Privacy Policy
Digital Studio by Alphalyr — Last updated: June 1, 2026
1. Overview
Digital Studio ("the App") is a Shopify attribution app developed by Alphalyr. It connects Shopify orders with Alphalyr's server-side tracking (S2S) service to measure marketing attribution for merchants who install it. Alphalyr acts as a data processor on behalf of the merchant (the data controller).
2. Data We Collect
When the App is installed on a Shopify store, it collects the following data from store visitors and orders:
- Visitor fingerprint UUID — a pseudonymous identifier computed server-side by hashing the visitor's IP address, Alphalyr account ID, and user agent string (SHA-256). No identifier is stored in the visitor's browser.
- IP address — collected from the request headers when a visitor beacon is received. Stored in our database for up to 30 days and used to match visitors to orders placed from the same device. Also used as an input to the fingerprint hash.
- User agent — browser and device string, used as part of the fingerprint hash. Not stored separately.
- UTM and click parameters — campaign tracking parameters (utm_source, utm_medium, utm_campaign, utm_content, utm_term) and advertising click IDs (gclid, fbclid, msclkid, gad_source, and Alphalyr-specific et_* parameters) captured from the page URL.
- Page path and referrer — the URL path visited and the referring URL.
- GDPR consent flags — whether the visitor has consented to analytics and advertising tracking, as reported by the store's consent management platform. The App integrates with Cookiebot, OneTrust, CookieYes, UserCentrics, iubenda, Pandectes, Termly, IAB TCF v2, and Shopify's native Customer Privacy API. Consent flags are forwarded with every attribution event.
- Customer ID — Shopify's numeric customer ID, stored in our database when the visitor is identified as a logged-in customer. Forwarded to Alphalyr as a SHA-256 hash (one-way, not reversible) and only when analytics consent has been given.
- Device type — mobile, tablet, or desktop, derived from the user agent string. Collected only when analytics consent is given. Not stored in our database; forwarded directly to Alphalyr.
- Product and category browsing data — product ID, handle, and price; category ID and URL slug — collected when a visitor views a product or collection page. Not stored in our database; forwarded directly to Alphalyr.
- Order data — order number, line items (variant ID, quantity, unit price), revenue, shipping, tax, discounts, discount codes, payment method, and currency. Collected via Shopify's
orders/create webhook at the moment an order is placed.
3. How We Use This Data
- To attribute Shopify orders to marketing campaigns on behalf of the merchant.
- To forward attribution data to Alphalyr's S2S API (
alphalyr.com) for reporting in the merchant's Alphalyr dashboard. Data forwarded includes: visitor fingerprint UUID, IP address, user agent, UTM/click parameters, page path, referrer, device type, product/category data, SHA-256 hashed customer ID (with consent), and order details. Alphalyr's own privacy policy governs downstream processing.
- We do not sell data to third parties. We do not use the data for advertising purposes of our own.
4. Data Retention
- Visitor hit records (fingerprint UUID, IP address, UTM parameters, customer ID, GDPR consent) are retained for a maximum of 30 days.
- Alphalyr configuration (tracking URL and account ID) is retained while the App is installed.
- Shopify session tokens are deleted immediately upon app uninstall.
- All remaining data (visitor records, configuration, sessions) is deleted within 48 hours of the App being uninstalled, in response to Shopify's
shop/redact GDPR webhook.
5. GDPR, CCPA & Your Rights
If you are a customer of a store using this App and wish to request access to, correction of, or deletion of your personal data, please contact the store directly. The store is the data controller. Alphalyr acts as a data processor on their behalf.
Merchants may submit data erasure or data portability requests to tech@alphalyr.com. We will respond within 30 days.
California residents: under the CCPA, you have the right to know what personal information is collected, to request deletion, and to opt out of sale. We do not sell personal information. Requests may be directed to tech@alphalyr.com.
6. Data Security
All data is transmitted over HTTPS. Customer identifiers are forwarded to Alphalyr as SHA-256 hashes only. IP addresses are stored temporarily and purged after 30 days. We do not store payment card information or Shopify passwords.
7. International Data Transfers
Our servers are hosted in the European Union. Data forwarded to Alphalyr's S2S API is processed by Alphalyr in accordance with their data processing agreement and applicable data protection law.
8. Contact
For privacy-related questions, contact us at tech@alphalyr.com or visit alphalyr.com.