Privacy Policy — PalecVNebo (A/B Testing)
Last updated: 2026-07-30
PalecVNebo ("the App", "we", "us") is operated by GOODEVAS LLC, 30N South Gould Street, Sheridan, Wyoming 82801, United States. This policy explains what data the App processes when a merchant installs it on their Shopify store, and how store visitors are affected.
1. Who is the data controller
For data the App processes on behalf of a merchant's store, the merchant is the data controller and GOODEVAS LLC is a data processor. For operating the App itself, GOODEVAS LLC is the controller. The App is designed around data minimization: it does not collect or store any customer personal data (no name, email, phone, or address).
2. What data we process
From the store admin (merchant):
- Shopify session/offline access token (to call the Shopify Admin API), stored encrypted at rest.
- A/B test configuration you create (test name, themes, traffic split, targeting, product scope).
- Your shop domain (*.myshopify.com) as the tenant identifier.
From store visitors (storefront A/B testing):
- A first-party anonymous visitor id (random UUID) stored in cookies/localStorage to keep a visitor in the same test group. This id is not linked to any Shopify customer, name, email, or account. Cookies:
_pvn_vid,_pvn_assignment,_pvn_tracked_*,_pvn_viewed_*(first-party, used only for consistent A/B bucketing and to de-duplicate view/participant pings). We record one row per (test, visitor) with the assigned group and your shop domain — used only to count participants per group. - Cart attributes
_pvn_test_id,_pvn_groupand_pvn_vidare added to the cart so resulting orders can be attributed to a test group. - Product-page views: for products in a running test we record, once per anonymous visitor and product, that the product page was viewed (test, anonymous visitor id, product, assigned group, shop domain). Used only to compute per-product conversion rates. No customer identity is involved.
Order data (minimal records, no customer identity): To measure conversion, the App receives order events via Shopify webhooks and reads order data from the Shopify Admin API. From each order we process only: order id, creation date, total price, the cart attributes above (test id, group, anonymous visitor id), and line-item product ids. We never request, store, or forward customer name, email, phone, or address. Minimal order records limited to these fields are stored so that test conversion can be computed reliably (including beyond Shopify's 60-day order API window); dashboards show aggregated counts and revenue per test group.
3. Why we process it (purpose & legal basis)
To provide the App's core function: running A/B tests and reporting participants and conversion per group. Legal basis: performance of the contract with the merchant / legitimate interests in providing the service. We do not sell data, use it for advertising, or share it for cross-context behavioral use.
4. Where it is processed (sub-processors)
- Fly.io (region: Amsterdam, EU) — runs the App backend over TLS.
- DigitalOcean (managed PostgreSQL, region: Frankfurt, EU) — stores the App's Shopify session tokens and technical test references. Encrypted in transit and at rest.
- Palec data service (hosted on DigitalOcean, region: Frankfurt, EU) — a dedicated data-processing service operated for the App; stores test configuration, anonymous participant rows, and minimal order records (no customer identity fields). GDPR export files are stored in DigitalOcean Spaces in the same region. Encrypted in transit and at rest.
- Shopify — source of theme, metafield, and order data via the Admin API.
5. Retention & deletion
Test configuration and aggregate results are kept while the App is installed. Anonymous participant rows and minimal order records are kept for the lifetime of the related test and are deleted when that test is archived or deleted (only aggregate results remain). On app uninstall we delete the store's session/token immediately. On Shopify's shop/redact request (≈48h after uninstall) we permanently delete all data for that store, wherever it is stored. On customers/redact we delete stored order records matching the orders listed in the request; the records contain no customer identity fields, so no further personal data exists to redact. On customers/data_request we compile an export of the minimal order records related to that customer (order id, date, total, attributed test and group) and make it available to the merchant inside the App; the export also carries the requester details Shopify provides (customer id, email, phone) solely so the merchant can tell whose request it answers. Export files are deleted automatically after 30 days, and a new request from the same customer replaces the previous export. After uninstall or erasure we may retain minimal plan-usage records (aggregate order counts used to enforce plan limits) for fraud and abuse prevention; these contain no personal data.
6. Cookies (storefront)
The App uses first-party cookies/localStorage solely to assign and remember a visitor's A/B test group (_pvn_vid, _pvn_assignment, _pvn_tracked_*). They are not used for advertising or cross-site tracking. The App integrates with Shopify's Customer Privacy API and honors the merchant's cookie consent banner: where the merchant has enabled consent collection and a visitor has not granted analytics consent, the App sets no cookies and records nothing about that visitor — they are excluded from tests entirely until consent is given. Where no consent requirement is configured by the merchant, processing proceeds by default. The App does not include a consent banner of its own; collecting consent remains the merchant's responsibility via Shopify's native privacy settings.
7. Security
TLS on all endpoints; tokens and data encrypted at rest; access scoped strictly per store (shop); least-privilege Shopify scopes (read_orders, read_products, write_products, read_themes, read_files).
8. Your rights
Depending on your jurisdiction (e.g. GDPR/CPRA) you may have rights to access, correct, delete, or restrict processing of personal data. Since the App stores no customer personal data, such requests for store visitors are typically satisfied automatically. Contact us for any request.
9. Changes
We may update this policy; material changes will be reflected by the "Last updated" date.
10. Contact
GOODEVAS LLC — privacy contact: forworklistsmail@gmail.com.