Effective date: 5 August 2026
1. Who we are
OB Session Personalization (the "App", "OB Session") is operated by OBSESSION ECOMMERCE DATA TOOLS LTD, a company registered in Cyprus with registration number HE 496073, with its registered office at Nikola Tsadioti, Pearl Park Block 6, Apartment 115, 8035 Paphos, Cyprus ("we", "us", "our"). References to "we" or "our" in this policy refer to OBSESSION ECOMMERCE DATA TOOLS LTD.
Privacy inquiries can be directed to legal@ob-session.com. Our United Kingdom representative under Article 27 UK GDPR is ASAO DS LTD, 86-90 Paul Street, London EC2A 4NE, United Kingdom (Company number 15072782).
This policy explains how the App handles personal data. It applies to the OB Session application installed on a merchant's Shopify store, not to the ob-session.com marketing website (which has its own policy).
2. Our role — controller and processor
- For data about shoppers on a merchant's storefront, the merchant is the data controller and OB Session is a data processor, acting on the merchant's documented instructions. Shoppers should refer to the merchant's own privacy notice for the controller-level disclosures that govern their data.
- For the merchant's own account, contact and billing data, OB Session acts as a controller.
A Data Processing Agreement (Section 17) sets out our processor obligations in full. To the extent we process shopper data as a processor, that processing is governed by that Agreement with the merchant as controller, and shoppers exercise their rights through the merchant (Section 13).
3. Configurable privacy — the identifier tier
OB Session is designed so that personalization does not require identification, and so that each merchant controls how long a shopper identifier persists. At onboarding the merchant selects an identifier tier (Section 3.1), recorded in the merchant's Data Processing Agreement. Longer-lived identifiers improve recommendation quality; the merchant chooses the trade-off.
All configurations are consent-gated (Section 6) — nothing is collected before the shopper grants consent. Where the shopper's region or consent state is more restrictive than the merchant's chosen configuration, the more restrictive setting always applies.
3.1 Identifier tier — how a returning visitor is recognized
| Tier | Identifier | Storage | Persistence | Cross-session | Cross-tab |
|---|---|---|---|---|---|
| Tier 1 (default) | Persistent ob-user-id + session identifier |
cookie + localStorage | Up to 365 days (rolling); recognizes a returning visitor across sessions | Yes | Yes |
| Tier 2 | Session identifier only | localStorage | ~60-minute rolling inactivity window; no identity outlives the session | No | Yes |
| Tier 3 | Session identifier only | sessionStorage | Per-tab: the identifier lives only as long as the tab and is cleared when it closes; a new tab is not traceable to the previous one | No | No |
4. Data we process
4.1 Merchant data
- Store information — shop domain, shop name, installation and configuration details.
- Merchant account contacts — on installation, Shopify provides the shop owner's or administrator's name and email, which we use to create and administer the account and to send service communications. For this data we act as a controller. Providing this data is necessary for us to enter into and perform our agreement with the merchant; Shopify supplies it on installation, and without it we cannot create or administer the account or provide the App.
- Catalog data — products, collections, variants, and metafield definitions, synced read-only via Shopify's Admin API, so that recommendations and analytics can reference the merchant's catalog.
- Order data (for billing, attribution, and model training) — order ID, order date, currency, total amounts, and line items (quantity, unit price, discount, product/variant references). Two flags are also read or recorded: a test flag — set by Shopify when an order is placed in test mode — so that test orders are excluded from billing and attribution; and attribution flags — recorded by OB Session to mark whether an order or line item was influenced by one of the App's recommendations. This data is used to attribute orders to the App's recommendations, to compute billing, and — because a completed purchase is a strong signal — to help train the recommendation model dedicated to the merchant. No customer fields (name, email, phone, address, or Shopify customer ID) are ever requested or stored.
4.2 Shopper data
Processed on the merchant's behalf, keyed only to pseudonymous identifiers, and described here by category (we do not build personal profiles from individual fields, and we do not publish our internal field list or derived feature set):
- Pseudonymous identifiers — randomly generated identifiers that distinguish the visitor, the session, and the parts of the page involved in an interaction, used to associate events within a visit (and, in Tier 1, across a returning visitor's visits). They are never linked to a customer account and are scoped to a single store (never shared across merchants).
