Privacy Policy
ClearSignal: Bot Traffic Detection for Shopify
Effective date: September 14, 2026
This Privacy Policy explains how Alpenglow Software LLC ("we," "us," "our"), operator of ClearSignal ("the App") collects, uses, stores, and protects information when you install and use the App through the Shopify platform. ClearSignal detects bot traffic that may be polluting your store's analytics by combining client-side fingerprinting, order-level signal analysis, and server-side signal correlation. A Shopify Web Pixel extension additionally captures storefront checkout and funnel events (such as checkout started, checkout completed, and add-to-cart) as bot-detection, order-integrity, and conversion-funnel signals. See Section 1 for details.
1. Information We Collect
Data from Shopify APIs
The App requests the following Shopify access scopes:
read_orders: used to attribute orders to AI-agent-driven traffic and to surface Shopify's own order-level risk assessment. For each order, the App reads and stores the order ID, order total and currency, sales channel and referrer information, and Shopify's risk recommendation, risk level, and risk assessment details. The App does not access or store customer names, addresses, email addresses, or payment information through this scope.read_products: used to resolve product titles and handles for the storefront pages your visitors and AI agents view, so reports display product names rather than raw identifiers. The App reads product title and handle only. It does not create, modify, or delete products.write_pixelsandread_customer_events: used to register and operate a Shopify Web Pixel that receives storefront checkout and funnel events. See "Data from the Web Pixel extension" below for exactly what these events contain.
Data from the Web Pixel extension (storefront events)
ClearSignal registers a Shopify Web Pixel that receives storefront events. The pixel runs in Shopify's sandboxed pixel environment and fires only where your visitors' analytics consent permits, as managed by Shopify's Customer Privacy controls. It subscribes to two categories of event, and from each it collects only non-identifying data:
Checkout events (checkout started and checkout completed), used as an order-integrity signal. From these we collect:
- The event type (checkout started or checkout completed)
- The Shopify order identifier and checkout token
- Shopify's first-party visitor identifier (
clientId), used to match a completed order to the bot-scored sessions that preceded it - The event timestamp and your shop domain
Funnel events (page viewed, collection viewed, product viewed, search submitted, product added to cart, product removed from cart, cart viewed, and the checkout contact-information, address, shipping-information, and payment-information steps), used to measure how bot versus human traffic moves through your store's conversion funnel. From these we collect only:
- The event type
- Shopify's first-party visitor identifier (
clientId) - The event timestamp
Funnel events carry no product, cart, collection, or order details and no order identifier — only the fact that an event of that type occurred, Shopify's clientId, and when. We do not receive or store customer names, email addresses, phone numbers, or postal addresses from any of these events. Shopify withholds those fields unless an app is separately approved for them, and ClearSignal does not request that approval.
Data collected through Shopify session
Shopify provides the following data as part of the standard app authentication process:
- Shop domain
- Staff member name, email address, and user ID
- Account role (store owner or collaborator) and email verification status
- Locale preference
- Session tokens, access tokens, and refresh tokens
This session data is managed by Shopify's official session storage library and is required for the App to function within the Shopify Admin.
Data from the Theme App Extension (storefront visitors)
ClearSignal installs a lightweight app embed block on your storefront that runs entirely in your visitors' browsers. This extension collects the following signals from storefront sessions:
- Browser fingerprint data: a bot probability score and browser attributes generated by FingerprintJS BotD, an open-source library that runs entirely in the visitor's browser. No data is sent to FingerprintJS servers.
- Behavioral signals: mouse movement patterns, scroll behavior, and interaction timing, used to distinguish automated from human behavior.
- Honeypot interactions: whether a session triggered invisible form fields that only automated scripts typically interact with.
