Privacy Policy
AB Test — A/B Testing & CRO for Shopify · Last updated July 22, 2026
AB Test (“the app”, “we”, “us”) is an A/B testing and conversion-optimization app for Shopify stores. This policy explains what data the app processes, why, how long we keep it, and the choices available to merchants and their shoppers. When the app processes data on behalf of a store, the merchant is the data controller and the app acts as a data processor.
Data we process
To run experiments and report results, the app processes:
- An anonymous visitor id. A random id (
_ab_vid) assigned to a storefront visitor to keep their experience consistent and to attribute events to the right test variant. It is never linked to a Shopify customer, name, or account. - Storefront behavioural events, collected server-side through Shopify’s Web Pixel: page views, product views, add-to-cart, checkout started, and checkout completed, with the associated product ids and order totals.
- Order revenue for attribution. Through Shopify’s
orders/createwebhook the app reads only the order id, order total, currency, and its own attribution id from the order’s note attributes. This lets the app measure revenue for checkouts that the Web Pixel cannot see (e.g. Shop Pay or third-party checkouts). - Coarse, non-identifying signals used for audience targeting: device type, new vs. returning, country, referrer, and UTM parameters.
Data we do not collect
The app does not read or store customer names, email addresses, phone numbers, or postal addresses. Its access to Shopify order data is limited to the order total, currency, and its own attribution id (Shopify Protected Customer Data, Level 1 — no protected customer fields are requested). Free-text search terms and raw URL query parameters (other than campaign identifiers) are discarded and never stored.
Cookies and similar technologies
The app sets a small number of first-party cookies on the storefront:
| Cookie | Purpose | Lifetime |
|---|---|---|
_ab_vid | Anonymous visitor id for consistent test bucketing | 1 year |
_ab_cache | Caches the visitor’s current assignment to avoid flicker | 30 minutes |
_ab_consent | Records the visitor’s analytics-consent state | 1 year |
_ab_seen | Distinguishes new vs. returning visitors for targeting | 1 year |
Consent
The app respects Shopify’s Customer Privacy API and common consent managers (OneTrust, Cookiebot). When a shopper declines analytics, the app stops sending storefront events for that shopper. Merchants remain responsible for displaying an appropriate consent banner for their region.
How we use the data
Data is used solely to operate A/B tests for the store: assigning visitors to variants, computing conversion and revenue metrics, and producing the aggregated results shown in the merchant’s admin. We do not sell personal data, and we do not use it for advertising or profiling.
Data retention
Raw event and assignment records are automatically deleted after 180 days. Only anonymized, aggregated experiment results are retained longer so historical tests remain readable. When a store uninstalls the app or a Shopify redaction request is received, the associated data is deleted (see below).
Sharing and sub-processors
- Hosting. The app runs on cloud infrastructure (Amazon Web Services). Data is encrypted in transit.
- Shopify. Data is received from and returned to the merchant’s Shopify store under Shopify’s platform terms.
- Merchant-configured integrations only. If a merchant enables an integration (e.g. GA4, Segment, Heap, Hotjar, Clarity), experiment membership is forwarded to that tool at the merchant’s direction. No integration is enabled by default.
We do not otherwise share data with third parties.
Shopify GDPR / privacy webhooks
The app implements Shopify’s mandatory privacy webhooks:
customers/data_request— assembles the records tied to the affected order(s) for the merchant to fulfil.customers/redact— deletes every event and assignment tied to the affected order(s).shop/redact— erases all data for the store (roughly 48 hours after uninstall).
Security
Data is transmitted over HTTPS and stored on access-controlled infrastructure. Stored integration credentials are encrypted at rest. Access to production systems is limited to authorized personnel.
International processing
Data may be processed in the country where our infrastructure is hosted. Where required, we rely on appropriate safeguards for cross-border transfers.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above.
Contact
For any privacy question or request, contact us at yadav.creators@gmail.com. Shoppers should direct requests to the store they interacted with; the merchant (as data controller) can then reach us to fulfil them.