Privacy Policy
This describes the Paceloop app for Shopify: what it reads from your store, what it keeps, where that lives, and when it is deleted. Every statement below reflects what the app actually does.
Last updated: 29 July 2026
Who we are
Paceloop is a growth planning and pace analytics app for Shopify stores. It is the controller of the data described on this page.
Contact us about anything on this page — including access, correction, or deletion requests — at hello@paceloop.app. We reply within one business day.
What Paceloop can access in your store
When you install the app, Shopify asks you to approve three permissions. Paceloop requests no others.
| Permission | What it is used for |
|---|---|
write_reports | Reads your store's sales, sessions, conversion rate, and new-vs-returning customer analytics — these produce your 90-day baseline, the feasibility check on your goal, the constraint diagnosis, and the weekly pace scoreboard. The same permission lets Paceloop write one thing back: a growth target in your Shopify Analytics, mirroring the goal you set in Paceloop so it appears where you already look. Paceloop creates and updates that target; it never deletes one. |
read_products | Product and variant unit costs, used to estimate margin. |
read_inventory | Inventory levels, used as one of the factors when diagnosing what is limiting growth. |
Your store's data stays untouched. The only thing Paceloop can write anywhere in your store is a growth target in Shopify Analytics — the goal you set in the app. It cannot create, edit, or delete products, orders, customers, inventory, themes, or settings, and it is never granted the ability to.
What Paceloop stores
Everything below is stored per store and is never mixed with, or made visible to, another merchant.
| What | Contents |
|---|---|
| Your Shopify session | The access token issued when you installed the app, plus the Shopify staff account's name and email address where Shopify provides them. Managed by Shopify's official session storage library. |
| Your plan record | The identifier of the pricing plan you selected. Kept for bookkeeping only — your access is checked against Shopify's billing API on every request, never against this record. |
| Your app preferences | Interface state such as whether you dismissed the setup guide, plus the most recent snapshot of your pace figures so Sidekick can answer instantly without re-querying your analytics. |
| Your growth cycles | The goal you set, the plan Paceloop proposed, the behaviors and cut list, your weekly check-ins, and the recommendations returned against them — together with snapshots of the aggregated analytics figures behind each of them (totals, rates, averages). |
Paceloop never stores your customers' personal data. No customer names, email addresses, shipping addresses, phone numbers, payment details, or individual order records are read into storage. Only aggregate figures — totals, rates, averages — are kept.
This is why, when Shopify sends us a customer data request or a customer erasure request on a shopper's behalf, we have nothing to return and nothing to erase: no customer-level data about them exists in Paceloop.
Where your data is stored
Paceloop runs on Fly.io in the US-East region (Ashburn, Virginia), with a managed PostgreSQL database. If your store is in the European Economic Area or the United Kingdom, this means your data is transferred to and processed in the United States.
All traffic to the app is encrypted in transit over HTTPS.
Shopify Sidekick
Paceloop can answer questions inside Shopify's Sidekick assistant. When you ask Sidekick about your pace, your constraint, a past cycle, whether a goal is realistic, or for a proposed plan, Sidekick calls Paceloop and Paceloop returns that information to Sidekick so it can answer you.
This only happens when you ask. Paceloop does not push your data to Sidekick in the background. Anything that would change your saved plan is never done from the conversation — you confirm it inside the app.
Shopify's own handling of Sidekick conversations is governed by Shopify's privacy policy, not this one.
Who else sees your data
No one. Paceloop does not sell, rent, or share your store data. It is not sent to any advertising network, data broker, or analytics vendor. It does not train any AI model.
The only parties involved are Shopify, which is where the data comes from, and our hosting provider, which stores it on our behalf under contract.
How long we keep it, and how it is deleted
Your data is kept while the app is installed, so your cycle history stays available to you.
| Event | What happens |
|---|---|
| You uninstall Paceloop | Every record described above is deleted — cycles, behaviors, cut lists, check-ins, preferences, pace snapshots, your plan record, and your session. |
| About 48 hours later | Shopify sends a store erasure request. We run the same deletion again, so that if the first one failed for any reason, nothing is left behind. |
| A shopper requests their data | We confirm there is none to return or erase, because Paceloop holds no customer-level data. |
Deletion is permanent. We keep no archived copy of an uninstalled store's cycles. Routine encrypted infrastructure backups may retain data briefly before rolling off.
Your rights
Depending on where you are, you may have the right to access, correct, export, or erase your personal data, to object to or restrict processing, and to complain to your local data protection authority.
You can exercise the erasure right at any time by uninstalling the app. For anything else, email hello@paceloop.app and we will respond within one business day.
Changes to this policy
If what Paceloop reads, stores, or shares changes, we update this page and change the date at the top. Material changes affecting installed stores will also be communicated in the app.
This website
Separately from the app, paceloop.app is our marketing site. It collects the following:
- The early-access form. If you submit it, your email address, store URL, and your answers on that form are stored in a private Google Sheet and emailed to us. We use them to contact you about Paceloop. We do not sell them or add you to unrelated mailing lists.
- Microsoft Clarity. Records how pages are used — clicks, scrolling, heatmaps. Form input fields are masked, so what you type into the form is never captured by it.
- Vercel Web Analytics. Aggregate page views and referrers. No cookies, no cross-site tracking.
- Google Analytics 4. Page views, referrers, and which buttons on this site get clicked. It sets cookies in your browser to recognise a returning visit. It never receives what you type into the form.
- Campaign attribution. If you arrive via a campaign link, the campaign parameters and referring page are held in your browser's session storage for that visit and attached to a form submission if you make one.
- Calendly. Loads only if you click to book a call, and only then receives the details you give it to schedule the meeting.
To have a form submission deleted, email hello@paceloop.app.