Security and privacy

Careful with your shoppers' data.

What Benchmyrk collects on your storefront, how consent is handled, where data lives and who can reach it.

On your storefront

What we collect from shoppers.

  • First-party and hashed

    A first-party cookie keeps each shopper in the same variant. On our servers the visitor ID is stored only as a keyed hash that differs per store.
  • No query strings

    Page addresses are stored without their query string, keeping only the five utm_ campaign tags, and a tag holding an email address is dropped.
  • Consent first on Shopify

    On Shopify stores nothing is collected until the shopper allows analytics in the store's cookie banner; withdrawing consent stops collection at once.
  • Heatmaps and replay off by default

    When a merchant turns them on, typed values and form fields are always masked, and account, checkout and order pages are fully masked by default.
  • No personal order details

    From Shopify orders we keep totals, item counts and refunds, never customers' names, emails, phone numbers or addresses.
  • No advertising use

    We don't sell data, use it for advertising, build profiles across different stores or use it to train AI models.

In the platform

How the data is protected.

  • Encrypted credentials

    Shopify access tokens and stored storefront passwords are encrypted with AES-256-GCM. Passwords are salted scrypt hashes; API tokens and email links are stored only as hashes.
  • Tenant isolation

    Every query is scoped to the workspace and the store. Each workspace sees only its own data.
  • Roles and approvals

    Owners, admins, editors and viewers. Launches can require approval, and changes to experiments and settings are recorded in an activity log.
  • Privacy requests from Shopify

    Customer data requests, customer deletions and store deletions sent by Shopify are handled automatically, with a due date for data requests.
  • AI is kept on a short leash

    AI proposals are validated on our servers. AI can't add custom JavaScript or redirects, and shoppers' personal details are never sent to it.
  • HTTPS and backups

    All traffic uses HTTPS. The database is backed up every six hours to separate object storage.

Where data lives

Our own servers, in Germany.

The application and its database run on servers we operate at Hetzner in Germany. Cloudflare provides the network in front of them and the object storage for files and backups.

Report a vulnerability

Tell us privately and give us reasonable time to fix it before sharing it. Please don’t access other people’s data or disrupt the service while testing. Use the help form and choose “Something else”.

Questions about data or security?

We'll walk through how Benchmyrk handles your store's data on a short call.