Privacy Policy
This notice covers the 100 Rocks merchant console (get.100.rocks) and our processing of storefront shopper data on your instructions. Marketing site visitors should read 100.rocks/privacy.
Who we are and our roles
100 Rocks is operated by Karen Charykov, Entrepreneur individuel (EI), trade name 100 Rocks, at 200 rue de la Croix Nivert, 75015 Paris, France. We provide storefront analytics, adaptive interface testing, and design-token tooling for supported storefront operators. For merchant console accounts we are the data controller. For shopper analytics on your storefront we act as your data processor under GDPR Art. 28. The Data Processing Addendum is accepted when an authorized merchant creates or connects a store. Contact: help@100.rocks. We have not appointed a data protection officer.
Merchant account data
We process the following categories for console users:
- Identity and contact: email, display name, avatar, and Shopify-derived email-verification status
- Authentication: credentials, session tokens, sign-in metadata, and Shopify embedded session identity
- Acquisition: first-touch entry path, named CTA identifier, sanitized external referrer hostname when the browser provides one, and validated UTM campaign fields when a campaign or CTA link precedes Auth-user creation; no storefront visitor identifier and no full referrer URL
- Account settings: language preference, organization and project configuration
- Compliance records: terms acceptance, store DPA acceptance version, timestamp, accepting user and source, store ownership and design-rights attestations, and Shopify activation evidence
- Billing references: billing provider; Stripe customer, subscription, product, price, and entitlement identifiers; or Shopify subscription, plan item, interval, status, current-period, and cancellation identifiers. Stripe handles direct-site payments, invoices, tax IDs where configured, and refunds. Shopify handles App Store subscription charges and invoices.
- Support and product telemetry: operational logs linked to your user id where needed to run the service
Email, authentication data, organization/store details, required legal acceptances, and billing details are necessary to operate the relevant account or subscription. Optional profile, avatar, campaign, and support information may be omitted. We obtain data from you, authorized users, your browser, Shopify when connected and for Shopify-managed billing status, Stripe for direct-site billing status, and our service infrastructure.
Shopify app data
When you connect the 100 Rocks Shopify app, we process the permanent shop domain, primary storefront domain, Shopify identifiers, install status and epoch, granted scopes, OAuth token material and expiration metadata, Shopify contact email, Web Pixel and theme-app-embed setup status, aggregate daily ShopifyQL session counts, and commerce event types made available through Shopify's Web Pixel sandbox. After explicit activation, we use the contact email to initialize an account or enrich the single matching anonymous storefront project. The email alone does not prove tenant ownership or authorize a merge. A verified Shopify session authorizes embedded, shop-scoped access; standalone console access requires mailbox verification. For Shopify-managed billing, we also process the active subscription identifier, plan item handle, billing interval, status, current paid period, scheduled-cancellation state, and reconciliation audit evidence returned by Shopify. The configured app scopes are write_pixels, read_customer_events, and read_reports; the app does not request read_orders or read_customers. We do not intentionally collect payment card data through the app.
Purposes and legal bases (GDPR)
- Initialize, provide, and secure the console (account data, Shopify-derived contact email, auth, embedded session authorization, project settings) — contract or requested pre-contractual steps (Art. 6(1)(b)) and legitimate interests in security (Art. 6(1)(f)).
- Understand account acquisition (immutable first-touch CTA, external referrer host, and campaign fields) — legitimate interests in measuring and improving our registration journey (Art. 6(1)(f)).
- Billing and subscription management (Stripe- or Shopify-managed subscription references) — contract (Art. 6(1)(b)) and legal obligation for tax/accounting records where applicable (Art. 6(1)(c)).
- Compliance and audit (terms and DPA acceptance, attestations, rights-request audits, and deletion audit rows) — legal obligation and legitimate interests (Art. 6(1)(c) / (f)).
- Support and service improvement (support correspondence, limited telemetry) — legitimate interests (Art. 6(1)(f)); you may object where applicable.
Retention — merchant account
- Profile, projects, and settings: until project or account deletion. Unclaimed Shopify installation records may be removed through installation cleanup, but an account or project created or claimed through Shopify remains until account or project deletion, subject to the legal-evidence and provider-retention exceptions below.
- Pending registration attribution: up to 30 days; stored account acquisition attribution: until account deletion. Attribution for abandoned anonymous accounts is removed after 30 days.
- Profile, projects, settings, Shopify-derived enrichment, and the authentication account are deleted with your account. A minimal deletion audit remains and may contain an opaque former user identifier, deletion source and counts, billing cancellation outcomes, avatar-removal status, and accepted terms evidence. Immutable contractual evidence may retain historical user and store identifiers, policy versions, acceptance source, Shopify actor, and timestamp, but not the contact email.
- Billing and invoice records: retained for applicable accounting, tax, fraud-prevention, dispute, and legal-claims periods. Stripe and Shopify separately retain provider-side billing data under their notices and legal obligations.
