Privacy Policy

ClearSignal: Bot Traffic Detection for Shopify

Effective date: September 14, 2026

This Privacy Policy explains how Alpenglow Software LLC ("we," "us," "our"), operator of ClearSignal ("the App") collects, uses, stores, and protects information when you install and use the App through the Shopify platform. ClearSignal detects bot traffic that may be polluting your store's analytics by combining client-side fingerprinting, order-level signal analysis, and server-side signal correlation. A Shopify Web Pixel extension additionally captures storefront checkout and funnel events (such as checkout started, checkout completed, and add-to-cart) as bot-detection, order-integrity, and conversion-funnel signals. See Section 1 for details.

1. Information We Collect

Data from Shopify APIs

The App requests the following Shopify access scopes:

Data from the Web Pixel extension (storefront events)

ClearSignal registers a Shopify Web Pixel that receives storefront events. The pixel runs in Shopify's sandboxed pixel environment and fires only where your visitors' analytics consent permits, as managed by Shopify's Customer Privacy controls. It subscribes to two categories of event, and from each it collects only non-identifying data:

Checkout events (checkout started and checkout completed), used as an order-integrity signal. From these we collect:

Funnel events (page viewed, collection viewed, product viewed, search submitted, product added to cart, product removed from cart, cart viewed, and the checkout contact-information, address, shipping-information, and payment-information steps), used to measure how bot versus human traffic moves through your store's conversion funnel. From these we collect only:

Funnel events carry no product, cart, collection, or order details and no order identifier — only the fact that an event of that type occurred, Shopify's clientId, and when. We do not receive or store customer names, email addresses, phone numbers, or postal addresses from any of these events. Shopify withholds those fields unless an app is separately approved for them, and ClearSignal does not request that approval.

Data collected through Shopify session

Shopify provides the following data as part of the standard app authentication process:

This session data is managed by Shopify's official session storage library and is required for the App to function within the Shopify Admin.

Data from the Theme App Extension (storefront visitors)

ClearSignal installs a lightweight app embed block on your storefront that runs entirely in your visitors' browsers. This extension collects the following signals from storefront sessions:

This data is transmitted to the App's server via a Shopify app proxy endpoint, which verifies request authenticity using HMAC signature validation.

ClearSignal's storefront component also sends a direct request to the App's server. From that request the App observes the visitor's network (IP) address and reduces it immediately to a truncated /24 network block (the final part of the address is discarded). This truncated block is used only to detect automated (bot) traffic, and is processed for all storefront sessions — including visitors who declined analytics consent — on the basis of the App's and the merchant's legitimate interest in fraud and bot detection, not on consent. It is never combined or compared across merchants, and is never used to identify an individual visitor.

Data from server-side processing

When a storefront session is scored, the App processes and stores:

Data from the optional Klaviyo integration

If you connect your Klaviyo account, the App additionally collects:

Klaviyo tokens are deleted immediately when you disconnect the integration or uninstall the App.

Data we do NOT collect

2. How We Use Your Information

We use the data we collect solely to provide and improve the App's services:

For the purposes of applicable data protection laws, you (the merchant) are the data controller for storefront visitor data collected through the App. Alpenglow Software LLC acts as a data processor, processing this data solely on your behalf and as described in this policy. For data we collect directly (such as support communications), we act as an independent data controller.

3. How We Process Visitor Data

Storefront visitor data flows through the App as follows:

  1. The theme app extension loads on your storefront and runs FingerprintJS BotD in the visitor's browser. No data leaves the browser until the next step.
  2. Fingerprint and behavioral signals are sent to the App's server via a Shopify app proxy endpoint with HMAC verification. A separate direct request also conveys the visitor's truncated /24 network block (see Section 1) for bot detection.
  3. The server correlates all available signals (fingerprint score, behavioral patterns, and IP reputation) and computes a bot probability score.
  4. The classification verdict and signal breakdown are stored in the database. Raw behavioral signal data is not stored after scoring.
  5. Aggregated results are displayed in your merchant dashboard.

