Legal
Privacy Policy
Last updated: September 2026
This Privacy Policy explains how Voralta (“Voralta,” “we,” “us”) handles personal information. It covers two separate things: the Suggesto Shopify app, which merchants install on their store, and this marketing website at https://suggesto.co. They are described in turn below, because the data involved is quite different.
The Suggesto app
Suggesto is a product recommendation quiz app for Shopify stores. Merchants install it, build a quiz, and their shoppers answer it to get product recommendations. This part of the policy covers personal data about merchants and their staff who use the Suggesto admin, and personal data about shoppers who take a quiz on a merchant's storefront.
Our role, and who controls what
For shopper data, the merchant whose store you are visiting is the data controller. They decide to run a quiz, they decide whether to collect email addresses, and they decide what happens to the results. Suggesto is their processor: we act on their instructions and do not use shopper data for our own purposes.
For merchant account data - the store that installed the app, the plan it is on, support correspondence - Suggesto is the controller.
Merchant data we process
- Store domain, Shopify store ID, store name, store contact email. To identify the installation and scope every record to the right store.
- Shopify staff first name, last name, email, locale, and account-owner flag. Supplied by Shopify when a staff member opens the app, and used to authenticate the session.
- Shopify access token. Required to call the Shopify Admin API on the store's behalf.
- Plan, subscription status, trial and grant history, billing events, and monthly usage counts. For billing, plan limits, and preventing repeat free trials.
- Feedback submitted in the app, including an optional contact email, an optional screenshot, and a technical diagnostics snapshot. Used to answer the support request. The contact email is stored only if the merchant ticks the contact box.
- Quiz content, product catalogue data, and tag library. To run the features the merchant configured.
Shopper data we process
Suggesto stores the following per quiz session, on behalf of the merchant:
- The answers chosen in the quiz. Always, as the shopper answers. Without this there is no recommendation.
- Session timestamps, completion or abandonment, and time to complete. Always.
- Product IDs recommended, clicked, added to cart, and purchased. Always, so the merchant can see whether the quiz works.
- Shopify cart token. When the quiz stamps its attribution onto the cart, so an add-to-cart can be matched back to the quiz.
- Order ID, order value, and order date. When an order results from a quiz session.
- Referring URL and browser user agent. Only when the shopper permits analytics processing - see Consent below.
- Email address and marketing consent flag. Only where the merchant has switched on email capture, and the shopper types an address and submits it.
We do not collect or receive payment card details, passwords, postal addresses, phone numbers, government identifiers, or a shopper's browsing history beyond the single referring URL described above.
Storefront storage
Suggesto sets no advertising or tracking cookies. Where a merchant uses the automatic discount feature, the storefront script keeps one entry in the browser's local storage - a pending discount code and the quiz it came from - so the discount can be applied once there are items in the cart. It is removed once applied. In the Shopify theme editor only, the widget uses session storage to keep a merchant's place while they adjust settings; this never runs for shoppers.
Consent
- Marketing consent. Email capture is off unless a merchant switches it on. When it is on, the shopper sees a labelled consent checkbox. An email is stored with the consent decision recorded alongside it, and nothing is sent to a marketing integration unless consent was actually given.
- Analytics consent. Suggesto reads Shopify's Customer Privacy API before storing the referring URL and browser user agent. If the store operates consent management and the shopper has not permitted analytics processing, neither is stored. The quiz itself keeps working: recording the answers is what lets the quiz produce the recommendation the shopper asked for, and that processing is necessary to provide the service they requested.
- Sale of personal data. Suggesto does not sell personal data and does not share it for cross-context behavioural advertising.
- Automated decision-making. Suggesto recommends products based on answers. These recommendations produce no legal or similarly significant effect. Suggesto does not profile shoppers for credit, employment, pricing, insurance, or any comparable decision.
Artificial intelligence
Merchants can ask Suggesto to draft a quiz or suggest product tags. When they do, we send product catalogue text (titles, descriptions, product types, vendors, existing tags) and the merchant's own store description to our AI provider, currently OpenAI.
No shopper personal data is sent to any AI provider. Not email addresses, not quiz answers, not sessions. Our provider does not train models on data submitted through its API.
Who we share app data with
- Shopify (global) - the platform the app runs on. Store, product, order and customer data originate there.
- Render (Frankfurt, EU) - application hosting and the PostgreSQL database where all data is stored.
- OpenAI (United States) - AI quiz drafting and product tagging. Product catalogue text only, no shopper data.
