How Ignis handles data.
Last updated 11 August 2026. Operated by Ignis International LLC ("Ignis", "we").
Ignis provides commerce and content software to merchants ("brands") who run their stores on Shopify. This page explains what data the Ignis platform processes, why, how we protect it, and how it is deleted. We collect the minimum data required to run each feature, and we do not sell personal data.
Whose data this covers
Two groups:
- Brands. The merchant accounts that install and use Ignis (account, contact, billing, and store-configuration data).
- Shoppers and visitors. The customers of those brands, and people who browse a brand's store without buying. Their data flows through Ignis only to power the features a brand has switched on, for example inventory sync, reviews, returns, loyalty and analytics.
What we collect and why
- Order data (product IDs, variant IDs, quantities, order identifiers). Used to keep pack inventory accurate, credit loyalty points, and process returns. This is the data behind the "protected customer data" access the app requests. We request it for app functionality only.
- Order detail, where a feature needs it. For the features that cannot work without it, such as return labels, loyalty, order-level analytics and server-side conversion tracking, Ignis reads the full order from Shopify under the brand's own connection. That order carries the shopper's name, email address, phone number and addresses.
- Product and store configuration. Catalog, pricing rules, and per-brand module settings needed to render features in the store and dashboard.
- Reviews and returns content that a shopper voluntarily submits (rating, review text, optional photos; return reason and shipping address for a return label), used only to provide that feature to the brand.
- Support messages a shopper sends through a brand's Ignis support form, including whatever the shopper chose to write, and a one-time code sent to their email address to verify them.
- Site activity, where a brand has switched on Ignis analytics. Page views, product views, cart events, checkout steps, the page address, the referring page, the campaign tags and advertising click identifiers on the link the shopper arrived on, and browser details such as user agent, language, screen size and timezone offset. Each event is tied to a random visitor identifier, not to a name. Where a shopper signs in or submits an email address to a brand's form, the browser sends us a one-way SHA-256 hash of that address, never the address itself.
- Brand account and billing data for authentication, support, and subscription management.
The shopper's IP address. We receive it, as any web service does, when a browser sends us a request. We use it to rate limit abuse, to let a brand exclude its own staff from its own figures, and, where a brand has switched on server-side conversion tracking, to send the conversion to Meta on that brand's behalf. We do not store a raw IP address in our analytics tables.
Data minimization. Where a feature does not need a shopper's name, email, phone, or address, Ignis does not request or store it. The Ignis Shopify app's own order webhook, for example, forwards only the order identifier, the customer identifier, order totals and line items, with no contact details and no addresses.
Cookies and similar technologies
On this website (ignishq.com) we use none. This site loads no analytics, no advertising tags, no external fonts and no third-party scripts, and it sets no cookies.
In the Ignis dashboard we keep your sign-in session in your browser's local storage so you stay signed in. We do not use it for advertising and we do not share it.
On a brand's storefront, Ignis places first-party identifiers in the shopper's browser. There are two ways this happens, and they are not the same:
- The Ignis Analytics pixel is switched on by the app when a brand installs Ignis. Shopify's own pixel manager will not load it at all unless the shopper has allowed analytics.
- The Ignis theme embed is off unless the brand switches it on in their theme editor. It runs on the storefront page itself, so it can also see marketing links, cart changes and form submissions.
These are what we set and why:
_pxa, a cookie and a matching local-storage entry, 365 days, renewed on each visit. A random visitor identifier so repeat visits by the same browser can be counted once. Where the Ignis analytics endpoint is on the same site as the store, our server re-issues the same identifier for 400 days, because browsers cut short the lifetime of cookies set by a script. It contains no name, email address or phone number._pxs, a cookie, 30 minutes rolling. A random session identifier, so a single visit is measured as one visit._pxl_excluded, a cookie and a local-storage entry, 10 years. Set only when a brand's own staff device asks to be excluded from that brand's analytics, so their visits do not distort the figures. A device carrying this flag sends nothing at all._fbpand_fbc, cookies, 90 days. Meta's browser identifier and click identifier. These appear only where the brand has connected Meta and chosen the browser-side option. In that case Ignis reads them, creates_fbpif the browser does not already have one, and can restore either from our own record if the browser has lost it. In that same case the storefront also loads Meta's own script fromconnect.facebook.net, which is Meta's code operating under Meta's terms._px_ftand_px_lt, local storage, until cleared. The first and most recent marketing source for this browser, taken from the link the shopper arrived on. This includes campaign tags and advertising click identifiers where the link carried them._px_buf,_px_attr_syncedand_px_blocked, local storage and session storage, until cleared. Working state, so events are not lost when a page closes and are not counted twice.
