Last updated: 6 August 2026
Propel Replays, listed on the Shopify App Store as “Session Recording Now” (the “App”), provides session recording and replay, heatmaps, on-site surveys, AI-generated summaries, and shopper analytics (the “Service”) to merchants who use Shopify to power their stores.
This Privacy Policy describes how personal information is collected, used, and shared when a merchant installs or uses the App in connection with a Shopify-supported store, and when a shopper visits a store where a merchant has enabled the App.
The App is operated by Alcaris Inc., an Ontario corporation doing business as Propel Commerce (“Propel”, “we”, “us”), 170-422 Richards St, Vancouver, BC V6B 2Z4, Canada. You can reach us at support@propelcommerce.io.
There are two distinct populations of people whose personal information is involved, and our legal role is different for each.
Store visitors (shoppers). When a shopper visits a merchant’s Shopify store, the merchant decides that the App will run, what it records, and why. The merchant is the controller under the GDPR and UK GDPR, and the business under the California Consumer Privacy Act as amended by the CPRA (the “CCPA”). Propel is the merchant’s processor and service provider. We process shopper information solely on the merchant’s behalf and on the merchant’s documented instructions, never for our own commercial purposes. The only internal uses we make of that information are the narrow ones privacy laws permit a service provider: securing our systems and preventing fraud, detecting and debugging errors, complying with legal obligations, and maintaining and improving the quality of the Service itself. We do not use it to build profiles for anyone else.
Merchant account and app-usage data. For information about merchants and their staff (account and contact details, billing records, support conversations, and how the App is used inside the Shopify admin), Propel is the controller and business in its own right. We use that information to provide, improve, secure, and market our own services, as described in Section 3.
Our processing of shopper information on a merchant’s behalf is governed by our Data Processing Agreement (the “DPA”), which forms part of our agreement with each merchant and carries the required processor and service-provider terms. Where the DPA and this Privacy Policy conflict on the processing of personal data, the DPA prevails.
When a merchant installs the App, we receive from the merchant’s Shopify account the store domain and general store settings, plus the name, email address, and other contact details of the people who install or administer the App. We also keep support communications (email and in-app chat) and product-usage analytics describing how merchant staff use the App inside the Shopify admin, for example which reports are opened and which features are configured. Our own product-analytics tooling receives merchant app-usage events only. No shopper data is sent to it.
When enabled by the merchant, the App collects the following information about people who visit that merchant’s store:
Interaction data: clicks, taps, scrolling, and
mouse or touch movement.
Pages viewed: the URLs of the pages visited,
including query-string parameters.
Behavior events: page navigation, product views,
cart adds and removals, checkout views, orders placed, JavaScript
errors, 404 pages, and rage clicks.
Page snapshots: structural snapshots of the pages
viewed (the page DOM), used to reconstruct the replay. Sensitive form
fields are masked by default, and payment fields are excluded
entirely and never captured.
Device and browser metadata: user agent, browser and
device type, language and locale, and referring page.
Network location: IP address, and the approximate
location derived from it (country, region, and city). We do not
collect precise GPS location.
Survey responses: answers a shopper chooses to give
to an on-site survey the merchant has configured.
Heatmap data: aggregated click counts and positions
for a given page, together with a crawler-captured screenshot of that
page.
Recording of the Shopify checkout is off by default. It is available only as an opt-in feature on the Enterprise plan, and where a merchant turns it on, payment fields are still excluded from capture, as they are everywhere else in the Service.
The App is installed through Shopify and requests only the access it needs to run the Service:
Theme access to read the store’s theme so the
merchant can install and position the App’s theme app embed, which
loads the recorder on the storefront.
Web pixels and customer events to receive the
standard storefront and checkout events Shopify publishes, which is
how the App learns about product views, cart activity, and checkout
steps.
App proxy so storefront requests to the App are
served from the merchant’s own domain.
Order data to attach conversion and funnel context
to sessions, so a merchant can see which sessions led to an order.
The App does not add script tags to the storefront. Delivery is through the theme app embed and the Shopify web pixel described above.
The recorder stores a small identifier in the browser (a cookie or browser storage entry) so that page views by the same visitor can be stitched into a single session and replayed in order. It is used for that purpose only, not for advertising.
Consent. Where a merchant enables consent enforcement, recording is gated on the consent signals reported by Shopify’s Customer Privacy API according to that merchant’s own Shopify privacy settings. The merchant selects the scope of that enforcement in the App’s settings (off, EU/EEA/UK visitors only, or all visitors), and consent gates recording only for visitors within the selected scope. Each merchant remains responsible for surfacing a consent prompt on its storefront, whether through Shopify’s cookie banner or a compatible privacy app.
We use merchant account, billing, support, and app-usage information to operate and provide the App, to authenticate and bill merchants, to respond to support requests, to improve and secure our products, to detect and prevent fraud and abuse, to comply with our legal obligations, and to send service messages and marketing messages about Propel products. Merchants can opt out of marketing messages at any time using the unsubscribe link in the message or by emailing us.
