1. Introduction
Welcome to Edition ("we," "our," or "us"). We develop and provide the "Edition DataLayer & Tracking" app (the "App") for Shopify merchants. The App adds a data layer to your storefront and checkout, so the events your shoppers trigger can be used by Google Tag Manager, and, if you turn it on, sends those events from our server to the advertising and marketing platforms you connect. This Privacy Policy explains what information the App handles, why, and how long we keep it, in connection with your use of the App and our services (collectively, the "Services").
By using our Services, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
The App is a tracking app, so unlike many apps it does handle information about the visitors to your store. It does so only on your behalf, only for the events and platforms you switch on, and only after the visitor has given consent. Importantly:
We DO NOT store your visitors' events, browsing history or contact details in our database.
We DO NOT sell visitor data or use it for our own purposes, and we never send it to a platform you have not connected.
We DO NOT see or store payment details.
The information we collect is limited to:
Store Information (Provided by Shopify)
Store Details: Your store domain and Shopify store ID. This is required for the App to connect to your store.
Access Credentials: The credentials Shopify issues so the App can connect to your store. These are stored encrypted.
Plan Information: Your current plan and billing period. Payments are handled entirely by Shopify, and we never see or store payment details.
Store Contact Email: Read from Shopify only when we need to send you a customer data request (see section 4). It is not stored.
Order Information (Provided by Shopify)
For each order placed in your store, the App stores the order ID and the times the order was placed and reported to Shopify for billing. This is used to count the orders on your plan. We store no names, email addresses, phone numbers, addresses or amounts for these orders.
Order IDs can be linked to a customer inside Shopify. For that reason we treat order records as personal data and handle them as described in sections 4 and 9.
Information You Enter in the App
App Configuration Data: Your Google Tag Manager container ID, which events are switched on, your power-up settings, and the settings for each platform you connect, such as pixel IDs, tag IDs and conversion labels, per market.
Platform Credentials: The API tokens and keys you enter so the App can send events server-side to a platform. These are stored encrypted and are never written to your storefront.
Visitor Information (Processed on Your Behalf)
Events: When a visitor views a page or product, searches, uses the cart, submits a newsletter or contact form, clicks a phone or email link, or moves through checkout, the App records the event in the data layer in the visitor's browser. Events include details such as the page address, the products, quantities and prices involved, and an event ID.
Customer Details: For customers who are logged in, and in checkout, events can include the customer's ID, email address, phone number, name, city, region, postal code and country. These are made available in the data layer both as entered and as SHA-256 hashes, so your tags can use them for matching.
Server-Side Tracking: Only if you turn on server-side tracking, events are also sent to our server and forwarded to the platforms you have connected. These events include the details above, the visitor's IP address and browser type (user agent), and advertising identifiers such as click IDs and the platforms' own cookie values. The platforms receive customer details as SHA-256 hashes, with one exception: Klaviyo, if you connect it, receives the email address, phone number and customer ID as entered, because Klaviyo identifies its profiles by them.
Consent: The App reads each visitor's consent choices from Shopify's Customer Privacy API. Events are held in the visitor's browser and are not sent anywhere until the visitor has given consent.
Cookies and Browser Storage: The App can set the following first-party cookies on your storefront, depending on the features you use: _edition_uid (a random visitor ID, 1 year), _edition_ud (hashed customer details only, used to recognise returning customers, 1 year), _edition_attribution (advertising click IDs, 90 days) and _edition_exclude_internal_traffic (marks your own staff's browsers so they are not tracked, 1 year). Events waiting for consent are kept in the browser's session storage until the tab is closed.
Technical Logs and Counters
Our servers keep technical logs to run and secure the Services. They can include your store domain and error details. We also count requests per store, for example how often the checkout pixel loads, to show you whether tracking is working. Logs are kept for short periods only, and the counters for 14 days.
3. How We Use Your Information
We use the information we collect for the following purposes:
To provide, operate, and maintain the App and our Services.
To authenticate your access to the App.
To add the data layer to your storefront and checkout, and to build the Google Tag Manager container you download.
To send events to the platforms you connect, when you turn on server-side tracking.
To show you whether tracking is working on your storefront and checkout.