- Page URL and referrer: the current page URL and referring URL, including whether UTM parameters or click IDs (such as
gclidorfbclid) are present. We store only the boolean presence of these parameters, not their raw values. - Durable visitor identifier (optional, off by default): if you enable order-to-session matching, ClearSignal stores a random, first-party identifier (
_clearsignal_sid) in the visitor's browser using local storage (localStorage). This is not a cookie and contains no name, email address, or other personal detail. Its sole purpose is to match a completed order back to the bot-scored sessions that preceded it. It is stored only where the visitor's analytics consent permits; otherwise a temporary, page-only identifier is used instead. This setting is off unless you enable it. See Section 9 for details. - Visit-counting cookie (
_cs_visit): a first-party cookie containing a random, non-durable token with a rolling 30-minute expiry. It is used to recognize that several page views belong to the same visit, so a visitor's page views can be counted as a single bot-filtered visit for reporting and for the usage meter that determines your plan's billing. It contains no name, email address, or other personal detail, builds no cross-visit profile, is set only where the visitor's analytics consent permits, and is cleared if the visitor withdraws consent. It is set independently of the order-to-session matching setting above and does not require that setting to be enabled. See Section 9 for details.
This data is transmitted to the App's server via a Shopify app proxy endpoint, which verifies request authenticity using HMAC signature validation.
ClearSignal's storefront component also sends a direct request to the App's server. From that request the App observes the visitor's network (IP) address and reduces it immediately to a truncated /24 network block (the final part of the address is discarded). This truncated block is used only to detect automated (bot) traffic, and is processed for all storefront sessions — including visitors who declined analytics consent — on the basis of the App's and the merchant's legitimate interest in fraud and bot detection, not on consent. It is never combined or compared across merchants, and is never used to identify an individual visitor.
Data from server-side processing
When a storefront session is scored, the App processes and stores:
- IP addresses: used for geographic analysis and queried against an IP reputation service. IP addresses are retained as part of session records.
- IP reputation scores: scores from the IPQualityScore API indicating the likelihood that an IP address is associated with bots, proxies, or data centers.
- Data center and ASN classification: whether the session originated from a cloud provider, hosting service, or residential network.
- Bot classification and session scores: the final classification verdict (DEFINITE_BOT, LIKELY_BOT, SUSPICIOUS, or LIKELY_HUMAN) and the underlying signal breakdown that produced it.
Data from the optional Klaviyo integration
If you connect your Klaviyo account, the App additionally collects:
- Klaviyo OAuth tokens: stored encrypted at rest using AES-256-GCM. Used to authenticate API calls to your Klaviyo account.
- Klaviyo profile data: email addresses, profile IDs, and activity metrics for profiles in your Klaviyo account, used to assess bot risk. This data is queried from Klaviyo's API and processed to generate bot scores.
- ClearSignal tags applied to profiles: when a profile is flagged, a tag (e.g., "ClearSignal: Bot Suspect") is written back to the Klaviyo profile through the Klaviyo API.
Klaviyo tokens are deleted immediately when you disconnect the integration or uninstall the App.
Data we do NOT collect
- Customer names, postal addresses, or payment information
- Raw click ID values (gclid, fbclid, etc.): only whether they are present
- Theme files or store source code
- Customer email addresses, unless you connect the Klaviyo integration and Klaviyo provides them as part of profile data
2. How We Use Your Information
We use the data we collect solely to provide and improve the App's services:
- Bot detection: we correlate fingerprint, behavioral, and IP reputation signals to score storefront sessions and classify them as bot or human traffic.
- AI-agent order attribution: we analyze each order's sales channel, referrer, and source data to identify orders driven by AI-agent traffic (e.g., ChatGPT, Microsoft Copilot) and estimate the revenue they contribute.
- Order risk surfacing: we display Shopify's own order-level risk recommendation and risk level in your dashboard so you can evaluate order quality.
- Analytics impact reporting: we use session classifications to calculate your true conversion rate and estimate how bot traffic may be distorting your analytics.
- Dashboard display: we surface bot percentage, session breakdowns, and signal details in the App's merchant dashboard.
- Klaviyo profile audit (if connected): we analyze Klaviyo profiles for bot-like behavior and tag suspected bot profiles so they can be excluded from campaigns.
- Subscription management: we store your current billing plan to gate features appropriately.