Where the theme embed is on, Ignis also writes those identifiers onto the brand's own Shopify cart as cart attributes, so an order can be matched to the visit that produced it.
Consent, described exactly. The Ignis Analytics pixel is not loaded by Shopify unless the shopper has allowed analytics, so no consent decision of ours is involved. The theme embed reads the shopper's choice from Shopify's Customer Privacy API and re-reads it whenever the shopper changes it. Where that shopper has declined analytics, the embed sends no events. Where a storefront does not have Shopify's Customer Privacy API present on the page at all, the embed treats analytics as allowed, so a brand using the theme embed should make sure their consent banner is in place. The brand is responsible for the consent banner on their own storefront and for their own cookie notice. This page is here so a brand can publish an accurate one.
A shopper can clear all of this at any time by clearing cookies and site data for that store in their browser.
How we protect it
- Encryption in transit. All traffic uses TLS/HTTPS; server-to-server calls are additionally signed (HMAC-SHA256) and rejected if unsigned or if the signing secret is not configured.
- Encryption at rest. Data is stored in a managed Postgres database that encrypts data at rest, and files are stored in object storage that does the same. On top of that, stored third-party credentials are encrypted by Ignis itself with AES-256-GCM before they are written. That extra layer covers credentials. Other data is protected by the database's own encryption at rest and by the controls below.
- Tenant isolation. Every brand's data is separated at the database level with row-level security, so one brand can never read another's data.
- Least-privilege access. Access to production data is limited to the personnel who operate the platform, and application code runs under a restricted database role rather than an owner role.
- Purpose limitation. Data is used only for the feature the brand switched on, and is never resold. Where a brand enables server-side conversion tracking, the data that feature sends is described under Who we share it with below.
No software or hosted service can be guaranteed secure, and we do not claim otherwise. We hold no security certification, and this page names only measures that are actually in place.
Artificial intelligence
Several Ignis features use AI. Here is what happens to data in them.
- We do not build or train our own AI models. There is no Ignis model, so no brand's data and no shopper's data is used to train one.
- Shopper data is not used to train anything. Not a model of ours, not a brand's.
- We use third-party AI providers, named in the list below. When a brand uses an AI feature, the prompt and any files that feature needs are sent to the relevant provider so it can produce the output the brand asked for.
- What a provider may do with a request is set by that provider's own terms, and those terms differ between them. We send requests through our own accounts with each provider, unless a brand has connected an account of its own. If this matters to your business, read the terms of the provider behind the feature you use, and connect your own account where Ignis supports it.
- Providers keep a short-term copy. AI providers generally retain a request for a limited period to detect and prevent abuse, and may have staff review content their systems flag as a possible policy breach. The providers we use publish periods of up to 30 days for this. That is their retention, not ours.
- One feature does involve training, and only when a brand asks for it. A brand can create a reusable image model from reference photographs they upload, so generated images keep the same look. That training runs at the brand's request, through our image provider, from the files that brand supplied and nothing else. The result is stored against that brand's account and is used only for that brand's own generations.
- If a brand uploads photographs of a real person, that brand is responsible for having that person's permission, including permission to create a reusable image model from their likeness. Our terms say the same thing.
- AI output can be wrong. We say so plainly in our terms. A brand reviews AI output before it reaches a customer or an ad platform.
We record how much AI a brand used, so we can bill it and show them their spend. That record holds the provider, the model name, the operation, the amount of work and the cost.
Who we share it with
We do not sell personal data. We share it only with the providers we need to run the features a brand has switched on, and only for the purpose named. This is the current list.
Always used, because they run the platform:
- Railway, application hosting. Processes everything the platform handles.
- Neon, managed Postgres database. Stores everything the platform stores.
- Cloudflare R2, file storage. Review photos, files attached to a support message, return labels, images and videos a brand uploads, and database backups.
- WorkOS, sign-in for brand accounts. The email address and name of the brand's staff. No shopper data.
- Vercel, hosting for this website and our documentation. Static pages only, no personal data.
- Stripe, payments and creator payouts. Brand billing details and creator payout details. No shopper data.
- Resend, transactional email. A shopper's email address, to send return labels, verification codes and support replies. A brand can use their own mail account instead.
Used only for the feature named, and only when a brand switches it on:
- EasyPost, return labels. The shopper's name and shipping address, to buy the label the brand offers.
- OpenAI, text generation. Support message content, including any personal details a shopper wrote into a support form, so the brand can be offered a drafted reply. Also the brand's own prompts and product text.
