1. Terms of Service
These Terms of Service ("Terms") govern your access to and use of the websites, applications, platform, and services operated by Funnelytics Inc. ("Funnelytics", "we", "us", "our"), a corporation incorporated in Ontario, Canada. This includes funnelytics.io, shopify.funnelytics.io, dashboard.funnelytics.io, app.funnelytics.io, the Funnelytics Shopify application, and any related products or services (together, the "Service").
Please read these Terms carefully. By creating an account, installing the Funnelytics Shopify app, or otherwise accessing or using the Service, you agree to be bound by these Terms. If you are agreeing on behalf of a company or other entity, you represent that you have authority to bind that entity, and "you" refers to that entity.
1.1 Definitions
- Platform — the Funnelytics analytics platform, including the visual journey canvas, dashboards, reports, and tracking script.
- Free App — the Funnelytics Shopify application and the free LTV Profit Map report available at no charge.
- Paid Subscription — any paid plan providing expanded access to the Platform.
- Services — our human-delivered engagements, including the Insights Sprint and Funnelytics Optimize, governed by Section 3 and by a signed Master Services Agreement and Scope of Work.
- Merchant Data — data we access or process from your connected store, connected advertising and marketing platforms, and our tracking script, together with data you upload or input into the Platform.
1.2 Order of precedence
Where you have signed a Master Services Agreement ("MSA") and/or a Scope of Work ("SOW") with us, the order of precedence in the event of a conflict is: (1) the SOW, (2) the MSA, (3) our Data Processing Agreement, (4) these Terms and the policies on this page. In all other cases, these Terms and the policies on this page govern.
1.3 Accounts and eligibility
You must be at least 18 years old and legally capable of entering into a binding contract. When you create an account you must provide accurate, complete, and current information. You are responsible for safeguarding your credentials and for all activity that occurs under your account. Notify us immediately at support@funnelytics.io of any suspected unauthorized access. Support is provided to the account owner and users the account owner has authorized.
1.4 The Free App and free tier
The Free App and the LTV Profit Map report are provided free of charge, with no time limit. You do not need a paid plan to install the app, connect your store, or receive your free report.
We may modify, add, or remove features, reports, and usage limits on the free tier at any time. We will give at least thirty (30) days' notice before materially reducing free-tier functionality or discontinuing the free tier, by email to the address on your account. The free tier is provided without any service level commitment and, as set out in Section 1.16, our liability in respect of the free tier is limited accordingly.
If a free-tier account remains inactive for twelve (12) consecutive months, we may deactivate it and delete the associated Merchant Data after giving thirty (30) days' notice.
1.5 Paid Subscriptions, fees, and renewal
Paid Subscription pricing, features, and limits are those published on our pricing page or stated in your order at the time of purchase. All fees are stated and charged in United States dollars (USD). Payment is processed by Stripe; we do not bill through Shopify.
- You will be billed in advance on a recurring basis, monthly or annually, according to the billing period you select.
- Subscriptions renew automatically at the end of each billing period at the then-current rate for your plan, until cancelled. We do not send renewal reminders. It is your responsibility to know your billing cycle dates.
- You authorize Funnelytics and its payment processor to charge your designated payment method for all fees when due.
- We may change subscription fees. Any change takes effect at the start of your next billing period, and we will give reasonable prior notice so that you can cancel before it applies. Continuing to use the Service after the change takes effect constitutes acceptance of the new fee.
- Where a promotional rate or discount is offered, it applies for the stated period only. Unless stated otherwise, that period is twelve (12) months, after which the price reverts to the then-current standard rate for your plan.
1.6 Usage limits and overages
Paid plans include stated usage limits, which may be based on tracked visitors, profiles, events, connected data sources, or other metrics. If you exceed your plan's limit in a billing period, we may apply an overage charge on your next invoice, or move you to the plan tier that accommodates your usage, in each case at the rates published at the time. We will notify you before applying a recurring tier change.
1.7 Cancellation, downgrades, and no refunds
You may cancel or downgrade at any time from your account settings or by emailing support@funnelytics.io. Cancellation takes effect at the end of your current billing period; you retain access until then. You are solely responsible for cancelling before your renewal date.
If you selected an annual plan — whether paid up front or in monthly instalments — you are responsible for the full twelve (12) month term. Cancelling an annual plan stops future renewal; it does not release you from the remainder of the current term.
All fees are non-refundable. We do not provide refunds or credits for partial billing periods, unused time, downgrades, plan changes, accounts that were not used, or fees paid in respect of the Services. This applies regardless of the reason for cancellation. Nothing in this Section limits any right you have that cannot be waived under applicable consumer protection law.
1.8 Taxes
All fees are exclusive of taxes. You are responsible for all sales, use, value-added, goods and services, harmonized sales, and similar taxes, duties, and levies imposed on the fees, other than taxes based on our net income. Where we are required to collect Canadian GST/HST or any other tax, it will be added to your invoice. If you are exempt or subject to a reverse-charge mechanism, you must provide valid documentation before purchase.
1.9 Late payment, failed payments, and chargebacks
If a payment fails or is not received when due, we may retry the charge and may suspend your access to the Platform after seven (7) days' notice. Amounts more than thirty (30) days overdue may accrue interest at 1.5% per month (19.56% per year), calculated daily. If you initiate a chargeback or payment dispute in respect of fees properly owed, we may suspend or terminate your account immediately and recover any related fees imposed on us. We reserve the right to recover reasonable costs of collection.
1.10 Data accuracy — please read this
The Platform produces analytical estimates and models, not accounting records. Lifetime value, attribution, cohort projections, forecasts, revenue-opportunity sizing, and similar outputs are calculated using statistical methods, first-party tracking, and the marketing-attribution fields available from your connected sources.
You acknowledge and agree that:
- Figures produced by the Platform will differ, sometimes materially, from figures reported by Shopify Analytics, Google Analytics, Meta Ads Manager, Google Ads, and other tools, because each uses different definitions, attribution models, and collection methods. Differences between systems are expected and are not a defect.
- Accuracy depends on factors outside our control, including consent and privacy settings, ad blockers, browser and operating system tracking restrictions, cookie lifetimes, cross-device behaviour, the completeness of your UTM and tagging conventions, and the data your connected platforms make available to us.
- Platform outputs are not suitable for financial reporting, statutory accounting, tax filing, audit, or investor reporting, and must not be used for those purposes.
