NudgePilot privacy policy
Last updated September 29, 2026
NudgePilot, a Shopify app and a plugin for WooCommerce, shows shoppers who seem unsure one short message with a store’s own shipping or returns terms, and measures whether that helps. It is operated by Strenvo Trading (KvK 96110910), Burgemeester Hogguerstraat 309, Amsterdam, the Netherlands. This policy explains what NudgePilot collects when a merchant installs or connects it and when shoppers visit that merchant’s store.
What we never store
NudgePilot never stores or logs shoppers’ names, email addresses, phone numbers, postal addresses, IP addresses, customer IDs, order IDs, cart contents, or payment details. It cannot link anything it stores to a person.
Information about shoppers
On a Shopify store, only when a shopper allows both analytics and preferences through the store’s cookie banner (Shopify’s Customer Privacy settings); on a WooCommerce store, only when a shopper allows statistics cookies in a cookie banner that uses the WP Consent API, or, if the store says it doesn’t ask for consent, unless a banner records a refusal, NudgePilot processes:
- a random session ID created in the shopper’s browser tab, which lasts at most 30 minutes;
- counts of actions on the store, such as product and cart views, cart changes, time spent in the cart, and visits to shipping or returns information;
- whether checkout started and a purchase was completed, with the checkout subtotal and currency (on WooCommerce, the order’s items subtotal, reported by the store’s own server once the order is paid);
- which experiment group the session is in and which message, if any, was shown;
- when a store turns on product comparison, the title, price, type, and store-chosen details of up to six products the shopper viewed, kept only in their browser tab and never sent to NudgePilot.
The shopper’s browser keeps the session ID and counts in session storage until the tab closes, and remembers a dismissed message for 7 days (a timestamp only). If a shopper declines or withdraws consent, NudgePilot stops, removes what it stored in session storage, and sends nothing.
On a WooCommerce store, the session ID is also kept in a first-party cookie, for the visit or for 24 hours once checkout starts, so the store can link a paid order to the visit. The store keeps the session ID on that order, on its own site, until it reports the sale to NudgePilot, and at most 48 hours.
Information about merchants
Through Shopify’s APIs, NudgePilot stores the store’s domain and the access token Shopify issues so the app can work, and counts the store’s sessions each month to apply its plan. The shipping and returns facts, message settings, and monthly result totals that a merchant enters or that NudgePilot calculates are saved in the merchant’s own Shopify store, not on our server. NudgePilot does not store staff names or email addresses.
For a WooCommerce store, NudgePilot stores the site’s address, a site ID, the plugin version, and the few settings its server needs (whether it’s on, the store’s currency, returns terms, and whether product comparison is on); shipping facts and other settings stay on the merchant’s own site. Its monthly result totals are kept on our server. Paid plans for WooCommerce stores are sold by Paddle, our reseller, which collects the merchant’s contact and payment details under its own privacy policy; NudgePilot receives only the plan, its status and dates, and Paddle’s customer and subscription IDs.
How we use it
Only to decide when to show the merchant’s message, to compare shoppers who see it with shoppers who don’t, and to report store-wide results to the merchant. We don’t sell data, use it for advertising, or combine it across stores.
Who processes it
| Provider | Purpose | Data |
|---|---|---|
| Fly.io | Hosting in Amsterdam, the Netherlands | Everything NudgePilot’s server stores |
| TypeSafe | Jev, the model that decides when to show a message (called Smart timing in the app). Hosted in the United States, under the EU Standard Contractual Clauses | Action counts only, with no session ID, store name, web address, or amount |
| Shopify | Delivers storefront requests and stores settings and results for Shopify stores | As described above |
| Paddle | Our reseller for WooCommerce paid plans: payment, tax, and invoices, under Paddle’s privacy policy | The merchant’s billing details, which Paddle collects itself; from NudgePilot, only the store’s ID and plan |
How long we keep it
- Per-session records are summarized into store-wide totals and deleted within 48 hours, and are never kept longer than 7 days.
- The store’s access token is kept while the app is installed and deleted when the merchant uninstalls it.
- When a merchant uninstalls NudgePilot, we delete that store’s data from our server as soon as Shopify notifies us, and again when Shopify sends its data deletion request 48 hours later.
- On Shopify, settings and result totals stay in the merchant’s store as private app data that NudgePilot can no longer read after uninstalling; a reinstall starts fresh.
- On WooCommerce, deleting the plugin deletes the store’s data from our server at once. After a disconnect, results are deleted after 30 days unless the store connects again, and a store we haven’t heard from in 90 days is deleted unless it has a paid plan.
- Server backups expire after 14 days.
- Server logs record which address was requested and when, never shopper details, and expire automatically.
Your rights
Because NudgePilot can’t link its data to a person, it has nothing to return or erase for an individual shopper; it still answers every request Shopify forwards. Shoppers can prevent all processing by declining analytics or preferences (on WooCommerce, statistics) in the store’s cookie banner. On WooCommerce, the store’s WordPress export and erasure tools include the session ID kept on orders. Merchants can remove all of their store’s data from NudgePilot’s server by uninstalling the app or deleting the plugin.
Contact
Questions or requests: hamet.gh@gmail.com. Shoppers can also contact the store they visited.
Changes
We’ll update this page and its date when these practices change.