Privacy Policy
Effective date: 1 May 2026 · Last updated: 1 May 2026
Who we are
Growth Layer is published by Sico Software Ltd, a company registered in Scotland. We provide Klaviyo anomaly detection, email flow automation, and anonymous visitor identification for Shopify merchants. We are registered with the UK Information Commissioner's Office (ICO). Privacy questions: privacy@sico.software.
Data we collect
Shopify store data. Orders (amounts, line items, fulfilment status) and refunds — received via the Shopify Admin API and used to build conversion attribution.
Klaviyo data (if connected). Campaign metrics (emails sent, open rates, click rates, unsubscribe rates, segment sizes). You supply a Private API key stored encrypted at rest. On Pro and Scale plans the app may also write to Klaviyo to trigger flows or update segments on your behalf.
Meta Ads and Google Ads data (if connected). Ad spend and conversion data via OAuth, used to correlate email performance with paid spend.
Visitor ID module data (optional add-on). A lightweight edge pixel collects anonymous browser signals (page URL, referrer, approximate geolocation from IP, session identifier) for visitors to your store. Raw IP addresses are hashed (SHA-256) before storage and never stored in plaintext.
Billing data. Plan and subscription status via Shopify's Billing API. We do not store payment card details.
We do not store payment card details. Any subscription billing is handled directly by Stripe.
How we use your data
- To detect statistical anomalies in your Klaviyo email performance
- To diagnose root causes and surface plain-English alerts
- To execute automation rules you have explicitly approved
- To identify anonymous high-intent visitors (Visitor ID module only)
- To sync matched visitor contacts to Klaviyo, Meta, and Google on your behalf
- To attribute conversion revenue to email flows and ad campaigns
- To send you nightly digest emails summarising anomalies and actions taken
Your customers' data (Visitor ID)
When the Visitor ID module resolves an anonymous visitor to a named contact, that contact's details (name, email) are stored in our database associated with your merchant account. As the Shopify merchant, you are the data controller for this information. We process it on your behalf as a data processor.
You are responsible for ensuring your store's privacy policy discloses the use of behavioural tracking pixels and the potential for anonymous visitors to be identified and contacted. We recommend updating your Shopify store privacy policy before enabling the Visitor ID module.
Data sharing
We do not sell your data. We share data only with sub-processors required to operate the service:
- RB2B, Inc. — Identity-graph provider (Visitor ID module only). Anonymous browser signals are transmitted to RB2B for identity resolution. RB2B's privacy policy governs their handling of this data.
- Meta Platforms, Inc. — When the Meta Ads integration and Visitor ID module are active, resolved contact hashes are uploaded to Meta Custom Audiences on your behalf.
- Google LLC — When the Google Ads integration and Visitor ID module are active, resolved contact hashes are uploaded to Google Customer Match lists on your behalf.
- Hetzner Online GmbH — our VPS provider (Germany, EU). All personal data is stored on this server.
- Resend Inc. — transactional email (account and billing notifications).
- PostHog Inc. — product analytics (page views, feature usage; no personal data).
- Sentry Inc. — error monitoring (stack traces; personal data scrubbed before transmission).
Data retention
We retain your data for as long as your account remains active and your store is connected. When you delete your account (or disconnect and ask us to), we schedule deletion of all tenant data within 48 hours. You may request deletion at any time by emailing privacy@sico.software.
For Shopify-embedded apps, we honour Shopify's mandatory GDPR webhooks
(customers/data_request, customers/redact, shop/redact) automatically, deleting or returning data within 30 days
of a verified request.
Your rights under UK GDPR
As a UK resident you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — correct inaccurate data
- Erasure — ask us to delete your data ("right to be forgotten")
- Portability — receive your data in a machine-readable format
- Restriction — ask us to limit how we process your data
- Objection — object to processing based on legitimate interests
To exercise any right, email privacy@sico.software. We will respond within 30 days. You also have the right to lodge a complaint with the ICO at ico.org.uk.
Security
All data is transmitted over TLS. Our server (Hetzner, Germany) is access-controlled via SSH key and Tailscale VPN. Integration credentials and API keys are encrypted at rest using pgcrypto symmetric encryption.
Cookies
We use one strictly necessary session cookie to keep you logged in. We do not use advertising or tracking cookies. PostHog analytics uses a first-party cookie; it does not track you across other sites.
Changes to this policy
Material changes will be communicated by email and by updating the effective date above. Continued use of the service after notification constitutes acceptance.
Contact
Sico Software Ltd · privacy@sico.software