- Insights, recommendations, roadmaps, and AI-generated commentary are informational. They do not constitute financial, legal, accounting, tax, or professional advice, and we do not guarantee any particular business outcome except as expressly set out in Section 3.4.
You are responsible for validating outputs before making commercial decisions based on them.
1.11 Merchant Data — your rights and the licence you grant us
You own, or have the necessary rights in, your Merchant Data. We claim no ownership in it.
You grant us a worldwide, non-exclusive, royalty-free licence to host, store, copy, transmit, process, analyze, and display Merchant Data solely as necessary to provide, maintain, secure, support, and improve the Service for you, and to comply with law. In respect of personal data within Merchant Data, we act as your data processor under Section 6.
We do not sell your Merchant Data. We do not use your store's customer data for our own marketing. We do not disclose it except to the sub-processors listed in Section 11, to the extent needed to operate the Service, or where required by law.
We may create and use aggregated, de-identified statistics derived from use of the Service (for example, benchmark conversion rates across a category) provided such statistics cannot reasonably be used to identify you, your store, or any individual, and are never presented in a way that identifies or is attributable to you.
1.12 Content you post
The Service lets you post, upload, link, store, and share content, including journey maps, annotations, and files. You are responsible for that content, including its legality and appropriateness, and you represent that you have the rights necessary to post it. We may remove content that is unlawful, infringing, abusive, defamatory, obscene, fraudulent, or otherwise unacceptable, at our discretion.
1.13 Intellectual property
The Service and all of its contents — including software, source code, the visual journey canvas, dashboards, report designs, templates, methodologies, frameworks, text, images, graphics, and the Funnelytics name and logo — are the property of Funnelytics Inc. or its licensors and are protected by copyright, trademark, database, and other intellectual property rights. You may view, download, or print portions of our published material for your own internal, non-commercial use. These Terms grant you no licence to use any Funnelytics trademark.
If you send us suggestions, feature requests, or feedback, you grant us a perpetual, irrevocable, royalty-free licence to use it without restriction or obligation to you. You are not required to provide feedback.
1.14 Publicity and use of your name
We will not use your company name, logo, results, metrics, or any statement attributable to you in any marketing material, case study, advertisement, sales asset, website, app store listing, or public post without your prior written consent. Consent is specific to the use approved and may be withdrawn for future use by writing to support@funnelytics.io.
Where you agree to participate in a recorded call, workshop, or interview for training, quality, or promotional purposes, any promotional material including your likeness will be approved by you before publication.
1.15 Confidentiality
Each party may receive information of the other that is marked confidential or that a reasonable person would understand to be confidential ("Confidential Information"). This includes, for us, the Platform's non-public functionality, pricing not publicly listed, and our methodologies; and for you, your Merchant Data, revenue and margin figures, advertising spend and performance, product roadmaps, and strategy.
Each party will: (a) use the other's Confidential Information only to perform under these Terms; (b) protect it with at least reasonable care; and (c) not disclose it to third parties except to employees, contractors, advisors, and sub-processors who need it and who are bound by confidentiality obligations at least as protective as these. These obligations do not apply to information that is or becomes public through no fault of the receiving party, was known to it without obligation of confidence, or is independently developed. Disclosure compelled by law is permitted with prompt notice where legally allowed. These obligations survive for three (3) years after termination, and indefinitely in respect of personal data and trade secrets.
1.16 Disclaimer of warranties
The Service is provided on an "AS IS" and "AS AVAILABLE" basis, without warranties of any kind, whether express, implied, statutory, or otherwise, including any implied warranties of merchantability, fitness for a particular purpose, non-infringement, accuracy, or course of performance.
We do not commit to any uptime or availability level and do not offer a service level agreement. We do not warrant that the Service will be uninterrupted, timely, secure, or error-free; that outputs will be accurate or complete; or that results obtained from use of the Service will meet your requirements or produce any particular commercial outcome.
1.17 Limitation of liability
To the maximum extent permitted by law:
(a) Excluded damages. Neither party, nor our respective directors, officers, employees, contractors, partners, agents, suppliers, or affiliates, will be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, lost revenue, lost sales, loss of business opportunity, loss of goodwill, loss of anticipated savings, business interruption, or loss or corruption of data, however caused and on any theory of liability, even if advised of the possibility.
(b) Aggregate cap. Our total aggregate liability arising out of or relating to the Service, these Terms, or any Services, for all claims combined, will not exceed:
- for claims relating to a Paid Subscription: the greater of (i) the total fees you paid to us for the Platform in the twelve (12) months immediately preceding the event giving rise to the claim, or (ii) five hundred US dollars (USD $500);
- for claims relating to the Free App or free tier: one hundred US dollars (USD $100);
- for claims relating to an Insights Sprint or Optimize engagement: the total fees you paid under the applicable SOW in the twelve (12) months immediately preceding the event giving rise to the claim.
(c) Carve-outs. Nothing in this Section limits liability for fraud, fraudulent misrepresentation, wilful misconduct, gross negligence, death or personal injury caused by negligence, a party's payment obligations, your breach of Section 2 (Acceptable Use), infringement of the other party's intellectual property, or any liability that cannot be limited under applicable law.
(d) Allocation of risk. You acknowledge that the fees for the Service reflect this allocation of risk and that these limitations are an essential basis of the bargain between us.
1.18 Indemnification
You will indemnify and hold harmless Funnelytics Inc. and its directors, officers, employees, contractors, and agents from and against any third-party claim, and any resulting losses, damages, liabilities, fines, and reasonable legal costs, arising from: (a) your use of the Service in breach of these Terms; (b) Merchant Data, including any claim that our processing of it on your instructions infringed a third party's rights or breached privacy or data protection law, where you did not have the lawful basis, notices, or consents required; (c) content you post; or (d) your breach of Section 2.
We will indemnify you against any third-party claim alleging that the Platform, as provided by us and used in accordance with these Terms, infringes that third party's copyright, trademark, or trade secret rights, and will pay damages finally awarded or agreed in settlement, subject to the cap in Section 1.17(b). This does not apply to claims arising from Merchant Data, your modifications, or use in combination with anything not provided by us. Our sole remedies, at our option, are to procure the right to continue, modify the Platform, or terminate and refund prepaid unused fees.
The indemnified party must give prompt notice, allow the indemnifying party to control the defence, and provide reasonable cooperation.
1.19 Suspension and termination
We may suspend or terminate your access to the Service, in whole or in part, immediately and without liability, where: you breach these Terms; payment is overdue as set out in Section 1.9; your use presents a security, legal, or operational risk to us or others; or we are required to do so by law or by a platform on which the Service depends.
