Last updated: April 9, 2026
EcomScout ("we", "us", "our") operates the website ecomscout.com, the EcomScout Chrome browser extension, and related APIs (collectively, the "Services"). This Privacy Policy explains what data we collect, why we collect it, how we use and protect it, and your rights regarding that data.
For questions, contact us at [email protected].
The EcomScout Chrome extension analyses publicly available data on Shopify-powered stores you visit. It does not:
The extension transmits the domain of a Shopify store you are viewing to our API to retrieve analytics for that store. No other browsing data is sent.
If you are in the European Economic Area (EEA), UK, or Switzerland, we process your data under the following legal bases:
We share data only with the service providers required to operate the Services:
| Provider | Purpose | Data Shared |
|---|---|---|
| Stripe | Payment processing | Name, email, payment token |
| PostHog | Product analytics | Anonymous usage events, device info |
| Google Analytics | Web analytics | Page views, sessions, device info |
| Google Tag Manager | Tag management | Script orchestration (no direct data) |
| Klaviyo | Email delivery | Email address, purchase info |
| Cloudflare | CDN, security, bot protection | IP address, request metadata |
| Vercel | Web hosting | Server logs, request metadata |
| MongoDB Atlas | Database hosting | All stored application data |
We do not sell, rent, or trade your personal data to third parties for advertising or marketing purposes.
Depending on your jurisdiction (GDPR, CCPA, etc.), you may have the right to:
To exercise any of these rights, email [email protected]. We will respond within 30 days.
We implement industry-standard security measures including HTTPS/TLS encryption in transit, encrypted databases at rest, access controls, and regular security reviews. However, no method of transmission or storage is 100% secure.
Our servers are hosted in the United States (AWS, Vercel) and the European Union (PostHog EU). If you are outside the US, your data may be transferred to and processed in the US. We rely on standard contractual clauses and our providers' compliance frameworks to ensure adequate protection.
The Services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us and we will promptly delete it.
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top. Continued use of the Services after changes constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy or wish to exercise your rights, contact us at: