How we handle Data on Essential CRO Split AB Testing app

Essential A/B Testing helps you find the best-performing version of your store while keeping your customer data safe and compliant with global privacy standards, including GDPR and CCPA. Unlike apps that build customer profiles, A/B testing only needs to know which version of a page a visitor saw and whether a purchase happened — it never needs to know who that visitor is. This guide explains exactly what we collect, what we don't, and how we protect it.


🔒 How We Identify Visitors — Without Identifying Them

To measure test results, we need to make sure a visitor keeps seeing the same version of your store. Here's how we do it privately:

✅ Each visitor gets a completely random ID generated in their own browser — like a raffle ticket number

✅ This ID is stored only in the visitor's own browser — never linked to their identity

✅ The ID is not derived from, or linked to, any personal information — no name, no email, no customer account, no IP address

✅ Bots and crawlers are filtered out before any ID is even created

Think of it like a cloakroom ticket: it tells us "ticket #47 saw version B and made a purchase," but it can never tell us who ticket #47 is.


🔒 What Data We Collect and Why

Data we store to measure your test results:

✅ The random visitor ID and which test version (A or B) was shown

✅ Test events: page viewed, product added to cart, checkout started, checkout completed

✅ Order ID and order total (to calculate revenue per test version)

✅ Basic technical context: page URL, browser type, and screen size (to ensure tests display correctly and to filter out bots)

✅ Checkout region only — city, province/state, and country (never a street address)


What we do NOT collect or store:

❌ Customer names, email addresses, or phone numbers

❌ Street addresses or any full shipping/billing address

❌ Credit card or payment information

❌ IP addresses

❌ Shopify customer accounts or profiles — visitor IDs are never linked to them


Why this data is necessary:

Without it, A/B testing simply cannot work. We need to know that the same visitor consistently saw version B, and whether that visit turned into an order and for how much — otherwise your test statistics would be meaningless. Everything we collect serves that single purpose.


🎯 Consent and Shopify's Customer Privacy Framework

Our tracking runs through Shopify's official Web Pixel system in strict privacy mode, which means:

✅ Our pixel is registered as analytics-only — marketing and preference tracking are disabled

✅ "Sale of data" is permanently disabled — we never sell or share visitor data

✅ The pixel automatically respects your store's cookie banner and Shopify's Customer Privacy consent settings

✅ Shopify reviewed and approved this configuration as part of the app review process

📊 Your Statistics Are Calculated Anonymously

When we calculate whether version A or B is winning, our statistics engine receives only aggregate numbers — visitor counts, conversion counts, and average order values per variant. No visitor IDs, no order IDs, no personal data of any kind leave the analytics database for this calculation. It's pure math on totals.


🌍 Privacy Compliance: GDPR, CCPA & DPA


GDPR Compliance (EU/UK):

✅ Data Minimization: We collect only what's needed to run and measure tests

✅ Purpose Limitation: Data is used exclusively for A/B test functionality and statistics

✅ Pseudonymization by design: Visitors are only ever known to us as random IDs

✅ Customer Rights: We support Shopify's mandatory data request, customer redaction, and shop redaction webhooks

✅ Transparency: This guide discloses exactly what we collect and why


CCPA/CPRA Compliance (California & US States):

✅ Right to know what data is collected

✅ Right to delete personal information

✅ We never sell customer data — sale of data is disabled at the platform level

Data Processing Agreement: We operate under Shopify's Data Processing Addendum as your data processor, process data only for the purposes above, and respond to all mandatory compliance requests routed through Shopify.


🗄️ Data Storage and Security

✅ All test and analytics data is stored in our secure, access-controlled database

✅ Encryption in transit (TLS/SSL) for all data transmission

✅ Statistical calculations use signed, authenticated requests between our own services

✅ Temporary test preview images auto-delete after 1 day

✅ No advertising networks or data brokers — ever


🗑️ Data Retention and Deletion Policy

✅ While the app is installed, test data is retained so your statistics and test history stay accurate

✅ If you uninstall, Shopify sends us a redaction request and your store's identifying information (store name, domain, email) is anonymized

✅ Visitor data is pseudonymous by design — it contains nothing that identifies a person

✅ You can request complete deletion of all your store's test data at any time by contacting our support


🛡️ Our Commitment

Essential A/B Testing is built on a simple privacy principle: great testing doesn't require knowing who your customers are.

✅ No customer profiles, no IP addresses, no personal identifiers

✅ Random, anonymous visitor IDs only

✅ Analytics-only tracking that respects visitor consent

✅ Full support for GDPR, CCPA, and Shopify's compliance framework

✅ Statistics calculated on aggregate numbers, never on individuals


Your customers trust you with their shopping — and you can trust us to never ask who they are.

Did this answer your question? Thanks for the feedback There was a problem submitting your feedback. Please try again later.

Still need help? Contact Us Contact Us