- Klaviyo (United States) - email marketing sync. Only where the merchant supplies a Klaviyo API key, and only for shoppers who gave marketing consent.
We share personal data with no one else. We do not sell it. We disclose it otherwise only where the law requires. Transfers outside the EEA and UK rely on the European Commission's Standard Contractual Clauses together with the UK Addendum.
How long we keep app data
- While the app is installed. Quiz sessions, answers and captured emails are kept so the merchant's analytics stay accurate and comparable over time.
- After uninstall. Data is retained for 48 hours so that a re-install restores the merchant's setup exactly as they left it. Shopify then sends a shop redaction request and we permanently delete the store's record and everything attached to it: quizzes, questions, answers, sessions, responses, captured emails and product data.
- On a customer erasure request. Shopify sends us a redaction request and we erase the captured email address and consent flag from every matching session, recording when we did so. The now-anonymous session is kept so the merchant's historic analytics do not silently change.
- On a customer data request. We compile the personal data we hold for that shopper and make it available to the merchant so they can answer their customer.
Merchants can also delete captured emails at any time from the Emails page in the app.
Security
- All traffic runs over HTTPS. Database connections are encrypted in transit.
- Data is encrypted at rest by our hosting provider, and backups are encrypted.
- Access to production systems is limited to personnel who need it, protected by a password manager and two-factor authentication.
- Shopify webhook deliveries are verified by HMAC signature before we act on them.
- We maintain a written security incident response policy, and will notify Shopify and affected merchants promptly - in any event within the deadlines required by law and by our Shopify Partner obligations.
Rights, and who to ask
Depending on where you live, you may have the right to access, correct, delete, port, restrict or object to the processing of your personal data, and to withdraw consent at any time.
- Shoppers. Contact the store whose quiz you took. They are the controller and can act on your request directly, including through Shopify's built-in customer data request and erasure tools. If you contact us first, we will refer you to them and assist them in responding.
- Merchants. Contact us using the details at the end of this policy.
You also have the right to complain to your local data protection authority. In the UK, that is the Information Commissioner's Office (ICO).
Children
Suggesto is not directed at children and we do not knowingly collect their data. Merchants are responsible for the audience of their own storefront.
This website
This part covers information collected through the marketing website at https://suggesto.co. It is separate from the app: browsing this site involves none of the store or shopper data described above.
Information we collect
- Information you give us. When you use our contact form, we collect your name, email address, message, and - if you choose to share it - your store URL. When you subscribe to our newsletter, we collect your email address (and confirm it via a double opt-in email).
- Information collected automatically. Like most websites, our hosting and infrastructure providers process basic technical data (such as IP address, browser type, and pages requested) to serve and secure the site.
How we use information, and our lawful basis
Under UK GDPR / EU GDPR, we rely on the following legal bases:
- To respond to your enquiries - our legitimate interest in answering you (and taking steps at your request).
- To send product news and updates - your consent, given when you subscribe and confirm. You can withdraw it at any time via the unsubscribe link in every email.
- To operate, secure, and improve the website - our legitimate interest in running a safe, functioning site.
We do not sell your personal information, and we do not use it for advertising.
Cookies & analytics
This site keeps cookies to a minimum and uses no advertising or cross-site tracking cookies. Where we measure traffic, we use Cloudflare Web Analytics, which is cookieless and does not profile you. Full details are in our Cookie Policy.
Who we share it with (processors)
We share information only with the providers we rely on to run the site, acting as our processors under contract:
- Hosting & CDN - to serve and secure the website.
- Resend - to deliver contact-form messages to us and manage newsletter subscriptions.
- Cloudflare Web Analytics - cookieless traffic measurement, where enabled.
International transfers
Some providers (for example, Resend) are based in the United States. Where personal data is transferred outside the UK or EEA, we rely on appropriate safeguards - such as the UK International Data Transfer Agreement / EU Standard Contractual Clauses, and the UK-US and EU-US Data Privacy Framework where applicable.
Data retention
We keep contact-form messages for as long as needed to handle your request and our reasonable records, and newsletter details until you unsubscribe. You can ask us to delete your information at any time.
Children
This website is intended for merchants and businesses, and is not directed to children.
Changes and contact
Changes to this policy
We may update this policy from time to time. When we do, we'll revise the “last updated” date above. Material changes affecting the app will be communicated to merchants in the app or by email.
Contact us
Suggesto is operated by Voralta, based in the United Kingdom. Questions about this policy, about the app, or about your information? Email us at support@suggesto.co.