Legal
Privacy Policy
Last updated: September 29, 2026
Rylo ("we", "us") is a Shopify app that tests prices on a store's live traffic and keeps the most profitable one. This policy explains what data Rylo collects from Shopify, from merchants, from shoppers on a merchant's storefront, and from visitors to heyrylo.com; why we collect it; how long we keep it; who we share it with; and how to exercise your rights.
1. Who is responsible
For merchant accounts and our own website, Rylo decides how data is used. For data about a merchant's shoppers, the merchant is responsible and Rylo processes that data on the merchant's behalf, only to provide the app. Shoppers with questions about a store should contact that store first; we will help the merchant respond.
Merchants: because Rylo tests prices on your storefront, we recommend your store's own privacy policy mention that you use a pricing app that stores a random identifier in the shopper's browser.
2. Data we get from Shopify
- Store details: shop name and domain, the store owner's name and contact email and phone, currency, time zone, and plan.
- Catalog: products, variants, prices, compare-at prices, item costs, and stock levels.
- Orders: order ID, date and store-local time, line items, quantities, prices paid, discounts and discount codes, shipping, tax and totals, refunds, and the cart attributes Rylo itself added (which test price the shopper saw). Also the conditions of the sale: sales channel, the referring site (domain only), the landing page (path and campaign tags, without ad click IDs), device type, operating system and browser family, browser language and screen width, and the shipping country and state/province. Shortly after each order, Rylo reads Shopify's customer journey summary for it: whether it was the customer's first order, days from first visit to purchase, and where the first and last visits came from. Shopify's order notifications also contain the customer's contact details, IP address, street address, postcode, and full browser user agent; Rylo ignores those fields and never stores them.
- Sales reports: aggregated figures from Shopify analytics (ShopifyQL), such as sales and sessions per product.
- Discounts and themes: your active discounts (so tests pause during your sales) and whether the Rylo theme app embed is on.
- Logged-in shoppers: when a shopper is logged in to your store, the storefront gives Rylo their Shopify customer ID so they keep the same price on any device. The ID is used only inside the shopper's price identifier described below.
Shopify access scopes
Every permission Rylo requests, and why:
read_productsRead your products, variants, and prices.write_productsUpdate prices and save Rylo’s pricing data on each product (metafields).read_reportsRead Shopify’s aggregated sales and sessions reports (ShopifyQL).read_ordersSee which price each order was bought at, to pick the best price and calculate the fee.read_all_ordersRead orders older than 60 days for sales baselines and up to 12 months of dashboard history.read_customersRequired by Shopify before the four customer-field scopes below can be granted.read_customer_nameRequired by Shopify to query its sales reports. Rylo never reads, stores, or displays customer names.read_customer_emailRequired by Shopify to query its sales reports. Rylo never reads, stores, or displays customer emails.read_customer_phoneRequired by Shopify to query its sales reports. Rylo never reads, stores, or displays customer phone numbers.read_customer_addressRequired by Shopify to query its sales reports. Rylo never reads, stores, or displays customer addresses.read_discountsDetect your sales and discount codes so tests pause while they run.write_discountsCreate and maintain the “Rylo Adaptive Pricing” discount that charges each shopper their price.read_inventoryRead item costs and stock, so prices are judged on profit and sold-out items pause.read_locationsStock levels are reported per location, so reading stock requires location access.read_cart_transformsCheck for cart transforms that would conflict with how Rylo charges prices.write_cart_transformsRemove a conflicting Rylo cart transform so checkout always charges the right price.write_app_proxyRun the storefront connection at /apps/rylo that keeps each shopper’s price consistent.write_pixelsInstall the Rylo web pixel, which restores a shopper’s price if their cookies are cleared.read_customer_eventsRequired by Shopify alongside write_pixels; the pixel reads only the browser identifier.read_themesCheck that the Rylo theme app embed is turned on in your live theme.
Used only on Rylo's own test stores, never on your store:
write_themesPublish and restore themes during Rylo’s automated storefront checks on its own test stores.write_inventorySet stock levels to test sold-out handling on Rylo’s own test stores.
