Legal · Data processing

Privacy Policy

Last updated: 2 September 2026

ProfitRank is a Shopify application operated by NoMilk ApS, Strøget 38, 7430 Ikast, Denmark, CVR 40266372 (“we”, “us”). This policy explains what data the app processes when a merchant installs it on their Shopify store. Questions about it go to hej@nomilk.dk.

Our role

When a merchant installs ProfitRank, the merchant is the data controller and ProfitRank is the data processor. We process store data solely to provide the service, on the merchant's instructions. We do not sell data, and we do not use it to build profiles for our own or anyone else's purposes.

What we store from a merchant's store

To score products by profitability, ProfitRank stores a copy of the following from Shopify:

  • Shop details: store domain, shop name, currency, timezone, install and uninstall dates, and an encrypted OAuth access token
  • Products and variants: Shopify product and variant identifiers, titles, vendor, product type, status, price, cost per item, and inventory quantities
  • Orders: Shopify order identifier, order totals, discounts, shipping amount and method, financial status, and the date the order was placed
  • Order line items: the products and quantities in each order, with prices and discounts
  • Returns and refunds: which products were returned, quantities, and reasons
  • Customer purchase statistics: the Shopify customer identifier, total spent, order count, average order value, and first and last order dates
  • Collections, locations and inventory levels
  • Data we derive from the above: product scores, score history, and portfolio metrics

What we do not store

ProfitRank does not store customer names, email addresses, phone numbers, billing or shipping addresses, or any payment or card details. We never receive card data — merchant subscription payments are handled entirely by Shopify.

The only customer-related identifier we hold is the numeric Shopify customer ID, which we use to calculate how much repeat value a product's buyers generate.

Storefront data and cookies

If a merchant enables ProfitRank's A/B testing feature, the app places a small script on their storefront which sets two cookies:

CookiePurposeDuration
pr_sid A randomly generated visitor identifier, used only to avoid counting the same visit twice 365 days
pr_variant Records which version of the product ordering the visitor was shown 365 days

These cookies contain no personal information — pr_sid is a random value not linked to any name, email or account. They are set only after the visitor has granted analytics consent through the store's cookie banner, using Shopify's Customer Privacy API. If consent is declined or not given, no cookies are set and no visit is recorded.

The same identifiers are attached to the shopper's cart so that a resulting order can be matched to the version they saw.

Server logs

Our servers keep standard technical logs (request times, error details) which may include IP addresses for a limited period for security and troubleshooting. These are not used to identify individuals.

Who we share data with

ProfitRank does not sell merchant or shopper data, and never shares it with third parties for marketing or advertising purposes. We use no third-party analytics, advertising, or tracking services inside the app.

The only companies that handle data on our behalf are the two sub-processors below, and they act solely on our instructions to run the service:

  • DigitalOcean — hosting. Our servers and database are located in the Netherlands, so all merchant and shopper data is stored and processed within the European Union.
  • Sentry — error monitoring. When the app hits an error, a technical report (stack trace, request path, timing) is sent to Sentry so we can fix it. We configure these reports so they contain no customer personal data.

How long we keep data

  • Store data is retained while the app is installed
  • Product score history is kept for 90 days; operational logs for 30 days
  • When a merchant uninstalls, Shopify sends us a shop redaction request 48 hours later, and we delete all of that store's data
  • When a shopper requests erasure through the merchant, Shopify sends us a customer redaction request; we delete that customer's record and remove their identifier from stored orders

We implement all three of Shopify's mandatory compliance webhooks (customers/data_request, customers/redact, shop/redact).

Individual rights

Because we act as a processor, shoppers should direct requests to access, correct or delete their data to the merchant whose store they purchased from. The merchant can raise the request with us through Shopify, and we will action it.

Merchants, and shoppers acting through their merchant, can also email hej@nomilk.dk to request a copy of the data we hold or to have it deleted. We respond to every such request within 30 days, in line with the GDPR and the CCPA.

Security

Access tokens are stored encrypted, all connections are encrypted in transit, and access to production data is limited to personnel who need it to operate the service.

Changes

We will update this page if our processing changes, and revise the date above.

Contact

Questions about this policy or about data we hold: hej@nomilk.dk

NoMilk ApS · CVR 40266372 · Strøget 38, 7430 Ikast, Denmark