S Smart Funnels
Home
LEGAL

Privacy policy

Last updated: 30 September 2026

Who we are

Smart Funnels is operated by IMR Ventures FZE, Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates. This policy explains what the Smart Funnels Shopify app (the app) collects on a store, where it sends it, and what we do with it. For questions or requests, write to [email protected].

Our role

A store (the merchant) installs the app to connect its Shopify store to its Smart Funnels account. For the data we collect through a store, we act on behalf of that merchant.

1. Which visitors the app covers

The app records visits and orders only for visitors who carry a Smart Funnels ID. There are two kinds:

  • a click ID, which a visitor gets by arriving through a Smart Funnels link (the link adds utm_fo_click_id to the page address);
  • a Page Script ID, which a visitor gets from the Smart Funnels Page Script when they arrive on a page where Smart Funnels tests versions of the store's own page.

There are two exceptions, both described in section 3: the Page Script's short diagnostic reports, sent for every visitor on a tested page who has not refused analytics, and the setup-check links our team opens. Apart from those, the app sends us no data about visitors without a Smart Funnels ID, and stores nothing about them in their browser.

2. What the pixel sends

The app adds a Shopify web pixel to the store. Shopify runs it only when the visitor has allowed analytics cookies, where the store's cookie banner asks for that. For each of these steps by a visitor with a Smart Funnels ID, the pixel sends us one record: page viewed, product viewed, added to cart, cart viewed, checkout started. Each record holds:

  • the visitor's click ID or Page Script ID;
  • the store's myshopify.com address;
  • the address of the page, including anything after the ?;
  • the type of step, its time, and Shopify's number for the event;
  • the products involved: product ID (for checkout, the product variant ID), name, price and quantity;
  • for the cart and checkout, the total and the currency;
  • the browser's user agent, a short text that names the browser, its version and the operating system.

The pixel does not send a purchase record; orders reach us once, as described in section 5. The pixel sends its records to the app's own server, which passes them on to Smart Funnels. The app's server passes on only the fields above and never the visitor's IP address.

3. What the Page Script sends

The app's theme embed adds the Smart Funnels Page Script to the store's pages. It does something only on stores where Smart Funnels has set up a test of the store's own pages. On the tested page, it shows each new visitor one version of the page, chosen at random, and records the visit. It does nothing for known bots, for visitors who arrived through a Smart Funnels link, and on cart, checkout and account pages.

The Page Script asks Shopify's consent tool whether the visitor has allowed analytics. If the visitor has refused, it shows the original page and records nothing (setup-check links, below, are the exception). If the page has no answer from Shopify's consent tool, the Page Script runs. On the store's other pages, it may finish two steps it started on the tested page, without asking the consent tool again: the country lookup (section 6) and saving the Page Script ID on the cart (section 4). Setup-check links are special addresses our team opens to check that a store's test works; on such a page the Page Script does not ask the consent tool, saves a Page Script ID in the browser and on the cart, and sends us the visitor ID if the browser holds one and the screen width, together with the Page Script ID and which page elements it found or, when the check cannot run, the page address.

When it records a visit, the Page Script sends our server, directly from the visitor's browser:

  • the visitor's Page Script ID and a random visitor ID;
  • the store's Page Script key, a code that tells Smart Funnels which store the page belongs to;
  • which version of the page was shown, the version of the store's test settings, and short codes that describe the page elements being tested (not the visitor);
  • anything after the ? in the page address, such as ad campaign tags;
  • the visitor's time zone;
  • how long the page took to decide.

When the test changes elements of the page, the Page Script also sends a short diagnostic report on every load of the tested page by a visitor who has not refused analytics, including reloads: the store's Page Script key, a Page Script ID, the visitor ID if the browser holds one, and which of the page elements it found. When it cannot change the page (an element is missing, or deciding takes too long), it sends a similar report.

Like every web server, ours also receives the visitor's IP address and user agent with each request. With a recorded visit, we keep the approximate location (country, region and city) that our network provider Cloudflare works out from the IP address, and the browser's name, the operating system and its version, the device type and the device model, read from the user agent. We do not keep the IP address or the full user agent with the visit, and we keep the visitor ID only in a scrambled (hashed) form. For the report sent on every load, we keep a scrambled form of the visitor ID and of the IP address, for 7 days. For a report that the page could not be changed, we keep a scrambled form of the visitor ID, as long as the visit records in section 9. Our server also uses the IP address to limit how many requests one address may send per minute; these counters expire after 60 seconds, and an address that goes over the limit is written, in full, to our server's log.

4. What the app stores in the visitor's browser and cart

Cookies, local storage and session storage are small pieces of text a website keeps in the visitor's browser; session storage is emptied when the visit ends.

Written by the pixel, only for a visitor who arrives through a Smart Funnels link:

  • the _foCId cookie: the click ID, kept for 7 days or 90 days (section 6);
  • the _foVistId session storage entry: the click ID, for the current visit only.

Written by the Page Script, only when it records a visit or on a setup-check link:

  • the _foCId cookie and local storage entry: the Page Script ID, kept for 7 days, with its time in _foCIdAt;
  • the _foVId cookie and local storage entry: the random visitor ID, kept for 7 days or 90 days (section 6), with its time and lifetime in _foVIdAt and _foVIdMaxAge;
  • the _foPsPick local storage entry: which version of each tested page the visitor was shown, kept for 7 days or 90 days (section 6);
  • the _foPsCart local storage entry: the Page Script ID waiting to be saved on the cart, removed once it is saved.

