CustomerJourney ← Back to site

Privacy

Effective 24 September 2026

CustomerJourney records what happens on a Shopify store so the merchant can see where shoppers struggle. This page describes what is actually collected, what is deliberately not collected, where it goes and how long it is kept — written from the shipping code rather than from intent.

Who is who

The merchant — the business running the Shopify store you are visiting — is the data controller. They decide that CustomerJourney runs on their store and what their pages display.

MoreCheckouts Limited, operating CustomerJourney, is a data processor acting on that merchant's instructions.

CustomerJourney is installed by a merchant on their own store and processes data about visitors to that store only. If you are a shopper wanting to exercise your rights, contact the merchant whose store you visited — they are the controller. We will help them respond.

What is collected

When a shopper visits a store with CustomerJourney installed and has given analytics consent, the app may record:

What is deliberately not collected

Form values are masked before transmission

Every value typed into an input, textarea or select is replaced inside the shopper's own browser, before anything leaves the device. Passwords, card details, addresses and any other typed input never reach our servers, because they are removed at source rather than filtered afterwards.

Checkout is never recorded

Session recording is delivered through a Shopify theme app extension, and theme extensions cannot load in Shopify's hosted checkout. Checkout pages have never been reachable by this product.

No cross-store tracking

CustomerJourney never links a shopper's identity across different merchants' stores. Each merchant's data is isolated, and there is no shared profile, shared identifier or audience built across stores. This is an architectural rule, not a setting.

Recording is selective

Not every visit is recorded. Recording is triggered by signals such as signs of friction or high-value activity, and only after the visitor has interacted with the page.

What masking does not cover

Masking protects what a shopper types. It does not remove personal information that the store itself displays as ordinary page text.

If a page renders a customer's name, delivery address, order history or email address as visible text — for example a logged-in account page or an order-status page — that text forms part of the page and can appear in a recording.

This is a property of how a store is built. The merchant, as controller, decides what their pages display and on which pages recording is enabled. We state this plainly because a policy implying "everything sensitive is masked" would be inaccurate.

Recording is gated on the shopper's analytics consent, read through Shopify's Customer Privacy API. Where a shopper has not given analytics consent, the pixel and the recorder do not run. The gate fails closed: if consent cannot be determined, nothing is captured.

The consent banner and its configuration belong to the merchant. CustomerJourney follows whatever consent state Shopify reports; it never overrides that state and never asks for consent on its own behalf.

AI connections

A merchant can connect their own AI assistant — such as Claude, ChatGPT or Cursor — to their CustomerJourney data. This is off by default and must be switched on by the merchant, who creates an individually revocable connection for each person.

When connected, that assistant can read the merchant's store data on request, including session recordings, journeys and captured page content. Data sent to an AI provider is then handled under that provider's terms, not ours, and leaves our infrastructure.

We do not use merchant or shopper data to train any AI model, and we do not sell data to anyone.

Identifiers in the browser

CustomerJourney does not set cookies. It stores a small number of values in the browser's local and session storage on the merchant's own domain — principally an anonymous visit identifier used to join the pages of a single visit together, plus recorder state. These are readable only by the store's own site, are not shared with any other domain, and carry no meaning outside that one store.

Where data is stored, and international transfers

Session recordings are stored in the European Union. They are held in Cloudflare R2 under EU jurisdiction, which constrains those files to EU infrastructure.

Other data is not. The application database, which holds events, sessions, aggregated statistics and the identifiers described above, is hosted in the United States. Scheduled processing also runs on US-hosted infrastructure.

Where personal data of people in the UK or EEA is transferred to the United States, that transfer relies on the safeguards offered by the relevant sub-processor, including Standard Contractual Clauses where applicable. Merchants who need a data processing agreement can request one at the address below.

Retention

How long session recordings are kept depends on the merchant's plan:

PlanRecordings kept for
Launch30 days
Grow30 days
Pro60 days
Scale90 days
Max90 days

Recordings are deleted automatically once they pass the retention period. Aggregated, non-identifying statistics derived from activity — counts, rates and findings — are kept for longer so that merchants can compare one period against another.

Legal bases

We process shopper data as a processor on the merchant's documented instructions. The merchant, as controller, relies on the shopper's consent for analytics and session recording; that consent is collected by the merchant's own consent banner and is the gate described above.

For merchant account data we rely on performance of a contract (operating the service the merchant subscribed to) and our legitimate interests in securing, supporting and improving it.

Security

Data is encrypted in transit and at rest by our infrastructure providers. Access to production systems is limited to those who need it. Each merchant's data is isolated, and the separation between merchants is enforced in the application itself rather than by convention.

No system is perfectly secure. If a breach affecting a merchant's data occurs, we will notify the affected merchant without undue delay so that they can meet their own obligations as controller.

Sub-processors

ProviderPurposeRegion
ShopifyStore platform and Web Pixels APIPer Shopify's terms
CloudflareEvent ingestion and recording storageEU
SupabaseApplication databaseUnited States
VercelScheduled jobs and hostingUnited States
GadgetAdmin application platformPer Gadget's terms

An AI provider a merchant chooses to connect (see AI connections) acts under its own terms and is not a sub-processor engaged by us.

Your rights

If you are in the UK or EEA you have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, to data portability, and to withdraw consent at any time — withdrawing consent stops future capture, and is done through the store's own consent controls.

Because the merchant is the controller, direct your request to the store you visited. We act on their instructions and will assist them. You also have the right to complain to your data protection authority; in the UK that is the Information Commissioner's Office.

Deletion

CustomerJourney implements Shopify's mandatory privacy webhooks:

Deletion is queued and carried out against the recording store itself, so an erasure removes the underlying files and not merely a database reference.

Merchant account data

Separately from shopper data, we hold what is needed to run a merchant's subscription: the store domain, the contact details Shopify provides, plan and billing status, and support correspondence. Payments are handled by Shopify; we never see card details. This data is kept while the merchant is a customer and for the period afterwards required for tax and accounting.

Changes to this policy

If this policy changes materially we will update the effective date at the top and, where the change affects merchants, tell them directly. Earlier versions are recorded in the source history of this site.

Contact

MoreCheckouts Limited — nick@morecheckouts.com.