- App functionality: we use your shop domain and session data to authenticate requests and deliver the App within the Shopify Admin.
- AI/ML: We do not use artificial intelligence or machine learning to process your data. Your data and your visitors' data are not used to train AI or machine learning models.
For the purposes of applicable data protection laws, you (the merchant) are the data controller for storefront visitor data collected through the App. Alpenglow Software LLC acts as a data processor, processing this data solely on your behalf and as described in this policy. For data we collect directly (such as support communications), we act as an independent data controller.
3. How We Process Visitor Data
Storefront visitor data flows through the App as follows:
- The theme app extension loads on your storefront and runs FingerprintJS BotD in the visitor's browser. No data leaves the browser until the next step.
- Fingerprint and behavioral signals are sent to the App's server via a Shopify app proxy endpoint with HMAC verification. A separate direct request also conveys the visitor's truncated /24 network block (see Section 1) for bot detection.
- The server correlates all available signals (fingerprint score, behavioral patterns, and IP reputation) and computes a bot probability score.
- The classification verdict and signal breakdown are stored in the database. Raw behavioral signal data is not stored after scoring.
- Aggregated results are displayed in your merchant dashboard.
Bot classifications represent probabilistic assessments, not definitive verdicts. Individual session records include the contributing signals so you can evaluate the basis for any classification.
Separately, order data (see Section 1) is read directly from the Shopify Admin API via the read_orders scope when an order is created. The resulting order attribution and risk record is stored on its own. It does not pass through the fingerprinting/scoring pipeline described above. The Web Pixel extension referenced in Section 1 delivers storefront checkout and funnel events (see Section 1) to the App's server, where checkout events are recorded as order-integrity signals and funnel events as aggregate conversion-funnel signals. We use Shopify's visitor identifier (clientId) from these events to match completed orders to the bot-scored storefront sessions that preceded them, so genuine buyers can be distinguished from bot traffic in your analytics, and to measure how bot and human traffic move through your store's funnel. This processing is performed only within your own store's data and is never combined or compared across merchants.
When order-to-session matching is enabled (off by default; see Section 9), the App additionally maintains a link between a completed order and the storefront session that preceded it, using the durable visitor identifier described in Sections 1 and 9. When an order is created, the App records an order-to-session join (an OrderSessionLink record) connecting the Shopify order to that visitor identifier, so that bot-scored page views can be attributed to the revenue they generated. When order-to-session matching is enabled and the visitor's analytics consent permits, the extension also writes the durable identifier (_clearsignal_sid) into the cart as a custom attribute when the visitor adds an item to their cart, so that the identifier is carried into the resulting Shopify order. This is the point at which the order-linked session data can become personal data: because a Shopify order can be tied to an identifiable customer, enabling this feature can make the linked session data personal data relating to that customer. See Sections 6, 7, and 9 for the corresponding retention limits and data rights.
4. Data Storage and Security
- All data is stored in a PostgreSQL database hosted on Railway (United States).
- Shopify access tokens and Klaviyo OAuth tokens are encrypted at rest using AES-256-GCM encryption.
- All connections use HTTPS/TLS encryption in transit.
- IP reputation results are cached with a 24-hour TTL and expire automatically.
- We do not sell your data or your visitors' data. We do not share data with third parties for marketing, advertising, or profiling purposes.
- In the event of a data breach affecting your data, we will notify you and Shopify within 24 hours of discovery, in accordance with Shopify's Partner Program Agreement and applicable law.
5. Third-Party Services
The App uses the following third-party services to operate:
| Service | Purpose | Data shared |
|---|---|---|
| Shopify Admin API | Authentication, order attribution data, order risk assessment | Session tokens, GraphQL order queries |
| FingerprintJS BotD | Browser-side bot detection (open source) | Runs entirely in visitor's browser. No data sent to FingerprintJS servers |
| IPQualityScore | IP reputation scoring | Visitor IP addresses |
| Inngest | Background job scheduling | Shop ID, session metadata (not visitor PII) |
| Railway | Application and database hosting | All stored data (encrypted in transit) |
| Klaviyo API (optional) | Profile audit and bot tagging | OAuth tokens, profile queries, tag writes (only when integration is connected) |
6. Data Retention
- While installed: Detection records, order attribution records, and reports are retained while the App is installed on your store. Bot-detection session records are additionally subject to the per-plan retention window described below, and are automatically purged once they age past it.
