Privacy policy

Last updated: October 6, 2026

Upshot is a Shopify app operated by leoworks (“we”). This policy explains what Upshot reads, stores and shares when a merchant installs it, and how that data is protected and deleted. It applies to the Upshot app and this website.

Summary

  • Upshot reads store totals (visits, orders, sales) to compare experiment variants. It doesn't store them.
  • Upshot doesn't read or store individual customer records — no names, emails, phone numbers or addresses.
  • We don't sell or rent data, and we don't use it for advertising.
  • Everything stored for a store is deleted when Shopify asks us to after the app is uninstalled.

Data we read from your store

  • Sales and visit totals per experiment variant and day range — sessions, conversions, orders, gross and net sales, discounts, product costs and profit. These are read when you open an experiment and aren't saved.
  • Experiments (rollouts), discounts, theme publishes and product prices, to keep the change log and add chart annotations.

Shopify only lets an app run these sales reports if it is approved for protected customer data, including name, email, phone and address fields. Upshot holds that permission for this reason only: it asks for totals and never requests customer-level rows or contact details.

Data we store

WhatWhyKept until
Store domain and the app's access tokenTo connect to your storeThe app is uninstalled
Change log entries (titles and times of experiments, discounts, theme publishes, price changes)Change log and chart annotationsShopify's shop data deletion request
Current product variant pricesTo detect price changesShopify's shop data deletion request
Your experiment notes and settingsShown back to you in the appShopify's shop data deletion request
Saved results of written-judgment checks (see below)To avoid repeating the same requestShopify's shop data deletion request
Access log: store, action, experiment and time each time the app reads sales or visit totalsSecurity and auditOne year, or Shopify's shop data deletion request

Upshot doesn't store staff names or emails. Shopify sends the shop data deletion request 48 hours after the app is uninstalled.

Who we share data with

  • Shopify — Upshot runs inside Shopify admin and adds annotations to your Analytics charts.
  • Cloudflare — hosts the app and its database (service provider).
  • TypeSafe — an AI service that answers three written questions about an experiment (which metric matters most, which other store changes might have affected it, whether the result supports your hypothesis). It receives the experiment name, per-variant totals and rates, the titles of other store changes during the test and your hypothesis text. It receives no customer data.

We share data with no one else, unless the law requires it.

This website

This site sets no cookies and uses no analytics or advertising trackers. When you click an install link, we record which link was clicked and when — nothing about you, your device or your IP address.

Security

Data is encrypted in transit and at rest. Access is limited to the operator, whose accounts use two-factor authentication. Test and production data are kept apart. If a security incident affects your data, we will notify you and Shopify without undue delay.

Your choices and rights

  • Turn chart annotations off, or delete them, from the app at any time.
  • Uninstall the app to stop all access; stored data is then deleted as described above.
  • To ask what we hold about your store, or to have it deleted sooner, email leodev19lee@gmail.com.
  • Customer data requests sent through Shopify are answered automatically: Upshot holds no customer records.

Changes

If we change how Upshot handles data, we will update this page and the date above. Material changes will be announced in the app before they take effect.

Contact

leoworks — leodev19lee@gmail.com