Privacy Policy

Last updated 21 August 2026

Sold So Many shows real numbers drawn from a merchant’s own Shopify store. This page explains exactly what the app reads, what it keeps, who it shares data with, and how long any of it lives.

Who we are

Sold So Many is a Shopify app built and operated by Mehmet Tekin (“we”, “us”). This policy covers the app, its theme app block and web pixel extensions, and the marketing site at wearebooster.com. You can reach us any time through our contact form.

It covers two groups: merchants who install the app, and shoppers who visit a store running it. For shopper data, the merchant is the data controller and we act as their processor — we handle that data on the merchant’s instructions, to run the app they installed.

What the app reads from your Shopify store

When you install, Shopify asks you to approve a set of access scopes. Within those scopes we read and store:

  • Store profile — your myshopify domain, storefront domain, store name, contact email, locale, and your plan and subscription status through Shopify Billing.
  • Products and inventory — product and variant IDs, titles, prices, inventory levels, and changes to those levels over time.
  • Orders — the Shopify order ID, order date, sales channel, the city / province / country recorded on the order, and the line items (product, variant, title, quantity).
  • Theme configuration — whether the Sold So Many app block is present and where, so we can tell you if proof is not rendering.

The app requests Shopify’s protected customer data scopes so it can read orders and customer events. From that data we store only the fields above. We do not store shopper names, email addresses, phone numbers, street addresses, or payment details — the app has no use for them, and none of them appear in the proof we show.

What the app collects on your storefront

Proof is only honest if it is measured. The app’s Shopify web pixel — which runs inside Shopify’s sandbox and honours the shopper consent settings you configure in Shopify — records:

  • a pseudonymous visitor identifier taken from Shopify’s own first-party _shopify_y cookie, plus a per-session identifier;
  • device type (mobile or desktop) and referral source category;
  • storefront activity: pages and products viewed, collections browsed, search terms entered, cart additions, checkouts started, and orders completed, with order value;
  • which proof elements were shown on which product, and whether they were interacted with.

The app also sets a small number of first-party functional cookies on the storefront (ssm_active_boosters, ssm_session_exposures, ssm_cohort, ssm_last_collection) so the proof a shopper sees stays consistent within a visit and can be measured. They are not used for advertising and do not track anyone across other websites.

We do not attempt to identify individual shoppers, we do not build shopper profiles, and we never use one store’s data to serve another store’s proof — everything the app learns is scoped to the store it came from.

As with any web request, our servers receive standard metadata including IP address. We use it transiently for security and abuse prevention; we do not store shopper IP addresses in our database or use them to profile anyone. Error diagnostics may record a browser user agent and the URL where an error occurred.

What we collect from merchants directly

  • Onboarding answers — store name, contact email, approximate monthly visitor range, and how you found us.
  • Support conversations — messages you send us by email or through the in-app chat.
  • Service email activity — which app emails we sent you and whether they were delivered and opened.
  • Product usage — which admin screens are used and which settings are changed, recorded at store level so we can see where the app is confusing.

How we use it

  • To compute the numbers the app shows — units sold, visitors, active carts, trending products — from your real store data.
  • To decide which proof to show on which product and page, and to measure whether it worked, so the app improves for your store.
  • To bill you on the right plan. Plan tiers are based on unique monthly visitors, counted from the pseudonymous visitor identifier above.
  • To send service email you need (trial, billing, limits, incidents), to answer support requests, and to keep the service secure and debuggable.

Under GDPR, we rely on performance of our contract with the merchant for running the app and billing it, on legitimate interests for security, aggregate product improvement, and measuring the app’s effectiveness with pseudonymous data, and on consent where consent is required — including the storefront consent settings you manage in Shopify.

Who we share data with

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We use a small set of vendors to run the service, each under their own data-processing terms:

  • Shopify — the platform the app runs on and the source of store data.
  • Fly.io — application hosting.
  • DigitalOcean — the managed PostgreSQL database where store data is stored.
  • Redis Cloud and Upstash — short-lived caching and real-time visitor counters.
  • Trigger.dev — background job processing (syncs, scheduled work).
  • Twilio SendGrid — delivery of merchant email.
  • Mixpanel and Microsoft Clarity — product analytics for the merchant-facing admin screens.
  • Crisp — in-app support chat for merchants.
  • Meta — a hashed version of a merchant’s email address, so we can measure which of our own ads led to an install or trial. No shopper data is sent to Meta.
  • Google Analytics — the wearebooster.com marketing site only. It is not present in the app or on your storefront.

We may also disclose data where the law requires it, or to protect our rights and the security of the service. If the app is ever transferred to another owner, we will tell affected merchants before any data moves.

Where data is processed

Our servers and database run in the United States. Where merchant or shopper data originates in the EEA or UK, transfers rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, applied through our agreements with the vendors listed above.

How long we keep it

  • Live visitor activity — a session drops out of the live count after five minutes of inactivity, and per-product visit history is purged after 30 days.
  • Order, product, and measurement data — kept while the app is installed, because the counts the app shows are computed from it.
  • After you uninstall — the store is flagged for deletion immediately. We act on Shopify’s shop redaction request, which Shopify sends 48 hours after uninstall, and delete the store’s data. We retain an aggregate, PII-free summary of the account (install and uninstall dates, plan, and total counts) for our own business records.
  • Customer redaction requests — when Shopify sends a customer redaction request, we delete the orders and line items it names, and keep a record that the request was completed: the Shopify customer identifier and contact email included in Shopify’s request, the date, and which order IDs were removed.
  • Customer data requests — when Shopify forwards a shopper’s data request, we return the data we hold for that store within the window Shopify sets.

Security

Data is encrypted in transit with TLS and at rest by our managed database provider. Shopify access tokens are held in our database and are only used by the app itself. Access to production systems is limited to the people who operate the service, and the app requests only the Shopify scopes its features actually need.

Your rights

Depending on where you live, you have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to complain to your data protection authority. We do not sell or share personal information as those terms are defined under California law.

Merchants: send the request through our contact form and we will respond within 30 days. Uninstalling the app also starts the deletion process described above.

Shoppers: please contact the store you shopped with — they control the data, and Shopify routes their request to us automatically. You can also write to us directly and we will help the merchant resolve it.

Children

The app is a business tool for Shopify merchants. It is not directed at children, and we do not knowingly collect data from anyone under 16.

Changes to this policy

If this policy changes we will update the date at the top of the page, and for material changes we will email merchants with an active install before the change takes effect.

Contact

Questions, requests, or anything that reads wrong here — our contact form reaches us directly, and a person answers.