ob.session is a behavioural recommender that runs on merchant storefronts to personalize what shoppers see. We are designed around a single principle: personalization should not require identification. We never see who your shoppers are, and we don't want to.
For shopper data we act as a processor on the merchant's behalf under GDPR; this page summarizes, in plain language, what our App Privacy Policy and Data Processing Agreement say in full. Detailed security questionnaire responses and our architecture documentation are available on request at legal@ob-session.com.
§1 · What we process on behalf of merchants
When ob.session is installed on a storefront, we process the following categories of data on the merchant's behalf:
- Pseudonymous identifiers — random identifiers for the visitor and the session. Never linked to a customer account, scoped to a single store.
- Interaction signals — how the shopper interacts with pages and products.
- Content and commerce context — the products, collections, and on-storefront cart context involved, and where a recommendation appeared.
- Navigation and traffic context — page type, navigation path, referrer, campaign parameters. URLs are recorded path-only.
- Search signals — store search terms, used as an intent signal, never to identify a shopper.
- Device and locale characteristics — basic properties of the shopper's device, browser, and locale.
- Catalog data — the merchant's products, collections and variants, synced read-only from Shopify.
- Order data — order-level records used for attribution, billing, and training the merchant's model. No customer fields (name, email, phone, address, or Shopify customer ID) are ever requested or stored.
Three properties apply across all of it:
- Nothing is collected before consent. Collection is gated behind the shopper's consent, captured through Shopify's Customer Privacy API and the merchant's consent banner, respecting the store's regional consent configuration.
- The merchant chooses how long a visitor is remembered. Three identifier tiers, fixed at onboarding: persistent (up to 365 days, recognizes returning visitors), session-only (~60 minutes), or per-tab (cleared when the tab closes).
- The script stays in its lane. Our first-party storefront script operates only on permitted catalog pages and does not read account, checkout, or form-input fields.
Full category descriptions are in our Privacy Policy; field-level schemas are in the technical exhibit to our Data Processing Agreement.
§2 · What we don't process
- No directly-identifying information. No names, email addresses, phone numbers, or postal addresses of shoppers.
- No payment or credential data. No payment details, no account credentials. Order records hold no customer fields.
- No device fingerprinting. No canvas signals, no audio-context probing, no font enumeration.
- No cross-site tracking. Identifiers are scoped to ob.session and to a single store, and are never shared with third parties for tracking.
- No cross-merchant data sharing. No merchant's catalog, products, orders, or shopper data is ever shared with, or made visible to, another merchant.
- No sale or sharing of data for third-party advertising. We do not sell, rent, or trade merchant or shopper data.
- No IP-based shopper profiling. We do not log shopper IP addresses to identify or profile shoppers. Transient infrastructure-level access logs may contain IPs for operational and security purposes and are retained for no longer than 30 days.
- No segments or audiences. Personalization is based on each shopper's own on-store behaviour; we do not group shoppers into segments, build demographic profiles, or perform any processing with legal or similarly significant effects (Article 22 GDPR).
§3 · Where data lives
| Infrastructure | Amazon Web Services — our sole sub-processor; all processing runs on AWS-native services |
| Default region | United States (us-east-1) |
| Alternative residency | Other regions, including the EU, available on request |
| Encryption in transit | TLS on all public endpoints and the event pipeline |
| Encryption at rest | AES-256 for databases, storage and backups |
§4 · International transfers
ob.session is an EU company (Cyprus) and processes personal data within the EEA and on AWS. Engaging us is not itself a restricted international transfer. Where data is processed in our default US region, the transfer from us to AWS in the United States relies on AWS's certification under the EU-US Data Privacy Framework (with the UK Extension for UK data) and/or the EU Standard Contractual Clauses in our agreement with AWS. Where a merchant opts for EU data residency, no such transfer occurs.
§5 · Per-merchant data isolation
Each merchant's data is processed in isolation:
- All data is keyed by store; a shop-level purge deletes across all tables.
- The recommendation model trained for one merchant is never shared with, or applied to, another merchant, and is deleted on uninstall or on the merchant's request.
- One merchant's catalog, products, orders, and shopper data are never shared with, or made visible to, other merchants.
- Identifiers are host-only and scoped to a single store — they never cross stores, and are never shared with third parties.
This is an architectural commitment, not a policy preference — the model serving each merchant is built for that merchant's store alone.
§6 · Security measures
The technical and organisational measures we commit to contractually (GDPR Art. 32, DPA Annex 2):
- Consent gating — no data collected before the shopper grants consent via Shopify's Customer Privacy API.
- Pseudonymisation and minimisation by design — randomly generated identifiers; no customer-identifying fields requested; order queries restricted to financial and attribution fields.
- Encryption — TLS in transit; AES-256 at rest.
- Least-privilege access — restricted to personnel who require it; secrets in a managed secrets store; access events logged.
- Tenant isolation — see §5.
- Fail-safe by design — if a recommendation cannot be served within the time limit, the merchant's default content is served, so a service interruption cannot break a page or checkout.
- Operational security — environment separation between development and production; dependency management and patching.
- Retention enforcement — deletion on a defined schedule (§7).
- Breach management — procedures to detect, investigate, mitigate and notify (§10).
§7 · Retention and deletion
Shopper data is retained only as long as needed for the configured purpose; stricter privacy tiers carry shorter retention. Representative periods:
| Data | Retention |
|---|---|
| Recommendation data keyed to pseudonymous identifiers | Follows the identifier tier: up to 365 days (Tier 1), session-scoped (Tier 2), per-tab (Tier 3) |
| Behavioral event data and A/B measurements | Up to 12 months (rolling) |
| Order-level records (billing/attribution; no customer fields) | Up to 24 months, or earlier on a customers/redact request |
| On-device identifiers | Per the identifier tier |
| Infrastructure access logs (may contain IPs) | Up to 30 days |
| Catalog/config and model artefacts | While the App is installed; deleted on uninstall |
On uninstall, all of a merchant's data is deleted within 30 days following Shopify's shop/redact request. We honour Shopify's customers/data_request and customers/redact compliance webhooks. Aggregated or anonymised data that can no longer be linked to any device or shopper is not personal data and may be retained.
Merchants may request export or deletion of their data at any time at legal@ob-session.com.
§8 · Sub-processors
We rely on a single sub-processor:
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services | All cloud infrastructure | United States (default us-east-1); other regions, including the EU, on request |
Shopify is the platform on which the App runs and is an independent party with its own agreement with the merchant — not our sub-processor. Merchants receive advance notice of sub-processor changes, with an opportunity to object, under the Data Processing Agreement.
§9 · Compliance posture
| Operating entity | OBSESSION ECOMMERCE DATA TOOLS LTD, registered in Cyprus (Reg. no. HE 496073) |
| Supervisory authority | Office of the Commissioner for Personal Data Protection (Cyprus) |
| GDPR role | Processor for shopper data (Art. 28 DPA, entered into at install); controller only for merchant account contacts |
| International transfers | See §4 — AWS Data Privacy Framework certification and/or Standard Contractual Clauses with AWS |
| US state privacy laws | We act as a service provider; we do not sell or share personal information (CCPA/CPRA) |
| Automated decision-making | None with legal or similarly significant effects (Art. 22 GDPR) |
| SOC 2 Type II / ISO 27001 / other formal attestations | Not currently certified; our infrastructure runs entirely on AWS, which maintains its own certifications. We are happy to discuss our controls on request. |
| Data Processing Agreement | Published at ob-session.com/legal/dpa; questions to legal@ob-session.com |
§10 · Vulnerability disclosure and incident response
Reporting a vulnerability
Security researchers may report vulnerabilities to legal@ob-session.com. We commit to:
- Acknowledging your report within 5 business days.
- Investigating in good faith and keeping you informed of remediation progress.
- Treating good-faith security research as authorised and not subject to legal action — provided you have not accessed data beyond what is necessary to demonstrate the vulnerability, have not disrupted service, and have given us reasonable opportunity to remediate before any public disclosure.
Personal data breaches
For shopper data we process on a merchant's behalf, we notify the affected merchant without undue delay, and no later than 72 hours after becoming aware of a personal data breach, with the information the merchant needs for its own GDPR Article 33/34 notifications, and we cooperate with the merchant's response. For the limited data we hold as a controller (merchant account contacts), we notify the supervisory authority and affected individuals as Articles 33/34 require.
§11 · Contact
One address covers all of it — security questionnaires, vendor risk reviews, vulnerability reports, sub-processor inquiries, data subject requests, privacy questions, and Data Processing Agreement and legal correspondence: legal@ob-session.com.
OBSESSION ECOMMERCE DATA TOOLS LTD
Nikola Tsadioti, Pearl Park Block 6, Apartment 115
8035 Paphos
Cyprus
Reg. no. HE 496073