Last updated 13 August 2026
Merchant documentation
Upsell Pilot turns verified Shopify data into visible opportunities, then prepares controlled and reversible experiments. It does not promise uplift and does not treat missing cost or inventory evidence as safe.
Install and onboard
Install Upsell Pilot from its Shopify listing and approve only the scopes shown by Shopify. Open the embedded app, confirm the connected shop and plan, complete the product and order sync, set profit and inventory guardrails, verify the Web Pixel and theme app extension, and run the first read-only scan.
A scan reads the minimum catalogue, order, refund, cost, inventory, publication, and measurement facts needed for an opportunity. It does not edit products, prices, collections, discounts, or the theme. Eligible, incomplete, and blocked findings remain visible with their source period, limitation, and next safe action.
Web Pixel, consent, and privacy
The Shopify Web Pixel records only allowlisted events needed to measure an app-owned experiment. When the required consent is unavailable, the visitor remains in control and Upsell Pilot emits no exposure. Browser events are pseudonymous; a purchase is counted only after a signed cart assignment is reconciled with an authenticated Shopify order.
Mandatory Shopify privacy webhooks handle customer data access, customer redaction, and shop redaction. See the privacy notice, data-processing summary, and subprocessor register.
Opportunities and evidence
Every opportunity is produced by a versioned deterministic rule. Its view names the observation window, source counts, completeness, confidence where applicable, risk, required remediation, and the exact tactic it could prepare. Missing evidence never becomes an estimated uplift.
Association tactics use bidirectional support, confidence, lift, and order-count floors. Inventory, publication, consent, theme, cost, currency, or sample gaps keep the opportunity blocked rather than hiding it.
Experiments and what a winner means
Saving a tactic creates configuration only. Preparing an experiment, approving its launch, and applying it are separate actions. Immediately before launch, Upsell Pilot rechecks the plan, consent-aware measurement, publication, market, profit, inventory, Shopify Function ownership, theme placement, worker health, and rollback evidence.
Eligible visitors receive a stable control or variant assignment for the registered experiment. A winner means the pre-registered binary primary metric passed its fixed horizon, sample, allocation, data-quality, guardrail, and uncertainty rules. Revenue, average order value, or contribution profit is descriptive unless a separately versioned protocol explicitly makes it the inferential metric. “No clear difference” and “insufficient data” are valid outcomes.
Attribution, refunds, and test orders
A Web Pixel checkout event is not purchase authority. Upsell Pilot attributes an order only when the authenticated Shopify order contains the valid app-issued assignment marker and the assignment, shop, experiment, variant, time window, currency, and duplicate checks agree. It does not join purchases by amount-and-time similarity.
Test, cancelled, ineligible, or duplicate orders do not support a decision. Partial and full refunds update refund-adjusted net revenue and contribution evidence. A late refund remains visible and can invalidate an apparent result.
Contribution profit and incomplete costs
Contribution evidence starts with authoritative order revenue, discounts, refunds, currency, product cost, and the merchant's versioned shipping, fulfilment, payment, and merchandising cost assumptions. The app shows the source and effective date of each assumption.
Unknown, stale, mixed-currency, or ambiguous cost is never treated as zero. Upsell Pilot may still show factual order and refund evidence, but it labels contribution incomplete and blocks a profit claim or profit-dependent automation until the merchant supplies current evidence.
Inventory and profit guardrails
Merchant guardrails define minimum contribution, maximum discount, inventory floors, and tactic-specific safety limits. Eligibility is checked when recommending, approving, assigning, adding to cart, and executing an app-owned Function where the surface permits it. Sold-out, unavailable, stale, or unknown inventory serves control. A guardrail failure overrides apparent conversion performance and stops the affected treatment.
The ten tactic families
- Product-page sticky add to cart: a theme-native purchase control with variant, quantity, sold-out, keyboard, and fallback checks.
- Product benefit strip: merchant-authored or source-verified benefit copy only; no generated guarantees.
- Product reassurance: verified policy, care, warranty, or sustainability facts without invented urgency or social proof.
- Product pairing: evidence-qualified complementary products with publication, inventory, and variant checks.
- Cart cross-sell: a bounded complementary offer that never duplicates the cart's native submission.
- Free-shipping progress: a truthful merchant threshold and currency-aware progress state.
- Cart value or quantity offer: an app-owned Function with exact threshold, discount, combinability, inventory, and margin controls.
- Gift-with-purchase: a configured gift variant and tier with threshold and stock enforcement; unavailable gifts fail closed.
- Collection merchandising: a proposed ordering remains separate from merchant approval and apply; restore respects intervening merchant edits.
- Thank-you and order-status recommendation: a static supported recommendation or next-order prompt, never misrepresented as an unsupported payment-changing one-click purchase.
Recommend, Approval, Autopilot, and emergency disable
Recommend prepares evidence and drafts without changing Shopify. Approval also requires a separate short-lived merchant approval and a subsequent apply action. Autopilot is optional and remains constrained by the same rule, plan, measurement, cost, inventory, experiment-capacity, and rollback gates. The global emergency switch disables every Upsell Pilot storefront tactic and app-owned Function. Clearing it reopens eligibility only; it does not silently relaunch a treatment.
Stop, keep, reconcile, and restore
Stop removes the active experiment treatment. Keep is available only for a measured, evidence-qualified winner and still requires the appropriate merchant authority. Restore returns the verified app-owned configuration captured before launch. If Shopify's response is lost or remote state differs from both expected states, the operation enters reconciliation and is never blindly repeated or overwritten.
Integrations
Core scanning and experimentation do not require another Fleeta product or OpenAI. An optional integration is inactive until a merchant authorises its implemented, same-shop data boundary. DPP Grid may provide verified product-passport facts; AI Social Share is a manual handoff rather than an automatic posting credential. Optional AI explains cited evidence only and cannot calculate money, inventory, ranking, or winners, or approve and launch a change.
Plans and billing
Plan selection, trials, upgrades, downgrades, cancellation, reactivation, and charges are presented through Shopify App Pricing. Upsell Pilot verifies the active Shopify entitlement on the server before launch or apply and enforces experiment and session limits there. It does not use attributed-revenue fees. The active plan and relevant limits remain visible in the app.
Troubleshooting
- No opportunities: finish the read-only scan and inspect blocked findings for missing order history, cost, inventory, consent, or publication evidence.
- No measurement: verify Customer events, consent, the app pixel, published theme, app embed or block, and the Diagnostics page.
- Launch blocked: read the exact readiness item; do not bypass a plan, worker, dead-letter, approval, Shopify-owner, or rollback requirement.
- Unknown Shopify write: use Reconcile once; do not repeat the mutation.
- Storefront problem: use Emergency disable, then disable the app block or embed in Shopify's theme editor if the embedded app is unavailable.
Uninstall, data access, and support
Before uninstalling, stop experiments and verify control when practical. Shopify's uninstall webhook revokes the installation, stops app-owned runtime work, and enters the authenticated deletion lifecycle. Theme app blocks can also be removed in the theme editor. Reinstall never silently restores an old live treatment.
Verified merchant staff can use the Privacy area for available exports and request status. For help, use the support page. Never send customer personal data, access tokens, passwords, card details, or webhook secrets.