To apply the order allowance of your plan.
To respond to support requests.
To meet our legal obligations, including handling data requests passed on by Shopify.
4. Our Role and Legal Basis for Processing (For EEA Users)
For order information and visitor information, you (the merchant) are the data controller and we act as your data processor. We process this information only to provide the Services to you and only as you configure the App. You decide which events are tracked and which platforms receive them, and you are responsible for showing visitors a consent banner and for describing your tracking in your own privacy policy.
For merchants in the European Economic Area (EEA), our legal basis for collecting and using the information described above is:
Performance of a Contract: The processing is necessary to provide the App and fulfill our contractual obligations to you.
Legal Obligation: The processing is necessary to handle data protection requests and meet other legal requirements.
Legitimate Interests: The processing is necessary to keep the Services secure and reliable, for example through technical logs.
When one of your customers asks for their data, Shopify passes the request to us. We then email you a file with everything the App holds for that customer's orders, so you can answer them. When Shopify asks us to delete a customer's data, we permanently delete the order records concerned.
5. Data Sharing and Disclosure
We do not sell, trade, or rent your information to third parties. We may share information only in the following limited circumstances:
Platforms You Connect: When you turn on server-side tracking, we send events to the platforms you have connected and enabled, on your instruction. These can include Google Analytics, Meta, TikTok, Pinterest, Snapchat, Microsoft Advertising, Reddit, X and Klaviyo. Each platform handles this data under its own terms and privacy policy, which you agree to with them.
Service Providers: We engage trusted third-party companies (Data Processors) to perform essential services on our behalf, such as hosting and email delivery. These providers are contractually obligated to handle your data securely and only for the purposes we specify.
Legal Compliance: We may disclose information if required to do so by law or in response to valid legal requests (e.g., court orders, subpoenas).
Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control.
List of Our Key Data Processors:
Shopify Inc. (Canada) – Platform provider
DigitalOcean (Frankfurt, Germany) – Application hosting, database and background job processing
Resend (United States) – Email delivery for customer data requests
We ensure all Data Processors comply with stringent data protection obligations.
6. Data Security
We implement reasonable administrative, technical, and physical safeguards designed to protect the information we collect. Access credentials and platform credentials are encrypted at rest, and all data is sent over encrypted connections. However, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
7. International Data Transfers
Your data is stored in the European Union (Frankfurt, Germany). Some of our Data Processors are based outside the EU: Shopify in Canada and Resend in the United States. Where information is transferred outside the EEA, we ensure such transfers are governed by appropriate safeguards, such as an adequacy decision or Standard Contractual Clauses approved by the European Commission, to protect your data in accordance with this policy and applicable law.
Many of the platforms you can connect are based outside the EU. Events you choose to send to them are transferred under those platforms' own terms.
8. Your Rights
Depending on your location, you may have certain rights regarding your information, such as the right to access, correct, or delete the personal data we hold. You can review and update most of your data directly within the App.
To exercise any other rights, please contact us at help@edition.dk. We will respond to your request in accordance with applicable law.
9. Data Retention
While the App Is Installed: We keep your settings for as long as the App is installed. Order records are deleted about 90 days after they have been reported to Shopify for billing.
Server-Side Events: Events are processed as they arrive and are not stored in our database. A small number of recently processed events are kept in our job queue for troubleshooting and are replaced as new events arrive.
When You Uninstall the App: Your store is marked as inactive, and your data is kept for about 48 hours in case you reinstall. Shopify then sends us a deletion request, and we permanently delete all of your store's data, including settings, platform credentials and order records.
Customer Deletion Requests: When Shopify asks us to delete a customer's data, we delete the order records concerned.
Cookies: The App's cookies expire after the periods listed in section 2, or earlier if the visitor clears them.
Backups: Data deleted from our systems may remain in encrypted backups until they expire on our providers' regular backup cycle.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last Updated" date. Your continued use of the App after any change constitutes your acceptance of the updated policy.
11. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at:
Edition
Email: help@edition.dk
Website: https://edition.dk
For EEA Residents: You have the right to lodge a complaint with a supervisory authority in your country of residence. In Denmark, this is Datatilsynet.