Last updated 13 August 2026
Privacy notice
This notice explains how Fleeta Limited processes merchant and store data when providing Upsell Pilot. Product features do not request or use optional customer name, email, phone, address, payment, or raw-profile fields. Shopify's mandatory privacy deliveries can nevertheless contain direct identity inside a short-lived encrypted raw envelope.
Controller and contact
Fleeta Limited (company 16675897), 50 Princes Street, Ipswich, England, IP1 1RJ operates Upsell Pilot. Privacy questions and rights requests can be sent to vytautas@fleeta.co.uk.
Data we process
- Shop domain, installation, plan, settings, roles, and audit events.
- Encrypted Shopify access and refresh tokens required to provide the app.
- Minimal product, variant, publication, price, cost, inventory, order-line, discount, and refund fields needed for scans and experiments.
- Exact authenticated Shopify webhook bodies held under purpose-bound encryption for durable processing. A mandatory privacy body can include email or phone even though Upsell Pilot never parses those fields into product records, logs, reports, AI requests, or merchant exports.
- Pseudonymous experiment assignment, consent state, exposures, cart actions, checkout completion, and aggregated results from the Shopify Web Pixel.
- Operational logs with secrets and direct customer identifiers redacted.
- Information voluntarily submitted through the public support form: first and last name, email, store URL, issue description, and an optional attachment. These fields are encrypted; an attachment remains quarantined until a reviewed safety check clears it.
Why we process it
We process data to perform the contract with the merchant, secure the service, prevent duplicate or unsafe changes, provide support, meet legal obligations, and improve reliability. Optional AI and integrations remain off unless the merchant uses them.
Sharing and international transfers
Shopify supplies the platform data. Hosting, backup, monitoring, and optional OpenAI processing act as service providers under contractual safeguards. AI requests use minimised store context, exclude customer personal data, and set response storage off. Upsell Pilot does not sell personal data.
Retention and deletion
Raw pseudonymous measurement events are retained for no more than 30 days, aggregated experiment evidence for up to 25 months, audit records for up to 24 months, and encrypted backups for up to 35 days. Encrypted raw webhook ingress is deleted after successful processing; mandatory privacy ingress has a 30-day processing and retention deadline, with overdue work treated as an operational incident. Uninstall and mandatory Shopify redaction requests trigger tenant deletion or irreversible aggregation, subject to legal and security retention requirements. Public support content is retained only while the case remains open, for no more than 90 days from receipt and no more than 30 days after resolution, whichever is earlier. A receipt is tied to a shop only when its exact active .myshopify.com domain is verified; otherwise it follows the fixed support horizon without a guessed tenant association.
Your rights
Depending on applicable law, individuals may request access, correction, deletion, restriction, portability, or object to processing, and may complain to the UK Information Commissioner. Shopify privacy requests are also processed through Shopify's mandatory webhook process.