Privacy Policy

AB Test — A/B Testing & CRO for Shopify · Last updated July 22, 2026

AB Test (“the app”, “we”, “us”) is an A/B testing and conversion-optimization app for Shopify stores. This policy explains what data the app processes, why, how long we keep it, and the choices available to merchants and their shoppers. When the app processes data on behalf of a store, the merchant is the data controller and the app acts as a data processor.

Data we process

To run experiments and report results, the app processes:

Data we do not collect

The app does not read or store customer names, email addresses, phone numbers, or postal addresses. Its access to Shopify order data is limited to the order total, currency, and its own attribution id (Shopify Protected Customer Data, Level 1 — no protected customer fields are requested). Free-text search terms and raw URL query parameters (other than campaign identifiers) are discarded and never stored.

Cookies and similar technologies

The app sets a small number of first-party cookies on the storefront:

CookiePurposeLifetime
_ab_vidAnonymous visitor id for consistent test bucketing1 year
_ab_cacheCaches the visitor’s current assignment to avoid flicker30 minutes
_ab_consentRecords the visitor’s analytics-consent state1 year
_ab_seenDistinguishes new vs. returning visitors for targeting1 year

Consent

The app respects Shopify’s Customer Privacy API and common consent managers (OneTrust, Cookiebot). When a shopper declines analytics, the app stops sending storefront events for that shopper. Merchants remain responsible for displaying an appropriate consent banner for their region.

How we use the data

Data is used solely to operate A/B tests for the store: assigning visitors to variants, computing conversion and revenue metrics, and producing the aggregated results shown in the merchant’s admin. We do not sell personal data, and we do not use it for advertising or profiling.

Data retention

Raw event and assignment records are automatically deleted after 180 days. Only anonymized, aggregated experiment results are retained longer so historical tests remain readable. When a store uninstalls the app or a Shopify redaction request is received, the associated data is deleted (see below).

Sharing and sub-processors

We do not otherwise share data with third parties.

Shopify GDPR / privacy webhooks

The app implements Shopify’s mandatory privacy webhooks:

Security

Data is transmitted over HTTPS and stored on access-controlled infrastructure. Stored integration credentials are encrypted at rest. Access to production systems is limited to authorized personnel.

International processing

Data may be processed in the country where our infrastructure is hosted. Where required, we rely on appropriate safeguards for cross-border transfers.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above.

Contact

For any privacy question or request, contact us at yadav.creators@gmail.com. Shoppers should direct requests to the store they interacted with; the merchant (as data controller) can then reach us to fulfil them.