You may terminate at any time by cancelling your subscription and, where applicable, uninstalling the Free App from your Shopify admin.
On termination: your right to access the Platform ends. You may export your data for thirty (30) days following termination by contacting support@funnelytics.io. We will delete or anonymize Merchant Data within ninety (90) days of termination, except where retention is required by law or where data has been aggregated and de-identified in accordance with Section 1.11. Uninstalling the Free App from Shopify immediately stops all further data access; deletion follows the process described in Section 8.
Provisions that by their nature should survive termination will survive, including Sections 1.7, 1.8, 1.9, 1.10, 1.11, 1.13, 1.14, 1.15, 1.16, 1.17, 1.18, and 1.20.
1.20 General
Governing law and venue. These Terms are governed by the laws of the Province of Ontario and the federal laws of Canada applicable in Ontario, without regard to conflict of laws principles. The parties submit to the non-exclusive jurisdiction of the courts of Ontario, Canada. The United Nations Convention on Contracts for the International Sale of Goods does not apply.
Informal resolution first. Before filing a claim, each party agrees to try to resolve the dispute informally by contacting the other and allowing thirty (30) days to reach a resolution.
Changes to these Terms. We may update these Terms. For material changes we will give at least thirty (30) days' notice by email to the address on your account or by prominent notice in the Service, and will update the "Last updated" date above. Continued use after the effective date constitutes acceptance. If you do not accept a material change, you may terminate before it takes effect; no refund is provided for the remaining term.
Assignment. You may not assign these Terms without our prior written consent, except to a successor in connection with a merger, acquisition, or sale of substantially all assets, on written notice to us. We may assign these Terms to an affiliate or in connection with a merger, acquisition, financing, or sale of assets.
Independent parties. Nothing here creates a partnership, joint venture, agency, or employment relationship.
Force majeure. Neither party is liable for delay or failure to perform (other than payment obligations) caused by events beyond its reasonable control, including acts of God, war, civil unrest, labour action, epidemic, failure of telecommunications or hosting providers, changes in third-party platform APIs or policies, or government action.
Third-party platforms. The Service depends on third-party platforms including Shopify, Meta, and Google. We are not responsible for changes to, restrictions imposed by, deprecation of, or outages affecting those platforms, or for their content, policies, or practices. Your use of those platforms is governed by their own terms.
No Shopify affiliation. Funnelytics is an independent third-party application. We are not affiliated with, endorsed by, or sponsored by Shopify Inc. Your use of Shopify and the Shopify App Store remains subject to Shopify's own terms.
Export and sanctions. You represent that you are not located in, and will not use the Service in, a country or by a person subject to Canadian, US, EU, or UK sanctions or export restrictions.
Notices. Notices to us go to support@funnelytics.io. Notices to you go to the email address on your account and are deemed received on the day sent.
Entire agreement, severability, waiver. These Terms, together with the policies on this page and any MSA or SOW, are the entire agreement between us on this subject and supersede prior discussions. If any provision is held unenforceable, it will be limited or severed to the minimum extent necessary and the remainder stays in effect. A failure to enforce any provision is not a waiver of it.
Language. The parties have requested that these Terms and all related documents be drawn up in English. Les parties ont demandé que cette convention et tous les documents s'y rattachant soient rédigés en anglais.
2. Acceptable Use Policy
Funnelytics is built to help merchants understand their customers. Some of that analysis operates on anonymized, aggregated behavioural data. Other parts of it — lifetime value by customer, high-value customer identification, repeat purchase and reactivation analysis, abandoned revenue reporting — necessarily involve identifiable customer data, which we process on your behalf, on your instructions, as your data processor.
That is a legitimate and intended use of the Service. It also means the legal responsibility for how that data was collected, and for what you do next with it, sits with you as the data controller.
2.1 Your responsibilities as controller
When you connect a store or advertising account, or deploy our tracking script, you represent and warrant that:
- you have a valid lawful basis (consent, contract, legitimate interests, or other applicable basis) for the collection and processing of the personal data you make available to us, and for the purposes for which you use our outputs;
- your own privacy policy accurately discloses that you use third-party analytics and attribution services, the categories of data collected, and the purposes — including, where applicable, that customer purchase history is used to calculate lifetime value and to inform marketing;
- where required by law, you have obtained and recorded valid consent before our tracking script collects data, and you have implemented a functioning consent mechanism and honour withdrawal of consent, opt-outs, and "do not sell or share" signals;
- you will handle data subject requests (access, correction, deletion, portability, objection) received from your customers, and will pass on to us any request that requires action in our systems;
- any outbound marketing, retargeting, or outreach you undertake using insights from the Service complies with applicable law, including Canada's CASL, the US CAN-SPAM Act and applicable state privacy laws, GDPR and the ePrivacy Directive, and any other law applicable to you and your customers.
2.2 Prohibited uses
You must not use the Service to:
- collect or process special category or sensitive personal data — including health, biometric, genetic, precise geolocation, racial or ethnic origin, religious belief, sexual orientation, trade union membership, government identifiers, or full payment card or financial account numbers — or to knowingly collect data from children under 13 (or the applicable minimum age in your jurisdiction);
- sell, licence, or disclose data derived from the Service, or personal data processed through it, to any third party, except where you have a lawful basis and, where required, explicit consent that the data may be sold or shared;
- deploy the tracking script on, or collect data from, any website, app, or property you do not own or are not authorized to instrument;
- circumvent, disable, or misconfigure a consent management platform, cookie banner, or privacy control in order to collect data you would not otherwise be permitted to collect;
- deliberately pass to us payment card data, passwords, health records, or government identifiers through tags, custom attributes, URL parameters, form capture, or any other mechanism;
- harass, bully, defraud, deceive, discriminate against, or unlawfully profile any individual, or use outputs to make decisions about individuals in a manner prohibited by law;
- reverse engineer, decompile, scrape, or attempt to derive the source code or underlying models of the Platform; use the Service to build or benchmark a competing product; resell, sublicence, or provide the Platform to third parties except as permitted under an authorized agency or partner arrangement;
- probe, scan, overload, or interfere with the security or integrity of the Service, circumvent usage limits, or share credentials to exceed licensed use;
- upload malware, or use the Service for any unlawful purpose or in breach of any applicable law.