- Anthropic, text generation. The brand's prompts and their own store data, for the assistant features.
- fal.ai, image and video generation, and the reusable image models described above. The brand's prompts and the images the brand uploads.
- Google, image generation on the routes where Ignis is configured to use it. The brand's prompts and the images the brand uploads.
- Klaviyo, or another marketing platform the brand connects. The email address a shopper gave to that brand.
- Meta, where the brand has connected a Meta account and switched on server-side conversion tracking. Covered in the paragraph below.
- Google Ads and TikTok, where the brand connects those accounts. Ignis reads that brand's own campaign and spend figures, and can publish content the brand made to the brand's own TikTok account. We do not send shopper personal data to either.
Brands on some plans use their own OpenAI, Anthropic or fal.ai accounts instead of ours. Where they do, their data goes to their own account with that provider and is billed there. A brand can also send store email through their own Resend account, their own SMTP host, or their own Gmail account, in which case Ignis does not handle the sending.
When a brand connects Meta and turns on server-side conversion tracking, we send order and event data to Meta on the brand's behalf and on the brand's instruction. Identifiers such as email address, phone number, name, city and postcode are hashed before they are sent. The shopper's IP address, browser user agent and Meta's own browser cookie identifiers are sent as they are, because Meta requires that form. This happens only for brands that have connected Meta and turned this on, and only where the shopper's consent allows it. Server-side conversion tracking to any other advertising platform is not something Ignis does today.
We also disclose personal data where the law requires it, and to a buyer of our business if Ignis is ever sold, in which case this page is updated first.
Changes to this list. We keep this list current on this page, and we update it before adding a new provider that handles personal data. The date at the top changes when we do. A brand who wants to be told directly can ask us to email them when this list changes, at [email protected].
Where your data is processed
Ignis is a United States company and the platform runs on United States providers. If you are in the United Kingdom, the European Economic Area or Switzerland, your personal data leaves that region when it reaches us.
We do not claim a transfer mechanism we have not put in place. A brand can enter into the UK and European Commission Standard Contractual Clauses with us for that transfer, as part of our data processing terms, and can ask us which transfer terms apply with each provider named above. Write to [email protected] and we will send you the current position.
Where a brand connects a provider of their own, such as their own advertising account or their own marketing platform, that provider's own location and terms apply to what the brand instructs us to send there.
How long we keep it and how it's deleted
We keep data only as long as needed to provide the service to the brand, or as required by law. Ignis honors Shopify's mandatory data-protection requests:
- Customer data request. We assemble the data we hold for a specific shopper and provide it to the brand, who is the one that received the request.
- Customer redaction. We delete a specific shopper's data when Shopify sends a redaction request, or remove their identity from a record that has to survive for the reasons given below.
- Shop redaction. When a brand uninstalls the app and Shopify sends a shop-redaction request, we delete that store's shopper data: reviews, returns, support conversations and messages, one-time codes, store credit and loyalty records, visitor tracking and identity records, signup-form captures, and our copy of the brand's order list.
Shop redaction removes the shopper data. It deliberately leaves the brand's own Ignis workspace in place, meaning their account, their team, their settings and the content they made, because a brand's account can outlive one Shopify install and deleting it would destroy work that is not customer data. A brand who wants that removed as well can ask us at [email protected].
Retention periods
Each brand chooses its own retention periods in their Ignis settings and switches automatic clean-up on. Until a brand turns clean-up on, shopper data is kept until one of the three requests above removes it. Clean-up also has to be switched on by us, per environment, before any of it runs. A brand can see in their settings which of the two applies to them, and nothing is removed until it says clean-up is running. When both are on, a daily job applies that brand's periods. These are the periods a brand can set, the default we suggest for each, and exactly what happens at the end of one:
- Visitor tracking. Default 13 months. The record linking a visitor to their email address, phone number or customer account is deleted. Those identifiers and the browser user agent are also removed from stored events. Traffic, order and revenue figures are not affected.
- Shopper records. Default 2 years. The name, email address, customer id and any stored shipping-label link are removed from reviews, returns, support conversations and our copy of the brand's order list. Those records themselves stay, so the brand keeps its reviews, its returns history and its accounts. Saved items are different: a saved item is only a shopper and a product, so the whole record is deleted rather than stripped, counted from when the shopper last touched their list. Anything still in progress, such as an open return or an open support conversation, is never removed no matter how old it is.
- Reviews the brand rejected. Same 2 year period. A review the brand chose not to publish is deleted outright, and any photos on it are deleted from our file storage at the same time.
