Privacy Policy
Effective 30 July 2026 · TrueMetrics for Shopify
TrueMetrics detects bot traffic on your store, corrects your reported conversion rate, and stops Klaviyo from emailing bots. This page explains what data the app collects, why, and how long it is kept. If anything here is unclear, contact metricstrue@gmail.com.
In short: we collect storefront behavior (page views, cart activity, checkout events) to score sessions as human or bot. We never store raw IP addresses or plaintext checkout email addresses. We do not sell data, and we do not block visitors, we measure and report.
What we collect
When TrueMetrics is installed, a Shopify Web Pixel runs on your storefront and sends the following to our server for scoring:
- Storefront events: page views, product views, cart additions, checkout started, checkout completed, and their timestamps. Each event is tied to a temporary, pixel-generated session identifier, not to a customer account.
- Browser user agent string, used to detect automation tools (headless browsers, scripts) impersonating real visitors.
- Request IP address, used only in the moment to look up which network organization it belongs to (for example, a cloud hosting provider rather than a residential ISP). This lookup runs against a local, offline database on our own server. The IP address itself is never sent to a third party and is never written to our database, only the resulting network-organization name is stored.
- Checkout email address, only when a session is already scored as a bot at checkout, and only if you have connected your own Klaviyo account. The email is converted to a one-way SHA-256 hash before it is stored or used. We cannot reverse a hash back into an email address, and the plaintext email is never saved.
We do not collect names, physical addresses, phone numbers, or payment details. Those never pass through TrueMetrics.
Why we collect it
- Bot scoring. Events and technical signals feed a rule-based scoring engine that classifies each session as human, suspicious, or bot, with the specific reasons always shown to you in the dashboard.
- Corrected reporting. Bot-scored sessions are excluded when we calculate your real, human-only conversion rate.
- Klaviyo suppression. If you connect your own Klaviyo API key, we match the hashed checkout email of a bot-scored session against your recent Klaviyo profiles and suppress that profile, so abandoned-cart emails stop going to bots. This only runs if you provide a Klaviyo key yourself. Without one, no suppression happens.
- Ad exclusion export. On request, you can download a CSV of hashed emails from bot-scored checkouts, ready to upload as a Meta exclusion audience. The file contains hashes only, never plaintext emails.
- Weekly digest email. If you turn this on and provide your own email address, we send you a weekly summary of bots caught and emails prevented. This goes to you, the merchant, never to your customers.
- Cross-store bot detection. A coarse, non-identifying pattern (browser family, network organization, behavior class) from confirmed bot sessions is shared across stores using TrueMetrics, so a bot caught on one store is recognized faster on another. This pattern cannot be traced back to an individual visitor or store.
What we do not do
- We do not block, redirect, or restrict any visitor. TrueMetrics measures and reports; it does not act as a firewall.
- We do not sell, rent, or share your store's data with advertisers or data brokers.
- We do not store raw IP addresses or plaintext checkout emails.
How long we keep data
Session and event data is kept on a rolling 30-day window and then discarded. If you uninstall TrueMetrics, all data associated with your store, including settings and session history, is deleted immediately as part of Shopify's uninstall notification to us.
Your rights and GDPR compliance
TrueMetrics implements all three Shopify-mandated GDPR webhooks:
customers/data_request: since we hold no directly identifiable customer data beyond a one-way email hash tied to a bot verdict, there is no personal profile to return.customers/redact: any stored hash matching a redaction request is purged.shop/redact: all data for the store is deleted.
You can also request deletion of your store's data at any time by contacting metricstrue@gmail.com.
Third parties
- Klaviyo: only contacted if you connect your own Klaviyo API key, and only to check and suppress profiles by hashed email match. We never see your Klaviyo password or account details beyond the key you provide.
- Resend: used to deliver the weekly digest email to the address you provide, if you enable it. No customer data is sent to Resend, only your summary numbers.
- Hosting: the app and its database run on Render. Data in transit is encrypted (HTTPS/TLS).
Changes to this policy
If this policy changes, the effective date at the top of this page will be updated. Material changes will be noted here.
Contact
Questions about this policy or your store's data: metricstrue@gmail.com