Privacy Policy — PalecVNebo (A/B Testing)

Last updated: 2026-07-30

PalecVNebo ("the App", "we", "us") is operated by GOODEVAS LLC, 30N South Gould Street, Sheridan, Wyoming 82801, United States. This policy explains what data the App processes when a merchant installs it on their Shopify store, and how store visitors are affected.

1. Who is the data controller

For data the App processes on behalf of a merchant's store, the merchant is the data controller and GOODEVAS LLC is a data processor. For operating the App itself, GOODEVAS LLC is the controller. The App is designed around data minimization: it does not collect or store any customer personal data (no name, email, phone, or address).

2. What data we process

From the store admin (merchant):

From store visitors (storefront A/B testing):

Order data (minimal records, no customer identity): To measure conversion, the App receives order events via Shopify webhooks and reads order data from the Shopify Admin API. From each order we process only: order id, creation date, total price, the cart attributes above (test id, group, anonymous visitor id), and line-item product ids. We never request, store, or forward customer name, email, phone, or address. Minimal order records limited to these fields are stored so that test conversion can be computed reliably (including beyond Shopify's 60-day order API window); dashboards show aggregated counts and revenue per test group.

3. Why we process it (purpose & legal basis)

To provide the App's core function: running A/B tests and reporting participants and conversion per group. Legal basis: performance of the contract with the merchant / legitimate interests in providing the service. We do not sell data, use it for advertising, or share it for cross-context behavioral use.

4. Where it is processed (sub-processors)

5. Retention & deletion

Test configuration and aggregate results are kept while the App is installed. Anonymous participant rows and minimal order records are kept for the lifetime of the related test and are deleted when that test is archived or deleted (only aggregate results remain). On app uninstall we delete the store's session/token immediately. On Shopify's shop/redact request (≈48h after uninstall) we permanently delete all data for that store, wherever it is stored. On customers/redact we delete stored order records matching the orders listed in the request; the records contain no customer identity fields, so no further personal data exists to redact. On customers/data_request we compile an export of the minimal order records related to that customer (order id, date, total, attributed test and group) and make it available to the merchant inside the App; the export also carries the requester details Shopify provides (customer id, email, phone) solely so the merchant can tell whose request it answers. Export files are deleted automatically after 30 days, and a new request from the same customer replaces the previous export. After uninstall or erasure we may retain minimal plan-usage records (aggregate order counts used to enforce plan limits) for fraud and abuse prevention; these contain no personal data.

6. Cookies (storefront)

The App uses first-party cookies/localStorage solely to assign and remember a visitor's A/B test group (_pvn_vid, _pvn_assignment, _pvn_tracked_*). They are not used for advertising or cross-site tracking. The App integrates with Shopify's Customer Privacy API and honors the merchant's cookie consent banner: where the merchant has enabled consent collection and a visitor has not granted analytics consent, the App sets no cookies and records nothing about that visitor — they are excluded from tests entirely until consent is given. Where no consent requirement is configured by the merchant, processing proceeds by default. The App does not include a consent banner of its own; collecting consent remains the merchant's responsibility via Shopify's native privacy settings.

7. Security

TLS on all endpoints; tokens and data encrypted at rest; access scoped strictly per store (shop); least-privilege Shopify scopes (read_orders, read_products, write_products, read_themes, read_files).

8. Your rights

Depending on your jurisdiction (e.g. GDPR/CPRA) you may have rights to access, correct, delete, or restrict processing of personal data. Since the App stores no customer personal data, such requests for store visitors are typically satisfied automatically. Contact us for any request.

9. Changes

We may update this policy; material changes will be reflected by the "Last updated" date.

10. Contact

GOODEVAS LLC — privacy contact: forworklistsmail@gmail.com.