Skip to content
Live Shoppers
  • Features
  • Shop together
  • Pricing
  • FAQ
  • Help
Add to your store
  • Features
  • Shop together
  • Pricing
  • FAQ
  • Help
Add to your store

Privacy policy

Last updated: [date]

On this page

  1. Our role
  2. Data we process
  3. Why we process it
  4. How long we keep it
  5. Who else processes it
  6. Security
  7. Your rights
  8. Changes
  9. Contact

Live Shoppers: Visitor Counter (“Live Shoppers”, “the app”) is a Shopify app made by [Company legal name], [registered address], registered with the Dutch Chamber of Commerce under number [KvK number] (“we”, “us”). This policy explains what data the app processes, why, and for how long.

1. Our role

For data about a store’s visitors and orders, the merchant who installs the app is the controller and we are the processor: we process that data only to provide the app to the merchant, on the merchant’s instructions (see our terms, section 7). For data about the merchant’s own account with us, we are the controller.

2. Data we process

About the store

  • The store’s myshopify.com domain, timezone and currency, and which of our plans it is on.
  • An access token issued by Shopify so the app can work with the store. It is stored encrypted (AES-256-GCM).
  • The merchant’s settings, campaigns and storefront texts.

About store visitors

Visitors are anonymous. The app never asks for, receives or stores a visitor’s name, email address, phone number or address.

  • Live presence: while a visitor has a page open, their browser keeps a connection to our realtime server and sends which page they are on; on desktop, where their pointer is and their clicks; on phones and tablets, which part of the page is on their screen and where they tap (all relative to elements on the page); and when they add a product to the cart. Other visitors on the same page receive this under a random name (e.g. “Fox”). These positions are not stored; they exist only in memory while the page is open.
  • Counts: how many visitors are on a page or on the store, how many products were added to carts or sold in the last hour. Kept in memory, per product, for at most one hour. For “38 viewed today”, our realtime server also remembers, for at most 24 hours and in memory only, which products a visit has looked at (by the visit’s random key), so each visit counts once; only the number per product and hour is stored.
  • Statistics: hourly totals per store (sessions, product views, add-to-carts, orders, revenue, the most visitors at once), without any identifier of a visitor.
  • Network data: like any web service, our servers see a visitor’s IP address and browser type while connected. The app does not store them. [Confirm the retention of hosting and proxy access logs, if any.]

Shop together (shared carts)

On stores that offer it, a visitor can start a shared cart and invite friends with a link; friends add products to that visitor’s cart. For this the app keeps, per shared cart: a random code, the cart’s identifier (encrypted), and a timeline of what happened (joined, which product was added or removed and its price, checked out), with members known only as Host and Friend 1, 2… and their random animal. Names that visitors type for their group, and the group’s chat messages and product shares, are sent only to the other members’ browsers and kept in our realtime server’s memory for at most 24 hours (so a reloaded page shows the conversation); they are never stored, and the merchant sees only how many messages were sent. When the host checks out, the order is matched to the shared cart through the cart attribute _shopper_cursors_group, and its order number and total are kept with it. When the store offers a reward for shopping together (free shipping or a discount), the host’s cart also carries _sc_reward, a signed code for the shared cart (no personal information), which the store’s checkout checks before applying the reward; what the reward took off the order is kept with the shared cart. When a member adds to or removes from the shared cart, their IP address is passed on to Shopify with that request only, as Shopify asks, so its abuse protection counts each shopper; we don’t keep it.

About orders

To show live sales (“12 sold in the last hour”, “size M just sold out”) and to report on campaigns, the app receives new orders from Shopify limited to: the order id and number, the ordered products and quantities, the order total, the discounts applied to it, and the order’s cart attributes. Customer details are not included in what we request from Shopify. From the cart attributes, only the app’s own attributes (_shopper_cursors, _shopper_cursors_seen and _shopper_cursors_group) are read; the rest is discarded.

Browser storage on the storefront

The app stores these items in the visitor’s browser. It sets no cookies and uses no third-party trackers.

