Privacy
In effect 25 August 2026
JourneyLens is an app for Shopify stores. It records what visitors do on a merchant’s storefront so the merchant can see why people leave without buying. This page explains exactly what it collects, what it deliberately does not, how long anything is kept and who else sees it.
JourneyLens is operated by the developer of JourneyLens, contactable at journeylensapp@gmail.com.
Who this covers
Two different people. Merchants, who install JourneyLens on their Shopify store, and visitors to those stores, whose behaviour the app records on the merchant’s behalf.
For visitor data the merchant is the controller and JourneyLens is the processor: we hold it only to show it back to that merchant, and we act on their instructions. For the merchant’s own account, session and support data we are the controller.
What the pixel collects from store visitors
JourneyLens installs a Shopify web pixel that runs in strict mode. Strict mode is what makes the rest of this section possible: Shopify removes names, email addresses, phone numbers and precise street addresses from every event before it reaches us. We never receive them and cannot recover them.
For each event the pixel sends us:
- An event id and a sequence number.
- The store’s domain.
- A visitor id supplied by Shopify. It identifies a browser so that separate actions can be joined into one visit. It is not a name and cannot be resolved to a person by us.
- The name of the event, such as viewing a product or starting checkout.
- When it happened.
- The page address it happened on, including anything in the query string, which on a search results page can include what the visitor typed.
- The event’s own details as Shopify supplies them after redaction: product titles, handles, prices, cart contents, checkout totals and currency, and the text of any error the checkout showed. Where a checkout address is present this can include the city, province and country, though never the street address or postal code.
- On a completed order, the order id. This is the only value we hold that a merchant can trace back to a named customer, using their own Shopify admin.
The pixel declares a single purpose, analytics, and explicitly declares that it does not sell or share data. Shopify only loads it for visitors whose consent covers that purpose. Merchants remain responsible for their own storefront consent banner and privacy notice.
What we read from the Shopify Admin API
JourneyLens requests three permissions and no others:
- Permission to create and update its own web pixel.
- Permission to receive the customer events described above.
- Permission to read products, used only when a merchant runs a store review, and only for the handful of products their own visitors already abandoned. We never read the whole catalogue.
We also read a small set of store settings at review time: currency, time zone, tax settings, how many countries the store ships to, and which accelerated checkout methods are switched on.
We do not request access to your orders or your customer records, and we cannot read them. That is a deliberate limit.
What we collect from merchants
- A Shopify session record, which includes the store domain, an access token, and the first name, last name and email address of the staff member Shopify supplies with it.
- Any message you send us for support.
- Ordinary server logs, which may include IP addresses, kept for operating and securing the service.
The store review, and Anthropic
JourneyLens includes an optional store review. It runs only when a merchant presses the button, at most once a day. When it runs, we send a summary to Anthropic PBC in the United States, which operates the Claude model that writes the review.
What is sent:
- Counts: how many visits there were, how many ended in a purchase, how many stopped at each stage, how many hit each type of checkout error.
- The store settings listed above, and the titles, handles and description text of the products visitors abandoned.
What is not sent:
- No visitor ids, and nothing identifying any individual.
- No orders and no customer records.
- No monetary amounts. They are withheld from the model on purpose.
Anthropic acts as our processor. Under its commercial terms, inputs and outputs sent through its API are not used to train its models. If you would rather this never ran for your store, simply do not press the button; nothing else in JourneyLens uses it.
Who else we use
- Railway: hosting for the application.
- Supabase: the database, hosted in the Asia Pacific (Seoul) region.
- Anthropic PBC (United States): the store review only, as described above.
Where data moves between countries, it does so under the standard contractual clauses our providers offer. We will tell merchants before adding another processor.
What we do not do
- We do not sell or share personal information.
- We do not use it for advertising, and we do not build profiles.
- We do not compare one store against another, and we never show one merchant’s data to another.
- We do not use any of it to train or fine-tune a machine learning model, our own or anyone else’s.
How long we keep things
Not one period for everything, because that would not be true:
- Visitor events and the visit summaries built from them is deleted automatically 90 days after they happened.
- Store reviews: kept until you uninstall, so you can read the last one.
- Session records: kept until you uninstall.
- Server logs: kept for a short operational period by our hosting provider.
When you uninstall JourneyLens, every event, visit summary and store review for your shop is deleted, and so is your session. Shopify also sends us a shop redaction request 48 hours later, and we run the same deletion again as a backstop.
Rights, requests and deletion
Depending on where you live you may have the right to see what we hold about you, correct it, delete it, or object to how it is used. Write to journeylensapp@gmail.com and we will answer within 30 days.
For store visitors, requests go through the merchant, because they are the controller and the only party who can identify the person. Shopify passes those requests to us automatically:
- A customer data request: we assemble every visit record connected to the orders named in the request. Email us and we will send it to the merchant so they can forward it.
- A customer redaction request: we delete every event and visit summary connected to the orders named, without being asked twice.
- A shop redaction request: we delete everything for that store.
Security
Data is encrypted in transit. Each store’s data is separated by its shop domain and is only ever served to that store’s authenticated admin session. Access tokens are stored in the database and never exposed to the browser. If we ever suffer a breach affecting merchant data we will notify Shopify and affected merchants without undue delay.
Children
JourneyLens is a business tool and is not directed at children. We do not knowingly collect anything from a child.
Automated decisions
The store review is written by a language model, but it makes no decision about any individual. It reads counts and store settings and writes advice for the merchant, who decides what to do.
Changes
If this policy changes we will update the date at the top, and for anything material we will tell merchants inside the app before it takes effect.