Rylo
Product

Setup

A switch and two numbers. Per product, or per variant.

Price testing

Up to five live prices per product, judged in dollars.

Profit tracking

Every dollar judged against your original price.

Price PromiseNew

Shoppers never watch a price move.

Guardrails

Min and max, freeze mode, a full log, off means off.

Built for Shopify

No theme edits. Uninstall and nothing lingers.

Explore the full product →
Price PromiseNewPricingLive demo
ProductPrice PromiseNewPricingLive demo

Legal

Privacy Policy

Last updated: September 29, 2026

Rylo ("we", "us") is a Shopify app that tests prices on a store's live traffic and keeps the most profitable one. This policy explains what data Rylo collects from Shopify, from merchants, from shoppers on a merchant's storefront, and from visitors to heyrylo.com; why we collect it; how long we keep it; who we share it with; and how to exercise your rights.

1. Who is responsible

For merchant accounts and our own website, Rylo decides how data is used. For data about a merchant's shoppers, the merchant is responsible and Rylo processes that data on the merchant's behalf, only to provide the app. Shoppers with questions about a store should contact that store first; we will help the merchant respond.

Merchants: because Rylo tests prices on your storefront, we recommend your store's own privacy policy mention that you use a pricing app that stores a random identifier in the shopper's browser.

2. Data we get from Shopify

  • Store details: shop name and domain, the store owner's name and contact email and phone, currency, time zone, and plan.
  • Catalog: products, variants, prices, compare-at prices, item costs, and stock levels.
  • Orders: order ID, date and store-local time, line items, quantities, prices paid, discounts and discount codes, shipping, tax and totals, refunds, and the cart attributes Rylo itself added (which test price the shopper saw). Also the conditions of the sale: sales channel, the referring site (domain only), the landing page (path and campaign tags, without ad click IDs), device type, operating system and browser family, browser language and screen width, and the shipping country and state/province. Shortly after each order, Rylo reads Shopify's customer journey summary for it: whether it was the customer's first order, days from first visit to purchase, and where the first and last visits came from. Shopify's order notifications also contain the customer's contact details, IP address, street address, postcode, and full browser user agent; Rylo ignores those fields and never stores them.
  • Sales reports: aggregated figures from Shopify analytics (ShopifyQL), such as sales and sessions per product.
  • Discounts and themes: your active discounts (so tests pause during your sales) and whether the Rylo theme app embed is on.
  • Logged-in shoppers: when a shopper is logged in to your store, the storefront gives Rylo their Shopify customer ID so they keep the same price on any device. The ID is used only inside the shopper's price identifier described below.

Shopify access scopes

Every permission Rylo requests, and why:

  • read_products Read your products, variants, and prices.
  • write_products Update prices and save Rylo’s pricing data on each product (metafields).
  • read_reports Read Shopify’s aggregated sales and sessions reports (ShopifyQL).
  • read_orders See which price each order was bought at, to pick the best price and calculate the fee.
  • read_all_orders Read orders older than 60 days for sales baselines and up to 12 months of dashboard history.
  • read_customers Required by Shopify before the four customer-field scopes below can be granted.
  • read_customer_name Required by Shopify to query its sales reports. Rylo never reads, stores, or displays customer names.
  • read_customer_email Required by Shopify to query its sales reports. Rylo never reads, stores, or displays customer emails.
  • read_customer_phone Required by Shopify to query its sales reports. Rylo never reads, stores, or displays customer phone numbers.
  • read_customer_address Required by Shopify to query its sales reports. Rylo never reads, stores, or displays customer addresses.
  • read_discounts Detect your sales and discount codes so tests pause while they run.
  • write_discounts Create and maintain the “Rylo Adaptive Pricing” discount that charges each shopper their price.
  • read_inventory Read item costs and stock, so prices are judged on profit and sold-out items pause.
  • read_locations Stock levels are reported per location, so reading stock requires location access.
  • read_cart_transforms Check for cart transforms that would conflict with how Rylo charges prices.
  • write_cart_transforms Remove a conflicting Rylo cart transform so checkout always charges the right price.
  • write_app_proxy Run the storefront connection at /apps/rylo that keeps each shopper’s price consistent.
  • write_pixels Install the Rylo web pixel, which restores a shopper’s price if their cookies are cleared.
  • read_customer_events Required by Shopify alongside write_pixels; the pixel reads only the browser identifier.
  • read_themes Check that the Rylo theme app embed is turned on in your live theme.

Used only on Rylo's own test stores, never on your store:

  • write_themes Publish and restore themes during Rylo’s automated storefront checks on its own test stores.
  • write_inventory Set stock levels to test sold-out handling on Rylo’s own test stores.

