Free store scan · Founding Brand Programme: 14 days free Scan your store →

Security and data

What Liftable can see, and what it can change.

The short version, for the person who has to say yes. The privacy policy and the terms say the same things at length.

The free scan

  • It needs your store address and an email. No install, no login, no card.
  • It reads only the pages any shopper can open.

What installing asks Shopify for

  • Nine permissions. Six only read: orders, products, themes, shipping settings, discounts, checkout events. Three can write, each for one thing: register Liftable’s checkout pixel, run a shipping test you have approved, run a discount test you have approved.
  • Install does not ask for permission to write to a theme, to shipping settings or to checkout.

What it can change on your store

  • Nothing, until you approve it. The agent can read the store and write down a proposal; it cannot start a test or approve its own work.
  • Liftable never edits your theme’s code, live or duplicate. A page change can only appear through Liftable’s theme app extension, which you switch on in the theme editor.
  • Shipping and discount tests run as Shopify Functions, and only once you have approved that test. Liftable does not uninstall apps.

Shopper data

  • The storefront pixel asks Shopify’s Customer Privacy API first. Until a shopper has consented to analytics it sets no cookie and sends nothing.
  • It records pages viewed, clicks, scroll depth and the names of form fields, never what was typed.
  • From an order we keep the order id, totals, discount codes, refunds and which side of a test it was on. We do not keep the customer’s name, email, phone number or address.

One store cannot see another

  • Every query is scoped to a single store by the database itself, with row-level security, not only by our code.
  • The one thing combined across stores is anonymised test effect sizes, kept only where at least five stores and ten tests contributed. A store’s owner can turn it off in Settings.

How long it is kept

  • Storefront pixel data: 90 days.
  • Order attribution records: 25 months.
  • Storefront scans, with their screenshots: 12 months.
  • A job deletes anything older, every day.

Where it is held, and who else touches it

  • Hosting on Vercel, the database on Neon. Access tokens and connector credentials are encrypted at rest with a key held outside the database.
  • The AI model is Anthropic’s. It reads your store’s own data to answer your questions and draft proposals; order data reaches it only as store totals, and data sent to it is not used to train it.
  • Sentry for error reports, Clerk for sign-in, Stripe for card billing, Resend for email, and Slack only if you connect it.

Leaving

  • Uninstalling revokes our access immediately and purges the store’s access token.
  • Shopify then sends a shop redaction, which deletes the store’s data, including the screenshots from its scans.

Certifications

  • This page claims none. If you need a security questionnaire answered, write to us and a person will answer it.

Questions about a store's data go to privacy@liftable.dev. The cookies this site and the pixel set are listed on the cookies page.

Security and data · Liftable