Privacy policy
For the Novece Cookie Consent Shopify app. Last updated 27 July 2026.
The short version. The app stores which cookie categories a visitor allowed, and nothing that identifies them. No name, no email address, no IP address, no advertising identifier. We do not sell data, we do not use it for advertising, and we do not combine it with data from anywhere else.
Who we are
Novece develops and operates the Cookie Consent app for Shopify. For the data described here we act as a processor on behalf of the merchant whose store has installed the app; the merchant is the controller. Reach us at support@novece.com.
What the app stores
| Data | Why | Kept for |
|---|---|---|
| Store domain and Shopify access token | To talk to the store’s Shopify admin on the merchant’s behalf | Until the app is uninstalled |
| Store settings, subscription state and trial dates | To run the banner, the trial and billing | Until the app is uninstalled |
| Merchant email address | To send the trial and payment notices described below | Until the app is uninstalled |
| Consent records: a random visitor identifier, approximate region (country), the categories allowed, and a timestamp | The merchant’s evidence that consent was given or refused | 12 months, then deleted automatically |
The visitor identifier is generated at random in the visitor’s own browser. It is not a Shopify customer ID, not derived from an email address or an IP address, and cannot be traced back to a person, an account or an order. We do not store IP addresses.
The store’s own country is read from Shopify when the merchant opens the app, to determine whether we are able to offer the app in that country. It is used at that moment and not stored.
What the app does not do
- It does not track visitors across sites or build profiles.
- It does not read or store visitor names, emails or IP addresses.
- It does not sell or share data with advertisers or data brokers.
- It does not scan the store. It blocks only the tracking scripts the merchant enters into it.
Cookies the app itself sets
One first-party cookie in the visitor’s browser, holding their own choice so they are not asked again on every page. It contains the categories allowed and the date of the choice — nothing else. Preview mode inside the admin writes no cookie at all.
Who else processes this data
- Shopify — hosts the store, and receives the visitor’s consent decision through its Customer Privacy API so that Shopify’s own pixels and checkout respect it.
- Render — hosting and the database the app runs on.
- Resend — delivery of the app’s notification emails to the merchant. Merchant email addresses only; no visitor data is ever sent by email.
Emails we send
To the merchant only, and only about their own account: two notices before a free trial ends, one if a payment fails, and one if the banner is switched off. There is no marketing email.
Deletion, and requests from visitors
Uninstalling the app deletes the store’s record and every consent
record belonging to it, through Shopify’s shop/redact
webhook. The app also implements Shopify’s
customers/data_request and customers/redact
webhooks.
A visitor who wants their consent record removed should contact the store they visited, since the merchant is the controller. Consent records hold no identifying data, so locating a specific visitor’s record generally requires the identifier from their own browser cookie. Merchants who need help with a request can write to us at support@novece.com.
Changes
If this policy changes we update the date at the top. Material changes are also announced inside the app.
This page describes what our app does with data. It is not a cookie policy for a merchant’s own store, and it is not legal advice. The app helps merchants meet their obligations around cookies; it does not make a store compliant on its own.