2.3 Minimizing what you send us
We recommend you configure your implementation to avoid transmitting unnecessary personal data — in particular, suppress capture of form fields containing personal information you do not need for analysis, and avoid placing personal data in URL parameters. Where we can compute an insight from a hashed identifier rather than raw personal details, we do.
2.4 Enforcement
We may investigate suspected breaches of this Policy and may suspend or terminate access under Section 1.19. Where a breach creates legal exposure for us or risk to individuals, we may suspend immediately and notify you afterwards.
3. Services Terms — Insights Sprint & Optimize
This Section governs our human-delivered engagements. Every Services engagement is documented in a signed Master Services Agreement and Scope of Work. Where the MSA or SOW addresses a matter, it governs. This Section applies to matters the MSA and SOW do not address, and sets out our standing commitments.
3.1 The Insights Sprint
The Insights Sprint is a fixed-scope, one-time diagnostic engagement, delivered over approximately six (6) weeks, for a fixed fee stated in your SOW. Access to the Funnelytics Platform is included for the duration of the Sprint. Deliverables are those listed in your SOW and typically include a mapped customer journey, a tracking and data audit, an analysis of products, channels, pages, and paths, and a prioritized twelve (12) week optimization roadmap with impact estimates.
The Sprint fee is payable in advance and is non-refundable, in accordance with Section 1.7.
3.2 Funnelytics Optimize
Optimize is an ongoing, monthly implementation service under which we design and run an optimization programme against your roadmap, including on-site A/B testing and conversion rate optimization work.
- Optimize is billed monthly in advance at the rate in your SOW, with a three (3) month minimum commitment.
- After the minimum commitment, Optimize continues month to month until either party gives thirty (30) days' written notice. Notice takes effect at the end of the following billing month. Fees for the notice period remain payable.
- Optimize requires an active Funnelytics Platform subscription throughout.
- Fees are non-refundable, including for months in which fewer tests were run than planned, where the shortfall results from factors described in Section 3.6.
3.3 What we do not guarantee
Except for the Performance Guarantee in Section 3.4, we make no representation, warranty, or guarantee regarding revenue, conversion rate, average order value, customer acquisition cost, return on ad spend, lifetime value, or any other commercial outcome. Impact estimates in a roadmap are estimates modelled from your data, not commitments. Individual A/B tests may produce flat or negative results; that is a normal and expected feature of testing, and a losing test is not a failure of performance under this agreement.
3.4 The Performance Guarantee
Our promise: if you implement the roadmap and don't get at least 15% more customers from the traffic we analyzed, we keep working with you — at no additional analysis fee — until you do.
Here is exactly how that works.
(a) What is measured. "15% more customers" means a relative increase of at least 15% in the visitor-to-customer conversion rate for the traffic sources and customer journeys identified as in scope in your roadmap ("Analyzed Traffic"), measured against the Baseline. Conversion rate is used rather than raw customer count so that the result is not distorted by increases or decreases in traffic volume, which are outside our control.
(b) Baseline. The Baseline is the visitor-to-customer conversion rate for the Analyzed Traffic over the ninety (90) day period immediately preceding the Implementation Start Date, as recorded in the Funnelytics Platform. The Baseline is calculated and confirmed in writing at the end of the Sprint. Platform data is the sole source of truth for measuring this guarantee.
(c) Measurement Period. The first Measurement Period is the twelve (12) weeks following the Implementation Start Date. The Implementation Start Date is the date agreed in writing following delivery of your roadmap.
(d) Conditions. The guarantee applies only if all of the following are true:
- You implement all roadmap items tagged red (high priority) within the Measurement Period — whether by your own team or through Optimize. Items you decline to implement, deprioritize, or materially alter without our written agreement are excluded, and where a declined item was material to the projected result, the guarantee does not apply.
- You maintain an active, paid Funnelytics Platform subscription and working tracking throughout the Measurement Period, and you remediate any tracking issues we identify and attribute to your systems within fifteen (15) business days of notice.
- You maintain conditions materially comparable to the Baseline period. Specifically, the guarantee does not apply where, during the Measurement Period: paid media spend on the Analyzed Traffic falls by more than 25% against the Baseline period average; you materially change pricing (more than 15% on products representing more than 25% of the Analyzed Traffic's revenue); you discontinue or substantially change products representing more than 25% of that revenue; you replatform, redesign the storefront outside the roadmap, or change checkout providers; or you run a materially different promotional strategy.
- You do not run a concurrent conversion optimization programme with another provider on the same pages or journeys, as this makes attribution of the result impossible.
- You provide timely access and responses as set out in Section 3.6, and you are not in arrears on any fee owed to us.
- You claim in writing within thirty (30) days of the end of the Measurement Period, to support@funnelytics.io.
(e) The remedy. If the conditions in (d) are met and the 15% threshold is not reached, we will continue to analyze your data and produce prioritized recommendations at no additional analysis fee for a further twelve (12) week cycle, and for successive twelve (12) week cycles thereafter, until the threshold is met.
This continues for as long as you continue to satisfy the conditions in (d) in each cycle — including continuing to implement the recommendations we issue and maintaining an active paid Platform subscription. The obligation ends if you stop implementing our recommendations, cancel or fail to pay for your Platform subscription, fall into arrears, breach these Terms, or notify us that you no longer wish to continue.
Continued work under this remedy covers analysis and recommendations only. It does not include Optimize implementation services, additional tracking build work, or new Sprints, each of which remains chargeable at our then-current rates unless your SOW says otherwise.
(f) Sole remedy. The remedy in (e) is your sole and exclusive remedy for failure to reach the 15% threshold. No refund, credit, or discount of the Sprint fee or any other fee is provided, and we have no other liability in respect of the guarantee.
3.5 If your tracking or data is not fit for analysis
During Weeks 1–2 of the Sprint we audit your tracking and data. If we determine that your tracking, tagging, or historical data is not sufficient to support reliable analysis, we will tell you in writing, identify precisely what is broken, and specify what must be fixed and by whom.
In that situation: we will remediate what falls within the Sprint scope; you must remediate what falls to your systems, team, or third-party providers; the Sprint timeline is extended by the time taken to remediate; the Performance Guarantee in Section 3.4 does not come into effect until remediation is complete and a valid Baseline can be established; and if remediation cannot be completed, we will deliver the analysis achievable from the available data, and no Performance Guarantee will apply.
No refund of the Sprint fee is provided in these circumstances. The audit, the diagnosis, and the remediation specification are themselves core deliverables of the Sprint.
