Privacy Policy
Last updated October 1, 2026
The short version. Noluco is a Shopify app. It notices how shoppers browse a store (for example, how long the shipping section stayed open) and tells the store why shoppers left. It never collects names, email addresses, phone numbers, postal addresses, payment details or anything a shopper types. It only runs after the shopper accepts the store's cookie banner.
1. Who we are
Noluco is a product of 8-FigureFellowship Inc., a Wyoming corporation ("Noluco", "we", "us"). Contact: vuk@8-figurefellowship.com.
We act in two roles:
- For shopper data, we are a processor (service provider) for the Shopify store that installed Noluco. The store decides to use Noluco and is responsible for telling its shoppers. Questions about a store's use of your data are best sent to that store.
- For merchant account data (the store's details and settings), we are the controller.
2. What we collect about shoppers
Only on stores that installed Noluco, and only after the shopper allowed analytics cookies through the store's cookie banner (Shopify's Customer Privacy API):
- A random visitor number we create and store in a first-party cookie on the store's domain.
- Identifiers other services already placed on the store: Meta's browser and click IDs (
_fbp, _fbc), Google's click ID (gclid), and Klaviyo's link code (_kx). These are random codes. We cannot turn them into a name or email.
- For logged-in shoppers, the Shopify customer number (not the name or email).
- Browsing signals: which product pages were viewed, which sections were opened or read (price, shipping, returns, size chart, reviews, subscription) and for how long, size or variant changes, whether an item was added to the cart, and phone or computer.
- Checkout progress: which checkout steps were reached and when, reported by Shopify. Never the content of any checkout field.
- Technical data: the browser's user agent and request times.
We never collect: names, email addresses, phone numbers, postal addresses, payment details, anything typed into forms or search, screen recordings, mouse trails, or data from shoppers who declined cookies.
3. What we collect about merchants
- The store's Shopify domain and the access Shopify grants the app when it is installed.
- The name and email of the store staff member who opens the app, as provided by Shopify.
- The store's Noluco settings, and API keys for services the store connects (such as Klaviyo). Keys are stored encrypted.
- A log of actions taken in the store's connected accounts and who approved them.
4. How we use it
- To work out why shoppers left without buying, and show the store a daily report.
- Only if the store connects them, and only for shoppers who allowed marketing cookies: to send the reason, together with that service's own random code, to the store's Klaviyo, Meta or Google account, so the store can reach the shopper with an answer through those services.
- To run, secure and improve Noluco.
We do not sell personal data. We do not use shopper data to train AI models. Where we use an automated model to classify browsing, it receives browsing signals only, never identifiers.
5. Who we share it with
- Service providers that run Noluco: Vercel (hosting, Frankfurt region), Supabase (database, Frankfurt), Shopify (platform).
- Services the store connects, as described in section 4: Klaviyo, Meta and Google. They receive the reason plus their own code, and match it to a person inside their own systems under their own privacy policies.
- Authorities, if required by law.
6. How long we keep it
- Raw browsing signals: 90 days.
- The diagnosed reason per visit (used for reports): 13 months.
- Records of actions in connected accounts: 24 months.
- When a store uninstalls Noluco, its connected API keys are deleted immediately and all of its data is deleted when Shopify sends the shop deletion request (about 48 hours later).
7. Your choices and rights
- Shoppers: decline or withdraw consent in the store's cookie banner and Noluco stops and deletes its cookies on your device. To have data deleted, ask the store: Shopify forwards the request to us and we delete it. Because we don't know your name or email, the store is the one that can identify your data. See data deletion.
- Depending on where you live (for example the EU, UK or California), you may have rights to access, delete or correct data, or to opt out of sharing for cross-context behavioral advertising. Noluco honors the opt-outs the store's cookie banner records, including Global Privacy Control where the store supports it.
- Merchants: email us for a copy of your account data or to delete it, or uninstall the app.
8. Security and transfers
Data is encrypted in transit, stored in the EU (Frankfurt), and connected API keys are encrypted at rest. Access is limited to people who need it to run Noluco. Where data moves between the EU and the US, we rely on the safeguards our service providers offer, such as standard contractual clauses.
9. Children
Noluco is a business tool for stores. It is not directed at children.
10. Changes
We will post changes here and update the date above. Material changes are announced to merchants in the app.