Privacy policy
Last updated 25 July 2026.
Appal: A/B Testing & CRO ("Appal", "we") is built and operated by OkayScale ApS, Denmark. This policy explains what the app stores when a merchant installs it on a Shopify store, why we store it, and how it gets deleted. Appal is free and we do not sell, rent or share data with advertisers or data brokers.
What the app reads from Shopify
Appal asks for two access scopes and nothing else:
- read_themes, to list the JSON templates in your live theme so you can pick which page to test and which alternate template is the B version. Appal does not write to your theme.
- read_orders, so the orders/create webhook can read the order total and the test assignment the storefront left on the cart. That is how a sale gets counted for the right version.
What we store
- Store record. Your myshopify.com domain and the offline access token Shopify issues at install. The token is required to call the Admin API on your behalf.
- Your test configuration. Test names, hypotheses, template names, traffic splits, goals, audience rules and any custom CSS or JavaScript you enter.
- Aggregate test events. For each visit that enters a test we store the test id, the version shown, a random visitor id generated in the browser, whether the device was mobile or desktop, and the traffic source (for example "google" or "direct").
- Attributed orders. When an order comes from a visitor in a test we store the Shopify order id, the order total, and which version they saw.
What we never store
Appal does not store customer names, email addresses, phone numbers, shipping or billing addresses, IP addresses, or any payment information. The random visitor id is generated in the shopper's browser, is not linked to a Shopify customer account, and cannot be used to identify a person.
What runs on your storefront
The theme app extension writes one first-party localStorage entry holding the version each visitor was assigned, so the same shopper keeps seeing the same version. It also writes a cart attribute with the same assignment, which is what lets the order webhook attribute the sale. No third-party cookies, no cross-site tracking, no external scripts.
Sub-processors
- Railway (application hosting and PostgreSQL database), servers in the United States.
- Shopify, as the source of the data and the platform the app runs inside.
Deletion and retention
Data is kept while the app is installed so historical test results stay available. When you uninstall, Shopify sends the app/uninstalled webhook and we delete the stored access token immediately. Shopify then sends shop/redact 48 hours later, and we erase every test, event and session belonging to the store.
We also answer the customer privacy webhooks. On customers/data_request we report the attributed-order rows we hold for the requested orders. On customers/redact we delete those rows. You can request erasure at any time by emailing us.
Your rights
Under GDPR you can ask for a copy of the data we hold about your store, ask us to correct it, or ask us to delete it. Write to silas@okayscale.dk and we will answer within 30 days.
Contact
OkayScale ApS, CVR 43937790, D Lauritzens Vej 12, 6700 Esbjerg, Denmark. Email silas@okayscale.dk.