Privacy Policy

Last updated: July 27, 2026

What We Collect

Ferret captures anonymized behavioral events from your storefront visitors, including:

We do not collect any personally identifiable information (PII) from your visitors — no names, email addresses, physical addresses, IP addresses, or payment information.

Session Identifiers

Ferret generates a random, anonymous session identifier stored in the visitor's browser sessionStorage. This identifier expires when the browser tab closes and cannot be used to identify or track individuals. Ferret does not set cookies and does not perform cross-site tracking.

Storefront Screenshots

Ferret captures screenshots of your storefront pages (as any visitor would see them) to analyze layout and design for conversion opportunities. These screenshots show only your published store content — they never include customer data, visitor sessions, or any information about individual shoppers.

Order Data

With your authorization, Ferret reads aggregate order statistics (order counts and totals) from Shopify to estimate the revenue impact of each recommendation. Individual order details, customer names, and shipping information are never accessed or stored.

How We Use Data

Behavioral events are processed into aggregated conversion findings. Our AI generates recommendation cards with specific, actionable fixes tailored to your store's theme and traffic patterns.

Data Retention

Raw event data is automatically purged within 30 days. Only aggregated findings and generated recommendation cards are retained for your dashboard. We never store session replays or recordings of visitor activity.

Third Parties

Aggregated finding data (page URLs, behavioral patterns, and error summaries — never raw visitor events) is processed through Anthropic's Claude API to generate recommendation cards. No visitor information is sold or shared with any other third party.

Data Storage

All data is stored in Supabase (hosted on AWS infrastructure) with row-level security enabled.

GDPR and CCPA Compliance

Ferret is compliant through data minimization and automatic purging. Since we do not collect PII from visitors, there is no personal data to access, correct, or delete. If a Shopify store uninstalls Ferret, all associated data (events, findings, cards, integration credentials, and session tokens) is deleted via our GDPR webhook handlers.

Contact

For privacy questions or data requests, contact us at support@ferretcro.com.