- Interaction and behavioral signals — such as page and product views, clicks, hovers, scrolling, cursor movement, how much of a product card is visible, focus/visibility, browser viewport dimensions, and add-to-cart / remove-from-cart actions. These are essential to the App's function.
- Content and commerce context — such as the products and collections viewed, cart contents and amounts on the storefront, and the placement where a recommendation appeared (for example, a widget or the product-listing grid). On product and collection pages this includes attributes of the catalog elements displayed (such as product titles and prices) — properties of the merchant's storefront layout, not information entered by the shopper.
- Navigation and traffic context — such as page type, navigation path, referrer, and campaign (UTM) parameters. URLs are recorded path-only: query strings are discarded, apart from pagination and filter state.
- Search signals — store search terms, processed as an intent signal and never used to identify a shopper.
- Device and locale characteristics — such as user agent, language(s), platform, time zone, and screen dimensions, used to improve recommendation quality.
Derived signals. From the categories above, OB Session derives behavioral signals and product-recommendation inferences. These are generated by the App; they are not additional data collected from the shopper, and the App's internal feature set is not itemised here.
The App's first-party storefront script operates only on permitted catalog pages and does not read account, checkout, or form-input fields.
4.3 What we do not process
- No directly-identifying information — no names, email addresses, phone numbers, or postal addresses of shoppers.
- No payment or credential data — no payment details, no account credentials.
- No active device fingerprinting — no canvas, audio-context, or font-enumeration techniques.
- No cross-site tracking — identifiers are scoped to OB Session and to a single store, and are never shared with third parties for tracking.
- No cross-merchant sharing — no merchant's catalog, products, orders, or shopper data is ever shared with, or made visible to, another merchant; the model trained for one merchant is never applied to another.
- No sale or sharing of data for third-party advertising. We do not sell, rent, or trade merchant or shopper data.
- No IP-based shopper profiling — shopper IP addresses are not logged to identify or profile shoppers; transient infrastructure access logs may contain IPs for security/operational purposes and are retained for no longer than 30 days.
5. How we use data, and our lawful bases
| Purpose | Data | Lawful basis (where GDPR applies) |
|---|---|---|
| Provide and operate the App for the merchant | Merchant + shopper data | Performance of the merchant's instructions (processor); merchant's own basis as controller |
| Administer the merchant's account and send service communications | Merchant account contacts | Performance of our contract with the merchant; our legitimate interests |
| Personalize recommendations and analytics | Shopper behavioral data | The merchant's lawful basis as controller (consent and/or legitimate interests), obtained through the store's consent framework |
| Train and operate the merchant-specific recommendation model | Shopper behavioral, catalog, and order data | As above. Models are per-merchant; they do not identify individuals and are not shared across merchants |
| Attribute orders and compute billing | Order data (no customer fields) | Performance of the contract with the merchant |
| Develop and improve the App, using aggregated, de-identified statistics | Derived from shopper behavioral data; once derived, the statistics contain no identifiers and are no longer personal data | Our legitimate interests (improving the service); the derived statistics themselves fall outside data protection law |
| Maintain security and prevent abuse | Technical/operational logs | Legitimate interests / legal obligation |
The App does not carry out automated decision-making producing legal or similarly significant effects on individuals (Article 22 GDPR); it personalizes the products a shopper is shown.
6. Consent
Collection of shopper data is gated behind the shopper's consent, captured through Shopify's Customer Privacy API and the merchant's consent banner. No identifiers are set and no behavioral data is collected before consent is granted, and collection respects the store's regional consent configuration. The merchant, as controller, is responsible for configuring consent and disclosing processing in its own privacy notice.
7. Cookies and device storage
When consent is granted, the App stores a small amount of first-party, strictly-functional data on the shopper's device — solely to maintain continuity of the pseudonymous session and to remember consent. It holds:
- a pseudonymous visitor and/or session identifier (with an activity timestamp);
- a per-tab window identifier;
- the consent state; and
- a transient queue of pending events, cleared once they are sent.
