OfferPilotAdd to Shopify

Privacy Policy

OfferPilot, operated by OPEN TALENT LAB SL.

Who we are

OfferPilot is operated by OPEN TALENT LAB SL ("OfferPilot", "we"), Luxemburgo 18, 28514 Nuevo Baztán, Madrid, Spain. For anything in this policy, contact support@useofferpilot.com. We are the data controller for merchants' account data, and a data processor acting on the merchant's behalf for the store data we read to do our job.

What OfferPilot does

OfferPilot decides, per shopping cart, the offer that maximises a store's incremental profit margin, and measures the honest uplift against a control group. To do that it reads store data from Shopify and stores the decisions it makes.

What data we access, and why

Data (Shopify scope)What it isWhy we need it
Products (read_products)Titles, prices, variantsTo know what can be offered and at what price
Inventory cost (read_inventory)Per-variant unit cost (COGS)Margin is computed from real cost, not guessed
Orders (read_orders)Past orders, line items, applied discountsCo-purchase affinity, the profit-leak report, attributing outcomes to decisions
Customers (read_customers)A customer's number of past orders onlyTo tell recurring from new buyers when classifying discount incrementality
Discounts (write_discounts)We create and delete single-use codesTo apply an accepted offer at checkout, then clean the code up

What we deliberately do not collect: we hold no customer personal data beyond what appears on order line items. We do not read customer names, emails, addresses, or payment details, and we never receive card data. Storefront requests carry a cart token; we strip its secret before it reaches our servers, so it cannot be used to alter a shopper's cart.

What we generate and store

For each cart, which offer the engine chose (or that it showed nothing), with the expected margin — for both the treatment and control arms, since the control's counterfactual is what makes the uplift honest. Plus the offer authorisations and minted discount codes (until they expire and are deleted), and derived analytics: co-purchase affinity, the profit-leak estimate, and the uplift report.

Where data lives

Hosted in the European Union — Google Cloud, region europe-southwest1 (Madrid); our infrastructure subprocessor is Google Cloud Platform. Stored in a private PostgreSQL database with per-shop row-level security, so one merchant's data is never reachable from another's session. Secrets are held in Google Secret Manager, never in source or logs.

Who we share it with

We do not sell your data, and we do not share it with third parties for their own purposes. The only parties involved are Shopify (the source of the store data and the platform the app runs on) and Google Cloud (our hosting subprocessor).

Retention and deletion

When a merchant uninstalls OfferPilot (app/uninstalled) we purge that shop's data — products, orders, affinities, decisions, offer authorisations, reports, and the subscription record. The same purge runs on Shopify's GDPR shop-redaction signal (shop/redact); nothing survives it, including any stored report and its share link. GDPR customer requests (customers/redact, customers/data_request) are acknowledged; we hold no customer personal data to return or erase beyond order line items, which belong to the merchant's own Shopify record.

Your rights (GDPR)

Merchants and their customers have the rights the GDPR grants — access, rectification, erasure, restriction, portability, and objection — most exercised through Shopify's own data-request tools, which we honour via the webhooks above. To reach us directly, use the contact address at the top.

Cookies and tracking

The embedded admin app uses only what Shopify App Bridge requires to authenticate the session. The storefront widget sets no tracking cookies: it reads the cart, asks our engine for an offer, and tags the resulting order so the uplift can be measured — nothing is used to profile a shopper across sites.

Changes

We may update this policy; for material changes we will notify merchants in-app or by email.