- Bot-detection session records (per-plan retention): Session records are retained on a rolling basis determined by your plan and then automatically deleted: Free: 15 days; Essentials: 35 days; Growth: 100 days. Your dashboard reports over a shorter window (Free: 7 days, Essentials: 30 days, Growth: 90 days); records are kept slightly longer than the reporting window so that reporting for the most recent period is complete before the records are deleted. Uninstalling the App, or a Shopify shop-redact request, deletes this data immediately regardless of the window.
- On uninstall: All data associated with your shop is permanently deleted immediately and automatically. This includes sessions, detections, order attribution records, Klaviyo tokens, and your shop record. Deletion is atomic and irreversible.
- GDPR shop/redact: If Shopify sends a shop data erasure request, all shop data is deleted within 48 hours.
- IP reputation cache: IP reputation scores are cached with a 24-hour TTL and expire automatically.
- Klaviyo tokens: Deleted immediately on disconnect or uninstall.
- Durable visitor identifier (
_clearsignal_sid): When order-to-session matching is enabled, the identifier stored in a visitor's browser is retained on a 30-day rolling basis: it is regenerated at least every 30 days, and is removed from the visitor's browser immediately if the visitor withdraws analytics consent. - Order-to-session join records (
OrderSessionLink): Retained for no longer than 13 months, after which they are purged. This window permits year-over-year revenue-attribution reporting before the linkage is removed. - Web Pixel checkout-event records: Records of storefront checkout events, which link a Shopify order to Shopify's visitor identifier, are retained for no longer than 13 months, then purged. They are deleted immediately on app uninstall, and on any customer redaction request covering the affected order.
- Order-linked session records: Bot-detection session records that have been linked to an order are de-identified (the durable identifier is removed) at approximately 90 days, so that the ability to relate a session to an individual does not outlive the order-attribution purpose.
The three retention limits above are additional ceilings on the storefront visitor-identification and order-attribution data; they do not override the immediate deletion described earlier in this section. Uninstalling the App, or a Shopify shop-redact request, deletes this data immediately regardless of these ceilings.
7. Your Rights
You have the right to:
- Access: View session classifications, signal breakdowns, and detection history through the App's dashboard.
- Deletion: Uninstalling the App immediately deletes all your data. You may also contact us to request deletion without uninstalling.
- Data portability: Contact us to request an export of your stored data.
- Correction: Contact us if you believe any stored data is inaccurate.
Regarding your store's visitors: ClearSignal's bot-detection extension does not collect names, email addresses, or other directly identifying information from storefront visitors (the optional Klaviyo integration is the exception; if connected, Klaviyo provides email addresses as part of profile data). However, if you enable order-to-session matching (see Section 9), the durable visitor identifier can be linked to a completed order, and through your Shopify order records to an identifiable customer. Where that link exists, the associated bot-detection session data becomes personal data relating to that customer. Separately, ClearSignal receives Shopify's first-party visitor identifier (clientId) through the Web Pixel checkout events described in Section 1; because those records link an order to that identifier, they are likewise treated as personal data, not as anonymous data. ClearSignal honors Shopify's customer privacy webhooks for all of this data: a customers/data_request surfaces the order-linked session records and Web Pixel checkout-event records we hold for the requested orders, and a customers/redact request deletes them. Sessions that were never linked to an order, including those of visitors who did not grant analytics consent, carry no durable identifier and remain anonymous and unmatchable to any individual. If a visitor contacts you with a data request, you may contact us and we will assist.
We respond to all data requests within 30 days.
8. International Data Transfers
Your data and your visitors' data are processed and stored on servers located in the United States. By using the App, you consent to the transfer of data to the United States for processing.