- Support correspondence and security/runtime logs: retained only while reasonably needed for support, security, disputes, and legal obligations, then deleted or de-identified.
- Product telemetry: user identifier removed when your account is deleted, except in the minimal deletion audit.
Storefront shopper analytics (processor)
When you install the tracker, we process shopper traffic on your instructions. You are responsible for your storefront privacy notice, lawful basis, and consent mechanism. Limited audience measurement may run before consent where applicable law permits it and the merchant configures that path. Behavior data remains consent-gated.
Data categories include page URLs and titles, navigation paths, referrer and campaign parameters, device, browser, and operating-system class, viewport, locale, coarse country/region/city signals, truncated IP (IPv4 /24 or IPv6 /48), bot classification, commerce funnel outcomes, opaque technical session keys in sessionStorage, and an opaque 30-minute visit key. Before persistent visitor storage is available, the visit key remains in per-tab sessionStorage. After analytics consent enables persistent visitor storage, it can be reused across tabs for the same 30-minute visit. The custom-site consent UI stores its decision in localStorage.adaptive_analytics_consent and purpose choices in localStorage.adaptive_analytics_purpose_consent. After analytics consent, the tracker may also store a persistent visitor identifier in localStorage for up to 12 months. On Shopify storefronts after analytics consent, the tracker may set the first-party rocks_session_key and rocks_visit_bridge cookies for up to 30 minutes to associate browser activity with Shopify Web Pixel commerce events; denial, Global Privacy Control, or study opt-out deletes them. We do not use third-party advertising cookies. The behavior tier adds pointer metrics, scroll depth, click and hesitation signals, and bounded normalized target tokens (such as element IDs, classes, selected data attributes, and roles) after consent. Merchant-facing heatmaps use aggregated interaction data. Production does not expose shopper session replay or merchant raw-event/session-metrics exports. Target tokens exclude visible text, input values, and raw full selectors.
Shopify compliance webhook requests and storefront shopper requests should be routed through you as controller. We support two separate rights packages: a merchant-account package for the console user, and a verified storefront-subject package for one supplied session or visitor identifier. That package contains retained matching sessions, events, latest/final metrics, consent transitions, session quota/access-tier records, and a completeness manifest. Subject erasure removes matching addressable events, sessions, metrics, and consent transitions. Session quota records remain so accounting stays accurate, but the matching session identifier is irreversibly replaced with a claim-specific tombstone. Non-identifying aggregate rollups remain.
AI-assisted design tooling
When a merchant triggers a design-token or site scan, 100 Rocks may process merchant-authorized storefront page content, including password-protected storefronts, screenshots, computed styles, fonts, and derived design evidence to suggest interface changes. Site scans run on Microsoft Azure compute and use Anthropic for AI inference. The workflow does not deliberately include shopper names, emails, payment data, or cart identity. Merchants can review generated outputs and resulting changes.
Retention — storefront analytics
- Raw events: 90 days
- Sessions and session metrics: 12 months
- Daily rollups and page layout references: 24 months
- Consent log (behavior tier): 25 months
Automated monthly pruning runs on EU-hosted database infrastructure. Aggregated rollups do not hold per-session behavioral scalars.
Generated heatmap versions follow the merchant's plan quota (three ready versions per page/device by default), not a 24-month calendar period.
Service providers and subprocessors
We use Supabase (database and authentication), Vercel (application hosting and CDN), Stripe (direct-site payment processing, subscriptions, invoices, and tax IDs where configured), Shopify (app installation, App Store subscriptions and invoices, admin APIs, and Web Pixel), Resend (transactional email), Cloudflare Turnstile where enabled (abuse protection), Microsoft Azure in North Central US (site-scan compute), and Anthropic (AI inference). Stripe may directly collect billing identity, address, tax, and payment-method information at direct-site checkout. Shopify may collect and retain corresponding billing information for Shopify-managed subscriptions. Primary application functions and database/authentication storage are configured in Paris/EU regions. Other provider operations may occur elsewhere under an adequacy decision, applicable Standard Contractual Clauses, or another lawful safeguard. Providers are bound by data-processing terms where applicable; the DPA identifies storefront-data subprocessors.
Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent; appeal a denied request; or use an authorized agent. We may verify identity and authority.
- Merchant account: download the merchant-account package or delete your account from Account → Data. Package audits store outcome, counts, version, and a package hash, not the package contents.
- Storefront shoppers: direct requests to you (controller). Authorized admins can generate the separate storefront-subject package or erase a verified subject. Audits store a legal reference, outcome, counts, and a keyed identifier hash, not the raw identifier.
You may complain to your local supervisory authority; in France, this is the CNIL. We do not use merchant account data for solely automated decisions that produce legal or similarly significant effects.
We do not sell or share personal data for cross-context behavioral advertising. Contact help@100.rocks ; we respond within the period required by applicable law.