Which storage mechanism is used, and how long each value persists, depends on the identifier tier (Section 3.1). For example, the persistent visitor identifier (cookie + localStorage, up to 365 days) exists only in Tier 1; in Tier 2 the identifier is session-scoped in localStorage; in Tier 3 it lives in sessionStorage and is cleared when the tab closes.
We collect the events described in Section 4.2 via our own first-party storefront script. The cookies and storage above are host-only (no shared domain), so identifiers never cross stores; they are set with Secure (on HTTPS) and SameSite=Lax, and contain only a random identifier or timestamp — no personal information. We do not use third-party cookies or third-party tracking pixels, and do not use cookies for cross-site tracking.
8. Retention and deletion
Shopper data is retained only as long as needed for the configured purpose; shorter privacy configurations carry shorter retention. The maximum retention periods are:
| Data | Retention |
|---|---|
| Recommendation data derived from a visitor's activity (and the current cart), keyed to pseudonymous identifiers | Follows the identifier tier (Section 3.1): up to 365 days in Tier 1; session-scoped (~60 minutes) in Tier 2; per-tab in Tier 3 |
| Behavioral event data and A/B measurements | Up to 12 months (rolling) |
| Order-level records (billing/attribution; no customer fields) | Up to 24 months, or earlier on a customers/redact request |
| On-device identifiers | Per Section 7 (session, or up to 365 days in Tier 1) |
| Infrastructure access logs (may contain IPs) | Up to 30 days |
| Merchant catalog/config and model artefacts | While the App is installed; deleted on uninstall |
On app uninstall, all of a merchant's data is deleted following Shopify's shop/redact request (Section 13). Aggregated or anonymised data that can no longer be linked to any device or shopper is not personal data and may be retained and used for internal and statistical purposes, including to develop and improve the App.
9. Sub-processors
We rely on the following sub-processor to operate the App:
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services | All cloud infrastructure — all OB Session processing runs on AWS-native services | AWS regions in the United States and/or the European Union |
Shopify is the platform on which the App runs and is an independent party with its own agreement with the merchant; it is not our sub-processor. We will give merchants advance notice of changes to our sub-processors as set out in the Data Processing Agreement, with an opportunity to object.
10. International data transfers
OB Session is an EU company (Cyprus). The personal data the App processes is hosted on Amazon Web Services, in AWS regions in the United States and/or the European Union. Where personal data is hosted with AWS in the United States, that transfer relies on the European Commission's adequacy decision for the EU-US Data Privacy Framework, under which AWS is certified (and, for UK data, the UK Extension to it), and/or the EU Standard Contractual Clauses in our agreement with AWS. The Standard Contractual Clauses are incorporated into the AWS Service Terms, published at aws.amazon.com/service-terms; a copy is also available on request at legal@ob-session.com. Where personal data is hosted in an AWS region in the EU, no such transfer occurs.
11. Security
We apply appropriate technical and organisational measures to protect personal data, as required by Article 32 GDPR — including encryption in transit and at rest, least-privilege access controls with audit logging, and per-merchant data isolation (a model trained for one merchant is never applied to another). Our full security posture is described on our security page (ob-session.com/security), and the detailed technical and organisational measures are set out contractually in the Data Processing Agreement.
12. Automated decision-making and profiling
The App analyses each shopper's own on-store behaviour to predict which products they are likely to be interested in, and personalizes recommendations accordingly. Under GDPR this automated analysis is a form of "profiling" (Article 4(4)) — but it is individual and behaviour-based: the App does not group shoppers into segments or audiences, and does not build demographic or cross-site profiles. This processing does not produce legal or similarly significant effects on any individual (Article 22 GDPR) — it affects only which products a shopper is shown. A shopper can limit it by declining consent, and a merchant can reduce it through the identifier tier (Section 3.1). The App does not use this processing for advertising or audience-building.