9. Storefront Tracking, Cookies, and Local Storage
ClearSignal's theme app extension runs in your store's storefront to collect the bot-detection signals described in Section 1. ClearSignal uses a single first-party cookie (_cs_visit, described below) for visit counting; all other storefront identifiers use browser local storage rather than cookies. This section explains how those techniques interact with your visitors' browsers and with their privacy choices.
Bot-detection signals
The extension reads browser characteristics (via FingerprintJS BotD) and observes behavioral signals to assess whether a session is automated. These signals are used solely to score sessions for bot detection on your store. They are not used to build a personal profile of the visitor, and they are not used to track visitors across other websites.
Consent-gated device read
The FingerprintJS BotD check reads information from the visitor's device (browser). Where your storefront's analytics consent settings indicate that a visitor has not granted analytics consent, ClearSignal does not perform this device read. Those sessions are still scored using server-side signals only, IP address and network (ASN) reputation, behavioral patterns, and honeypot interactions, none of which access information stored on the visitor's device.
Durable visitor identifier (optional, off by default)
If you enable order-to-session matching, a setting that is off by default, ClearSignal stores a random, first-party identifier in each visitor's browser using local storage (localStorage). This is not a cookie. The identifier (_clearsignal_sid) contains no name, email address, or other personal detail, is scoped to your store's domain only, and is never shared or reused across other websites. Its sole purpose is to link a completed order back to the bot-scored page views that led to it.
This identifier is stored only where your visitors' analytics consent permits. Where a visitor has not granted analytics consent, or where the setting is off, ClearSignal instead uses a temporary identifier that exists only for the current page and is discarded when the page is closed. If a visitor withdraws analytics consent, ClearSignal removes the stored identifier from their browser and reverts to the temporary identifier.
Visit-counting cookie (_cs_visit)
ClearSignal sets a single first-party cookie, _cs_visit, on your store's domain. It holds a random, non-durable token with a rolling 30-minute expiry (refreshed as the visitor continues browsing) and contains no name, email address, or other personal detail. Its sole purpose is to recognize that several page views belong to the same visit, so a visitor's page views can be collapsed into one bot-filtered visit — both for the counts shown in your reports and for the usage meter that determines your plan's billing. It is not used to build a cross-visit profile of the visitor and is not shared or reused across other websites.
This cookie is set only where your visitors' analytics consent permits. It is set independently of the order-to-session matching setting above; unlike the durable visitor identifier, it does not require you to enable durable tracking. Where a visitor has not granted analytics consent, the cookie is not set, and if a visitor withdraws analytics consent ClearSignal clears it from their browser.
Checkout and funnel events via Shopify Web Pixel
ClearSignal registers a Shopify Web Pixel that receives checkout and funnel events from your storefront (see Section 1). This pixel runs in Shopify's sandboxed environment and is gated by Shopify's Customer Privacy controls, so it fires only under the analytics consent your visitors have granted. It does not read information from the visitor's device and does not set any identifier of its own. It receives Shopify's own first-party visitor identifier (clientId), which ClearSignal uses to match completed orders to the sessions that preceded them and to measure bot-versus-human movement through your store's funnel, within your store only.
No cross-site tracking
None of these techniques track visitors across different websites or link a visitor's activity on your store to their activity elsewhere. All collected signals are used solely for bot detection and order attribution on your store.
Your responsibilities as merchant
By enabling the App's storefront extension, you represent that your store's privacy policy and consent mechanisms adequately disclose the use of browser fingerprinting, behavioral analysis, and local-storage-based durable visitor identification for bot detection and order attribution purposes, and that your store's consent management (via Shopify's Customer Privacy API) is configured to reflect your visitors' choices. You are responsible for compliance with applicable privacy laws regarding your store's visitors.
10. Children's Privacy
The App is designed for use by Shopify merchants (business users) and is not directed at children under 13. We do not knowingly collect personal data from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date at the top of this page. Continued use of the App after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have questions about this Privacy Policy or want to exercise your data rights, contact us at: