Trust & Security

Last reviewed: 24 July 2026

ob.session is a behavioural recommender that runs on merchant storefronts to personalize what shoppers see. We are designed around a single principle: personalization should not require identification. We never see who your shoppers are, and we don't want to.

For shopper data we act as a processor on the merchant's behalf under GDPR; this page summarizes, in plain language, what our App Privacy Policy and Data Processing Agreement say in full. Detailed security questionnaire responses and our architecture documentation are available on request at legal@ob-session.com.


§1 · What we process on behalf of merchants

When ob.session is installed on a storefront, we process the following categories of data on the merchant's behalf:

  • Pseudonymous identifiers — random identifiers for the visitor and the session. Never linked to a customer account, scoped to a single store.
  • Interaction signals — how the shopper interacts with pages and products.
  • Content and commerce context — the products, collections, and on-storefront cart context involved, and where a recommendation appeared.
  • Navigation and traffic context — page type, navigation path, referrer, campaign parameters. URLs are recorded path-only.
  • Search signals — store search terms, used as an intent signal, never to identify a shopper.
  • Device and locale characteristics — basic properties of the shopper's device, browser, and locale.
  • Catalog data — the merchant's products, collections and variants, synced read-only from Shopify.
  • Order data — order-level records used for attribution, billing, and training the merchant's model. No customer fields (name, email, phone, address, or Shopify customer ID) are ever requested or stored.

Three properties apply across all of it:

  • Nothing is collected before consent. Collection is gated behind the shopper's consent, captured through Shopify's Customer Privacy API and the merchant's consent banner, respecting the store's regional consent configuration.
  • The merchant chooses how long a visitor is remembered. Three identifier tiers, fixed at onboarding: persistent (up to 365 days, recognizes returning visitors), session-only (~60 minutes), or per-tab (cleared when the tab closes).
  • The script stays in its lane. Our first-party storefront script operates only on permitted catalog pages and does not read account, checkout, or form-input fields.

Full category descriptions are in our Privacy Policy; field-level schemas are in the technical exhibit to our Data Processing Agreement.

§2 · What we don't process

  • No directly-identifying information. No names, email addresses, phone numbers, or postal addresses of shoppers.
  • No payment or credential data. No payment details, no account credentials. Order records hold no customer fields.
  • No device fingerprinting. No canvas signals, no audio-context probing, no font enumeration.
  • No cross-site tracking. Identifiers are scoped to ob.session and to a single store, and are never shared with third parties for tracking.
  • No cross-merchant data sharing. No merchant's catalog, products, orders, or shopper data is ever shared with, or made visible to, another merchant.
  • No sale or sharing of data for third-party advertising. We do not sell, rent, or trade merchant or shopper data.
  • No IP-based shopper profiling. We do not log shopper IP addresses to identify or profile shoppers. Transient infrastructure-level access logs may contain IPs for operational and security purposes and are retained for no longer than 30 days.
  • No segments or audiences. Personalization is based on each shopper's own on-store behaviour; we do not group shoppers into segments, build demographic profiles, or perform any processing with legal or similarly significant effects (Article 22 GDPR).

§3 · Where data lives

InfrastructureAmazon Web Services — our sole sub-processor; all processing runs on AWS-native services
Default regionUnited States (us-east-1)
Alternative residencyOther regions, including the EU, available on request
Encryption in transitTLS on all public endpoints and the event pipeline
Encryption at restAES-256 for databases, storage and backups

§4 · International transfers

ob.session is an EU company (Cyprus) and processes personal data within the EEA and on AWS. Engaging us is not itself a restricted international transfer. Where data is processed in our default US region, the transfer from us to AWS in the United States relies on AWS's certification under the EU-US Data Privacy Framework (with the UK Extension for UK data) and/or the EU Standard Contractual Clauses in our agreement with AWS. Where a merchant opts for EU data residency, no such transfer occurs.

§5 · Per-merchant data isolation

Each merchant's data is processed in isolation:

  • All data is keyed by store; a shop-level purge deletes across all tables.
  • The recommendation model trained for one merchant is never shared with, or applied to, another merchant, and is deleted on uninstall or on the merchant's request.
  • One merchant's catalog, products, orders, and shopper data are never shared with, or made visible to, other merchants.
  • Identifiers are host-only and scoped to a single store — they never cross stores, and are never shared with third parties.

This is an architectural commitment, not a policy preference — the model serving each merchant is built for that merchant's store alone.