For features being rolled out. Until a feature launches, its scopes are not used, and we update this policy when it does:
read_draft_ordersPrivate quote links: a priced draft order for high-ticket and wholesale buyers.write_draft_ordersCreate those quote-link draft orders.read_marketsUse the right currency and market for sales on stores that sell in several countries.read_returnsReturn prevention: read return requests to see which products and prices get returned.read_marketing_eventsShow Rylo sales on your Shopify marketing calendar.write_marketing_eventsAdd Rylo sales to that calendar.read_online_store_navigationRead your URL redirects before sending a share of traffic to a Rylo-hosted product page.write_online_store_navigationCreate the redirects for that Rylo-hosted product page test.read_inventory_transfersReorder planning: see stock already on its way in.read_inventory_shipmentsReorder planning: see incoming shipments.read_localesKnow which languages your store uses.read_translationsRead your translations for Rylo’s storefront text (sale badge, reserved-price note).write_translationsSave translations of that storefront text.unauthenticated_read_product_listingsRylo-hosted product page: show your products.unauthenticated_read_product_inventoryRylo-hosted product page: show what’s in stock.unauthenticated_read_product_tagsRylo-hosted product page: filter and group products by tag.unauthenticated_read_checkoutsRylo-hosted product page: read the shopper’s cart.unauthenticated_write_checkoutsRylo-hosted product page: add to cart and hand off to Shopify checkout.unauthenticated_read_contentRylo-hosted product page: show your store’s pages and content.unauthenticated_read_selling_plansRylo-hosted product page: show subscription options.unauthenticated_read_metaobjectsRylo-hosted product page: show your custom product content.unauthenticated_read_product_pickup_locationsRylo-hosted product page: show local pickup availability.unauthenticated_read_customersRylo-hosted product page: let a logged-in shopper see their own reserved price.unauthenticated_write_customersRylo-hosted product page: let a shopper sign in to their store account.
3. Data we collect from shoppers on the storefront
When a merchant turns on the Rylo theme app embed, Rylo runs on their storefront to show each shopper one consistent price. Rylo does not collect shopper names, email addresses, phone numbers, addresses, payment details, or browsing history, and does not track shoppers across other websites.
- A random price identifier (cookie
_rylo_seed, 30 days). It decides which test price the shopper sees. For logged-in shoppers it is derived from their Shopify customer ID. - Price notes in the browser: the reserved price and its expiry in local storage (
_rn_keys), short-lived session storage keys that keep the page from flickering, and cart attributes and line properties (rylo_s,rylo_p,_rylo_*) so checkout charges the reserved price. - Rylo web pixel: reads the browser identifier Shopify assigns to the visitor, turns it into a one-way hash inside Shopify's sandbox, and links that hash to the price identifier. This lets a shopper keep their price if their browser clears cookies. The pixel does not record events or page content.
- Price exposures: when a shopper views a tested product, a hashed form of their price identifier, the product variant, the price shown, and the time.
- Price promises: the price reserved for the shopper, when the reservation ends, and whether they bought.
- Shop sign-in (optional): if the shopper chooses to link their Shop account, a hashed Shop identifier linked to their price identifier.
How prices are assigned. Test prices are assigned at random within the merchant's min and max. They are not based on who the shopper is, where they are, their device, or their purchase history, and Rylo makes no other automated decisions about shoppers. Nobody pays more at checkout than the price they were shown.
Consent. The price identifier and pixel are used only so a shopper sees one consistent price, not for analytics or advertising, so they run regardless of a shopper's cookie choices. Storefront requests do go through our servers, where the shopper's IP address is used briefly for rate limiting and is not stored with any of the data above.
4. Data we collect from merchants and website visitors
- Your Rylo account: name, email, optional phone and profile photo, team members and their roles, and your sign-in method (email code or Google).
- Settings you enter: min and max prices, item costs, reservation window, rounding, and other configuration.
- Support and sales contact: what you send us by email, the demo or audit forms on heyrylo.com (name, email, phone, store URL, revenue range), and demo bookings.
- Store audits and Store Watch: when you enter a store address on heyrylo.com, we read that store's public product catalog, plus your email or phone if you subscribe to updates. No shopper data is involved.
- Usage and diagnostics: error reports and performance traces, product analytics on the heyrylo.com web app, and page analytics and ad-conversion measurement on heyrylo.com (see section 7).
5. How we use data
- Run price tests, keep each shopper's price consistent, and show results and pricing history.
- Measure how demand at each price changes with conditions such as time of day, traffic source, device, and region, to build demand curves. These conditions are never used to set one shopper's price.
- Pause tests during your sales and when products sell out.