13. Compliance webhooks and data subject requests
The App subscribes to Shopify's mandatory compliance webhooks:
customers/data_request— when a shopper asks a merchant to view their data, we respond within the timeframe Shopify requires. Because the App holds no customer-identifying fields, it cannot link its pseudonymous browsing data to a named individual; where the request identifies specific orders, we return the order-level records we hold for those order IDs (which themselves contain no identifying fields).customers/redact— within the timeframe Shopify requires, we delete the order records identified in the request. All other data held by the App is pseudonymous (browsing identifiers not linked to a customer account), cannot be associated with the customer, and expires automatically under the retention schedule.shop/redact— within 30 days of app uninstallation, we delete all of the merchant's data across all systems.
Because the App processes data in pseudonymous form and cannot identify a shopper (GDPR Article 11), it is not obliged to acquire additional information solely to identify a data subject. Shoppers wishing to exercise their rights should contact the merchant (the controller); we assist the merchant in responding.
14. Your privacy rights
Which rights apply, and who can fulfil them, depends on your relationship to us. We handle data-subject requests the same way regardless of where the individual is located.
14.1 If you are a merchant — data we control
For the account-contact data we hold as a controller (Section 4.1), you have the GDPR / UK GDPR rights of access, rectification, erasure, restriction, objection, and data portability; the right to withdraw consent where we rely on it (without affecting processing carried out before withdrawal); and the right to lodge a complaint with a supervisory authority (in Cyprus, the Office of the Commissioner for Personal Data Protection). To exercise these, contact legal@ob-session.com; we respond within the period required by applicable law (for GDPR, within one month).
14.2 If you are a shopper — data we process for a merchant
Here we are a processor, so you exercise your rights with the merchant (the controller), and we assist them. Note, however, that we hold this data only in pseudonymous form and cannot identify you (GDPR Article 11): we hold no name, email, or account link, so we generally cannot locate "your" browsing data to provide or delete it on request, and we are not required to acquire additional data in order to do so. That data instead expires automatically under our retention schedule (Section 8). The only records we can locate for a specific person are order-level records, using the order IDs Shopify provides with a deletion request (Section 13) — and those hold no identifying fields.
14.3 United States (California and other states)
For shopper data we act as a service provider to the merchant, and we do not "sell" or "share" personal information as those terms are defined under the CCPA/CPRA and comparable state laws. Where state privacy laws apply (including California, Virginia, Colorado, Connecticut, Utah, and others as enacted), residents have rights to know, access, delete, correct, and opt out of sale/sharing and targeted advertising — none of which we perform. The categories we process, our purposes, and our retention are in Sections 4, 5 and 8.
14.4 Other jurisdictions
Where other data protection laws apply (for example LGPD in Brazil, PIPEDA in Canada, or the Australian Privacy Principles), we honour the equivalent rights and support the merchant's compliance.
15. Children
The App is a business-to-business service and is not directed at children. We do not knowingly process children's personal data. The age of digital consent varies by country (for example, 14 in Cyprus, up to 16 elsewhere in the EEA, and 13 in the United States); because the App cannot determine a visitor's age, the merchant, as controller, is responsible for its store's age and consent requirements and its consent framework.
16. Changes to this policy
We may update this policy from time to time. Material changes will be communicated to merchants (for example, in the app admin or by email), and the effective date above will be updated.
17. Data Processing Agreement
A Data Processing Agreement reflecting our processor obligations — including the categories above, the merchant's chosen privacy configuration, sub-processors, international transfers, security measures, and deletion — is published at ob-session.com/legal/dpa and is incorporated into our agreement with each merchant at installation. Questions: legal@ob-session.com.
18. Relationship with Shopify
OB Session operates within Shopify's platform and privacy framework. Merchants and shoppers should also review Shopify's own Privacy Policy and GDPR resources.
19. Contact us
All privacy, data-protection, security and legal correspondence — including data subject requests, Data Processing Agreement questions, sub-processor inquiries, and vulnerability reports — should be sent to legal@ob-session.com.
OBSESSION ECOMMERCE DATA TOOLS LTD Nikola Tsadioti, Pearl Park Block 6, Apartment 115, 8035 Paphos, Cyprus Reg. no. HE 496073