~ / privacy

Privacy Policy

Last updated: 21 June 2026

This Privacy Policy explains how QSortby ("QSortby", "we", "us") collects, uses, retains, and protects information when a merchant installs our Shopify app and when shoppers visit a store that uses it. By installing QSortby, the merchant agrees to this policy.

1. Who controls the data

The merchant who installs QSortby is the data controller for their store's data. QSortby acts as a data processor, handling data on the merchant's behalf to provide the service. First-party store data remains owned by the merchant.

2. Merchant & store data we process

To rank products by sales velocity and keep your storefront updated, QSortby accesses, via the permissions you grant at install:

  • Orders & refunds — used to compute real-time sales velocity.
  • Products — titles, identifiers, and segment attributes (e.g. category) used to build rankings and write ranking metafields.
  • Inventory levels — used to demote sold-out products.
  • Store & account details — shop domain and an access token needed to call the Shopify Admin API. Access tokens are encrypted at rest.

3. Shopper data collected by the storefront pixel

If the merchant enables QSortby's storefront features, a lightweight first-party pixel may collect passive behavioral signals from store visitors to support merchandising and (where enabled) personalization. These can include:

  • Page views, products viewed, and recently-viewed history
  • Scroll, hover, search, and cart interaction signals
  • Session metadata such as referrer, device type, and timestamps
  • Technical data including IP address and user-agent string

This data is tied to an anonymous visitor/session identifier. QSortby does not use it to build identified profiles of named individuals, and does not require shopper purchase history.

4. How we use data

  • To compute and publish best-seller rankings and ranking metafields
  • To maintain a Best Sellers collection and demote out-of-stock items
  • To operate, secure, debug, and improve the service
  • To provide support you request

5. What we never do

  • We never sell or rent personal data.
  • We never share shopper data with third parties for their own marketing.
  • We never use behavioral signals to manipulate or exploit shoppers.

6. Data retention

Behavioral event data is retained on a rolling basis (approximately 90 days) and then pruned. Ranking data reflects a rolling 24-hour window. Merchant account data is retained for the life of the installation and deleted on the schedule below after uninstall.

7. Sub-processors & infrastructure

QSortby runs on dedicated cloud infrastructure provided by DigitalOcean, and uses Shopify's APIs and native event delivery. Where a merchant enables QSortby's optional AI personalization features, product and behavioral signals may be processed by OpenAI to generate embeddings and intent predictions. Data is processed only to deliver the service described here.

8. Your rights & GDPR

QSortby is built to be GDPR-compliant. We honor Shopify's mandatory data-protection webhooks:

  • Data request — we surface the data we hold for a shopper on request.
  • Customer redaction — we delete a shopper's data, including IP/user-agent records and recently-viewed history.
  • Shop redaction — when a store uninstalls, we delete its data (within 48 hours of Shopify's redaction request, typically 30–48 days after uninstall per Shopify's schedule).

To make a data request directly, email support@qsortby.com.

9. Security

Access tokens are encrypted at rest (AES-256-GCM). All API and webhook traffic uses HTTPS, and webhook authenticity is verified. Internal service calls require an authenticated token.

10. Changes to this policy

We may update this policy as the product evolves. Material changes will be reflected by the "last updated" date above.

11. Contact

Questions about this policy or your data? Email support@qsortby.com.

See it on your store Book a demo