Bot classifications represent probabilistic assessments, not definitive verdicts. Individual session records include the contributing signals so you can evaluate the basis for any classification.

Separately, order data (see Section 1) is read directly from the Shopify Admin API via the read_orders scope when an order is created. The resulting order attribution and risk record is stored on its own. It does not pass through the fingerprinting/scoring pipeline described above. The Web Pixel extension referenced in Section 1 delivers storefront checkout and funnel events (see Section 1) to the App's server, where checkout events are recorded as order-integrity signals and funnel events as aggregate conversion-funnel signals. We use Shopify's visitor identifier (clientId) from these events to match completed orders to the bot-scored storefront sessions that preceded them, so genuine buyers can be distinguished from bot traffic in your analytics, and to measure how bot and human traffic move through your store's funnel. This processing is performed only within your own store's data and is never combined or compared across merchants.

When order-to-session matching is enabled (off by default; see Section 9), the App additionally maintains a link between a completed order and the storefront session that preceded it, using the durable visitor identifier described in Sections 1 and 9. When an order is created, the App records an order-to-session join (an OrderSessionLink record) connecting the Shopify order to that visitor identifier, so that bot-scored page views can be attributed to the revenue they generated. When order-to-session matching is enabled and the visitor's analytics consent permits, the extension also writes the durable identifier (_clearsignal_sid) into the cart as a custom attribute when the visitor adds an item to their cart, so that the identifier is carried into the resulting Shopify order. This is the point at which the order-linked session data can become personal data: because a Shopify order can be tied to an identifiable customer, enabling this feature can make the linked session data personal data relating to that customer. See Sections 6, 7, and 9 for the corresponding retention limits and data rights.

4. Data Storage and Security

5. Third-Party Services

The App uses the following third-party services to operate:

ServicePurposeData shared
Shopify Admin API Authentication, order attribution data, order risk assessment Session tokens, GraphQL order queries
FingerprintJS BotD Browser-side bot detection (open source) Runs entirely in visitor's browser. No data sent to FingerprintJS servers
IPQualityScore IP reputation scoring Visitor IP addresses
Inngest Background job scheduling Shop ID, session metadata (not visitor PII)
Railway Application and database hosting All stored data (encrypted in transit)
Klaviyo API (optional) Profile audit and bot tagging OAuth tokens, profile queries, tag writes (only when integration is connected)

6. Data Retention

The three retention limits above are additional ceilings on the storefront visitor-identification and order-attribution data; they do not override the immediate deletion described earlier in this section. Uninstalling the App, or a Shopify shop-redact request, deletes this data immediately regardless of these ceilings.

7. Your Rights

You have the right to:

Regarding your store's visitors: ClearSignal's bot-detection extension does not collect names, email addresses, or other directly identifying information from storefront visitors (the optional Klaviyo integration is the exception; if connected, Klaviyo provides email addresses as part of profile data). However, if you enable order-to-session matching (see Section 9), the durable visitor identifier can be linked to a completed order, and through your Shopify order records to an identifiable customer. Where that link exists, the associated bot-detection session data becomes personal data relating to that customer. Separately, ClearSignal receives Shopify's first-party visitor identifier (clientId) through the Web Pixel checkout events described in Section 1; because those records link an order to that identifier, they are likewise treated as personal data, not as anonymous data. ClearSignal honors Shopify's customer privacy webhooks for all of this data: a customers/data_request surfaces the order-linked session records and Web Pixel checkout-event records we hold for the requested orders, and a customers/redact request deletes them. Sessions that were never linked to an order, including those of visitors who did not grant analytics consent, carry no durable identifier and remain anonymous and unmatchable to any individual. If a visitor contacts you with a data request, you may contact us and we will assist.

We respond to all data requests within 30 days.

8. International Data Transfers

Your data and your visitors' data are processed and stored on servers located in the United States. By using the App, you consent to the transfer of data to the United States for processing.

