Privacy policy
Last updated: July 18, 2026
Perzaz ("we", "us") provides storefront personalization and assessment software to e-commerce merchants ("merchants"). This policy explains what we collect, why, and the choices available to you — whether you are a merchant using our app or a visitor to a merchant's store where Perzaz runs.
Data we process on merchant storefronts
When Perzaz runs on a merchant's store, we act as a service provider to that merchant and process:
- A first-party visitor identifier (a random ID stored in a cookie and local storage on the merchant's domain). It contains no personal details.
- Occupational interest signals — for example that a visitor engaged with content for nurses or firefighters — expressed as scores against a fixed, merchant-approved list of occupational categories.
- Engagement and campaign data — page views, reading behavior, UTM parameters, and advertising click identifiers where permitted.
- Purchase funnel events (add to cart, checkout) via the merchant's Shopify pixel, without payment details.
Collection respects Shopify's Customer Privacy consent signals: where consent is required and not given, we do not store or transmit this data.
Assessments and health-adjacent information
Merchants can offer wellness-style assessments built with Perzaz. We designed this feature so that Perzaz does not store your answers or scores:
- Your answers are scored in your browser; your result is shown to you on screen.
- If you request an emailed report, your score summary is transmitted directly to the merchant's email platform (such as Klaviyo) or sent as a one-time email on the merchant's behalf — and is not retained in Perzaz's database.
- We store only your occupational category (e.g. "healthcare") and a one-way cryptographic hash of your email address — never the answers, scores, or your raw email.
The merchant is the controller of any report you request; their own privacy policy governs how they use it.
Data we process for merchants
- Shopify account/session data needed to operate the embedded admin.
- OAuth tokens for integrations the merchant connects (e.g. Klaviyo), stored encrypted at rest and used only to deliver assessment results.
- Contact details submitted through our website forms (name, email, company, message) to respond to inquiries.
Retention
- Storefront event data is deleted after 90 days.
- Visitor profiles and integration tokens persist until the merchant uninstalls Perzaz or requests deletion.
- The visitor ID cookie lasts up to 400 days.
Sharing
We do not sell personal information. We share data only with infrastructure processors that host and operate the service (Supabase, Fly.io, Cloudflare), with email and marketing platforms at the merchant's direction (Klaviyo, Resend), and where required by law.
Your choices
- Visitors: use the store's cookie/consent controls; clearing cookies removes the Perzaz identifier. Contact the merchant to exercise data rights over their records.
- Merchants: uninstalling Perzaz removes your session; you may request deletion of all shop data at any time.
- Anyone: email privacy@perzaz.com with questions or requests.
Changes
We'll update this page when our practices change and revise the date above. Material changes will be announced to merchants in the app.