Privacy policy
This policy explains what information PageStax collects and how it is used. PageStax is an app for Shopify merchants that builds and publishes store pages, offers, reviews and A/B tests, with analytics. It applies to merchants who install PageStax (“you”) and to shoppers who visit pages a merchant has published with it.
Who we are
PageStax is operated by EDIUD LLC (“we”, “us”). For any question about this policy or your data, email support@pagestax.com.
Information we process about merchants
- Store identity and access: your shop domain (for example your-store.myshopify.com) and the Shopify access tokens Shopify issues when you install the app. The tokens let PageStax act on your store only within the permissions you approved.
- Store data fetched from Shopify: products, variants, prices, inventory, images, shipping settings and theme files, read through Shopify’s APIs so pages can show your real catalogue and be published to your store. Discounts are created in your store when you turn on an offer that needs one.
- Content you create: page drafts, published pages, saved sections, offers, journeys (funnels), A/B tests, review settings and app settings.
- Sign-in session: when you use PageStax outside Shopify admin (at app.pagestax.com), a signed session cookie keeps you signed in.
- Agent tokens you create for the command-line tool: we store only a one-way hash of each token, with its label and when it was created and last used. We cannot read a token back.
- Plan and billing status reported by Shopify’s Billing API. Payment is handled entirely by Shopify; we never receive or store card or bank details.
- Support email: if you write to us, we keep the correspondence to answer you.
Information we process about shoppers
On pages published with PageStax, and in the PageStax cart when a merchant turns it on, we record analytics events so the merchant can measure pages, offers and tests:
- A random visitor identifier generated in the shopper’s browser and stored there. It is not linked to a name, email address or Shopify customer account.
- Events such as page views, add-to-cart, offers shown, accepted or declined, which test variant was shown, and the page, section, product and variant involved.
- Purchases, received from Shopify’s checkout through a Shopify web pixel: the order reference, order value, currency and the PageStax attributes attached to the cart.
- Reviews a shopper chooses to submit: the rating, review text, the display name they enter and, where the form asks for it, an optional order number used to mark the review as verified.
Analytics does not collect shoppers’ names, email addresses, postal addresses or payment details, and we do not store IP addresses with events. A merchant can shorten how long their events are kept and can choose to drop the visitor identifier from stored events.
How we use information
- To provide the app: build, render and publish pages, apply the offers and discounts the merchant set up, collect and display reviews, and show the merchant their analytics and test results.
- To sign merchants in, enforce plan limits and keep the service secure and working.
- To answer support requests.
We do not sell personal information, we do not use shopper data for advertising, and we never share one merchant’s data with another.
Service providers (sub-processors)
We use the following providers to run PageStax:
- Cloudflare (Workers, KV, D1 and Pages): hosts the app and stores merchant content, settings and analytics events.
- Tinybird (EU region, Frankfurt): receives a copy of the anonymous analytics events for analysis.
- Shopify: the platform the app runs on; provides store data, sign-in, billing and checkout events.
Our website and published pages load web fonts from Google Fonts, which means the visitor’s browser requests font files from Google.
How long we keep information
- Raw analytics events are kept for up to 180 days (or less if the merchant sets a shorter window). After that only aggregated daily totals remain.
- Merchant content and settings are kept while the app is installed.
- On uninstall, access tokens and agent tokens are deleted immediately. About 48 hours later Shopify sends a shop data deletion request (shop/redact), and we then delete the shop’s pages, drafts, offers, journeys, reviews, billing record and analytics.
- We keep a minimal record of each privacy request we receive (its type, the shop and when it arrived) as evidence that it was handled.
Your rights and privacy requests
PageStax handles Shopify’s mandatory privacy webhooks: customer data requests, customer deletion requests and shop deletion requests. Because analytics events use a random identifier rather than a customer account, we hold no analytics data that can be tied to a named customer.
Shoppers who want to access, correct or delete their information should contact the merchant whose store they visited. When Shopify forwards a customer data deletion request (customers/redact), PageStax anonymizes that customer’s reviews linked to the listed orders: the display name becomes “Anonymous” and the order number is removed. For a data access request (customers/data_request) we record which reviews are linked so the merchant can answer it. A merchant can also hide or delete any review in the app, and can email us to help with a request.
Merchants can view, change and delete their content in the app, and can ask us about their data at any time at support@pagestax.com. Depending on where you live, you may have further rights under data protection law, such as objecting to processing or complaining to a supervisory authority.
Security
- All connections to PageStax use HTTPS (TLS).
- Webhooks from Shopify are verified with an HMAC signature before they are processed.
- Sign-in session cookies are signed, HTTP-only and secure.
- Shopify access tokens are held server-side and never sent to the browser; agent tokens are stored only as hashes.
No system is perfectly secure, but we work to protect the information we hold and will notify affected merchants of a breach as required by law.
Children
PageStax is a business tool for merchants and is not directed at children. We do not knowingly collect information from children.
International processing
Our providers operate data centres in several countries, so information may be processed outside the country where you or your shoppers are located.
Changes to this policy
We will update this page when our practices change and revise the date at the top. If a change is significant we will also tell merchants in the app or by email.
Contact
EDIUD LLC (ediud.com), operator of PageStax — support@pagestax.com.