Version 1.0, in effect from [[EFFECTIVE_DATE]]
Revenue Radar ("the App") is operated by PÉCI Szolgáltató Korlátolt Felelősségű Társaság (PÉCI Kft., a Hungarian limited liability company), Aradi utca 5., 2119 Pécel, Hungary, company registry number Cg. 13-09-089813, tax number 12761609-2-13 ("we", "us"). This policy explains what data the App processes when a Shopify merchant ("you") installs it, why, and what happens to that data.
For data about your store's visitors and customers, you are the data controller and we act as your data processor under Article 28 GDPR. Your customers should direct privacy requests to you; Section 8 explains how the App supports you in answering them. For your own account data (Section 3.A) we act as an independent controller, solely to provide the service.
This policy also records the processing terms between you and us. The subject-matter, nature and purpose of the processing are the analytics service described in Sections 2–4; its duration is the time the App is installed (deletion per Section 7); the types of personal data are listed in Section 3; the categories of data subjects are the visitors and customers of your store who browse, add to cart or check out.
We process visitor data only on your documented instructions, which you give by installing and keeping the App installed; we will inform you if we consider an instruction to infringe data protection law. Persons we authorise to process the data are committed to confidentiality. You grant a general authorisation for the sub-processors in Section 5; we announce intended changes by updating that list and flagging material changes in the App (Section 12), and you may object to a change by raising it at the contact address or by uninstalling the App. We assist you with data subject requests (Section 8) and, taking into account the nature of the processing, with your obligations under Articles 32–36. On request we make available the information necessary to demonstrate compliance with these terms and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, on reasonable notice and at your expense. You remain responsible for the lawfulness of the processing on your storefront, including informing your visitors in your own privacy notice.
Revenue Radar is an analytics dashboard. It shows you where checkout abandonment loses you revenue. It never contacts your customers: it sends no email, no SMS, and stores no customer contact details of any kind.
| Category | Fields | Purpose |
|---|---|---|
| Store identity | myshopify domain, store timezone, currency, plan type | operating the App, cutting days in your timezone |
| Installing staff account | name, email, locale (Shopify session record) | authentication into the embedded App |
| API access token | Shopify-issued token | making the Admin API calls the App needs |
The App's web pixel records four storefront events: product added to cart, cart viewed, checkout started, checkout completed. For each event it stores: Shopify's pseudonymous visitor identifier (clientId), a session key, checkout token, order amounts and currency, the products involved (id, title, price, quantity), page referrer, screen-size presence, cookie availability, a one-way hash of the browser's user agent, and a bot score.
No name. No email address. No phone number. No postal address. No payment details. No IP address. Not for your customers, not from any source.
This is not only practice but a structural limit: the App requests only the write_pixels and read_customer_events Shopify scopes. It has no API permission to read customer records or orders, so the pseudonymous visitor identifier we hold cannot be converted into a person's identity by us — the permission to do so does not exist in the App's installation.
| Category | Fields | Purpose |
|---|---|---|
| Monthly visitor counts | visitor identifier per month | measuring the free plan's visitor threshold |
| Daily aggregates | per-day, per-product totals; no visitor identifiers | the dashboard's numbers |
| Digest opt-out list | salted hash of an email address, never the address | honouring unsubscribe permanently |
| Digest interest flag | store domain + yes/no | measuring demand for a weekly summary |
| Audit log | operational events (install, uninstall, privacy webhooks) | evidence that requests were honoured |
Processing under this policy happens to provide the analytics service you installed (Art. 6(1)(b) — contract, for your account data) and on your behalf under your instructions as controller (Art. 28, for visitor data). We use no data for advertising, profiling beyond the bot-filtering described above, or sale. The App's own pixel declares analytics purpose only; marketing and preference purposes are disabled and data sale is flagged as not applicable. We do not sell personal information and do not share it for cross-context behavioural advertising, as those terms are defined in the California CCPA/CPRA and similar US state privacy laws.
| Sub-processor | Service | Location |
|---|---|---|
| Shopify International Ltd. / Shopify Inc. | platform, billing, webhooks | EU/Canada/US |
| Vercel Inc. | application hosting | United States |
| Neon, LLC (a Databricks, Inc. affiliate), provisioned via the Vercel Marketplace | PostgreSQL database | United States (AWS us-east-1) |
We use no email delivery provider: the App currently sends no email at all.
