PickBack Privacy Policy
Pickback Privacy Policy
Effective Date: 5th October 2026
Welcome to Pickback ("Pickback", "we", "our", or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard information when you install, access, or use the Pickback Shopify application (the "App") and its related admin dashboard, onboarding, storefront journey tracking, "Continue shopping" storefront block, recommendations, analytics, and checkout web pixel (collectively, the "Services").
Pickback helps Shopify merchants let their logged-in shoppers pick up where they left off. It remembers a shopper's recent browsing context, such as the collection, filters, sort order, search, and products viewed, and shows it back to them on the storefront.
We are committed to complying with applicable privacy and data-protection laws, including, where relevant, the General Data Protection Regulation (EU) 2016/679 (GDPR), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA), the India Digital Personal Data Protection Act 2023 (DPDP Act), and other applicable laws in the regions where our Merchants operate.
If you have questions about this Privacy Policy, please contact us at apps@seventhtriangle.com.
1. Who We Are
Pickback is a Shopify application developed and maintained by Seventh Triangle Consulting. We act as a data processor when handling store and shopper information on behalf of Shopify merchants ("Merchants"). The Merchant remains the data controller for their shoppers' ("Customers") personal data.
2. Information We Collect
| Category | Examples | Source | Purpose |
|---|---|---|---|
| Merchant Account Data | Store domain, installation date, Shopify session data, access and refresh tokens, granted scopes, plan and subscription status | Directly from Shopify through OAuth, app sessions, and Shopify APIs | • Authenticate Merchant access • Operate the App • Check the Merchant's plan |
| Customer Journey Data | Shopify customer ID, collections viewed, applied filters, sort order, page number, search queries and result counts, products viewed (handle, ID, title, variant, product type, vendor), timestamps, and a random per-tab session ID | Collected on the Merchant's storefront by the App's theme extension, only for logged-in Customers who have given consent | • Save and restore a Customer's browsing context • Show the "Continue shopping" block and recommendations |
| Guest Browsing Data | Recent collections, filters, and viewed products of a shopper who is not logged in | Kept only in the shopper's own browser; uploaded to the App when the shopper logs in | • Carry the shopper's journey over to their Customer account after login |
| "Continue shopping" Block Activity | Customer ID, number of saved journeys shown, and which journey was clicked | The App's "Continue shopping" block on the Merchant's storefront | • Measure how often Customers resume a journey |
| Purchase Data | Checkout token, order ID, Customer ID, purchased product IDs, handles, and variant IDs, and order processed time | The App's web pixel on checkout completion, then Shopify Admin APIs | • Remove purchased products from saved journeys • Measure resume and conversion rates |
| Consent Records | Customer ID, consent status (granted or denied), Shopify consent ID, IP address, and time of update | Shopify Customer Privacy API on the storefront and the request to our servers | • Record each Customer's privacy choice • Delete journey data when consent is denied |
| Store Product Data | Product handles, titles, product types, and variant information | Shopify Admin APIs | • Build "Recommended for you" suggestions |
| App Settings & Onboarding Data | Journey expiry period (7 to 90 days), conversion threshold for the view-to-purchase report, banner heading, icon, and accent colour, app embed and block status, onboarding completion | Provided by Merchants through the App dashboard and generated during setup | • Save Merchant preferences • Support onboarding • Control storefront behaviour |
| Analytics & Operational Logs | Aggregated reports (most-used filters, searches that did not lead to a product view including the search text, products viewed often but rarely bought, resume rate), server logs containing shop domains, Customer IDs, and product IDs, and errors with timestamps | Generated by the App from journey and purchase events and server activity | • Show analytics to Merchants • Troubleshoot issues |
Pickback does not collect Customer names, email addresses, phone numbers, postal addresses, or payment card data. Payment information is handled by Shopify's own checkout and billing infrastructure.
3. Cookies, Session Storage, Local Storage, and Storefront Tracking
On the storefront. Pickback does not set cookies on the Merchant's storefront. It uses the shopper's browser storage to:
- Keep a short buffer of the current journey and up to 5 guest journeys in local storage.
- Keep a random session ID, sync flags, and a flag that the "Continue shopping" block was displayed in session storage, cleared when the browser tab closes.
The App's journey-tracking script checks the shopper's choice through Shopify's Customer Privacy API before it stores or sends browsing data. If consent is not given, or is withdrawn, it does not track browsing and clears its own browser storage.
The "Continue shopping" block appears only to logged-in Customers who already have saved journeys. It reports when it is shown and clicked, as described in section 2.