§6 · Security measures

The technical and organisational measures we commit to contractually (GDPR Art. 32, DPA Annex 2):

  • Consent gating — no data collected before the shopper grants consent via Shopify's Customer Privacy API.
  • Pseudonymisation and minimisation by design — randomly generated identifiers; no customer-identifying fields requested; order queries restricted to financial and attribution fields.
  • Encryption — TLS in transit; AES-256 at rest.
  • Least-privilege access — restricted to personnel who require it; secrets in a managed secrets store; access events logged.
  • Tenant isolation — see §5.
  • Fail-safe by design — if a recommendation cannot be served within the time limit, the merchant's default content is served, so a service interruption cannot break a page or checkout.
  • Operational security — environment separation between development and production; dependency management and patching.
  • Retention enforcement — deletion on a defined schedule (§7).
  • Breach management — procedures to detect, investigate, mitigate and notify (§10).

§7 · Retention and deletion

Shopper data is retained only as long as needed for the configured purpose; stricter privacy tiers carry shorter retention. Representative periods:

DataRetention
Recommendation data keyed to pseudonymous identifiersFollows the identifier tier: up to 365 days (Tier 1), session-scoped (Tier 2), per-tab (Tier 3)
Behavioral event data and A/B measurementsUp to 12 months (rolling)
Order-level records (billing/attribution; no customer fields)Up to 24 months, or earlier on a customers/redact request
On-device identifiersPer the identifier tier
Infrastructure access logs (may contain IPs)Up to 30 days
Catalog/config and model artefactsWhile the App is installed; deleted on uninstall

On uninstall, all of a merchant's data is deleted within 30 days following Shopify's shop/redact request. We honour Shopify's customers/data_request and customers/redact compliance webhooks. Aggregated or anonymised data that can no longer be linked to any device or shopper is not personal data and may be retained.

Merchants may request export or deletion of their data at any time at legal@ob-session.com.

§8 · Sub-processors

We rely on a single sub-processor:

Sub-processorPurposeLocation
Amazon Web ServicesAll cloud infrastructureUnited States (default us-east-1); other regions, including the EU, on request

Shopify is the platform on which the App runs and is an independent party with its own agreement with the merchant — not our sub-processor. Merchants receive advance notice of sub-processor changes, with an opportunity to object, under the Data Processing Agreement.

§9 · Compliance posture

Operating entityOBSESSION ECOMMERCE DATA TOOLS LTD, registered in Cyprus (Reg. no. HE 496073)
Supervisory authorityOffice of the Commissioner for Personal Data Protection (Cyprus)
GDPR roleProcessor for shopper data (Art. 28 DPA, entered into at install); controller only for merchant account contacts
International transfersSee §4 — AWS Data Privacy Framework certification and/or Standard Contractual Clauses with AWS
US state privacy lawsWe act as a service provider; we do not sell or share personal information (CCPA/CPRA)
Automated decision-makingNone with legal or similarly significant effects (Art. 22 GDPR)
SOC 2 Type II / ISO 27001 / other formal attestationsNot currently certified; our infrastructure runs entirely on AWS, which maintains its own certifications. We are happy to discuss our controls on request.
Data Processing AgreementPublished at ob-session.com/legal/dpa; questions to legal@ob-session.com

§10 · Vulnerability disclosure and incident response

Reporting a vulnerability

Security researchers may report vulnerabilities to legal@ob-session.com. We commit to:

  • Acknowledging your report within 5 business days.
  • Investigating in good faith and keeping you informed of remediation progress.
  • Treating good-faith security research as authorised and not subject to legal action — provided you have not accessed data beyond what is necessary to demonstrate the vulnerability, have not disrupted service, and have given us reasonable opportunity to remediate before any public disclosure.

Personal data breaches

For shopper data we process on a merchant's behalf, we notify the affected merchant without undue delay, and no later than 72 hours after becoming aware of a personal data breach, with the information the merchant needs for its own GDPR Article 33/34 notifications, and we cooperate with the merchant's response. For the limited data we hold as a controller (merchant account contacts), we notify the supervisory authority and affected individuals as Articles 33/34 require.

§11 · Contact

One address covers all of it — security questionnaires, vendor risk reviews, vulnerability reports, sub-processor inquiries, data subject requests, privacy questions, and Data Processing Agreement and legal correspondence: legal@ob-session.com.

OBSESSION ECOMMERCE DATA TOOLS LTD
Nikola Tsadioti, Pearl Park Block 6, Apartment 115
8035 Paphos
Cyprus
Reg. no. HE 496073