Where a sub-processor processes data in the United States, transfers rely on the EU-U.S. Data Privacy Framework or Standard Contractual Clauses (Decision 2021/914), as applicable to that provider. As with any US-based provider, data held by them remains subject to US legal process (CLOUD Act) regardless of transfer mechanism; the data at stake here is the pseudonymous analytics data described above, which contains no customer identity.
| Data | Kept for |
|---|---|
| Raw analytics events | 30 days, then purged automatically on a rolling basis |
| Daily aggregates | while the App is installed (they contain no visitor identifiers) |
| Monthly visitor counts | the current and the previous month; older months are purged automatically |
| Account/session data | deleted on uninstall |
| Ordinary audit rows | 90 days, purged on a rolling basis whether or not the App is still installed |
| Everything else, including digest hashes | deleted 48 hours after uninstall, when Shopify sends the shop redaction request |
GDPR compliance audit rows (customers/data_request, customers/redact, shop/redact) | 3 years, and they survive the shop redaction -- see the note below |
Why the compliance rows outlive the deletion. When we act on an erasure request we write one audit row saying we did. If a later uninstall erased that row too, the proof of the erasure would be destroyed within 48 hours of the erasure itself -- and the proof is the point of the row. These rows carry the shop's domain, which is a business identifier; they carry no customer or visitor identifier at all. They are the only thing we keep past the shop redaction, and they are purged after three years.
The App implements all three mandatory Shopify privacy webhooks:
customer identities (Section 3.C), there is no customer record we could add beyond what you already have. The audit row evidences receipt.
identifiers are deleted.
for the store, with one stated exception: the GDPR compliance audit rows described in Section 7, which record that an erasure was performed and carry no customer identifier.
For your own account data (Section 3.A), where we act as controller: you may request access to, correction, deletion or restriction of that data at privacy@peci.io at any time; account data is in any case deleted on uninstall (Section 7). Providing it is necessary to operate the App — without it the App cannot be installed.
Section 1 makes us the controller for the data in Section 3.A -- the account data Shopify gives us when you install. This section says how you exercise your rights over it. (Your *visitors'* rights are a different matter and run through you as their controller: see Section 8.)
hold about you. Section 3.A is the complete list; there is no other place we keep it.
-- they are mirrored from your Shopify staff account when you sign in. Correct them in Shopify and our copy follows at your next sign-in. We cannot edit them independently, and it would be misleading to imply otherwise.
and Shopify's shop redaction request 48 hours later removes the rest, apart from the compliance audit rows named in Section 7. No separate request is needed. If you want confirmation that it happened, or want it done sooner, write to us.
portable form. On request we will also export our own copy.
only to authenticate you into the App, so in practice restricting it means the App can no longer sign you in.
contract with you (Art. 6(1)(b)), not on consent, for this data -- see Section 4. There is no consent to withdraw.
We answer within one month. If we need longer because a request is complex, we will say so within that month and explain why. You can also complain to a supervisory authority: see Section 13.
All data moves over TLS. Encryption at rest is provided by the database sub-processor. Access tokens are held in the database under those infrastructure protections and access controls; the App applies no additional application-level encryption of its own. Payment data never reaches us: all billing runs through Shopify's billing system. If we become aware of a personal data breach affecting data we process for you, we will notify you without undue delay (Article 33(2) GDPR) with the information you need for your own notification duties.
The App is a business tool for Shopify merchants and is not directed at children. We do not knowingly process children's data.
Each version of this policy carries a version number and the date it took effect. They are listed in the version history at the end of this page. When we revise it, the new version gets its own number and date, what changed is recorded there, and the version it replaces stays available at its own address, so it remains possible to establish what this policy said on a given day.
We review this policy at least once a year, and whenever the App changes what it does with data. Material changes will be announced in the App.
You may lodge a complaint with a data protection supervisory authority. In Hungary, where we are established, this is the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH, naih.hu); you may also complain to the authority of your own EU member state.
Privacy and data protection (including Art. 28 processing questions): privacy@peci.io. General legal: legal@peci.io. Hosting provider: Vercel Inc. (United States).
Each version of this document is listed with the period it was in effect. Version numbers were assigned on 2026-08-31, when this register was created.
| Version | In effect | What changed | Copy |
|---|---|---|---|
| 1.0 | [[EFFECTIVE_DATE]] – current | First published version. | this page |