- Calculate Rylo's fee and bill it through Shopify.
- Answer support requests and send service emails.
- Secure, debug, and improve the app.
- Follow up on demo and audit requests you submit, and measure our own marketing.
- Comply with legal obligations and enforce our terms.
We use shopper and store data to provide Rylo to that merchant, and we do not sell data or share it for advertising. With the merchant's consent under our Terms of Service, we also keep that store's price-test data in de-identified form, with store, product, order, and shopper identifiers replaced by random keys, including after uninstall, and use it to improve Rylo's pricing models for all merchants. That copy keeps each product's general category (for example “Snowboards”) and product type, but no product names, discount codes, campaign names, or other text the merchant wrote, and no full page addresses or referring websites other than well-known platforms such as Google or Instagram.
6. How long we keep data
- Price exposures and price promises: while the app is installed. After a deletion request for that customer, the shopper identifier is removed and the price result is kept.
- Identity links: while the app is installed, or until a deletion request for that customer.
- Order results and sale conditions: while the app is installed, because results and billing depend on them. Order IDs are removed when Shopify sends a deletion request for that customer.
- Browser storage: the
_rylo_seedcookie expires after 30 days without a visit; price notes expire with the reservation window; session keys clear when the tab closes. - Store data: until 48 hours after uninstall, when Shopify sends its store-deletion request and we delete it. For stores that accepted our Terms, the de-identified copy described in section 5 is kept.
- Your Rylo account and sales contacts: until you ask us to delete them.
7. Who we share data with
We share data only with service providers that process it for us under contract, plus Shopify:
- Shopify: the platform Rylo runs on, including billing.
- Supabase (database and sign-in), Vercel (hosting), Trigger.dev (background jobs), and Upstash (rate limiting and visitor counts).
- Sentry: error and performance monitoring. Session replays are off inside the Shopify admin; elsewhere all text, inputs, and images are masked.
- PostHog: product analytics and session recording on the heyrylo.com web app only, never inside the Shopify admin. Password fields are masked.
- Resend (email), Slack (internal alerts about sign-ups, demo requests, and store activity), Zoom (demo calls), Cloudflare Turnstile (bot protection on forms), and OpenAI (the chat assistant on heyrylo.com, which receives what you type and the public audit of your store).
- Google Analytics, Meta, OpenAI Ads, and Cherrie: page analytics and measurement of our own ads on heyrylo.com, never inside the Shopify admin. Meta and OpenAI may receive your IP address and browser type, and hashed contact details when you submit a form. Cherrie also receives the contact details you submit so we can follow up. None of these receive shopper data from your storefront.
- Legal: we may disclose data when required by law, to protect our rights, or as part of a merger or sale of the business.
8. Where data is stored and how it is protected
Data is stored and processed mainly in the United States. Some providers may process data in other regions under their own safeguards.
- All traffic is encrypted in transit (HTTPS/TLS), and the database and its backups are encrypted at rest.
- Shopify access tokens are additionally encrypted with AES-256-GCM.
- Shopper identifiers are stored in pseudonymous or hashed form.
- Production data is kept separate from test data, and access is limited to the people who run Rylo.
- We follow an incident response process and will notify affected merchants of a breach as required by law.
9. Your rights and Shopify privacy requests
Depending on where you live (for example under the GDPR, UK GDPR, or US state privacy laws), you may have the right to access, correct, delete, or port your personal data, to object to or restrict processing, and to complain to a data protection authority. We provide these rights to everyone. Email marcos@heyrylo.com and we will respond within 30 days.
Rylo handles Shopify's mandatory privacy requests as follows:
- Customer data request (
customers/data_request): we send the merchant a report of every record linked to that customer and their orders. - Customer deletion (
customers/redact): we delete that customer's identity links and remove their shopper identifier and order IDs from every other record. What remains (which price was shown and whether it sold) can no longer be linked to that customer or their orders. - Store deletion (
shop/redact): 48 hours after uninstall, we delete the store's data, keeping only the de-identified price-test data described in section 5.
10. Children
Rylo is a business tool and is not directed at children. We do not knowingly collect data from children.
11. Changes to this policy
We will update this policy when our practices change, including when a feature using the upcoming scopes above launches, and change the date at the top. For significant changes we will notify merchants in the app or by email.
12. Contact
Questions, requests, or a data processing agreement: marcos@heyrylo.com.