Littledata takes security for our customer's data seriously, and along with our data security policy, this guide will help you understand what we do and do not track.
Littledata's systems, hosted in AWS US-East-1, accept webhooks and API responses from Shopify (all using SSL) and process the data for forwarding to data destinations (Google Analytics or Segment). The data never leaves the USA.
All access to Littledata's secure systems is limited to a handful of senior full-time employees, on a least privilege basis, using multi-factor authentication.
Our tracking script also tracks some pseudo-anonymous fields from the end user's browser and stores them temporarily in the cloud for use in this event processing.
Our policy is to store and process as little personally identifiable (PII) data as possible, and the specifics of how we handle PII fields is below.
We also store non-PII data in our MongoDB instance, for up to 2 months after the event, to use in refunds and error investigation. All data is encrypted in transit and at rest.
|Data field||Received by Littledata||Temporary storage *||Relayed to Google||Relayed to Segment||Relayed to Facebook **|
|Partial IP address ***||✔||✔||✔||✔||✔|
|Platform specific client ID ****||✔||✔||✔||✔||✔|
|Shopify customer number||✔||✔||✔||✔||✔|
|Contents of the shopping cart (item name, sku and quantity)||✔||✔||✔||✔||✔|
** All data relayed to Facebook is hashed.
*** Last octet is anonymized
**** GA client ID / Segment Anonymous ID / fbp / fbc