Privacy and data collection
Dozenfold is designed to collect the minimum storefront evidence needed to investigate failures and journey outcomes. Its session model is anonymous, and screen replay is off unless a store turns on error-session replay.
Session identity
The storefront creates a random session UUID. It expires after 30 minutes of inactivity and is not used for fingerprinting, cross-session identity, or building a shopper profile.
When Shopify’s customer-privacy API is available, the theme monitor waits for permitted analytics consent. The Web Pixel is configured for permitted analytics processing. A visitor who denies the required consent does not receive a Dozenfold session identifier.
Custom storefronts can run in cookieless mode. The SDK then stores nothing in the browser and sends events without an identifier; the collector groups them under a server-side visitor id that changes every UTC day. It is derived from the store, IP address and user agent under a daily secret; IP and user agent are hash inputs only and are not stored. Error-session replay never runs in cookieless mode.
Evidence history and billing records
The public paid plans include 30 days of storefront evidence history. This is the investigation window, not a deletion deadline for account, subscription or usage records.
Session-based billing also keeps period totals and a minimal record of each counted session, including a hashed identifier scoped to the store and app. It prevents the same session from consuming quota twice, even across billing periods or a reinstall. It does not link different sessions into a shopper profile and does not contain event payloads or page contents.
The browser’s 30-minute inactivity rule does not erase these server-side billing records. They remain with the store’s billing history and are removed when the store record is deleted through the data-deletion process. Uninstalling stops new collection but does not immediately delete all stored data. For deletion questions, contact privacy@dozenfold.com.
Data Dozenfold can capture
- normalized page and navigation context
- funnel events and commerce outcomes
- JavaScript, promise, CSP, resource, request, GraphQL, and cart-operation failures
- LCP, INP, and CLS field measurements
- privacy-safe friction patterns
- explicitly tracked allowlisted business milestones with bounded numeric/boolean properties
- page-view endpoint outcome totals using only coarse provider/route/method enums, status classes and fixed latency buckets—never endpoint URLs, hosts, headers, bodies or successful-request payloads
- environment and release context
- coarse diagnostic context: a two-letter country code from the network edge (unknown and Tor exits are dropped), connection type and data-saver mode (Chromium browsers only), a device-memory band (Chromium browsers only), a processor-core band, and the name of a social app’s in-app browser derived from the user agent, which itself is not stored
- for errors: whether the shopper was online, and whether the failing code belonged to a browser extension (the extension’s identifier is not kept)
URLs and messages are normalized or redacted where needed to avoid storing sensitive values.
Optional error-session replay
Off by default. When a store turns it on in Settings, a separate recorder loads in sessions that are sampled and have analytics consent. It keeps the last minute of masked page reconstruction in the browser and uploads it only when an error happens. It then records the rest of that session until the shopper is idle for 5 minutes, for up to 30 minutes after the first error. Inputs are always masked; page text is masked unless the store chooses “Mask inputs only”. Replays are stored privately for 30 days and deleted with the store’s data.
Data Dozenfold does not capture
- video or screenshots; DOM snapshots and page text only through opt-in error-session replay
- mouse movement or keystroke streams
- form and input values
- request or response bodies and authentication headers
- a persistent customer or device identity
- full private source files
Access to workspace evidence follows the app’s tenant boundary. Do not paste customer secrets into release labels, URLs, or other metadata intentionally sent to monitoring tools.