which handles request processing
and orchestration, operates globally. Transfers to non-US regions (e.g., Meta
CAPI) only occur when a specific integration is enabled for the store.
10.5 California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the right to:
Know what personal information we collect and how it's used
Request deletion of your personal information
Opt-out of the "sale" or "sharing" of personal information (we do not sell data)
Non-discrimination for exercising your rights
To exercise these rights, contact support@headless.life. We will respond within 45 days.
Note for Merchants: If you are subject to CCPA, you must provide appropriate privacy notices to your California customers about our analytics tracking.
11. Children's Privacy
Our service is not intended for children under 18. Use of the service requires a
Shopify account, and Shopify requires account holders to be at least 18 years
old (or the age of majority in their jurisdiction). We do not knowingly collect
personal information from children.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.
13. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us at:
Headless Analytics
Email: support@headless.life
14. Data Controller and Processor Roles
For Merchant Account Data:
• Data Controller: We (Headless Analytics) control merchant account information
• This includes: email, store URL, billing info, subscription status
For Anonymous Behavioral Data:
• Data Controller: You (the Shopify merchant)
• Data Processor: We (Headless Analytics) process on your behalf
• We follow your instructions and provide infrastructure only
Important Distinction:
Because the behavioral data is anonymous, typical GDPR data subject rights
(access, deletion, portification) cannot be fulfilled for individual visitors.
The data exists only in aggregate form.
Your Obligations as Merchant:
• Provide privacy notice to visitors about anonymous analytics
• Obtain explicit consent if enabling Meta CAPI
• Respond to visitor questions about tracking (explain it's anonymous)
• Implement consent management if required by law
• Include our tracking in your privacy policy
Data Processing Agreement (DPA):
A standard DPA is available upon request for merchants who require it for
compliance purposes. Email support@headless.life
15. Information for Store Visitors
If you visited a Shopify store using Headless Analytics:
What Data We Have:
We have a persistent visitor identifier for the store you visited (a cookie and
a local storage entry on that store's domain) and behavioral events associated
with it. We also have a session identifier that is refreshed after a period of
inactivity. PII fields that reach us (email, phone, name, address fragments)
are hashed before storage; the IP address is processed in readable form only
long enough to forward it to Meta when Meta CAPI is enabled, and is not
retained as part of your analytics history.
Can You Request Your Data?
For data we hold, you can request access by contacting the store owner. The
store owner is the Data Controller for behavioral data on their store. For
data Meta holds, only Meta can fulfill that request.
Can You Request Deletion?
The store owner can request deletion of the store's analytics data at any time,
and data is also automatically deleted at the end of the plan's retention
period. For data Meta holds, only Meta can fulfill that request.
How to Prevent Tracking:
• Contact the store owner and ask them to disable analytics
• Use browser privacy features (JavaScript blocking, Privacy Badger, uBlock Origin)
• Use private/incognito browsing mode
• The store owner is responsible for honoring your requests
Questions About Specific Store's Data Collection:
Contact the store owner directly. They are the Data Controller and responsible
for their tracking practices. We only provide technical infrastructure.
16. Technical Data Flow
How Data Moves Through Our System:
Step 1: Event Collection
• Store visitor triggers event (page view, purchase, etc.)
• Our tracking script sends event to our servers, associated with a
persistent visitor identifier scoped to the store
• PII fields (if present) are hashed via SHA-256 before they reach our
analytics store
Step 2: Storage
• Events are stored with metadata:
- Store ID (which store sent this)
- Event type (page view, conversion, etc.)
- Hashed PII fields (irreversible by us)
- Persistent and session visitor identifiers (scoped to the store)
- Technical data (browser, device type)
- Timestamp and location (country-level)
• We cannot reverse the SHA-256 hash to find the original PII
• We do not retain the visitor's IP address in the analytics store
Step 3: Aggregation
• Data is aggregated for merchant dashboards
• Merchants see: "50 conversions from Meta ads"
• Merchants do not see individual-level user journeys
Step 4: Meta CAPI (if enabled)
• Hashed PII, the hashed visitor identifier, and the visitor's IP and
user agent are sent to Meta
• Meta uses the data on Meta's side for ad attribution and matching
• The merchant is responsible for obtaining consent before enabling
Step 5: Retention and Deletion
• After the active plan's retention period (90 days on Free, 720 days on
Growth, no time limit on Pro), data is automatically deleted
• Deletion is permanent and cannot be recovered
• We do not retain ClickHouse data beyond the active plan's retention
period, and we do not keep parallel backups that outlive the retention
window.