ab.one – A/B Testing for Shopify
This Privacy Policy explains how kreativkonnekt GmbH ("we", "us", "our"), operating the ab.one application, collects, uses, discloses, and protects information when you use our A/B testing service for Shopify stores.
This policy applies to:
By using ab.one, you agree to the collection and use of information in accordance with this policy.
kreativkonnekt GmbH
Fuhlsbüttler Straße 421
22309 Hamburg, Germany
Managing Directors: Michael Wanjek, Nikolas Schaffmann
Commercial Register: HRB 188943 (Amtsgericht Hamburg)
VAT ID: DE451767536
Tax Number: 43/738/02587
Privacy Contact: hi@ab.one
When you install and use ab.one, we collect:
| Data Type | Purpose |
|---|---|
| Shop name, URL, email | Account identification and communication |
| Contact name, phone | Support and billing contact |
| Shopify OAuth access tokens | API access to manage A/B tests (stored encrypted) |
| Theme ID | To inject tracking scripts and test variants |
| Plan selection, usage metrics | Billing and service limits |
| Onboarding data (industry, company size, goals) | Product improvement and personalization |
| Timezone, currency, country | Localization and reporting |
When visitors browse a Shopify store using ab.one, we collect:
| Data Type | Purpose |
|---|---|
| Pseudonymous Visitor ID (UUID) | Track test participation across sessions |
| Device type (mobile/desktop) | Device-specific test targeting |
| Viewport dimensions | Responsive design testing |
| UTM parameters | Traffic source attribution |
| Referrer URL and domain | Traffic source analysis |
| Country/region (from Shopify) | Geographic test targeting |
| Test variant assignments | A/B test logic |
| Behavioral events | Conversion tracking |
Behavioral events collected:
page_viewed – Page URL visitedproduct_added_to_cart – Add-to-cart actioncheckout_started – Checkout initiation with order valuecheckout_completed – Purchase completion with order valueWe explicitly do NOT collect the following from storefront visitors:
The Visitor ID we generate is a random UUID stored in the visitor's browser localStorage. It cannot be linked to any personal identity.
abone.liquid) injected into your Shopify theme that manages test assignments and emits eventsab.one requests the following Shopify API permissions:
| Scope | Purpose |
|---|---|
read_themes, write_themes | Inject tracking script and test variants |
read_products, read_collections | Display resources for test targeting |
read_orders | Conversion tracking and revenue attribution |
read_content | Access metafields for test configuration |
write_pixels | Deploy Web Pixel Extension |
Under GDPR Article 6, we process data based on the following legal grounds:
| Purpose | Legal Basis | GDPR Article |
|---|---|---|
| Provide A/B testing service | Contract performance | Art. 6(1)(b) |
| Generate test reports and analytics | Legitimate interest | Art. 6(1)(f) |
| Billing and subscription management | Contract performance | Art. 6(1)(b) |
| Product improvement and development | Legitimate interest | Art. 6(1)(f) |
| Customer support and communication | Contract performance | Art. 6(1)(b) |
| Fraud prevention and security | Legitimate interest | Art. 6(1)(f) |
Legitimate Interest Assessment: Our legitimate interests in providing analytics and improving our service do not override the privacy rights of individuals, as we only process pseudonymous data that cannot identify specific persons.
We share data with the following service providers who process data on our behalf:
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Database and authentication | EU (Frankfurt) |
| Shopify | Platform integration, OAuth | Global |
| PostHog | Product analytics | EU |
| Infisical | Secrets management | US |
| Mailgun | Transactional email | US/EU |
We do NOT:
Our primary data processing occurs within the European Union (Supabase Frankfurt region).
For subprocessors located in the United States (Infisical, Mailgun), we ensure appropriate safeguards through:
| Data Category | Retention Period | Deletion Trigger |
|---|---|---|
| Merchant account data | Duration of service | App uninstallation |
| Test configurations | Duration of service | App uninstallation |
| Visitor event data | Until merchant deletion request | Merchant request or uninstall |
| Aggregated reports | Retained for historical analysis | May be anonymized and retained |
| Access tokens | Duration of service | App uninstallation (immediate) |
When a merchant uninstalls ab.one:
abone.liquid) are removedThis process is automated and immediate upon uninstallation.
Merchants can request deletion of all their data at any time by:
We will process deletion requests within 30 days.
We implement appropriate technical and organizational measures to protect your data:
While we take reasonable precautions, no internet transmission or electronic storage is 100% secure. We cannot guarantee absolute security but commit to promptly addressing any security incidents.
ab.one primarily uses browser localStorage (not cookies) to store:
We read (but do not set) the Shopify _shopify_y cookie to correlate with Shopify's visitor identification when available.
Because we use localStorage rather than cookies for visitor tracking, and our tracking is essential for the A/B testing service functionality, separate cookie consent is typically not required. However, merchants are responsible for their store's overall cookie compliance.
You have the following rights regarding your personal data:
| Right | Description | How to Exercise |
|---|---|---|
| Access (Art. 15) | Request a copy of your data | Email hi@ab.one |
| Rectification (Art. 16) | Correct inaccurate data | Email hi@ab.one |
| Erasure (Art. 17) | Request deletion of your data | Email hi@ab.one or uninstall |
| Restriction (Art. 18) | Limit how we process your data | Email hi@ab.one |
| Portability (Art. 20) | Receive your data in portable format | Email hi@ab.one |
| Object (Art. 21) | Object to processing based on legitimate interest | Email hi@ab.one |
| Withdraw Consent | Withdraw previously given consent | Email hi@ab.one |
Supervisory Authority: You have the right to lodge a complaint with your local data protection authority. In Germany, this is the Hamburgische Beauftragte für Datenschutz und Informationsfreiheit.
UK residents have equivalent rights to those listed above under the UK General Data Protection Regulation.
California residents have the following rights:
Categories of Personal Information Collected (per CCPA definitions):
We do NOT sell personal information as defined under CCPA.
To exercise your California privacy rights, contact hi@ab.one.
We will respond to verified requests within:
For storefront visitor data, ab.one acts as a Data Processor under GDPR. The merchant (Shopify store owner) is the Data Controller and is responsible for:
Merchants requiring a formal Data Processing Agreement (DPA) for compliance purposes can request one by contacting hi@ab.one.
ab.one is a business-to-business service intended for Shopify merchants. Our service is not directed at children under 16 years of age.
We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 16, we will take steps to delete that information promptly.
If you believe we have inadvertently collected information from a child, please contact hi@ab.one.
ab.one uses automated processing for:
These automated processes:
No profiling or automated decision-making affects individual visitors in a meaningful way.
We may update this Privacy Policy from time to time. When we make changes:
The "Last updated" date at the top of this policy indicates when it was last revised.
We encourage you to review this policy periodically. Continued use of ab.one after changes constitutes acceptance of the updated policy.
For any questions, concerns, or requests regarding this Privacy Policy or our data practices:
Privacy Inquiries
Email: hi@ab.one
General Support
Email: hi@ab.one
Postal Address
kreativkonnekt GmbH
Fuhlsbüttler Straße 421
22309 Hamburg
Germany
We aim to respond to all inquiries within 5 business days.
Our service may contain links to third-party websites (e.g., Shopify). We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.
If kreativkonnekt GmbH is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will provide notice before your data becomes subject to a different privacy policy.
We may disclose your information if required by law, such as to comply with a subpoena, court order, or similar legal process, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
This Privacy Policy is effective as of January 18, 2026.
© 2026 kreativkonnekt GmbH. All rights reserved.
We're here to help. Contact us anytime with questions about how we handle your data.