BotShield Privacy Policy
Effective date: August 20, 2026
This Privacy Policy explains how BotShield processes information when the application is installed on a Shopify store. BotShield is operated under the Alboro name.
1. Information we process
BotShield is designed to monitor storefront behavior, calculate behavioral risk scores, and protect checkout flows against automated bot traffic while strictly adhering to data minimization principles.
Depending on how the application is used and configured, we may process:
- Shopify store information, including the store's myshopify.com domain.
- Application installation, authentication tokens, and administrative session information required to connect and operate BotShield with the merchant's Shopify store.
- Storefront behavioral events such as page views, product views, collection views, searches, cart views, add-to-cart events, cart removals, checkout starts, checkout completions, and security alert displays.
- Pseudonymous event identifiers and event timestamps.
- A pseudonymous Shopify-provided client identifier used to group related events into visitor sessions without identifying individuals.
- Shopify cart identifiers read from the standard cart cookie or storefront event context to synchronize protection states with the shopping cart, encrypted at rest using AES-256-GCM.
- Transient network and transport headers (such as IP addresses) processed ephemerally in memory at the server level to compute a pseudonymous cryptographic network fingerprint for security, ticket authentication, and rate limiting. Raw IP addresses are not stored in our application database.
- Derived metrics and security data including session durations, event counters, behavioral risk scores, risk levels, and detected behavioral signals.
2. Information BotShield does not collect
The BotShield storefront pixel and backend are designed not to collect customer names, email addresses, telephone numbers, postal or shipping addresses, payment card details, account passwords, third-party advertising cookies, browser canvas fingerprints, or the text of customer search queries.
3. How we use information
We process the information described above to:
- Provide BotShield's traffic and bot monitoring functionality.
- Group storefront activity into pseudonymous visitor sessions.
- Calculate behavioral risk scores and risk levels.
- Detect rapid, unusual, automated, or malicious browsing behavior.
- Synchronize protection states with the Shopify checkout to prevent automated bot checkouts.
- Display traffic, risk, and protection analytics to the merchant.
- Maintain the security, rate limiting, reliability, and integrity of the service.
- Diagnose technical problems and prevent abuse of application infrastructure.
4. Shopify customer privacy choices
BotShield uses a Shopify Web Pixel configured with standard customer privacy settings (analytics=false, marketing=false, preferences=false, sale_of_data=disabled) and operates in accordance with Shopify's customer privacy framework. Shopify controls whether the pixel executes based on applicable merchant and visitor consent settings.
5. Service providers
We use trusted third-party infrastructure providers to host and operate BotShield. These providers process information only as necessary to provide infrastructure services to us:
Cloud application hosting provided through Render and managed database infrastructure provided through Supabase (PostgreSQL).
Shopify Inc., which provides the core e-commerce platform, APIs, Web Pixel execution environment, and authentication services in accordance with its own privacy policies.
6. Data retention and deletion
Information is retained for the duration of the merchant's active installation to provide continuous protection, maintain service security, and support merchant analytics.
Access to historical session and event records in the merchant dashboard is governed by the retention window of the merchant's active subscription plan (3 days on Free, 14 days on Starter, 60 days on Pro, and 180 days on Unlimited).
When a merchant uninstalls BotShield or when Shopify issues a shop redaction request (SHOP_REDACT compliance webhook), all store data, sessions, events, usage, and billing snapshots are completely and permanently deleted from our database.
7. Data security and encryption
We employ industry-standard technical and organizational security measures, including HTTPS encryption in transit, AES-256-GCM encryption for stored cart identifiers, HMAC-SHA256 token verification, and principle-of-least-privilege access controls.
While no system can guarantee absolute security, BotShield is designed around data minimization and pseudonymous processing to minimize risk.
8. Privacy requests and compliance
Merchants and store visitors have rights regarding their data under applicable data protection laws. Because BotShield processes only pseudonymous identifiers and does not store direct customer contact records, requests related to a specific store visitor should be directed to the corresponding Shopify merchant.
We promptly process all automated privacy and compliance webhooks received from Shopify, including mandatory shop redaction requests.
9. Children's privacy
BotShield is a business-to-business application designed for Shopify merchants and is not directed to children under 16. We do not knowingly collect personal information from children.
10. Changes to this policy
We may update this Privacy Policy to reflect changes in our practices, features, or applicable legal requirements. Any material updates will be reflected with a revised effective date at the top of this page.
11. Contact information
For questions, concerns, or inquiries regarding this Privacy Policy or BotShield's data practices, please contact us at:
BotShield / Alboro
Email: sergioramirezmoron@gmail.com