Script Safe

Privacy Policy

Last updated: August 15, 2026

Overview

ScriptSafe (“the App”) is a Shopify application that scans a merchant's storefront for third-party tracking scripts, helps migrate them into Shopify's supported Web Pixels framework, and lets merchants build automations triggered by store orders. This policy explains what data the App collects, why, and how it's handled.

ScriptSafe is developed and operated by Squarebuz.

Who this policy covers

This policy covers two groups:

  • Merchants who install ScriptSafe on their Shopify store.
  • That merchant's customers, whose order and account data ScriptSafe processes in order to power features the merchant has configured, such as order-triggered automations.

If you're a shopper with a question about how a specific store uses ScriptSafe, that store is your first point of contact — we process data as a service provider to the merchant, not as the party who decides what's collected or why.

Data we collect

Shopify access we request

When a merchant installs ScriptSafe, Shopify grants the App the following permissions. We request only what each feature needs:

  • write_pixels — lets the App create and update your store's Shopify Web Pixel, so we can migrate your existing tracking pixels (Google Analytics, Meta, TikTok, Pinterest, Snapchat, LinkedIn, Microsoft UET, and others) into Shopify's supported framework.
  • read_customer_events — read-only. Lets the App confirm which tracking pixels are already natively installed on your store, which isn't always detectable by scanning your theme code alone.
  • read_orders — delivers new orders to the App in real time via webhook, which drives any order-based automations you've configured.
  • write_customers — lets the App write a single flag onto a customer record — for example, marking that a customer has completed a verified first order. The App does not read back or export your customer list.

We also subscribe to the app/uninstalled and app/scopes_update webhooks to keep access in sync with what you've authorized, and to the three mandatory Shopify privacy webhooks described under “Your rights” below.

Content you submit directly

  • Script or code snippets you paste in for scanning.
  • Marketing-platform IDs and API credentials (Google Analytics 4, Meta, TikTok, Pinterest, Snapchat, LinkedIn, Microsoft UET) that you provide so the App can configure your Web Pixel.

Order and customer data, via webhook

When an order is placed on your store, ScriptSafe receives the order ID, order name, total, currency, and discount code; line item SKUs and properties; and the customer's Shopify ID, tags, and order count. This is what powers merchant-configured automations.

Email addresses: ScriptSafe does not currently access customer email addresses. Shopify gates email access separately from the App's general subscription approval, and ScriptSafe has not requested or been granted it. If you build a postback automation (see “Who we share data with” below), any fields you choose to forward are sent to the destination you configure — so if that destination or a field you map into it happens to include an email address from elsewhere, that flows through your configuration, not ours. Should ScriptSafe's own access to email ever change, we'll update this policy before that access is used.

Checkout-side storage

ScriptSafe maintains a small key/value store tied to each Shopify customer ID — used for things like remembering whether a customer has already dismissed an on-site banner. This only applies to logged-in customers; guests get nothing stored, since there's no stable ID to attach it to.

From your customers directly: none

ScriptSafe has no customer-facing interface of its own. All data described above reaches us via the merchant's Shopify store, not by way of anything a customer submits to ScriptSafe directly.

Who we share data with

  • Anthropic — when you ask ScriptSafe to explain a script or extract migration settings from it, the script's text (capped at 12,000 characters) is sent to Anthropic's API. We don't deliberately include customer or order data in that request — only the code you submitted.
  • Postback URLs you configure — if you build an automation that forwards data to your own systems (a CRM, an affiliate platform, etc.), only the specific fields you configure are sent, and only to an HTTPS destination. Outbound requests are SSRF-guarded (private and internal IP ranges are blocked) and rate-limited.
  • Shopify — as the platform ScriptSafe runs on.

We do not sell data, and we do not share it for advertising purposes.

Cookies & tracking

ScriptSafe does not set any cookies of its own. This is by design: Shopify's checkout sandbox doesn't allow cookies at all, which is exactly why the checkout-side storage described above exists — as a server-side alternative for the small amount of state ScriptSafe needs to keep.

Data retention

  • Scan results and detected scripts are kept for 90 days, or the 20 most recent scans per store — whichever is smaller.
  • Automation run logs are kept for 90 days.
  • Uninstalling the App erases all shop-scoped data within 48 hours, triggered automatically by Shopify's shop/redact webhook.
  • If a customer's data is subject to a verified erasure request, we delete it immediately — including their checkout-side storage entry.

Your rights

ScriptSafe implements Shopify's three mandatory privacy webhooks:

  • customers/data_request — when triggered, we look up and log what we hold about the customer (which types of data, and how much, not the raw values themselves) so the merchant can respond to the request.
  • customers/redact — deletes the customer's data from ScriptSafe, including their checkout-side storage entry.
  • shop/redact — on uninstall, or a shop-level redact request, erases all data tied to the shop.

If you're a merchant, you can also reach us directly at support@squarebuz.com to request that we remove your data sooner. If you're a customer with a question about a specific store's data, that store is your first point of contact — they can trigger these requests through Shopify on your behalf.

Security

  • Each merchant's data is isolated from every other merchant's.
  • Outbound postbacks are sent only over HTTPS and are SSRF-guarded against private and internal network addresses.
  • Our logs are designed to exclude personal data.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected with an updated “Last updated” date above.

Contact

Questions about this policy or how ScriptSafe handles data: support@squarebuz.com