- Signup form captures. Default 2 years. The email address captured by a popup or signup form is removed from the prize record. The prize and the discount code stay. A gift that was promised and not yet sent is never removed.
- One-time codes. Default 30 days. Expired sign-in and verification codes, which hold an email address and an IP address, are deleted.
A brand can set any of these to a longer period, up to ten years, or to "keep forever". Each one also has a shortest period we allow, so a brand cannot set clean-up so aggressive that it removes data the service still needs. Those minimums are 30 days for visitor tracking, 90 days for shopper records and signup captures, and 1 day for one-time codes. Separately from the periods, a record that is still in progress is never removed at any age. That protection comes from the record's own state, not from the minimum period.
Store credit and loyalty balances are kept. They are a financial record of what a brand owes a shopper, and deleting one would not cancel the obligation, it would only destroy the brand's record that it exists. When a shopper asks to be erased, we remove the identity from the store credit record and keep the amount, so the shopper can no longer be linked to it and the brand's accounts stay correct. A loyalty points balance is removed on that request, because a points balance is not a debt in money. The history of how points were earned and spent stays, with the shopper's identity taken off it, so the brand's own records still add up.
Backups. We take a backup of the database every day, store it in encrypted object storage, and keep it for 30 days. When a record is deleted, whether by a retention period, a redaction request or a brand uninstalling, it is removed from the live system straight away and then ages out of the backups within 30 days. We do not restore a backup in order to bring deleted personal data back. If we ever have to restore one to recover from a failure, we re-apply the deletion.
Your rights
If you are a brand. You control which modules are active. You can change your retention periods at any time in your Ignis settings. You can disconnect Ignis by uninstalling the app, which starts the deletion described above. You can ask us for a copy of your account data, for a correction, or for deletion, by writing to [email protected].
If you are a shopper. Depending on where you live, you may have the right to ask for a copy of the personal data held about you, to have it corrected, to have it deleted, to receive it in a portable form, to object to or restrict certain processing, and to withdraw a consent you previously gave. You will not be treated differently for exercising any of these rights.
The brand you shopped with is the one who decides how your data is used, so the fastest route is to ask them. Their request reaches us through Shopify's own compliance channel and we act on it.
You can also come to us directly. Write to [email protected] and tell us which store you shopped with and the email address you used there. Because we hold your data on that brand's behalf, we will verify the request and then either action it or pass it to that brand to confirm, and we will tell you which we did. We answer within one month of receiving a request we can verify, and we will tell you if we need longer than that.
We may need to keep some records even after a deletion request, where the law allows or requires it. Store credit is the clearest example, and it is described above.
If you are in the United Kingdom or the European Economic Area and you are not satisfied with how we handled your request, you can complain to your national data protection authority.
California and other US state privacy rights
If you live in California, or in another US state with a comprehensive privacy law, you have rights to know what personal information is collected about you, to have it deleted, to have it corrected, to receive a copy, and to opt out of its sale or sharing. You will not be discriminated against for using them.
We do not sell personal information, and we do not share it for cross-context behavioural advertising for our own purposes.
Where a brand has connected Meta and switched on server-side conversion tracking, we send that brand's order and event data to Meta on the brand's instruction. Under California law that can count as "sharing" by the brand. The brand decides whether it happens, and the brand is responsible for offering their shoppers the opt-out. Ignis applies the choice a shopper makes: where a shopper has opted out of the sale or sharing of their data, we either stop sending person-linked data for that shopper, or send it with Meta's own limited-data-use flag set, so the conversion still counts and Meta limits what it does with the person-linked fields.
To exercise any of these rights with us directly, write to [email protected]. An authorised agent may make a request for you if they give us proof that you authorised them.
Children
Ignis is business software sold to brands. It is not directed to children, and we do not knowingly collect personal data from anyone under 16. Where a brand's storefront reaches shoppers, that brand is responsible for the age of its own audience. If you believe a child's personal data has reached us through a brand's store, write to [email protected] and we will delete it.
If something goes wrong
If we become aware of a breach of security that affects personal data we hold for a brand, we notify that brand without undue delay after we confirm it, tell them what we know, and help them with the notifications they have to make. Because we hold the data on the brand's behalf, the brand decides whether and how to notify their own customers and any regulator. We do not notify a brand's customers on the brand's behalf.
Changes to this policy
We update this page when the platform changes. The date at the top is the date of the current version. Where a change materially affects how we handle personal data, we will tell brands through the app or by email before it takes effect.
Contact
Questions about privacy or a data request: [email protected].