3.6 Your obligations and dependencies
Our ability to deliver depends on you. You will:
- provide timely read access to your Shopify store, advertising accounts, email and CRM platforms, analytics tools, and website as required by the SOW;
- nominate a named point of contact with authority to make decisions, and a technical or ecommerce resource able to implement or approve changes;
- respond to requests for information, approvals, and feedback within three (3) business days;
- attend scheduled workshops and reviews, or reschedule with reasonable notice.
Where delay is caused by you, timelines extend accordingly. Fees are not reduced or extended, and Sprint weeks not used because of your delay are not carried forward beyond ninety (90) days from the original start date. If an engagement is inactive on your side for more than sixty (60) consecutive days, we may close it as delivered, with deliverables provided as they stand.
3.7 On-site testing, third-party tools, and rollback
Under Optimize we implement changes and experiments on your storefront. You should understand exactly how this works.
- Authorization. You authorize us, and any subcontractor we engage, to access your storefront and connected systems and to deploy, modify, and remove experiments and optimizations as contemplated by the SOW.
- Third-party testing tools. On-site experiments are typically deployed using third-party experimentation platforms such as Shoplift or Intelligems. Those tools are not our products. They are licensed separately, they are governed by their own terms and privacy policies, and we are not responsible for their availability, accuracy, security practices, or pricing. Your SOW states whose account is used and who bears the licence fee.
- Coordination and approval. We coordinate with your ecommerce or development team before deploying, and we do not deploy material changes without your approval. You remain responsible for maintaining backups of your theme and store configuration.
- Our remediation commitment. If an experiment or change we deploy causes a defect on your store — including any interruption to checkout — we will roll it back and remediate at our cost, as a priority, at no charge to you. Where the defect affects checkout or another revenue-critical path, we will begin remediation as soon as we are made aware and will work continuously until resolved. Notify us immediately at support@funnelytics.io and through your Slack Connect channel.
- What that commitment is and is not. Our commitment is to fix it, fast, at our cost. It is not an assumption of financial liability for revenue, profit, or sales lost while the defect existed, or for any other consequential loss. Those remain excluded under Section 1.17(a) and subject to the cap in Section 1.17(b). We are not responsible for defects arising from changes made by you or your other providers, from third-party tool failures, from Shopify platform changes, or from your existing theme or app conflicts we were not made aware of.
3.8 Deliverables and intellectual property
On full payment, you own the deliverables created specifically for you — your journey maps, your data audit findings, your roadmap, and your reports — and may use them without restriction in your business.
We retain all rights in our methodologies, frameworks, analytical models, templates, report structures, scoring systems, the Platform, and any general knowledge, skills, and experience acquired in the course of delivery. Nothing in a SOW transfers those rights or restricts our use of them for other clients. Neither party's pre-existing intellectual property transfers to the other.
3.9 Personnel, subcontractors, and non-solicitation
We deliver through a combination of employees and contractors, and may engage subcontractors, provided we remain responsible for their performance and they are bound by confidentiality obligations at least as protective as Section 1.15. We may substitute personnel with comparable skills.
During an engagement and for twelve (12) months afterwards, neither party will directly solicit for employment or engagement any individual who was materially involved in delivering the engagement for the other. Responses to general public job advertisements are not a breach.
3.10 Communication and Slack Connect
Engagements are typically run through a shared Slack Connect channel. You acknowledge that Slack Technologies is a sub-processor (Section 11) and that information you place in that channel — including reports, screenshots, and account data — is processed by Slack. Do not place payment card data, passwords, health data, or government identifiers in the channel. Share credentials only through a password manager or the access-delegation features of the relevant platform, never in plain text.
3.11 Suspension for non-payment
If any Services fee is more than fifteen (15) days overdue, we may suspend delivery, including pausing running experiments and withholding deliverables, until payment is received. Suspension does not extend the term or reduce fees, and the guarantee conditions in Section 3.4(d) are not satisfied during any period of arrears.
4. Legacy Products & Plans
Funnelytics has been through more than one generation of product. This Section sets out how earlier purchases relate to what we sell today.
4.1 Funnelytics 3.0 is a distinct product
The Funnelytics Shopify application, the LTV Profit Map, and the current Shopify-focused Platform (together, "Funnelytics 3.0") were built independently of Funnelytics 1.0 and 2.0.
Lifetime Deal licences, Founding Member entitlements, AppSumo licences, legacy plan grandfathering, and any other historical entitlement apply only to the product and plan for which they were purchased. They confer no licence, credit, discount, or entitlement of any kind in respect of Funnelytics 3.0, its paid tiers, or the Services. The Free App and the free LTV Profit Map report are available to all merchants at no charge, including legacy licence holders.
4.2 Legacy plans and grandfathered pricing
Merchants on legacy or grandfathered plans continue on the terms and pricing applicable to those plans while those plans remain available, subject to our right to change fees under Section 1.5 and to modify or discontinue products under Section 4.4. Legacy plan limits, overage behaviour, and upgrade mechanics continue as previously communicated: for legacy plans, exceeding a feature limit results in an automatic upgrade to the next tier for the remainder of the subscription period, pro-rated immediately and billed in full from the next cycle.
4.3 Map by Funnelytics
Funnelytics Map, including Map Pro, remains available and supported for existing users. It is maintained in its current state. We do not commit to new features, integrations, or a development roadmap for Map, and it is not part of Funnelytics 3.0. Existing Map entitlements, including free-forever mapping access, are unaffected.
4.4 Modification and discontinuation of legacy products
We may modify or discontinue any legacy product, plan, or feature. Where we discontinue a legacy product or plan on which you hold a paid or lifetime entitlement, we will give at least ninety (90) days' notice by email and, where reasonably possible, provide a migration path or comparable alternative. No refund is provided in respect of lifetime or previously consumed entitlements.
4.5 Resale and account transfer
Reselling means selling a Funnelytics account, workspace, or project to a third party outside the Funnelytics platform. Resale of Lifetime Deal licences, workspaces, and projects is prohibited. Resale or attempted resale may result in termination without notice and without refund. This does not prohibit: including a workspace or project in a service agreement with the primary owner; transferring ownership of a subscription within Funnelytics; or subscriptions purchased through a Funnelytics affiliate link. Support is provided to the account owner.
4.6 Legacy Marketplace and Providers platform
All transactions and interactions on the Funnelytics Providers platform are between you and the provider. Funnelytics is not a party to and is not responsible for disputes between providers and users. Review any provider's own terms before contracting with them.