The Page Script may also keep a copy of the store's test settings in local storage (_foPsSettings), which holds nothing about the visitor. Local storage entries are not deleted when their time is up; the Page Script stops using them and overwrites them later.

Written by the app's theme embed, only for a visitor with a Smart Funnels ID:

  • the cart attribute foCId: the visitor's click ID or Page Script ID, so it is saved with the order;
  • the _foCartId and _foCartIdAt cookies: which ID the cart holds and when the browser first got that ID, kept for 7 days.

The theme embed does not ask the store's cookie banner before writing these.

5. What the app collects from orders

When an order is placed, Shopify notifies the app. The app asks Shopify for these order fields only: the order ID and number, the total and currency, the items (product ID, name, price, quantity), the order's cart attributes and the address the buyer landed on. It does not request the customer's name, email, phone number or addresses. Cart attributes can hold text that other apps on the store put there; from them and from the landing address, the app reads only the Smart Funnels ID. If the order carries a Smart Funnels click ID or Page Script ID, the app sends us: the store's myshopify.com address, the order ID and number, that ID, the total and currency, and the items. Orders without one are not sent to us.

6. Visitor country and cookie lifetime

To choose how long the IDs in section 4 are kept, the visitor's browser asks ipwho.is, an outside service, which country the visitor is in. The pixel does this when a visitor arrives through a Smart Funnels link, and the Page Script does it when it first shows a visitor a version of a tested page. This shares the visitor's IP address with ipwho.is, whose own privacy policy applies. The answer stays in the browser and is not sent to us. Visitors in the European Union, Iceland, Liechtenstein, Norway, the United Kingdom, Switzerland or Quebec, and visitors whose country is unknown, get 7 days; everyone else gets 90 days.

7. What we use the data for

We use this data to match each visit and order to the Smart Funnels link or page test that led to it, to report the results to the merchant, to train the models that choose which version of a page to show, and to check that tracking works. We do not use it to build advertising profiles, and we do not sell or rent it. We make no decisions about visitors that have legal or similarly significant effects.

When a merchant installs the app, Shopify gives us the store's address and an access key, which we keep while the app is installed and delete when it is uninstalled. We use the access key only to run the app for that store: to turn on the pixel, to keep the Page Script up to date, and to give Smart Funnels a list of the store's published products, collections and pages (titles and addresses) for setting up tests.

8. Who else processes the data

These providers store or process the data for us:

  • Hetzner Online GmbH hosts, in Germany, our servers, the server that trains the models from the copy described below, and a copy of our backups.
  • Cloudflare, Inc. carries traffic to our servers and stores backups.
  • Amazon Web Services (Frankfurt, Germany) stores a copy of recorded checkouts, purchases and upsells (with page addresses, products, order IDs and numbers, and the link to the order in the store's admin), and of recorded Page Script visits (with approximate location, browser, device, time zone, the part of the page address after the ? and the scrambled visitor ID, but no IP address or user agent), for reporting and for training our models.
  • Functional Software, Inc. (Sentry) receives our servers' error reports, logs and a sample of requests, which can include page addresses, Smart Funnels IDs, order IDs and, from the log line in section 3, IP addresses; it stores them in its data centre in Germany.

In addition, ipwho.is receives the visitor's IP address directly from the browser, as described in section 6, and we disclose data to authorities where the law requires it.

9. How long we keep it

We keep visit and order records for as long as we need them to provide Smart Funnels: to report test results to the merchant and to train the models that choose which version of a page to show. When a merchant uninstalls the app, it stops collecting new data from their store: the pixel, the order notices and the theme embed stop at once, a page a visitor still has open stops running the Page Script within an hour, and we delete the store's access key. A merchant can ask us at [email protected] to delete their store's records.

The app's database holds only the store's address and access key, deleted when the app is uninstalled. The app's server log keeps the order IDs named in shoppers' privacy requests (section 10) until newer log lines replace them; it never logs the visitor IDs, page addresses or products the pixel sends. Diagnostic reports sent on every load, which carry a scrambled IP address, are deleted after 7 days. Orders from a store not yet linked to a Smart Funnels account are deleted after 90 days. Our backups are deleted within about ten weeks.

10. Your rights and requests

Shoppers who want to see or delete their data should contact the store where they shopped; Shopify passes such requests on to us. We cannot link a visit to a person's name or email, so we find a shopper's records through the order IDs in the request. Within 30 days, as Shopify requires, we send the store a copy of those records or delete them, as asked. Copies in our backups are removed as the backups expire (section 9). Merchants can write to [email protected] about their store's data. You also have the right to complain to your data protection authority.

11. Security

Data sent over the internet to and from our servers is encrypted (HTTPS). Access to the server that runs the app and receives the data is limited to the people who operate Smart Funnels and its hosting provider.

12. International transfers

Our servers are in Germany, and our company is registered at the address at the top of this policy. Cloudflare carries data through its network worldwide, and ipwho.is is reached directly from the visitor's browser, so data may be processed outside your country.

13. Changes

We will post changes on this page and update the date at the top.

S Smart Funnels
© 2026 Smart Funnels · Privacy