What Rebilder stores about your shoppers
Events describe requests, not people: no names, no emails, no payment data, no cookies, no cross-site tracking.
Rebilder’s records are about requests to your store, not about the people making them. A recorded event contains a timestamp, the requester’s classification (agent, human, crawler, or protocol — plus the agent platform when identifiable), the URL requested on your own store, technical request context like the Accept header and referrer, what was served, and how long it took.
If you wire the order join (the Shopify webhook or the outcomes API), Rebilder additionally stores what you report about each order: an order id, timestamp, order value, currency, the product URLs on it, and any attribution evidence you choose to send. From a Shopify order webhook, only those fields are extracted — customer name, email, and address in the webhook payload are discarded, never stored.
What is deliberately absent
- No names, email addresses, accounts, or payment details — the event stream carries no consumer personal data beyond what you, the merchant, already lawfully process in operating your store.
- No cookies set on your shoppers and no cross-site tracking — Rebilder observes requests to your store only.
- No shopper profiles: a human visit is recorded as kind “human” with no platform and no identity. Two visits by the same person are just two rows.
What this means for your privacy policy
Because events carry no shopper identity, adding Rebilder does not add a new category of personal data to what you process. Most merchants cover it under existing analytics/service-provider language. (This is context, not legal advice — check with your counsel for your jurisdiction.)