Privacy Policy

Last updated: 2026-08-07

This notice covers the 100 Rocks merchant console (get.100.rocks) and our processing of storefront shopper data on your instructions. Marketing site visitors should read 100.rocks/privacy.

100 Rocks is operated by Karen Charykov, Entrepreneur individuel (EI), trade name 100 Rocks, at 200 rue de la Croix Nivert, 75015 Paris, France. We provide storefront analytics, adaptive interface testing, and design-token tooling for supported storefront operators. For merchant console accounts we are the data controller. For shopper analytics on your storefront we act as your data processor under GDPR Art. 28. The Data Processing Addendum is accepted when an authorized merchant creates or connects a store. Contact: help@100.rocks. We have not appointed a data protection officer.

We process the following categories for console users:

Email, authentication data, organization/store details, required legal acceptances, and billing details are necessary to operate the relevant account or subscription. Optional profile, avatar, campaign, and support information may be omitted. We obtain data from you, authorized users, your browser, Shopify when connected and for Shopify-managed billing status, Stripe for direct-site billing status, and our service infrastructure.

When you connect the 100 Rocks Shopify app, we process the permanent shop domain, primary storefront domain, Shopify identifiers, install status and epoch, granted scopes, OAuth token material and expiration metadata, Shopify contact email, Web Pixel and theme-app-embed setup status, aggregate daily ShopifyQL session counts, and commerce event types made available through Shopify's Web Pixel sandbox. After explicit activation, we use the contact email to initialize an account or enrich the single matching anonymous storefront project. The email alone does not prove tenant ownership or authorize a merge. A verified Shopify session authorizes embedded, shop-scoped access; standalone console access requires mailbox verification. For Shopify-managed billing, we also process the active subscription identifier, plan item handle, billing interval, status, current paid period, scheduled-cancellation state, and reconciliation audit evidence returned by Shopify. The configured app scopes are write_pixels, read_customer_events, and read_reports; the app does not request read_orders or read_customers. We do not intentionally collect payment card data through the app.

When you install the tracker, we process shopper traffic on your instructions. You are responsible for your storefront privacy notice, lawful basis, and consent mechanism. Limited audience measurement may run before consent where applicable law permits it and the merchant configures that path. Behavior data remains consent-gated.

Data categories include page URLs and titles, navigation paths, referrer and campaign parameters, device, browser, and operating-system class, viewport, locale, coarse country/region/city signals, truncated IP (IPv4 /24 or IPv6 /48), bot classification, commerce funnel outcomes, opaque technical session keys in sessionStorage, and an opaque 30-minute visit key. Before persistent visitor storage is available, the visit key remains in per-tab sessionStorage. After analytics consent enables persistent visitor storage, it can be reused across tabs for the same 30-minute visit. The custom-site consent UI stores its decision in localStorage.adaptive_analytics_consent and purpose choices in localStorage.adaptive_analytics_purpose_consent. After analytics consent, the tracker may also store a persistent visitor identifier in localStorage for up to 12 months. On Shopify storefronts after analytics consent, the tracker may set the first-party rocks_session_key and rocks_visit_bridge cookies for up to 30 minutes to associate browser activity with Shopify Web Pixel commerce events; denial, Global Privacy Control, or study opt-out deletes them. We do not use third-party advertising cookies. The behavior tier adds pointer metrics, scroll depth, click and hesitation signals, and bounded normalized target tokens (such as element IDs, classes, selected data attributes, and roles) after consent. Merchant-facing heatmaps use aggregated interaction data. Production does not expose shopper session replay or merchant raw-event/session-metrics exports. Target tokens exclude visible text, input values, and raw full selectors.

Shopify compliance webhook requests and storefront shopper requests should be routed through you as controller. We support two separate rights packages: a merchant-account package for the console user, and a verified storefront-subject package for one supplied session or visitor identifier. That package contains retained matching sessions, events, latest/final metrics, consent transitions, session quota/access-tier records, and a completeness manifest. Subject erasure removes matching addressable events, sessions, metrics, and consent transitions. Session quota records remain so accounting stays accurate, but the matching session identifier is irreversibly replaced with a claim-specific tombstone. Non-identifying aggregate rollups remain.

When a merchant triggers a design-token or site scan, 100 Rocks may process merchant-authorized storefront page content, including password-protected storefronts, screenshots, computed styles, fonts, and derived design evidence to suggest interface changes. Site scans run on Microsoft Azure compute and use Anthropic for AI inference. The workflow does not deliberately include shopper names, emails, payment data, or cart identity. Merchants can review generated outputs and resulting changes.

Automated monthly pruning runs on EU-hosted database infrastructure. Aggregated rollups do not hold per-session behavioral scalars.

Generated heatmap versions follow the merchant's plan quota (three ready versions per page/device by default), not a 24-month calendar period.

We use Supabase (database and authentication), Vercel (application hosting and CDN), Stripe (direct-site payment processing, subscriptions, invoices, and tax IDs where configured), Shopify (app installation, App Store subscriptions and invoices, admin APIs, and Web Pixel), Resend (transactional email), Cloudflare Turnstile where enabled (abuse protection), Microsoft Azure in North Central US (site-scan compute), and Anthropic (AI inference). Stripe may directly collect billing identity, address, tax, and payment-method information at direct-site checkout. Shopify may collect and retain corresponding billing information for Shopify-managed subscriptions. Primary application functions and database/authentication storage are configured in Paris/EU regions. Other provider operations may occur elsewhere under an adequacy decision, applicable Standard Contractual Clauses, or another lawful safeguard. Providers are bound by data-processing terms where applicable; the DPA identifies storefront-data subprocessors.

Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent; appeal a denied request; or use an authorized agent. We may verify identity and authority.

You may complain to your local supervisory authority; in France, this is the CNIL. We do not use merchant account data for solely automated decisions that produce legal or similarly significant effects.

We do not sell or share personal data for cross-context behavioral advertising. Contact help@100.rocks ; we respond within the period required by applicable law.