Growth Layer — Privacy notice
This notice covers data processing specific to the Growth Layer Shopify app. The sico-wide privacy notice applies in addition.
1. What data we collect
When you connect your store to Growth Layer — through Shopify's approval screen, or by pasting an existing Custom App token — we read and store:
- Shop identity — shop domain, shop name, currency, timezone.
- Store data — orders, refunds, customers, products and store analytics, read through the Shopify Admin API with read-only permissions and used for conversion attribution.
- Klaviyo metrics — aggregated email send counts, open rates, click rates, and revenue figures pulled via your Klaviyo Private API key. We do not store individual subscriber email addresses or subscriber-level profile data.
- Anomaly records — computed anomaly events (metric name, z-score, severity, detected timestamp) and AI-generated diagnoses (root-cause tag, narrative, suggested action). These are derived data — they reference campaign metrics but contain no end-customer personal data.
- Action log — a record of actions you approve or dismiss within the app.
- Meta and Google Ads credentials (if connected) — stored encrypted, and used to upload Visitor ID audiences to your own ad accounts (see sub-processors).
- Visitor ID data (optional module) — if you turn Visitor ID on, we ask Shopify for permission to add a storefront script tag. Its pixel collects anonymous browser signals from your store's visitors (page URL, referrer, approximate location from IP, a session identifier); IP addresses are hashed (SHA-256) before storage. When a visitor is resolved to a named contact, their name and email are stored against your account. For that data you are the controller and we are your processor.
Your Klaviyo Private API key is stored encrypted at rest and is never logged in plaintext.
2. Legal basis
Processing is necessary to perform the contract you entered when signing up (UK GDPR Art. 6(1)(b)). Connecting your Klaviyo account is voluntary; you may disconnect it at any time from Settings, which immediately revokes and deletes the stored key.
3. How we use the data
Solely to provide the Growth Layer features: anomaly detection on your email campaign metrics, AI-assisted root-cause diagnosis, and one-click remediation actions. Klaviyo metric data is not shared with third parties and is not used to train AI models beyond the single diagnostic call made per anomaly (prompts contain only aggregate metrics, never subscriber data).
4. Data retention
Store data is retained while your store is connected. If you connected through Shopify's approval screen and then uninstall the app, Shopify sends us a GDPR erasure webhook 48 hours later and we purge all store-specific records within 30 days. Shopify sends no such webhook for a store connected with a pasted token: disconnecting removes the stored token, and you can ask us to delete the rest at the address below. Your Klaviyo API key is deleted immediately when you disconnect it from Settings.
5. Sub-processors
- Hetzner — VPS hosting; data stored in EU.
- Stripe — billing for your Growth Layer subscription.
- Resend — transactional email.
- PostHog (EU) — product analytics (page-level only).
- RB2B, Inc. — identity resolution for the Visitor ID module only; anonymous browser signals are sent to RB2B.
- Meta Platforms and Google — only when Visitor ID and the matching ads integration are both on: hashed contact details of resolved visitors are uploaded to your Meta Custom Audiences or Google Customer Match lists on your behalf.
- Anthropic — AI diagnosis of anomalies; prompts contain only aggregate metric values, no personal data. Anthropic does not use API inputs for training by default.
6. Contact
Privacy queries: privacy@sico.software.