We use shopper information solely on the merchant’s behalf, to provide the Service to that merchant: to reconstruct and play back sessions, to build heatmaps, to deliver and record surveys, to produce analytics and funnel reports, and to generate AI summaries of recorded activity for that merchant.
We do not use shopper information for our own advertising or marketing, we do not use it to build profiles for any other business, and we do not sell or share it (as those terms are defined by the CCPA). We retain, use, and disclose it only for the limited and specified business purposes set out in the DPA, only within our direct business relationship with the merchant, and we do not combine it with personal information we receive from other sources except where a privacy regulation expressly permits a service provider to do so. If we use deidentified data, we maintain it in deidentified form and do not attempt to reidentify it.
AI summaries. To produce the merchant-facing summaries in the App, replay event streams, and heatmap screenshots with their click statistics, are sent to our AI sub-processor (OpenAI) through its API. Under the API terms that apply to us, that data is not used to train its models. Summaries are returned to, and visible only to, the merchant whose store the data came from.
We do not sell personal information and we do not share it for cross-context behavioral advertising, as those terms are defined by the CCPA. We do not disclose shopper information to data brokers, advertising networks, or any other party for their own purposes.
We disclose personal information only to the service providers and sub-processors that host, transmit, secure, and support the App, each bound by a written contract requiring at least the same level of privacy protection we are held to, and each prohibited from selling or sharing the information or using it outside our instructions. The current list matches Annex III of the DPA:
Shopify Inc. App platform, customer and order data,
theme integration.
Cloudflare, Inc. CDN, web application firewall,
DDoS protection, edge compute.
Heroku (Salesforce) Application hosting and runtime.
Amazon Web Services Object storage (S3) and
transactional email (SES).
Papertrail Application log management.
New Relic Application performance monitoring.
OpenAI AI replay and heatmap summaries.
Rollbar Error monitoring.
We notify merchants of intended changes to this list, and merchants may object, on the terms set out in Section 7 of the DPA.
We may also disclose personal information where we are legally required to do so: to comply with applicable laws and regulations, to respond to a subpoena, search warrant, or other lawful request for information, or to establish, exercise, or defend legal claims. Where we receive a request of that kind relating to information we hold on a merchant’s behalf, we will notify the merchant unless we are legally prohibited from doing so.
If you are in the European Union, the European Economic Area, or the United Kingdom, you have the right to access the personal data held about you, to have it corrected or erased, to restrict or object to its processing, to receive it in a portable form, and to lodge a complaint with your local supervisory authority.
Where Propel is the controller (merchant account and app-usage data), our legal bases are the performance of our contract with the merchant, our legitimate interests in operating, securing, and improving our products, and compliance with our legal obligations. Contact us directly to exercise your rights over that data.
Where the data relates to a visit to a merchant’s store, the merchant is the controller and decides the legal basis. Please direct your request to that merchant. We will assist the merchant in responding, as required by the DPA.
Depending on your state of residence, you may have the right to know what personal information is collected about you and how it is used and disclosed, to request deletion of it, to request correction of it, to opt out of its sale or sharing, and to opt out of certain profiling. You will not be denied service, charged a different price, or given a different level of quality for exercising any of these rights.
Propel does not sell or share personal information (as the CCPA defines those terms), and does not use or disclose it for cross-context behavioral advertising.
For information collected when you visited a merchant’s store, the merchant is the business and Propel is its service provider, so we cannot act on your request on our own. Please contact the merchant whose store you visited. We will help that merchant locate, export, correct, or delete the relevant data, and we honor opt-out preference signals such as Global Privacy Control where they are passed to the App through the merchant’s Shopify privacy settings and Shopify’s Customer Privacy API and the merchant’s consent-enforcement settings apply them to your visit.
For merchant account and app-usage data, where Propel is the business, contact us at support@propelcommerce.io and we will respond within the time allowed by applicable law. We may need to verify your identity before acting, and an authorized agent may submit a request on your behalf with proof of authorization.
For data we process on a merchant’s behalf, retention matches Annex II of the DPA:
Session-replay and heatmap data: a 30-day rolling
window on every plan, free through Enterprise. Older data is purged
automatically.
Logs: 90 days.
Deletion requests: a merchant may request deletion
of specific records at any time by emailing support@propelcommerce.io. We complete deletion within 5 business
days.
Merchant account data, for which we are the controller, is retained for the life of the merchant’s account with us and for any period we are required to keep it by law. A merchant can stop all processing of shopper data at any time by disabling or uninstalling the App.
Personal information handled through the App is processed and stored in Canada and the United States, on the infrastructure of the sub-processors listed in Section 4.
Where personal data is transferred out of the European Union, the European Economic Area, or the United Kingdom, the transfer is protected by the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum where applicable, or another lawful transfer mechanism, as set out in Section 8 of the DPA.
We may update this privacy policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal, or regulatory reasons. The date at the top of this page shows when it was last revised, and we will notify merchants of material changes through the App or by email.
For more information about our privacy practices, if you have questions, or if you would like to make a complaint, please contact us by e-mail at support@propelcommerce.io or by mail using the details provided below:
Alcaris Inc., doing business as Propel Commerce
170-422 Richards St
Vancouver, BC V6B 2Z4
Canada