Privacy Policy

Last updated: 28 July 2026

In one paragraph. Savrena is server-side conversion tracking for Shopify stores. Merchants install it on their own store; we receive that store's shopping events and forward them to the advertising and analytics platforms the merchant has configured. We do not sell data, we do not build cross-merchant profiles, and we do not use one merchant's data to serve another. Contact email addresses and phone numbers are hashed in the shopper's browser before they reach us.

1. Who we are

Savrena is operated by 95 Info Services, India ("Savrena", "we", "us"). This policy covers the Savrena website at savrena.com, the Savrena console, the Savrena Shopify app, and the tracking scripts and server endpoints that make up the service.

2. Our role: processor for merchants, controller for accounts

Our role depends on whose data it is.

3. What we collect

3.1 Merchant account data

3.2 Shopper data from the browser pixel

When a merchant enables our storefront pixel, we receive, for each tracked event:

3.3 Shopper data from server webhooks

We also receive events directly from Shopify and, where the merchant uses one, from their third-party checkout provider. This is the part of the service that works when the browser cannot — it is how a purchase is recorded for a shopper who completes checkout off-site or on a device where scripts are blocked.

These webhook payloads are sent to us by Shopify or the checkout provider in their own format, and can contain the customer's plain-text contact details and delivery address. We store the payload as received so that a merchant can audit exactly what arrived and, if needed, replay it. We derive hashed identifiers from it for onward sending. The stored payload is deleted on the merchant's retention schedule (section 8).

3.4 IP address and approximate location

We record the IP address the event arrived from. It is used to derive an approximate country/region/city, and it is forwarded to advertising platforms that require it for conversion matching and fraud checks. We use a local IP-to-location database; no lookup is sent to a third party.

3.5 Website visitors

Our own marketing pages carry no analytics, no advertising tags and no third-party scripts. Standard server logs are kept for security and reliability.

4. How we use data

We do not sell personal data, share it for cross-context behavioural advertising of our own, build profiles that span merchants, or use one merchant's data to benefit another.

5. Who we share data with

Event data is shared with the advertising and analytics destinations that the merchant chooses and connects with their own credentials. Nothing is sent to a destination the merchant has not configured. Depending on that configuration, recipients may include:

Meta (Conversions API) · Google Ads · Google Analytics 4 · Google Tag Manager · Microsoft Advertising · TikTok · Snapchat · Pinterest · Reddit · X · Klaviyo

Each of those platforms acts under its own privacy policy and terms once it receives the data.

We also use a small number of infrastructure providers to run the service — application hosting, managed database hosting, and an email provider for alerts and reports. They process data only to provide their service to us, under contract.

We may disclose data where required by law, or in connection with a merger or acquisition, in which case we will give notice before your data becomes subject to a different policy.

6. Hashing and consent signals

7. The Savrena first-party identifier

Our pixel stores a randomly generated first-party identifier on the store's own domain, valid for up to one year. It contains no personal data and cannot identify anyone by itself. Its only purpose is to connect a later purchase to the earlier visit that led to it — for example an order placed days after an ad click. It is scoped to one merchant's store and is never used to follow a shopper across unrelated sites.

8. How long we keep data

DataRetention
Raw event payloadsMerchant-configurable; 60 days by default, then permanently deleted
Delivery logs and sent payloadsMerchant-configurable; 60 days by default
Hashed identity records and attributionUp to 12 months from last activity, so late-converting orders can still be attributed
Merchant account and audit recordsFor the life of the account, plus what we must keep for legal and accounting purposes

Uninstalling the app or closing the account deletes the associated store data.

9. Shopify data requests and deletion

We implement Shopify's mandatory compliance webhooks:

10. Your rights

Depending on where you live, you may have rights to access, correct, delete, port or restrict the processing of your personal data, and to object to it or withdraw consent.

Shoppers: please contact the store you shopped with. They are the controller of your data and we act on their instructions; we will assist them in responding to you.

Merchants and account holders: contact us directly using the details in section 14.

11. Security

No system is perfectly secure, and we cannot guarantee absolute security.

12. International transfers

We are based in India, and our infrastructure providers may process data in other countries. The advertising platforms a merchant connects to are largely US-based and operate globally. Where required, transfers rely on appropriate safeguards such as the European Commission's standard contractual clauses.

13. Children

The service is not directed to children, and we do not knowingly collect their personal data.

14. Changes and contact

If we make a material change to this policy we will update the date at the top and, for significant changes, notify account holders by email.

Questions, requests, or privacy concerns: 95dott@gmail.com
95 Info Services, India