4.7 Legacy courses and digital products
For historical purchases of Funnelytics Academy courses, Vault, Agency Ignite Swipe Files, Quick Wins Templates, and the Template Library: Vault, Swipe Files, Quick Wins Templates, and Template Library products are non-refundable once activated. Individual Academy course purchases were refundable within fourteen (14) days of purchase, except FaaStrack and guest courses, which are non-refundable. Deposits are non-refundable. Refunds could be declined where 25% or more of course content had been viewed. These products are no longer sold.
4.8 Event Processor (beta)
Where you have access to the Event Processor, use is subject to a fair-use policy based on a 10x factor: fair use is ten times the profiles your licence allows (for example, a 100,000-profile licence allows 1,000,000 events). For data sources, fair use is one data source per 100,000-profile tier; for unique data object types, three per source. We do not charge for exceeding these during the beta, and reserve the right to change this on notice.
5. Privacy Policy
At Funnelytics Inc. we value your privacy and the importance of safeguarding your data. This Privacy Policy describes our privacy practices. "Personal Data" means any information that, on its own or in combination with other available information, can identify an individual.
We work to meet our obligations under, among others: Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial legislation; Quebec Law 25; the EU and UK General Data Protection Regulation (GDPR); Brazil's LGPD; California's CCPA/CPRA and CalOPPA; the Colorado Privacy Act, Utah Consumer Privacy Act, Connecticut Data Privacy Act, and Virginia CDPA; and South Africa's POPIA.
5.1 Two different roles
It matters which of the following applies:
- We are the controller of Personal Data about our own users, prospects, and website visitors — the people who create Funnelytics accounts, contact us, or browse our sites. This Policy describes how we handle that data.
- We are a processor of Personal Data within Merchant Data — the data we access from a merchant's connected store, connected advertising and marketing platforms, and tracking script. That data is handled on the merchant's behalf, on the merchant's instructions, under Section 6 and Section 8. If you are a customer of a merchant that uses Funnelytics, that merchant is the controller of your data; see Section 5.11.
5.2 Scope
This Policy applies to Funnelytics Inc. websites, domains, applications, services, and products. It does not apply to third-party applications, websites, products, services, or platforms reached through non-Funnelytics links, which have their own practices.
5.3 Personal Data we collect as controller
- Account Information — name, email address, password, company name, role.
- Payment Information — billing address, phone number, and payment method details. Card details are collected and stored by Stripe; we do not store full card numbers.
- Communications — messages you send us through support, email, forms, scheduling tools, and chat, and records of calls and workshops where you have consented to recording.
- Device and Usage Data — collected automatically as you interact with our sites and product, using cookies, server logs, and similar technologies: IP address, browser and device type, pages viewed, referring URLs, and in-product actions.
- Third-party sources — we may receive Personal Data from analytics providers, social and advertising platforms, payment providers, and fraud-prevention services.
5.4 Merchant Data from connected platforms
When a merchant connects a store or an advertising or marketing platform, we access and process that data as a processor. What we access from Shopify is set out in full in Section 8. What we access from advertising and marketing platforms is set out in Section 9.
We use that data solely to provide the analytics, reporting, and attribution features of the Service and, where a merchant has engaged us, to deliver the Services. Access to store data is read-only. We do not use it for our own marketing, we do not sell it, and we do not share it except with the sub-processors listed in Section 11.
5.5 Purpose and legal basis
Where we act as controller, we process Personal Data because it is: necessary to perform our contract with you (providing and billing for the Service, supporting you); necessary for our legitimate interests (securing the Service, preventing fraud and abuse, understanding how the product is used so we can improve it, and marketing our services to business contacts in a manner consistent with applicable law); necessary to comply with a legal obligation; or based on your consent, where consent is required — for example for certain cookies and marketing communications. You may withdraw consent at any time.
Where we act as processor, the merchant is responsible for establishing the legal basis, as set out in Section 2.1.
5.6 Sharing and disclosure
We share Personal Data with: the sub-processors and service providers listed in Section 11, under contract and only as needed to operate the Service; professional advisors, where necessary; and public authorities or other parties where required to comply with a legal obligation, respond to lawful requests, enforce our terms, or protect the rights, property, or safety of Funnelytics, our users, or others.
We do not sell Personal Data, and we do not share it for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA. We do not use or disclose sensitive personal information for purposes requiring a right to limit under the CPRA.
5.7 International transfer and storage
Data accessed from connected ecommerce platforms is stored and processed in the United States, in a ClickHouse Cloud database running on Amazon Web Services infrastructure in the US East (N. Virginia) region. Behavioural data collected through the Funnelytics tracking script is stored on Amazon Web Services infrastructure in the Canada Central region. Account identity data used for support and communications is processed in the United States. Other Personal Data may be transferred to and maintained on servers outside your jurisdiction.
Where processing involves transferring Personal Data from the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (with the UK International Data Transfer Addendum where applicable) as the transfer mechanism, together with supplementary technical and organizational measures. Canada benefits from an EU adequacy decision in respect of commercial organizations subject to PIPEDA.
5.8 Cookies
A cookie is a small file your browser stores on your device. We use: strictly necessary cookies to run the Service and keep you signed in; preference cookies to remember how you like to use it; and analytics cookies to understand and improve the product and our marketing. Where required by law, we request consent for non-essential cookies before setting them, and you can change or withdraw your choices at any time through the cookie controls on our site or your browser settings. Blocking strictly necessary cookies may prevent parts of the Service from working.
5.9 Retention
We retain Personal Data only as long as necessary for the purpose it was collected and as required by law. In practice:
- Account and billing records — for the life of the account and then up to seven (7) years, to meet Canadian tax and corporate record-keeping requirements.
- Merchant Data from connected platforms — for the life of the connection, and then deleted or anonymized within ninety (90) days of disconnection or account termination, subject to Section 8.6 for Shopify redaction requests.
- Behavioural tracking data — retained for the retention period applicable to the merchant's plan, and in any event deleted or anonymized within ninety (90) days of account termination.
- Support communications — up to three (3) years after last contact.
- Marketing contact data — until you unsubscribe or object, and then on a suppression list to ensure we honour that choice.
Aggregated, de-identified data as described in Section 1.11 may be retained indefinitely.
5.10 Automated processing
The Platform profiles customer behaviour and produces scores, segments, and AI-generated commentary (see Section 10). These outputs are analytical and advisory. We do not use them to make automated decisions producing legal effects or similarly significant effects on individuals. If a merchant uses our outputs to make significant decisions about individuals, the merchant is responsible for compliance, including any requirement to provide human review.