For features being rolled out. Until a feature launches, its scopes are not used, and we update this policy when it does:

  • read_draft_orders Private quote links: a priced draft order for high-ticket and wholesale buyers.
  • write_draft_orders Create those quote-link draft orders.
  • read_markets Use the right currency and market for sales on stores that sell in several countries.
  • read_returns Return prevention: read return requests to see which products and prices get returned.
  • read_marketing_events Show Rylo sales on your Shopify marketing calendar.
  • write_marketing_events Add Rylo sales to that calendar.
  • read_online_store_navigation Read your URL redirects before sending a share of traffic to a Rylo-hosted product page.
  • write_online_store_navigation Create the redirects for that Rylo-hosted product page test.
  • read_inventory_transfers Reorder planning: see stock already on its way in.
  • read_inventory_shipments Reorder planning: see incoming shipments.
  • read_locales Know which languages your store uses.
  • read_translations Read your translations for Rylo’s storefront text (sale badge, reserved-price note).
  • write_translations Save translations of that storefront text.
  • unauthenticated_read_product_listings Rylo-hosted product page: show your products.
  • unauthenticated_read_product_inventory Rylo-hosted product page: show what’s in stock.
  • unauthenticated_read_product_tags Rylo-hosted product page: filter and group products by tag.
  • unauthenticated_read_checkouts Rylo-hosted product page: read the shopper’s cart.
  • unauthenticated_write_checkouts Rylo-hosted product page: add to cart and hand off to Shopify checkout.
  • unauthenticated_read_content Rylo-hosted product page: show your store’s pages and content.
  • unauthenticated_read_selling_plans Rylo-hosted product page: show subscription options.
  • unauthenticated_read_metaobjects Rylo-hosted product page: show your custom product content.
  • unauthenticated_read_product_pickup_locations Rylo-hosted product page: show local pickup availability.
  • unauthenticated_read_customers Rylo-hosted product page: let a logged-in shopper see their own reserved price.
  • unauthenticated_write_customers Rylo-hosted product page: let a shopper sign in to their store account.

3. Data we collect from shoppers on the storefront

When a merchant turns on the Rylo theme app embed, Rylo runs on their storefront to show each shopper one consistent price. Rylo does not collect shopper names, email addresses, phone numbers, addresses, payment details, or browsing history, and does not track shoppers across other websites.

  • A random price identifier (cookie _rylo_seed, 30 days). It decides which test price the shopper sees. For logged-in shoppers it is derived from their Shopify customer ID.
  • Price notes in the browser: the reserved price and its expiry in local storage (_rn_ keys), short-lived session storage keys that keep the page from flickering, and cart attributes and line properties (rylo_s, rylo_p, _rylo_*) so checkout charges the reserved price.
  • Rylo web pixel: reads the browser identifier Shopify assigns to the visitor, turns it into a one-way hash inside Shopify's sandbox, and links that hash to the price identifier. This lets a shopper keep their price if their browser clears cookies. The pixel does not record events or page content.
  • Price exposures: when a shopper views a tested product, a hashed form of their price identifier, the product variant, the price shown, and the time.
  • Price promises: the price reserved for the shopper, when the reservation ends, and whether they bought.
  • Shop sign-in (optional): if the shopper chooses to link their Shop account, a hashed Shop identifier linked to their price identifier.

How prices are assigned. Test prices are assigned at random within the merchant's min and max. They are not based on who the shopper is, where they are, their device, or their purchase history, and Rylo makes no other automated decisions about shoppers. Nobody pays more at checkout than the price they were shown.

Consent. The price identifier and pixel are used only so a shopper sees one consistent price, not for analytics or advertising, so they run regardless of a shopper's cookie choices. Storefront requests do go through our servers, where the shopper's IP address is used briefly for rate limiting and is not stored with any of the data above.

4. Data we collect from merchants and website visitors

  • Your Rylo account: name, email, optional phone and profile photo, team members and their roles, and your sign-in method (email code or Google).
  • Settings you enter: min and max prices, item costs, reservation window, rounding, and other configuration.
  • Support and sales contact: what you send us by email, the demo or audit forms on heyrylo.com (name, email, phone, store URL, revenue range), and demo bookings.
  • Store audits and Store Watch: when you enter a store address on heyrylo.com, we read that store's public product catalog, plus your email or phone if you subscribe to updates. No shopper data is involved.
  • Usage and diagnostics: error reports and performance traces, product analytics on the heyrylo.com web app, and page analytics and ad-conversion measurement on heyrylo.com (see section 7).

