~ / privacy

Privacy Policy

Last updated: 22 August 2026

This Privacy Policy explains how QSortby ("QSortby", "we", "us") collects, uses, retains, and protects information when a merchant installs our Shopify app and when shoppers visit a store that uses it. By installing QSortby, the merchant agrees to this policy.

1. Who controls the data

The merchant who installs QSortby is the data controller for their store's data. QSortby acts as a data processor, handling data on the merchant's behalf to provide the service. First-party store data remains owned by the merchant.

2. Merchant & store data we process

To rank products by sales velocity and keep your storefront updated, QSortby accesses, via the permissions you grant at install:

  • Orders & refunds — used to compute real-time sales velocity.
  • Products — titles, identifiers, and catalog attributes (category, margin, launch date) used to build rankings. QSortby also creates metafield definitions on your products so you can supply those attributes.
  • Inventory levels — used to demote sold-out products.
  • Customers & customer events — customer id and order history, used to rank for returning shoppers and to join purchases back to the ranking that produced them.
  • Write access — QSortby writes collection membership, order tags, and product metafield definitions. It never edits your product content, prices or inventory.
  • Store & account details — shop domain and an access token needed to call the Shopify Admin API. Access tokens are encrypted at rest.

3. Shopper data collected by the storefront pixel

If the merchant enables QSortby's storefront features, a lightweight first-party pixel may collect passive behavioral signals from store visitors to support merchandising and (where enabled) personalization. These can include:

  • Page views, products viewed, and recently-viewed history
  • Scroll, hover, search, and cart interaction signals
  • Session metadata such as referrer, device type, and timestamps
  • Technical data including IP address (coarsened before storage) and user-agent string

This data is keyed to a first-party visitor/session identifier. When a shopper is signed in we also store their Shopify customer id and a one-way hash of their order email, so purchases can be joined to the ranking that led to them — we never store names, addresses or plaintext email. Past orders are used only to rank products for that shopper (reorder and cart-history signals); QSortby builds no advertising profile and nothing that follows a shopper across stores.

QSortby sets no cookies of its own. It stores a first-party visitor identifier and a recently-viewed list in your storefront's own localStorage (keys prefixed qsortby_), and reads Shopify's own _shopify_y cookie so a checkout purchase can be matched to the ranking that led to it.

To attribute an order to the ranking that produced it, QSortby writes hidden note attributes onto the cart — a visitor identifier, the surface, and the A/B variant — which Shopify carries into the order, and may tag the resulting order in your Shopify Admin. These live on your own order record and are removed with the order under your Shopify retention settings.

Consent. Where your theme loads Shopify's Customer Privacy API, QSortby honors it: with analytics consent withheld we drop every behavioral event and keep only a minimal, non-identifying session record, so contextual ranking still works. On themes that do not load that API we cannot read a consent decision, so collection follows your own banner configuration — enable Shopify's consent API on your theme if you serve regions that require prior consent.

4. How we use data

  • To compute and publish best-seller rankings and keep app-managed collections in order
  • To maintain a Best Sellers collection and demote out-of-stock items
  • To attribute orders to the ranking or offer a shopper engaged with
  • To operate, secure, debug, and improve the service
  • To provide support you request

5. What we never do

  • We never sell or rent personal data.
  • We never share shopper data with third parties for their own marketing.
  • We never use behavioral signals to manipulate or exploit shoppers.

6. Data retention

Behavioral event data is retained for the life of the installation, so long-window rankings and year-over-year reporting stay accurate. Derived visitor profiles and the IP/user-agent rollup are pruned after 12 months, and order records after 24 months. Ranking reads your order lines over whatever window each collection is set to. Merchant account data is retained for the life of the installation and deleted on the schedule below after uninstall.

7. Sub-processors & infrastructure

QSortby runs on dedicated cloud infrastructure provided by DigitalOcean, and uses Shopify's APIs. Shopify order, product and inventory events reach us through Google Cloud Pub/Sub. Where a merchant enables QSortby's optional AI features, product and behavioral signals may be processed by OpenAI to generate embeddings and state predictions. Data is processed only to deliver the service described here.

8. Your rights & GDPR

QSortby is built to be GDPR-compliant. We honor Shopify's mandatory data-protection webhooks:

  • Data request — we surface the data we hold for a shopper on request.
  • Customer redaction — we delete a shopper's data, including IP/user-agent records and recently-viewed history.
  • Shop redaction — when a store uninstalls, we delete its data (within 48 hours of Shopify's redaction request, typically 30–48 days after uninstall per Shopify's schedule).

To make a data request directly, email hello@qdn.vn.

9. Security

Access tokens are encrypted at rest (AES-256-GCM). All API and webhook traffic uses HTTPS, and webhook authenticity is verified. Internal service calls require an authenticated token.

10. Changes to this policy

We may update this policy as the product evolves. Material changes will be reflected by the "last updated" date above.

11. Contact

Questions about this policy or your data? Email hello@qdn.vn.

10 days full access Install free