Skip to content
Pairfully
  • Product
  • Sample report
  • Free AI check
  • Pricing
  • Docs
Log inStart free

Legal

Privacy policy

Effective 27 September 2026

Pairfully reads visits to a website and reports why the serious visitors didn’t buy. This policy covers visitors to our customers’ websites, whose visits we judge; shoppers at stores that turn on our optional recovery features; and our customers themselves, who have accounts with us. The short version for visitors: no cookies, no recordings, and nothing that follows you past today. The data sheet at the end lists every field.

1. Visitors to sites that use Pairfully

When a website runs our script, it sends us a compact description of each visit: the pages viewed and the time on each, how far down each page was scrolled, the visible label of the links and buttons clicked, whether a form was started, sent or rejected and which field was invalid, JavaScript error messages, the referrer and UTM tags, and the device class. The country is looked up from the connection on our server. Every field is listed in the data sheet below.

  • No cookies and no localStorage. A random tab id is kept in sessionStorage and deleted when the tab closes.
  • Our server keeps a one-way hash of the connection’s IP address and browser to count return visits within a day. The key behind it changes every 24 hours and the hash is deleted after 24 hours.
  • Nothing typed into a form is read. No recordings, screenshots or mouse movement are captured.
  • Paths that look like they contain an email address or a long number are masked before they leave the browser.
  • Email addresses, phone and card-like numbers, access tokens, ids and URL query strings are removed from click labels, form and field names, error messages and lead fields, in the browser and again on our server.

EU and UK consent rules cover more than cookies, so whether a site needs to ask its visitors before running Pairfully depends on that site and its other tools. The data sheet is written so a customer’s lawyer can decide. If a customer passes lead-form fields to us with identifyLead, emails, phone numbers and fields named like contact details are removed before anything is stored or judged. Free text is kept, with any email address, phone number, token or id written inside it removed.

2. Shoppers at stores that turn on recovery

Stores can connect Shopify and turn on three optional features. Each is off until the store owner turns it on.

  • Checkout alerts. A checkout extension sends us the checkout steps a shopper reaches (started, payment submitted, completed), a random checkout id, and the text of any error message Shopify shows them. Never names, emails, addresses or payment details. We count these to tell the store when checkout stops working.
  • Cart-recovery emails. Shopify sends us each checkout: the shopper’s email address, what was in the cart, the link back to it, and whether the shopper agreed to marketing from the store. We email only shoppers who agreed, at most twice, in the store’s name. Every email has an unsubscribe link for that store. One checkout in ten is held back from emails so the store can see what the emails add. The email address is encrypted, and checkouts are deleted after 30 days; order records (order id, total, checkout id) after four months. We act on Shopify’s data-deletion requests. To word the email and decide whether to offer the store’s discount, our AI infrastructure provider reads the cart and the checkout steps reached, never the shopper’s email.
  • Save-the-sale messages. When a shopper who looks ready to buy starts to leave, the site may show them one short message the store wrote, such as its delivery terms or a discount code. Half of eligible shoppers are picked at random not to see it, to measure what it adds. It is shown at most once per visit and never on checkout pages.

Stores that connect Shopify also share returns and refunds: the product, Shopify’s return reason, and the note left with it, with emails, phone numbers and ids removed. Our AI infrastructure provider reads them to say why things come back. They are deleted after four months.

On Shopify stores the script also adds a hidden attribute to the shopper’s cart holding the random tab id, so a checkout can be matched to the visit. It holds nothing else.

3. The AI visibility check

The check sends a few shopper-style questions, built from what a site sells and where, to OpenAI and Perplexity, and reads which websites their answers name. It reads the site’s home page and robots.txt to suggest fixes. Our AI infrastructure provider reads the answers to judge how they treat the business. No visitor or shopper data is involved.

4. Our role

For visitor data, our customer is the controller and Pairfully is a processor acting on their instructions. We process it only to produce the customer’s reports, alerts and lead scores, and we delete it when the customer deletes the site or the retention period for their plan ends. We do not sell, share or combine it across customers.

5. Customers with an account

  • Account data: your email address, name, organisation name and role.
  • Site configuration: domain, what the site sells, an ideal-customer description and key pages.
  • Billing: plan, payment references and invoices, handled by our card provider. We never see card numbers.
  • Alert targets you configure: an email address, a Slack webhook or a WhatsApp number.

