Privacy Policy

Last updated: September 18, 2026

What data we collect

When the post-purchase survey is shown to a customer on your order confirmation (Thank you) page or Order status page, we store:

  • Your shop's myshopify.com domain
  • The Shopify order number the survey was shown on
  • Order context used for your analytics: the order total and currency, whether it was the customer's first order with your store, and the items purchased (product and variant identifiers, product title, quantity and line price)
  • For each question the customer answers, their answer: multiple-choice and multi-select selections, rating-scale scores (including NPS, CSAT and CES), and any open text, comment or "Other" text they choose to write
  • For each question the customer skips, the fact that it was skipped
  • The question's wording, type and, for rating scales, its range, as they were when the customer answered, so the response stays readable if you later edit or delete the question
  • Whether you have dismissed the response in your dashboard
  • The time the survey was shown and the time of each answer

We do not collect customer names, email addresses, shipping or billing addresses, or payment details, and we have no Admin API access to your store's order or customer records. Because open-text and comment fields accept free input, a customer could include personal information if they choose to type it; we store these responses as written, and we recommend your questions do not ask customers for sensitive details.

Information stored in the customer's browser

So that customers are not asked the same question twice, the survey on the Thank you page stores a short record in the customer's own browser (local storage). It is named with your shop's domain and the order identifier, and it lists the IDs of the questions already answered for that order. The Order status page stores nothing in the browser. This record stays on the customer's device, is never sent to us, and contains no names, contact details or answers. We do not use cookies or tracking pixels, and we do not track customers across sites. The survey can publish an event that pixels the merchant has installed may receive, as described under Shopify Flow and analytics events below.

Merchant account data

To operate your account we also store information about your shop rather than your customers: your myshopify.com domain, your store's timezone (used to report your analytics in local time), your survey configuration, and your current plan, including the subscription identifier and plan handle we retrieve from Shopify to determine whether your store is on the Free or Growth plan. We also store the access token Shopify issues for your store when you install the app, with its refresh token; the only Shopify Admin API call we make with it is sending responses to Shopify Flow. We store your store's numeric Shopify ID to look up your plan. Billing itself is handled entirely by Shopify; we never receive or store your payment details.

How we use this data

Response and order-context data is used to populate the analytics dashboard visible to the merchant who installed the app, including response breakdowns, attribution reporting ("how customers find you"), revenue attribution, and NPS, CSAT, and CES reporting. The only other use is making each response available to the merchant's own Shopify Flow workflows and store pixels, described below. We do not share, sell, or use this data for advertising, and we do not use it to train machine learning models.

Shopify Flow and analytics events

Zenith sets no cookies and ships no tracking pixel of its own. It sends nothing to Google or to any other analytics provider, and has no connection to any of them. Two features let the merchant use responses in their own tools, and neither leads anywhere unless the merchant sets it up.

Shopify Flow. When a response is stored, the app sends the response data to Shopify Flow in the merchant's store. The merchant's own workflow decides what happens to it, which can include sending it to Google Sheets, Slack, or email through Shopify's connectors, using the merchant's own accounts. If the merchant has no workflow for it, nothing happens.

Analytics event. After a response is stored, the survey publishes an event on the customer's page containing four fields: the question ID, the question text, the answer, and the order ID. It is published only when the customer has allowed analytics tracking, as reported by Shopify's customer privacy API. Any pixel the merchant has installed on their store can receive it, including a custom pixel the merchant adds to forward it to Google Analytics. Zenith does not send the event anywhere itself. If the merchant has no pixel set up to receive it, nothing happens with it.

Free-text answers and comments are never included in the event. This is deliberate: Google's policies prohibit sending Google Analytics anything it could use to identify a person, and text a customer types is where that information usually appears.

Anything a merchant's workflow or pixel sends on is held in the merchant's own accounts, under their own settings, and is not deleted when Zenith deletes its data. Both features are documented in full, including every field each one receives, on our integrations page.

Service providers

We rely on third-party infrastructure providers that process data on our behalf solely to operate the service: Railway, for application hosting and database storage, and Sentry, for error monitoring. Error reports sent to Sentry may include technical and diagnostic information, such as your shop's domain and details of the failed request, when a problem occurs. These providers are permitted to use the data only to provide their services to us.

Data retention and deletion

When the app is uninstalled, we delete all data we hold for the shop: survey responses, order context, your survey configuration, your plan record and the access token. Shopify sends a shop redaction request about 48 hours after uninstall, and we repeat the deletion then. Merchants can export their response data at any time from the dashboard.

Merchants can dismiss an individual response. A dismissed response is left out of your score and answer breakdowns and your CSV exports. Dismissing does not delete it: the response stays stored, still appears in your response list and recent responses feed marked as dismissed, and can be restored. A response that reached Shopify Flow or was published as an analytics event before it was dismissed is not recalled.

To have a customer's survey data deleted, the customer can ask the merchant to erase their data. When the merchant erases a customer's data in Shopify, Shopify sends us a customer redaction request, and we delete that customer's survey data as described below.

GDPR and data requests

We process customer data requests and erasure requests in accordance with Shopify's mandatory privacy webhooks. The data we store is linked to a Shopify order and may relate to an identifiable customer, so it can constitute personal data even though we hold no names or contact details directly. Because we hold no direct contact information and the relevant data is available to the merchant in their dashboard, customer data requests are fulfilled by the merchant as the data controller. Erasure requests reach us from Shopify when a merchant erases a customer's data from their Shopify admin. When we receive an erasure (customer redaction) request, we delete the survey responses and the associated order context for the supplied order identifiers. Shop-level redaction, triggered when the app is uninstalled, deletes all stored data for the shop.

Contact

Questions about this policy or about how we delete data can be sent to support@zenithsurvey.app. If you are a customer and want your survey data deleted, please contact the store you ordered from; if you write to us instead, we will pass your request to that store.