Pickback's checkout web pixel runs in Shopify's sandbox under Shopify's customer privacy settings. It sends only the store domain and checkout token.
In the App dashboard. We and Shopify use session tokens and the cookies needed to install the App and authenticate Merchants.
These technologies are used only to operate the App. They are not used for advertising or cross-site tracking.
4. Legal Bases for Processing
Where GDPR or similar laws apply, we rely on the following legal bases:
- Contractual Necessity - to provide the App and Services requested by Merchants.
- Consent - for storefront journey tracking, which runs only after the Customer has given consent through the Merchant's consent banner and Shopify's Customer Privacy API. The Merchant is responsible for collecting that consent.
- Legitimate Interests - to secure, monitor, and support the App and to prevent misuse.
- Legal Obligation - to comply with privacy laws and Shopify's mandatory privacy webhooks.
5. How We Use Information
- To install, authenticate, operate, and maintain the App.
- To save a logged-in Customer's recent browsing journeys and show them back in the "Continue shopping" storefront block.
- To suggest products of the same product type in "Recommended for you".
- To remove products a Customer has purchased from their saved journeys.
- To show Merchants aggregated analytics, such as most-used filters, searches that did not lead to a product view, and resume rate.
- To save Merchant settings such as journey expiry, conversion threshold, and banner appearance.
- To record Customer consent choices and delete journey data when consent is denied.
- To investigate bugs and failed requests, and to limit excessive requests.
- To comply with legal obligations and Shopify platform requirements.
We do not use Customer data for advertising, profiling across stores, or any purpose other than providing the Services to the Merchant whose store it came from.
6. How We Share Information
We do not sell or rent personal data, and we do not share it for cross-context behavioural advertising. We share information only as needed to run the App:
- With Shopify for authentication, API access, storing journey data in the Merchant's customer metafields, webhook delivery, and billing.
- With the Merchant whose store the data came from, through the App dashboard and the storefront block.
- With our hosting providers, such as Amazon Web Services (AWS), which run the App's servers and store its data.
- For Legal Reasons if disclosure is required by law, regulation, or legal process.
7. International Data Transfers
Our App servers are hosted on Amazon Web Services (AWS) in the AP-South-1 (Mumbai) region. Journey data shown on the storefront is also stored in the Merchant's Shopify store, on Shopify's infrastructure. Depending on the Merchant's and Customer's location, information may be transferred to and processed in countries outside their own jurisdiction.
8. Data Subject and Consumer Rights
Depending on applicable law, individuals may have rights to access, correct, delete, restrict, or object to certain processing of personal data, and to withdraw consent.
- Withdrawing consent: Customers can withdraw consent at any time through the Merchant's cookie or privacy banner. Pickback then stops tracking and deletes that Customer's saved journeys and journey events.
- Deletion requests: when a Merchant or Shopify sends a customer redaction request, we delete that Customer's saved journeys, journey events, and consent records.
- Other requests: Customers should contact the Merchant, as the data controller. Merchants can contact apps@seventhtriangle.com with any privacy request.
9. Security Measures
- HTTPS/TLS for data in transit.
- Signature verification of every storefront request through Shopify's App Proxy, and of every webhook from Shopify.
- Customer identity taken from Shopify's signed logged-in customer ID, not from data sent by the browser.
- Rate limiting on storefront and pixel endpoints.
- Shopify authentication flows and session tokens for the App dashboard.
No method of transmission or storage is completely secure, but we take reasonable steps to protect information handled through the App.
10. Data Retention
| Data | Retention |
|---|---|
| Saved journeys shown to Customers | Expire after the period the Merchant sets (7 to 90 days, default 30) |
| Journey and purchase events | Deleted automatically after 90 days |
| Purchased-product records used to update journeys | Up to 90 days, or the latest 200 entries |
| Consent records, analytics reports, and settings | While the App is installed |
| Shopify session data | Until the App is uninstalled |
When a Merchant uninstalls the App, or Shopify sends a shop redaction request, we delete the store's data from our database. Data stored in the Merchant's own Shopify customer metafields stays in their store under their control.
11. Children's Privacy
The App is intended for businesses and is not directed to children. We do not knowingly collect personal information from children.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will revise the effective date above.
13. Contact Us
If you have questions, requests, or concerns about this Privacy Policy, please contact:
Privacy Team
Pickback / Seventh Triangle Consulting
Second Floor, The Berry Coworks, Plot No 15, Sector-142, Noida, Uttar Pradesh - 201304
Email: apps@seventhtriangle.com
© 2026 Seventh Triangle Consulting. All rights reserved.