AB Slide Cart Drawer & Upsells
Privacy policy
Updated September 13, 2026
AB Apps provides AB Slide Cart Drawer & Upsells. This policy explains the information we process to operate the app, measure cart performance, and respond to privacy requests. Contact us at hello@abapps.co.
Information and purposes
We process the store domain, app settings, product and variant information, discounts, and theme activation information to display and configure the cart drawer. Shopify authentication provides installation and merchant account information, including account identifiers and, where supplied, the merchant account name, email, locale, and access credentials. These credentials allow the app to perform its authorized functions.
For cart analytics, we process interaction types and timestamps, pseudonymous visitor identifiers, and cart experiment identifiers and variants. This measures cart openings, checkout activity, product upsell interactions, and the performance of different cart designs.
When Shopify order access is enabled, we process order identifiers, totals, currency, relevant line-item identifiers, quantities and prices, and the app's cart attribution attributes. This links permitted cart interactions to purchases and measures revenue, conversion and upsell performance. Order and visitor identifiers are pseudonymous personal data, not anonymous data. We do not request customer names, email addresses, phone numbers, addresses or payment card details for this reporting. We do not import a store's historical orders automatically.
We also retain the minimum identifiers needed to authenticate, deduplicate and fulfil Shopify privacy requests. Customer contact fields in a Shopify privacy request are not copied into our request records.
Customer choices and analytics
The cart remains usable when analytics is refused. Storefront analytics uses Shopify's Customer Privacy API to check whether analytics processing is permitted. When the decision is unavailable or permission is refused, the app does not create analytics identifiers or record new analytics events.
When analytics is permitted, first-party browser storage and app-specific cart attributes maintain cart and experiment attribution. Purchase reporting requires a valid, signed attribution proof from a permitted cart visit. Withdrawing consent stops new browser tracking. The app clears its browser attribution and sends the withdrawal to the reporting service; a network failure leaves a pending request for retry. When the service receives the withdrawal, the related attribution proof is invalidated. Missing, expired or revoked proofs are excluded from purchase reporting. Merchants should configure their Shopify privacy settings and consent banner for their store.
Sharing and service providers
We do not sell, rent or trade customer data, or share it with advertisers. We use Shopify for app authentication, storefront integration, order notifications and privacy requests, and Fly.io to host the application and its database. Hosting is currently in the United States.
We use PostHog for app page usage and diagnostic session recordings to improve the merchant experience and investigate errors. The recording configuration masks input values and visible text, blocks images, video, canvas and embedded frames, and removes URL query strings and fragments from page tracking. This diagnostic processing is separate from customer cart and purchase reporting.
We process store customer data on the merchant's behalf for the purposes described above. Merchants control how their store uses the app and remain responsible for their customer notices and instructions. We use merchant account and support information to operate, secure and support the service. We may disclose information where required by applicable law.
Retention and deletion
Store settings and detailed reporting records are retained while the app is installed so merchants can operate their cart and compare its historical performance. Merchants can request earlier access or deletion. We do not keep this information for unrelated advertising or future services.
When Shopify delivers an app uninstallation or shop deletion notification, the app deletes that store's application records and authentication sessions. Shopify customer deletion requests remove matching customer and order reporting data. A minimal consent suppression record is kept while the app remains installed to prevent an older attribution permission from being reused after deletion or withdrawal. Automatic database snapshots expire after five days, so deletion from an active database does not instantly remove an older snapshot.
Privacy request records are retained while the request is being handled. Completed or deleted requests retain a minimal status record; the requested customer and order identifiers are removed from that record. Technical application logs are retained for no more than 14 days; Fly.io hosted application log search currently retains logs for seven days. Contact us about deletion of diagnostic or support records.
Access, deletion and questions
Customers may contact the store where they shopped to request access or deletion. Shopify forwards applicable requests to the app. Merchants can open Privacy requests in the app to download the data matching a request and record fulfilment. The download is available only to the authenticated merchant for that store. Downloading a file does not itself send it to the customer.
Merchants can also contact hello@abapps.co with privacy instructions, access or deletion requests, and questions about our service providers. Please identify the store and request; do not email passwords or payment details.
Security
The hosted database volume is encrypted at rest and the app uses HTTPS for data in transit. Shopify authentication protects merchant access; Shopify webhook authentication protects notifications and privacy requests. Signed attribution proofs and checks scoped to the store protect reporting and data exports.
Policy updates
This version describes cart and order reporting, customer consent, and privacy request handling for AB Slide Cart Drawer & Upsells. We display the policy in the app and link to it from our App Store listing. We will notify merchants in the app and by email of material changes before introducing a new use of their data.