5. How we use data

  • Run price tests, keep each shopper's price consistent, and show results and pricing history.
  • Measure how demand at each price changes with conditions such as time of day, traffic source, device, and region, to build demand curves. These conditions are never used to set one shopper's price.
  • Pause tests during your sales and when products sell out.
  • Calculate Rylo's fee and bill it through Shopify.
  • Answer support requests and send service emails.
  • Secure, debug, and improve the app.
  • Follow up on demo and audit requests you submit, and measure our own marketing.
  • Comply with legal obligations and enforce our terms.

We use shopper and store data to provide Rylo to that merchant, and we do not sell data or share it for advertising. With the merchant's consent under our Terms of Service, we also keep that store's price-test data in de-identified form, with store, product, order, and shopper identifiers replaced by random keys, including after uninstall, and use it to improve Rylo's pricing models for all merchants. That copy keeps each product's general category (for example “Snowboards”) and product type, but no product names, discount codes, campaign names, or other text the merchant wrote, and no full page addresses or referring websites other than well-known platforms such as Google or Instagram.

6. How long we keep data

  • Price exposures and price promises: while the app is installed. After a deletion request for that customer, the shopper identifier is removed and the price result is kept.
  • Identity links: while the app is installed, or until a deletion request for that customer.
  • Order results and sale conditions: while the app is installed, because results and billing depend on them. Order IDs are removed when Shopify sends a deletion request for that customer.
  • Browser storage: the _rylo_seed cookie expires after 30 days without a visit; price notes expire with the reservation window; session keys clear when the tab closes.
  • Store data: until 48 hours after uninstall, when Shopify sends its store-deletion request and we delete it. For stores that accepted our Terms, the de-identified copy described in section 5 is kept.
  • Your Rylo account and sales contacts: until you ask us to delete them.

7. Who we share data with

We share data only with service providers that process it for us under contract, plus Shopify:

  • Shopify: the platform Rylo runs on, including billing.
  • Supabase (database and sign-in), Vercel (hosting), Trigger.dev (background jobs), and Upstash (rate limiting and visitor counts).
  • Sentry: error and performance monitoring. Session replays are off inside the Shopify admin; elsewhere all text, inputs, and images are masked.
  • PostHog: product analytics and session recording on the heyrylo.com web app only, never inside the Shopify admin. Password fields are masked.
  • Resend (email), Slack (internal alerts about sign-ups, demo requests, and store activity), Zoom (demo calls), Cloudflare Turnstile (bot protection on forms), and OpenAI (the chat assistant on heyrylo.com, which receives what you type and the public audit of your store).
  • Google Analytics, Meta, OpenAI Ads, and Cherrie: page analytics and measurement of our own ads on heyrylo.com, never inside the Shopify admin. Meta and OpenAI may receive your IP address and browser type, and hashed contact details when you submit a form. Cherrie also receives the contact details you submit so we can follow up. None of these receive shopper data from your storefront.
  • Legal: we may disclose data when required by law, to protect our rights, or as part of a merger or sale of the business.

8. Where data is stored and how it is protected

Data is stored and processed mainly in the United States. Some providers may process data in other regions under their own safeguards.

  • All traffic is encrypted in transit (HTTPS/TLS), and the database and its backups are encrypted at rest.
  • Shopify access tokens are additionally encrypted with AES-256-GCM.
  • Shopper identifiers are stored in pseudonymous or hashed form.
  • Production data is kept separate from test data, and access is limited to the people who run Rylo.
  • We follow an incident response process and will notify affected merchants of a breach as required by law.

9. Your rights and Shopify privacy requests

Depending on where you live (for example under the GDPR, UK GDPR, or US state privacy laws), you may have the right to access, correct, delete, or port your personal data, to object to or restrict processing, and to complain to a data protection authority. We provide these rights to everyone. Email marcos@heyrylo.com and we will respond within 30 days.

Rylo handles Shopify's mandatory privacy requests as follows:

  • Customer data request (customers/data_request): we send the merchant a report of every record linked to that customer and their orders.
  • Customer deletion (customers/redact): we delete that customer's identity links and remove their shopper identifier and order IDs from every other record. What remains (which price was shown and whether it sold) can no longer be linked to that customer or their orders.
  • Store deletion (shop/redact): 48 hours after uninstall, we delete the store's data, keeping only the de-identified price-test data described in section 5.

10. Children

Rylo is a business tool and is not directed at children. We do not knowingly collect data from children.

11. Changes to this policy

We will update this policy when our practices change, including when a feature using the upcoming scopes above launches, and change the date at the top. For significant changes we will notify merchants in the app or by email.

12. Contact

Questions, requests, or a data processing agreement: marcos@heyrylo.com.

© 2026 Rylo
ProductPrice PromisePricingAboutBlogHelpPrivacyTerms
Built for Shopify