Privacy policy
Last updated: October 6, 2026
Upshot is a Shopify app operated by leoworks (“we”). This policy explains what Upshot reads, stores and shares when a merchant installs it, and how that data is protected and deleted. It applies to the Upshot app and this website.
Summary
- Upshot reads store totals (visits, orders, sales) to compare experiment variants. It doesn't store them.
- Upshot doesn't read or store individual customer records — no names, emails, phone numbers or addresses.
- We don't sell or rent data, and we don't use it for advertising.
- Everything stored for a store is deleted when Shopify asks us to after the app is uninstalled.
Data we read from your store
- Sales and visit totals per experiment variant and day range — sessions, conversions, orders, gross and net sales, discounts, product costs and profit. These are read when you open an experiment and aren't saved.
- Experiments (rollouts), discounts, theme publishes and product prices, to keep the change log and add chart annotations.
Shopify only lets an app run these sales reports if it is approved for protected customer data, including name, email, phone and address fields. Upshot holds that permission for this reason only: it asks for totals and never requests customer-level rows or contact details.
Data we store
| What | Why | Kept until |
|---|---|---|
| Store domain and the app's access token | To connect to your store | The app is uninstalled |
| Change log entries (titles and times of experiments, discounts, theme publishes, price changes) | Change log and chart annotations | Shopify's shop data deletion request |
| Current product variant prices | To detect price changes | Shopify's shop data deletion request |
| Your experiment notes and settings | Shown back to you in the app | Shopify's shop data deletion request |
| Saved results of written-judgment checks (see below) | To avoid repeating the same request | Shopify's shop data deletion request |
| Access log: store, action, experiment and time each time the app reads sales or visit totals | Security and audit | One year, or Shopify's shop data deletion request |
Upshot doesn't store staff names or emails. Shopify sends the shop data deletion request 48 hours after the app is uninstalled.
Who we share data with
- Shopify — Upshot runs inside Shopify admin and adds annotations to your Analytics charts.
- Cloudflare — hosts the app and its database (service provider).
- TypeSafe — an AI service that answers three written questions about an experiment (which metric matters most, which other store changes might have affected it, whether the result supports your hypothesis). It receives the experiment name, per-variant totals and rates, the titles of other store changes during the test and your hypothesis text. It receives no customer data.
We share data with no one else, unless the law requires it.
This website
This site sets no cookies and uses no analytics or advertising trackers. When you click an install link, we record which link was clicked and when — nothing about you, your device or your IP address.
Security
Data is encrypted in transit and at rest. Access is limited to the operator, whose accounts use two-factor authentication. Test and production data are kept apart. If a security incident affects your data, we will notify you and Shopify without undue delay.
Your choices and rights
- Turn chart annotations off, or delete them, from the app at any time.
- Uninstall the app to stop all access; stored data is then deleted as described above.
- To ask what we hold about your store, or to have it deleted sooner, email leodev19lee@gmail.com.
- Customer data requests sent through Shopify are answered automatically: Upshot holds no customer records.
Changes
If we change how Upshot handles data, we will update this page and the date above. Material changes will be announced in the app before they take effect.
Contact
leoworks — leodev19lee@gmail.com