Skip to content

Delta Labs policies & help

Privacy Policy

Last updated July 13, 2026

Overview

Delta Labs LLC ("Delta Labs", "we", "us") provides a profit-focused website optimization platform for Shopify merchants. This policy describes how we handle personal and store data when you use delta-labs.co and connect a Shopify store.

We connect to your store via OAuth, optionally deploy a behavioral web pixel, and may create hidden alternate product page templates for optimization tests. You approve changes before they apply to your live storefront.

Our dashboard is hosted on our own domain — not embedded in Shopify Admin.

Data we collect

  • Account data: email address, role, and authentication metadata when you sign up (stored via Supabase Auth).
  • Shopify connection data: shop domain and granted OAuth scopes (for example, themes, pixels, orders, and analytics). Access tokens are stored encrypted in Supabase Vault; we never store them in your browser.
  • Behavioral analytics: session identifiers, product views, time-on-page, page URL, referrer, browser user agent, and UTM parameters via a Shopify Customer Events web pixel (with applicable consent signals). Our pixel does not collect customer names, emails, or phone numbers in behavioral events.
  • Order attribution data:order value, line items, cart attributes, checkout tokens, and related order metadata via Shopify webhooks to attribute orders to optimization test variants. We estimate profit using the merchant's configured margin; when no margin is configured, order revenue is used as a proxy.

How we use data

We do not sell personal data. We use collected data to operate optimization tests, measure estimated profit impact using configured margin assumptions or an order-revenue proxy, provide dashboards, and improve the service.

We exclude sessions with very short time-on-page (under 2 seconds) from analysis to reduce bot and accidental traffic noise.

Shopify & uninstall

When you uninstall the Delta Labs Shopify app, we revoke stored API credentials and disconnect the workspace. While Shopify access remains available, we also attempt to remove the web pixel and registered app-owned hidden theme templates. Shopify may revoke app access before that cleanup finishes, so pixel and theme-asset removal is best-effort. Contact support if a tracked asset remains.

Approximately 48 hours after uninstall, Shopify sends a mandatory shop/redact compliance webhook. We then erase remaining shop-scoped analytics and test records for that store.

GDPR & data subject requests

We comply with applicable privacy laws, including GDPR, via Shopify mandatory compliance webhooks. We respond within 30 days of a valid request.

  • customers/data_request: We provide merchant-held analytics tied to requested orders where applicable. Our pixel does not store customer names, emails, or phone numbers in behavioral events.
  • customers/redact: We delete analytics data and specified order IDs.
  • shop/redact: We delete remaining shop data after uninstall, as described above.

Contact hello@delta-labs.co for access, correction, or deletion requests.

Subprocessors

We use trusted infrastructure providers including Supabase (database, auth, encrypted secrets), Vercel (application hosting), and Shopify (commerce platform APIs) to operate the Service.

Retention

App-owned assets for completed tests become eligible for automated cleanup after 30 days while the app remains installed. On uninstall, Delta attempts immediate removal while Shopify access remains available; that cleanup is best-effort because access may already be revoked. Shop-scoped analytics and test records are removed on shop/redact.

Contact

Privacy questions: hello@delta-labs.co