Privacy policy
What we capture, what we deliberately do not, how long we keep it, and how to have it removed. Written to be read rather than to be skipped.
Last updated: 21 July 2026
Behaviour, not identity
- We record how shoppers interact with a storefront — scrolls, clicks, taps, navigation.
- We do not record payment details, passwords, or Shopify's hosted checkout.
- Replay retention is set by plan: 30, 90, 180 or 365 days, then it is deleted.
- We do not sell personal data or share it with advertising networks.
This summary is for orientation only. The sections below are the policy.
1. Who this covers
This policy covers DynoWeb: the Shopify app, this website, and the support we provide over email.
There are two groups of people involved and it matters which one you are. Merchants are the store owners who install the app — with respect to their own data, we are the controller. Shoppers are the visitors to a merchant's storefront — with respect to their behaviour data, the merchant is the controller and we act as a processor on that merchant's instructions.
If you are a shopper who wants data about your visit removed, the merchant whose store you visited is the right first point of contact. You can also write to us at the address at the bottom of this page and we will help route it.
2. What we collect
From merchants, to run your account: the details Shopify shares when you install an app, your store URL, your plan and billing status, and anything you choose to send us in a support email.
From storefront visits, to produce the analysis the app exists for:
- Interaction behaviour — pointer movement, scrolling, clicks and taps, and navigation between pages.
- Page and element context — which page and which element an interaction landed on.
- Technical context — device type, browser, screen size, approximate location derived from IP at country or region level, and referrer.
- Commerce context — cart and product events such as add-to-cart, so the behaviour can be read as a funnel rather than as generic page views.
Session replay is a reconstruction of a visit assembled from these events. It is not a video recording of anyone's screen and it does not access anything outside the merchant's storefront.
3. What we do not collect
- Payment card numbers, bank details or any other payment credentials.
- Passwords, or the contents of password fields.
- The contents of sensitive form inputs, which are excluded from capture.
- Anything from Shopify's hosted checkout, which is not available to apps.
- Behaviour on any site other than the storefront the app is installed on.
We do not sell personal data, and we do not share it with advertising networks or data brokers.
4. How we use it
- To produce the heatmaps, session replays, reports and suggestions the merchant installed the app to receive.
- To trigger on-site nudges the merchant has configured, and to measure whether they worked.
- To attribute the effect of an applied change against its baseline.
- To operate, secure and debug the service, including investigating support requests.
- To bill for the service through Shopify.
We do not use a merchant's storefront data to build products for anyone else, and we do not use it to identify individual shoppers by name.
5. AI processing
Some features — suggestions, reports, and the assistant and agent — use AI models to interpret behaviour data and draft proposed changes. The input to those features is behavioural and commerce data from the merchant's own store.
Proposed changes are shown for approval before anything is applied to a live storefront. The agent drafts; the merchant decides.
Where a merchant connects their store data to an external client over MCP — for example Claude, Cursor or ChatGPT — data flows to that client at the merchant's direction, and the operator of that client handles it under their own terms.
6. How long we keep it
Session replay retention is set by the merchant's plan: 30 days on Free, 90 days on Growth, 180 days on Pro and 365 days on Custom. When a recording passes its retention window it is deleted.
Aggregated and de-identified analysis — the shape of a heatmap, the outcome of a measured change — may be kept longer, because it no longer describes an individual visit.
Merchant account and billing records are kept for as long as the account exists, and afterwards only where a legal or accounting obligation requires it.
8. Your rights
Depending on where you live, you may have the right to access the personal data held about you, to have it corrected or deleted, to object to or restrict how it is processed, and to receive a copy in a portable form.
Merchants can exercise these rights by writing to us directly. Shoppers should contact the merchant whose storefront they visited, since that merchant is the controller of storefront behaviour data — we act on their instructions and will support any request they pass to us.
Merchants: uninstalling the app stops collection. If you also want the data already collected deleted rather than left to expire under the retention windows above, email us and ask.
9. Security
Data is encrypted in transit, access is limited to the people who need it to operate the service, and sensitive inputs are excluded at the point of capture rather than filtered afterwards.
No service can promise perfect security. If we become aware of a breach affecting personal data we will notify affected merchants and the relevant authorities as required.
11. Children
The service is intended for businesses. It is not directed at children, and we do not knowingly collect personal data from children.
12. Changes to this policy
If this policy changes we will update the date at the top of the page. Where a change is material we will tell merchants rather than relying on you to re-read it.
13. Contact
Questions about this policy, or a request about your data, go to help@dynoweb.app. Include your store URL if you are a merchant, or the storefront you visited if you are a shopper — it is the fastest way for us to find the right records.
Related reading: the help centre covers what is captured in practice, and pricing lists the retention window attached to each plan.

