Privacy Policy
Last updated: 28 July 2026
In one paragraph. Savrena is server-side conversion tracking for Shopify stores. Merchants install it on their own store; we receive that store's shopping events and forward them to the advertising and analytics platforms the merchant has configured. We do not sell data, we do not build cross-merchant profiles, and we do not use one merchant's data to serve another. Contact email addresses and phone numbers are hashed in the shopper's browser before they reach us.
1. Who we are
Savrena is operated by 95 Info Services, India ("Savrena", "we", "us"). This policy covers the Savrena website at savrena.com, the Savrena console, the Savrena Shopify app, and the tracking scripts and server endpoints that make up the service.
2. Our role: processor for merchants, controller for accounts
Our role depends on whose data it is.
- Shopper data — we are a processor. When a shopper browses or buys from a merchant's store, the merchant is the controller of that data. We process it only to carry out the merchant's tracking configuration, on their instructions. The merchant is responsible for having a lawful basis, for their own privacy notice, and for collecting consent where it is required.
- Merchant account data — we are the controller. For the account details of the merchant or agency using our console (name, email, store connection, billing status), we decide the purposes and are the controller.
3. What we collect
3.1 Merchant account data
- Account email address and password hash
- Organisation and store names, Shopify store domain and access token
- Destination credentials you enter (advertising platform access tokens, API keys, conversion IDs) — stored encrypted at rest
- An audit log of configuration changes made in the console
- Optional alert and report email addresses
3.2 Shopper data from the browser pixel
When a merchant enables our storefront pixel, we receive, for each tracked event:
- Page URL, referrer, event name, timestamp, and product/order details such as item IDs, quantities, value and currency
- Advertising click identifiers present in the URL or in first-party cookies set by the advertising platforms (for example
gclid,wbraid,gbraid,fbclid,_fbp,_fbc) and UTM campaign parameters - A first-party Savrena identifier (see section 7)
- Browser user agent and screen characteristics
- Hashed contact details — where the shopper has provided an email address or phone number to the store, the pixel applies a SHA-256 hash in the browser before transmission. The plain-text value never leaves the shopper's device via the pixel.
3.3 Shopper data from server webhooks
We also receive events directly from Shopify and, where the merchant uses one, from their third-party checkout provider. This is the part of the service that works when the browser cannot — it is how a purchase is recorded for a shopper who completes checkout off-site or on a device where scripts are blocked.
These webhook payloads are sent to us by Shopify or the checkout provider in their own format, and can contain the customer's plain-text contact details and delivery address. We store the payload as received so that a merchant can audit exactly what arrived and, if needed, replay it. We derive hashed identifiers from it for onward sending. The stored payload is deleted on the merchant's retention schedule (section 8).
3.4 IP address and approximate location
We record the IP address the event arrived from. It is used to derive an approximate country/region/city, and it is forwarded to advertising platforms that require it for conversion matching and fraud checks. We use a local IP-to-location database; no lookup is sent to a third party.
3.5 Website visitors
Our own marketing pages carry no analytics, no advertising tags and no third-party scripts. Standard server logs are kept for security and reliability.
4. How we use data
- To deliver conversion and analytics events to the destinations the merchant has configured
- To deduplicate events so a single purchase is not counted twice across browser, server and checkout sources
- To attribute an order to the marketing touchpoints that preceded it, and to produce the merchant's reports
- To show the merchant the exact payload we sent to each destination, and to reconcile it against their real orders
- To detect bot and invalid traffic so it is not sent onward as a real event
- To operate, secure, support and bill the service
We do not sell personal data, share it for cross-context behavioural advertising of our own, build profiles that span merchants, or use one merchant's data to benefit another.
5. Who we share data with
Event data is shared with the advertising and analytics destinations that the merchant chooses and connects with their own credentials. Nothing is sent to a destination the merchant has not configured. Depending on that configuration, recipients may include:
Meta (Conversions API) · Google Ads · Google Analytics 4 · Google Tag Manager · Microsoft Advertising · TikTok · Snapchat · Pinterest · Reddit · X · Klaviyo
Each of those platforms acts under its own privacy policy and terms once it receives the data.
We also use a small number of infrastructure providers to run the service — application hosting, managed database hosting, and an email provider for alerts and reports. They process data only to provide their service to us, under contract.
We may disclose data where required by law, or in connection with a merger or acquisition, in which case we will give notice before your data becomes subject to a different policy.
6. Hashing and consent signals
- Email addresses and phone numbers collected by the pixel are SHA-256 hashed in the shopper's browser. Our identity records store the hash, not the address.
- Phone numbers are normalised to E.164 before hashing so the same number matches consistently.
- Consent signals are carried through. Where a merchant's storefront supplies Consent Mode v2 values, we attach
ad_user_dataandad_personalizationto the conversions we upload, and the receiving platform applies them. - Honouring shopper consent on the storefront is the merchant's responsibility, using their consent banner or Shopify's customer-privacy settings.
7. The Savrena first-party identifier
Our pixel stores a randomly generated first-party identifier on the store's own domain, valid for up to one year. It contains no personal data and cannot identify anyone by itself. Its only purpose is to connect a later purchase to the earlier visit that led to it — for example an order placed days after an ad click. It is scoped to one merchant's store and is never used to follow a shopper across unrelated sites.
8. How long we keep data
| Data | Retention |
|---|---|
| Raw event payloads | Merchant-configurable; 60 days by default, then permanently deleted |
| Delivery logs and sent payloads | Merchant-configurable; 60 days by default |
| Hashed identity records and attribution | Up to 12 months from last activity, so late-converting orders can still be attributed |
| Merchant account and audit records | For the life of the account, plus what we must keep for legal and accounting purposes |
Uninstalling the app or closing the account deletes the associated store data.
9. Shopify data requests and deletion
We implement Shopify's mandatory compliance webhooks:
shop/redact— we permanently purge all of that shop's data.customers/redactandcustomers/data_request— we hold no plain-text personal data keyed to an individual Shopify customer ID in our identity records, so there is nothing to return or erase per customer beyond the raw payloads that age out under section 8.
10. Your rights
Depending on where you live, you may have rights to access, correct, delete, port or restrict the processing of your personal data, and to object to it or withdraw consent.
Shoppers: please contact the store you shopped with. They are the controller of your data and we act on their instructions; we will assist them in responding to you.
Merchants and account holders: contact us directly using the details in section 14.
11. Security
- All data is transmitted over TLS.
- Destination credentials are encrypted at rest with authenticated encryption; they are never displayed back in full once saved.
- Console access is protected by password, and administrative access additionally requires time-based two-factor authentication.
- Access to production data is limited to the personnel who need it to operate the service.
No system is perfectly secure, and we cannot guarantee absolute security.
12. International transfers
We are based in India, and our infrastructure providers may process data in other countries. The advertising platforms a merchant connects to are largely US-based and operate globally. Where required, transfers rely on appropriate safeguards such as the European Commission's standard contractual clauses.
13. Children
The service is not directed to children, and we do not knowingly collect their personal data.
14. Changes and contact
If we make a material change to this policy we will update the date at the top and, for significant changes, notify account holders by email.
Questions, requests, or privacy concerns: 95dott@gmail.com
95 Info Services, India