Shopper Privacy

Sometimes a shopper asks you to show or delete the data you hold about them. This might be a GDPR "right to be forgotten" request, a CCPA deletion request, or another subject access request. A vs B gives you two actions on any project to answer this: erase one shopper, or export a copy of everything stored about them.

If you run a Shopify store, A vs B already handles Shopify's three mandatory privacy webhooks (automatic messages Shopify sends when something happens). You do not need to set anything up.

What A vs B stores about a shopper

Every shopper is identified by a visitor ID: a random, anonymous ID the snippet assigns in the browser and stamps on everything that shopper does. Under that ID, A vs B may hold:

  • Tracking events: page views, clicks, and custom events.
  • Metric events: the conversion and revenue signals your experiments measure, plus segment labels like cart_band and purchaser. Those two are sent automatically once a running experiment targets shoppers by cart value or purchase history.
  • Orders and their line items: the purchases used for revenue and attribution.
  • Profit records: the nightly profit figures for that shopper's orders.
  • Error diagnostics: technical logs tied to that shopper's sessions.
  • Visitor profile: a small summary (has purchased before, order count, lifetime spend). Commerce audiences (visitor groups defined by shopping behavior, like repeat buyers) use this profile to target shoppers.

Erasing a shopper removes all of the above for that one visitor ID, and nothing for anyone else.

Erasure is immediate: retention is separate

Erasure happens right away, whenever you ask. That is different from automatic retention: a timer that hides old data from your reports once your plan's window passes. That window runs from 90 days on Free up to 730 days on our largest plans. You never wait for retention to catch up before honoring a deletion request.

Both actions start the same way: open Project Settings → Privacy and enter the shopper's Visitor ID. Export a copy assembles everything A vs B holds for that shopper into one downloadable file, without deleting anything. Erase this shopper asks you to confirm, then permanently deletes their data. Every erasure and export you run shows up under Recent privacy jobs, including a job that reads "Erased 0 records." when there was nothing to remove.

Erase a shopper

Click Erase this shopper, then confirm. A vs B queues a background job that deletes the shopper's events, metric events, orders, line items, profit records, error diagnostics, and visitor profile. The job appears under Recent privacy jobs and finishes with a count of how many records it removed. Even a shopper with no stored data produces a job that reads "Erased 0 records.", so you always have proof the request was actioned.

Erasure is permanent and cannot be undone.

Export a shopper

Click Export a copy. A vs B assembles everything it holds for that shopper into a single downloadable file. When the job finishes, a Download link appears on it. The export is exactly the footprint that erasure would remove, so it doubles as a preview of what a deletion would cover.

Export files are sensitive and expire

An export contains a shopper's personal data. Only your team, signed in to the dashboard, can use the download link. The file deletes itself after 7 days, so request a fresh export if you need it again.

Finding a shopper's visitor ID

The visitor ID is the avsb_vid value stamped on the shopper's orders and events. On a Shopify store it rides the order as a cart attribute; you can also look it up on the Orders health page. If a shopper contacts you by email, match them to an order first, then use that order's visitor ID.

Shopify compliance webhooks

The Shopify App Store requires every app to answer three privacy webhooks. A vs B declares and handles all three automatically: you do not need to do anything.

Shopify webhookWhat A vs B does
customers/redactErases every shopper (visitor) tied to the named orders, and the named orders themselves.
customers/data_requestExports the data held for every shopper tied to the requested orders.
shop/redactPurges all commerce data for the store: sent by Shopify about 48 hours after the app is uninstalled.

Each webhook is verified as genuinely from Shopify, mapped to your project, and turned into the same background jobs as the manual actions above. A request that matches no data we hold is still acknowledged, so it never fails silently on Shopify's side.

Uninstalling is not the same as shop redact

Uninstalling the app stops new data from coming in and turns off its webhooks. Your historical data stays until Shopify separately sends shop/redact, typically about 48 hours after uninstall. That message is what triggers the full purge.

Was this helpful?