9. Storefront Tracking, Cookies, and Local Storage

ClearSignal's theme app extension runs in your store's storefront to collect the bot-detection signals described in Section 1. ClearSignal uses a single first-party cookie (_cs_visit, described below) for visit counting; all other storefront identifiers use browser local storage rather than cookies. This section explains how those techniques interact with your visitors' browsers and with their privacy choices.

Bot-detection signals

The extension reads browser characteristics (via FingerprintJS BotD) and observes behavioral signals to assess whether a session is automated. These signals are used solely to score sessions for bot detection on your store. They are not used to build a personal profile of the visitor, and they are not used to track visitors across other websites.

Consent-gated device read

The FingerprintJS BotD check reads information from the visitor's device (browser). Where your storefront's analytics consent settings indicate that a visitor has not granted analytics consent, ClearSignal does not perform this device read. Those sessions are still scored using server-side signals only, IP address and network (ASN) reputation, behavioral patterns, and honeypot interactions, none of which access information stored on the visitor's device.

Durable visitor identifier (optional, off by default)

If you enable order-to-session matching, a setting that is off by default, ClearSignal stores a random, first-party identifier in each visitor's browser using local storage (localStorage). This is not a cookie. The identifier (_clearsignal_sid) contains no name, email address, or other personal detail, is scoped to your store's domain only, and is never shared or reused across other websites. Its sole purpose is to link a completed order back to the bot-scored page views that led to it.

This identifier is stored only where your visitors' analytics consent permits. Where a visitor has not granted analytics consent, or where the setting is off, ClearSignal instead uses a temporary identifier that exists only for the current page and is discarded when the page is closed. If a visitor withdraws analytics consent, ClearSignal removes the stored identifier from their browser and reverts to the temporary identifier.

Visit-counting cookie (_cs_visit)

ClearSignal sets a single first-party cookie, _cs_visit, on your store's domain. It holds a random, non-durable token with a rolling 30-minute expiry (refreshed as the visitor continues browsing) and contains no name, email address, or other personal detail. Its sole purpose is to recognize that several page views belong to the same visit, so a visitor's page views can be collapsed into one bot-filtered visit — both for the counts shown in your reports and for the usage meter that determines your plan's billing. It is not used to build a cross-visit profile of the visitor and is not shared or reused across other websites.

This cookie is set only where your visitors' analytics consent permits. It is set independently of the order-to-session matching setting above; unlike the durable visitor identifier, it does not require you to enable durable tracking. Where a visitor has not granted analytics consent, the cookie is not set, and if a visitor withdraws analytics consent ClearSignal clears it from their browser.

Checkout and funnel events via Shopify Web Pixel

ClearSignal registers a Shopify Web Pixel that receives checkout and funnel events from your storefront (see Section 1). This pixel runs in Shopify's sandboxed environment and is gated by Shopify's Customer Privacy controls, so it fires only under the analytics consent your visitors have granted. It does not read information from the visitor's device and does not set any identifier of its own. It receives Shopify's own first-party visitor identifier (clientId), which ClearSignal uses to match completed orders to the sessions that preceded them and to measure bot-versus-human movement through your store's funnel, within your store only.

No cross-site tracking

None of these techniques track visitors across different websites or link a visitor's activity on your store to their activity elsewhere. All collected signals are used solely for bot detection and order attribution on your store.

Your responsibilities as merchant

By enabling the App's storefront extension, you represent that your store's privacy policy and consent mechanisms adequately disclose the use of browser fingerprinting, behavioral analysis, and local-storage-based durable visitor identification for bot detection and order attribution purposes, and that your store's consent management (via Shopify's Customer Privacy API) is configured to reflect your visitors' choices. You are responsible for compliance with applicable privacy laws regarding your store's visitors.

10. Children's Privacy

The App is designed for use by Shopify merchants (business users) and is not directed at children under 13. We do not knowingly collect personal data from children.

11. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date at the top of this page. Continued use of the App after changes constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy or want to exercise your data rights, contact us at:

Email: support@alpenglowsoftware.com