5.11 Your rights
Subject to applicable law, you may: request access to your Personal Data; request correction or deletion; object to or request restriction of processing; withdraw consent; request a portable copy; and, in California and certain other jurisdictions, exercise rights to know, delete, correct, and opt out of sale or sharing. We do not discriminate against anyone for exercising a privacy right.
To exercise a right, email support@funnelytics.io. We will verify your identity, respond within the period required by applicable law (generally thirty (30) days, or forty-five (45) days under the CCPA/CPRA), and tell you if we need more time. An authorized agent may submit a request on your behalf with proof of authority.
If you are a customer of a merchant that uses Funnelytics, the merchant controls your data. Please contact the merchant first. You may also contact us and we will assist the merchant in responding, or act on the merchant's instruction.
Complaints. If you are not satisfied with our response, you may complain to your data protection authority: in Canada, the Office of the Privacy Commissioner of Canada or your provincial authority; in Quebec, the Commission d'accès à l'information; in the EU or UK, your national supervisory authority or the Information Commissioner's Office. You may also raise a concern with us first at support@funnelytics.io.
5.12 Children
The Service is not directed to children under 13, or the equivalent minimum age in the relevant jurisdiction, and we do not knowingly collect Personal Data from them. If you believe a child has provided us Personal Data, contact us and we will take appropriate action.
5.13 Security
See Section 12.
5.14 Merger or acquisition
If we go through a business transition such as a merger, acquisition, financing, or asset sale, Personal Data may be transferred as part of that transaction. We will give notice before Personal Data becomes subject to a materially different privacy policy.
5.15 Changes to this Policy
We may update this Policy. Material changes will be notified by email to account holders or by prominent notice on our sites, and the "Last updated" date above will change.
6. Data Processing Agreement
In the course of providing the Service, Funnelytics Inc. processes personal data on your behalf. To document how we do that and the obligations of each party, we make a Data Processing Agreement ("DPA") available free of charge to anyone who uses the Service.
The DPA forms part of the contract between Funnelytics, as processor, and you, as controller. It covers: the subject matter, nature, purpose, and duration of processing; categories of data subjects and personal data; our obligation to process only on your documented instructions; confidentiality of personnel; the security measures we apply; the terms on which we engage sub-processors; assistance with data subject requests; breach notification; deletion and return of data; audit and information rights; and international transfers, incorporating the European Commission's Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum.
To request the DPA, email support@funnelytics.io. We will countersign and return a fully executed copy. Where you have signed an MSA with us, the DPA is incorporated into it.
7. GDPR & CPRA
What is Funnelytics doing about GDPR and CPRA?
We have dedicated internal resources to data protection since our founding in 2018, because we value our customers' — and their customers' — right to privacy. Compliance with international privacy law is important to us and to the merchants who trust us with their data.
What Funnelytics customers need to do
- Disclose us in your own privacy policy. Make sure it communicates that you use third-party analytics and attribution services, what is collected, and why.
- Obtain and manage consent where required, including for our tracking script, and honour withdrawals and opt-out signals. See Section 2.1.
- Sign a DPA with us if you process data of individuals in the EU, UK, or another jurisdiction requiring one. Email support@funnelytics.io — we are happy to sign, at no charge.
- Route data subject requests. Handle requests from your own customers, and pass on to us anything requiring action in our systems.
Overview of GDPR and CPRA
The General Data Protection Regulation and the California Privacy Rights Act regulate the processing of personal data, including its collection, storage, transfer, and use. Key elements include: expanded individual rights, including erasure and access to a copy of one's personal data; compliance obligations covering policies, security controls, impact assessments, records, and written agreements with vendors; mandatory breach notification to authorities and, in some cases, to affected individuals; additional obligations where organizations profile or monitor individuals; and enforcement, with GDPR fines reaching the greater of €20 million or 4% of annual global turnover.
8. Shopify App Data Use & Permissions
This Section explains exactly what data the Funnelytics Shopify app accesses from a connected store, why each permission is required, how that data is used, where it is stored, and how you can have it deleted. It supplements our Privacy Policy and Data Processing Agreement, which continue to apply in full.
8.1 What the app does
The app helps you and your team improve store performance by giving you visibility on metrics that regular store analytics often do not expose — customer lifetime value, marketing attribution, time to conversion, and time to repeat purchase. When you connect your Shopify store, Funnelytics reads your order, customer, and product data and uses it to produce per-customer LTV reporting and to attribute revenue back to the marketing source that acquired each customer.
The Shopify data connection is read-only. Funnelytics never creates, edits, or deletes anything in your Shopify store through this connection.
Separately, if you install our tracking script or engage us for Optimize, changes may be made to your storefront — but only with your authorization and coordination, as set out in Sections 3.7 and 8.5. Those are distinct from the read-only data connection described here.
8.2 What data we access
- Order information — order totals, line items, financial status, timestamps, and the marketing-attribution fields recorded on the order (landing site, referring site, source).
- Customer information — name and email address, used to group a customer's orders together so lifetime value can be calculated per customer. Where possible we derive a hashed identity key rather than storing raw personal details.
- Product information — product and variant details (title, SKU, price), used to attribute lifetime value to specific products.
We access only what our reporting requires. We do not request access to your store's payment, payout, banking, dispute, fulfilment, shipping, theme, script, discount, or content data, and we request no write permissions of any kind.
8.3 The permissions we request, and why
| Permission | Why Funnelytics needs it |
|---|---|
read_orders | The core data source. Order totals, line items, and timestamps are the basis of every lifetime-value calculation, and the marketing-attribution fields recorded on each order are what let us trace revenue back to its source. Without this permission the app cannot function. |
read_customers | Lifetime value is measured per customer, so we need to link a customer's orders to a single identity using their name and email. Shopify also includes customer details within each order record, so this permission is technically required to read orders. |
read_products | Lets us map each order's line items back to your catalogue so lifetime value can be broken down by product — for example, which products your highest-value customers buy. |
read_inventory | Order line items reference product variants rather than products directly. Variant data (SKU, price) is needed to link each line item accurately to your catalogue for product-level reporting. |
read_draft_orders | Some merchants — particularly wholesale or invoice-based sellers — realise revenue through draft orders. Including them ensures lifetime value reflects all realised revenue, not only standard online-checkout orders. |
read_all_orders | Lifetime value is inherently historical and needs a customer's full order history. Shopify's standard access is limited to the most recent 60 days, which is not enough to calculate LTV or run cohort analysis, so this permission extends the available history. |
All six permissions are read-only. We never request permission to modify your store or your data.
