This policy covers TestIQ, the EcomIQ Shopify app for demand testing — merchants publish fake-door test products, replace add-to-cart with a waitlist, and measure demand. It supplements the main EcomIQ Privacy Policy, which sets out who we are and your rights.
1. Controller & processor roles
EcomIQ (PBF Piotr Białozor-Fiećko, NIP PL8461552859, ul. Józefa Chełmońskiego 12, 14-200 Iława, Poland) provides TestIQ. For the store data you connect and for the shopper data collected through your tests (including waitlist email addresses), the merchant is the controller and EcomIQ acts as a processor, processing that data only to provide the app’s features on your instructions. For your own account/contact data, we are the controller.
2. Data we access and collect
We access and collect only what is needed for the features you enable:
- Shopify store data — shop domain, and the fake-door products, variants, and publications TestIQ creates and manages on your behalf. Scopes requested:
read_products,write_products,read_publications,write_publications. - Shopper waitlist emails (personal data) — when a shopper submits the waitlist form on one of your test pages, we store their email address so you can notify them and measure demand. These emails belong to you (the merchant); we process them only to provide the service, and they are deletable (see §6–7).
- First-party demand measurement — for each test we record page views (“exposures”) and waitlist signups (“conversions”) against a pseudonymous, storefront-scoped visitor identifier (a random id, not a cross-site tracker). This is functional measurement used to compute your test’s conversion rate; it is not used to profile shoppers.
- Access tokens — credentials to call the Shopify Admin API, stored encrypted at rest.
3. Your own tracking tags on test pages
If you configure them, TestIQ fires your own Meta Pixel & Conversions API, Google Ads tag, and a GA4-compatible dataLayer on your fake-door pages, so your demand tests appear in your own advertising and analytics accounts. In that case the data flows to your Meta / Google accounts under your control and their terms — TestIQ facilitates the events but does not receive or store that advertising data itself. These tags are consent-gated using Shopify’s Customer Privacy (consent) API: they do not fire without the shopper’s marketing/analytics consent where consent is required. TestIQ does not integrate any advertising platform’s API on its own account, and requests no ad-platform data access.
4. How we use the data
We use the data solely to provide the features you enable — publishing your test products, showing the waitlist, measuring demand, computing results (frequentist and Bayesian), and giving you the waitlist to export. We do not sell data, use it for our own advertising, or build shopper profiles. Humans do not access your data except (a) with your consent, (b) for security or to comply with law, or (c) in aggregated/anonymized form for operating the service. We never log raw email addresses.
5. Storage, security & transfers
Data is hosted on Cloudflare’s developer platform. Access tokens are encrypted at rest (AES-GCM); all transport is over HTTPS. Where data is processed outside the EEA, we rely on appropriate safeguards (Standard Contractual Clauses and/or the EU–U.S. Data Privacy Framework).
6. Retention
Waitlist emails and test data are retained until you delete the test, uninstall the app, or request deletion. First-party measurement counts are retained for the life of the test. Access tokens are kept until you uninstall.
7. Shopify data-protection requests
As a Shopify app, TestIQ honors Shopify’s mandatory data-protection (GDPR) webhooks:
customers/data_request— if a store customer requests their data, we make any waitlist data we hold for that email available to you, the store owner.customers/redact— we delete the waitlist email(s) associated with the identified customer.shop/redact— 48 hours after a store uninstalls TestIQ, Shopify notifies us and we erase that store’s data — including all waitlist emails — from our systems.
We acknowledge these requests and complete the action within the timeframe Shopify requires.
8. Deletion & your rights
Uninstalling TestIQ stops processing and triggers deletion of your stored access tokens and data, as above. You can delete individual tests (which removes their waitlist emails), or request access or deletion via support. See the Data Deletion page and the main Privacy Policy for your full rights.
9. Sub-processors
Shopify (the platform you install from and that bills the subscription) and Cloudflare (hosting and storage). We share data with these providers only to operate the service. Any Meta/Google/GA4 tags you enable send data to your own accounts with those providers, under your control.
10. Contact
Questions about TestIQ’s data handling: support@ecomiq.tools.
This policy is provided in good faith and accurately describes how TestIQ works today.