We use this to run your account, send the reports and alerts you asked for, and bill you.

6. Sub-processors

  • Our AI infrastructure provider processes the visit summary to judge each visit. It receives the summary only, after the personal-data removal described above, under a data processing agreement. The provider is named in our DPA, available on request.
  • Railway hosts the application and database.
  • Cloudflare R2 stores encrypted backups.
  • Resend delivers email: reports, alerts, sign-in codes, and cart-recovery emails for stores that turn them on.
  • OpenAI and Perplexity answer the AI visibility check’s questions. They receive the questions only.
  • Shopify, for stores that connect it, sends us checkouts and orders as described in section 2.
  • Sentry records application errors in the signed-in app only. It is not loaded on our marketing pages, and it is set not to collect IP addresses.
  • Bachs processes card payments. We never see card numbers.

7. Retention

Judged sessions are kept for 90 days on the Free plan, 13 months on Growth and Scale and 25 months on Agency, then deleted. Weekly reports are kept for the life of the account. Account data is deleted within 30 days of account closure. Store checkouts, including shopper email addresses, are deleted after 30 days, and order records after four months.

8. Your rights

Customers can export or delete their data from Settings or by emailing us. Visitors to customer sites cannot be identified from what we hold, so there is nothing to look up; if you believe otherwise, contact the site owner or us at privacy@pairfully.com.

Data sheet

Every field the script sends, what happens to it, and who handles it.

  • Page path, in order, with timing. Segments that look like an email address or contain six or more digits in a row are replaced with * in the browser.
  • Referrer: the referring site and page only (origin and path), on the first page view.
  • UTM tags: utm_source, utm_medium, utm_campaign, utm_term and utm_content on the landing URL. Other query parameters are never sent.
  • Scroll depth: the furthest point reached on each page, as a percentage.
  • Clicks: the visible label of the nearest link or button, cut at 40 characters, with emails, long numbers, tokens and ids removed. Three fast clicks are sent as a rage click with the same label, or the element’s tag name when there is no link or button.
  • Forms: started, sent or rejected, the form’s name or id, and the name of an invalid field. Never field values.
  • JavaScript errors: the message, with URL query strings, emails, long numbers, tokens and ids removed, cut at 120 characters.
  • Device class: phone, tablet or desktop, from the user-agent string.
  • Country: looked up from the connection on our server. The IP address itself is not stored.
  • Daily visitor hash: a one-way hash of the IP address and browser with a key that changes every 24 hours. Deleted after 24 hours.
  • Tab id: a random value in sessionStorage, deleted when the tab closes. Sent with each batch.
  • Goals and purchases: that a goal you define, or a purchase, happened.
  • Ad click ids (gclid, fbclid and similar): only that one was present, recorded as 1, to tell paid visits from unpaid ones. The id itself is never sent.
  • Shopify cart attribute: on Shopify stores, the random tab id is added to the cart as a hidden attribute so a checkout can be matched to the visit.
  • Checkout steps (stores with checkout alerts on Shopify): started, payment submitted or completed, a random checkout id, and the text of error messages shown. No personal details.
  • Store checkouts (stores with cart-recovery emails): the shopper’s email, encrypted; cart contents; the link back to the cart; marketing consent. Deleted after 30 days.
  • Lead fields: only if you call identifyLead. Up to 20 fields; contact details, including ones written inside free text, are removed before anything is stored or judged.
  • Retention: judged visits are kept for 90 days on Free, 13 months on Growth and Scale, and 25 months on Agency. Weekly reports are kept for the life of the account.
  • Where it’s handled: Railway (hosting), Cloudflare R2 (encrypted backups), our AI infrastructure provider (judging), Resend (email), Sentry (errors, signed-in app only), Bachs (payments), and for the AI visibility check, OpenAI and Perplexity (questions only).

9. Changes

We will post changes here and, for material changes, email account owners at least 14 days before they take effect.

Back to home
Pairfully

Why serious visitors left without buying, in your inbox every Monday.

Product

  • What you get
  • Sample report
  • How it decides
  • Pricing
  • Free AI check
  • Install guides
  • MCP server
  • API

Company

  • Why I built this
  • hello@pairfully.com
  • Log in

Legal

  • Privacy policy
  • Data sheet
  • Terms
  • Refund policy

© 2026 Pairfully