Privacy Policy
Last updated 2026-09-12. This policy covers the Overture app for Shopify and the overture.lol website ("Overture", "we"). Contact: support@overture.lol.
Who this is for
Two groups of people are affected by Overture: merchants who install the app on their Shopify store, and shoppers who interact with a popup on a merchant's storefront. For shopper data, the merchant is the data controller and Overture acts as their processor: we handle the data on the merchant's instructions, for the purposes below, and for no other purpose.
What we collect and why
| Data | From | Why |
|---|---|---|
| Store domain, an API access token, the plan the store is on | Shopify, on install | To run the app for that store and show the right visitor allowance |
| Klaviyo API key (encrypted at rest) | The merchant, in the app | To sync captures to the merchant's own Klaviyo account |
| Products, collections, homepage text, theme colours | The merchant's store | To draft popup copy and match the look; a summary is sent to Anthropic's API to write the draft |
| Shopper email or phone number, quiz answers, consent record (the consent text shown, the page URL, time and network address), a random visitor id, the discount code minted | The shopper, through the popup | To deliver the code, sync the contact to the merchant's ESP with proof of consent, and let the merchant see their captures |
| Order id, order number, total, discount codes used, and the buyer's email | Shopify, when an order is placed | To attribute orders to the popup that earned them, so the merchant sees revenue per popup |
| Popup interaction events (shown, step viewed, closed) | The storefront widget | Counts for the merchant's dashboard and A/B tests |
We do not collect names, addresses, payment details or order line items. We do not use shopper data to build profiles across stores, and we never sell it.
Where it goes
Overture runs on servers provided by Fly.io in the United States, with data stored in a Neon database in the United States. Our sub-processors are:
- Shopify — the platform the app runs on; source of store and order data.
- Fly.io — application hosting.
- Neon — database hosting, encrypted at rest.
- Anthropic — receives a summary of the merchant's public store content (products, collections, homepage text) to draft popup copy. No shopper data is ever sent.
- Klaviyo — only when the merchant connects their own account; captures are sent to it on the merchant's behalf.
How long we keep it
- Shopper captures, events and order data are kept while the app is installed on the store, so the merchant's reporting stays complete.
- When a merchant uninstalls, Shopify sends a deletion request 48 hours later and we delete the store's captures, events, orders, connection keys and queued work.
- When Shopify forwards a customer's request to be forgotten, we delete that customer's captures and remove their email from any order records.
- Webhook receipts are kept as an audit trail without any personal identifiers.
How we protect it
All traffic is encrypted in transit. Databases and backups are encrypted at rest. Merchant API keys and refresh tokens are additionally encrypted by the app with a key held only in the hosting environment. Access to production is limited to the operator, and reads of shopper data in the app are logged. See our security page for how incidents are handled.
Your rights
Shoppers should direct access, correction or deletion requests to the merchant whose store they used; the merchant can request them through Shopify and we act on them automatically. Merchants can export or delete their data by contacting us. If you are in the EU, UK or a jurisdiction with similar rights, they apply as described here, and you may complain to your local supervisory authority.
Changes
We will update this page when the practice changes and note the date at the top. Material changes are announced inside the app.