  • shopper-cursors:token (session storage): a short-lived key that lets the browser connect to our realtime server.
  • shopper-cursors:visitor (local storage): a random key for the current visit, shared by the browser’s tabs, so a visitor keeps the same random name and color from page to page and counts as one shopper however many tabs are open. A new visit (after 30 minutes without the store open) gets a new key, so it doesn’t follow anyone from visit to visit.
  • shopper-cursors:session (local storage): when the store was last open in this browser, to count a visit once and tell when a new one starts. shopper-cursors:cart-tag (session storage): marks that the cart was tagged.
  • shopper-cursors:together (local storage, only while in a shared cart): the shared cart’s code, the member’s key and the name they chose. Removed when the shared cart ends, and after 24 hours at most.
  • shopper-cursors:group (local storage, only on stores using impact measurement): whether the visitor is in the control group. The same value is added to the cart as the attribute _shopper_cursors.
  • shopper-cursors:seen (session storage): marks that the visitor was shown something live in this visit (other shoppers, viewer badges, the live corner or the product block). Once the cart has something in it, the cart gets the attribute _shopper_cursors_seen, so the merchant can see how many orders came from shoppers who saw Live Shoppers. It says nothing about the visitor beyond that.

Merchants can make the app wait for the visitor’s consent through Shopify’s Customer Privacy API (on by default). Until consent is given, the app does not connect or store anything.

3. Why we process it

To provide the app’s features to the merchant (live cursors, viewer badges, shopper activity, campaigns and reports), to keep the service secure and working, and to bill for it through Shopify. We do not sell data, use it for advertising, or combine it across stores.

4. How long we keep it

Pointer and screen positions, clicks and taps, who is on which pageOnly in memory while the page is open
Add-to-cart and sales counts per product1 hour (in memory; sales also in our database for 2 hours)
Shared carts (Shop together) and their timelines90 days; names typed by visitors are never stored
Order lines waiting to be countedAt most 1 hour
Hourly statistics per store90 days
Store settings, campaigns, access tokenWhile the app is installed; deleted when Shopify asks us to, 48 hours after uninstall
Database backups7 days

5. Who else processes it

  • Hetzner Online GmbH (Germany), which hosts our servers and database in its data center in the United States.
  • Shopify, the platform the app runs on, which handles installation, billing and the order data it sends us.

International transfers

Our servers are in the United States, so data from stores and visitors in the European Economic Area, the United Kingdom and Switzerland is transferred there. We protect these transfers with the European Commission’s Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) [and the UK Addendum / Swiss amendments] in our agreement with our hosting provider. [Confirm the transfer mechanism with counsel.]

What is transferred is limited by design: visitors stay anonymous, pointer and screen positions are never stored, and order data is reduced to products, quantities and totals. The data is encrypted in transit, and access tokens are also encrypted at rest.

We will inform merchants before adding a new subprocessor.

6. Security

All connections are encrypted (HTTPS/WSS). Access tokens are encrypted in our database. Only [the people who operate the app] have access to the servers. The database is backed up nightly. If we become aware of a breach affecting a merchant’s data, we inform that merchant without undue delay.

7. Your rights

Visitors of a store should contact that store first, as the controller. We support merchants in answering requests; Shopify’s data request and deletion notices reach us automatically, and we act on them. Because visitors are anonymous, we normally hold no data that can be linked to a person. Merchants can contact us at [contact email] to access, correct or delete their data. You can also complain to your data protection authority; in the Netherlands, the Autoriteit Persoonsgegevens.

8. Changes

We will post changes here and inform merchants of material changes in the app or by email.

9. Contact

[Company legal name], [registered address], [contact email].

Live Shoppers

Shoppers see each other on your store, live.

  • Features
  • Pricing
  • FAQ
  • Help
  • Privacy policy
  • Terms
  • Support

© 2026 Live Shoppers

Shopify is a trademark of Shopify Inc. Live Shoppers is not affiliated with or endorsed by Shopify.