8.4 How we use your data
We use Shopify data only to provide the analytics features of the app — LTV reporting, marketing attribution, cohort and funnel analysis, and the related dashboards and reports — and, where you have engaged us for Services, to deliver those Services. We act as a data processor, handling this data on your behalf and on your instructions.
- We do not sell your data.
- We do not use your store's customer data for our own marketing.
- We do not share it with anyone except the sub-processors listed in Section 11, and only to the extent needed to operate the Service.
- Your store's customer data and any behavioural data collected by our tracking script are kept separate from our customer-support systems.
8.5 The tracking script
Where you choose to install the Funnelytics tracking script on your storefront, it collects behavioural data about visitor journeys — pages viewed, sequence, referring source, and events you configure. Installation is your decision and under your control, and you are responsible for obtaining any consent required before it collects data (Section 2.1). Behavioural data is stored separately from Shopify data, on Amazon Web Services infrastructure in the Canada Central region.
8.6 Where your data is stored
Data accessed from your connected Shopify store is stored and processed in a ClickHouse Cloud database (operated by ClickHouse, Inc.) running on Amazon Web Services infrastructure in the US East (N. Virginia) region. Behavioural data collected through the Funnelytics tracking script is stored separately on Amazon Web Services infrastructure in the Canada Central region. Account identity data used for support is processed by Intercom in the United States. Where this involves transferring personal data from the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses.
8.7 Accessing or deleting your data
If you are a merchant, you can disconnect the app at any time from your Shopify admin, which immediately stops all further data access. You can also disconnect and uninstall the app from within the Funnelytics dashboard. You may request access to, or deletion of, the data we hold by contacting support@funnelytics.io.
If you are a customer of a merchant that uses Funnelytics, the merchant controls your data — contact them, or contact us and we will assist.
Shopify data requests. Funnelytics honours Shopify's mandatory customers/data_request, customers/redact, and shop/redact webhooks. On receiving a customer data request we retrieve the corresponding data and provide it to the merchant within thirty (30) days. On receiving a customer redaction request we delete that customer's personal data from our systems within thirty (30) days. On receiving a shop redaction request — which Shopify sends 48 hours after uninstall — we delete the store's data from our systems within thirty (30) days. We apply these rights to everyone, regardless of where they live.
9. Connected Ad Platform & Marketing Tool Data
Attribution requires knowing what you spent, not only what you sold. Where you choose to connect an advertising or marketing platform, this Section explains what happens.
9.1 What you can connect
You may connect advertising and marketing platforms including Meta (Facebook and Instagram) Ads, Google Ads, and other platforms we support or add over time. Connecting is always your choice, made through the platform's own authorization flow, and you can disconnect at any time from the Funnelytics dashboard or by revoking access in the platform.
9.2 What we access
- Campaign structure — account, campaign, ad set, and ad names and identifiers, and the URLs and UTM parameters associated with your ads.
- Performance and spend metrics — impressions, clicks, spend, and platform-reported conversions, generally at campaign, ad set, or ad level.
- Creative metadata — where available, so performance can be attributed to specific creative.
We do not request or use audience lists, customer match lists, uploaded contact lists, or individual-level user data from advertising platforms. Advertising platform data we ingest is generally aggregated and does not identify individuals; where any identifier is included, it is processed as Merchant Data under Section 5.4.
Access is read-only. We do not create, edit, pause, or delete campaigns, budgets, or creative through these connections. Where an optimization recommendation involves changing spend, your team or your media buyer makes the change.
9.3 How we use it
Solely to join spend and click data to your revenue and lifetime-value data, so we can report customer acquisition cost, return on ad spend, and lifetime value by channel, campaign, and journey — and, where you have engaged us for Services, to deliver those Services.
9.4 Accuracy
Figures we report will not match the numbers in Meta Ads Manager or Google Ads. Those platforms use their own attribution windows, view-through and modelled conversions, and self-reported conversion counts. Ours are calculated from your first-party order data. Section 1.10 applies in full.
9.5 Your authority to connect
You represent that you are authorized to connect each account, including where the account is owned by an agency or a third party on your behalf, and that connecting it does not breach that platform's terms or any agreement you have with your agency.
10. AI Features
Parts of the Service use large language models to interpret your data and generate written insights, summaries, anomaly explanations, and recommendations, including in our reports and in Vision AI.
Model provider. Our AI features are powered by Anthropic (Claude), accessed through Anthropic's commercial API and listed as a sub-processor in Section 11. To deliver an insight, relevant data — which may include aggregated metrics, journey and product data, and in some cases identifiers within Merchant Data — is transmitted to Anthropic's API for processing and returned to you.
Your data is not used to train models. Under our agreement with Anthropic, data submitted through the commercial API is not used to train their models. We do not use Merchant Data to train any model of our own, and we do not permit any sub-processor to use it for that purpose.
Outputs are probabilistic, and you must review them. AI-generated content is produced by a statistical model. It can be incomplete, can misinterpret context, and can state something confidently that is wrong. AI output is a starting point for your judgement, not a substitute for it, and Section 1.10 applies in full. Do not act on an AI-generated recommendation with material financial consequences without validating the underlying data.
Human delivery. Where you have engaged us for the Insights Sprint or Optimize, AI-generated analysis supports our team; it does not replace it. Recommendations delivered as part of a Services engagement are reviewed by a person.
Availability. AI features depend on a third-party provider and may be interrupted, changed, rate-limited, or discontinued. They are not covered by any service level commitment.
11. Sub-processors
Below are the sub-processors currently authorized by Funnelytics Inc. to process Customer Data and to assist us in providing the Service.
| Sub-processor | Purpose | Data received | Location |
|---|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting and infrastructure | All hosted data | US East (N. Virginia) and Canada Central |
| ClickHouse, Inc. | Managed analytics database (ClickHouse Cloud) for ecommerce, order, and advertising analytics data | Merchant Data | AWS US East (N. Virginia) |
| Anthropic PBC | AI model provider (Claude) powering AI-generated insights and Vision AI | Data submitted for insight generation; not used for model training | United States |
| Intercom, Inc. | Customer support communications | Account identity data (name, email) only. Does not receive behavioural analytics or connected-store customer data | United States |
| Slack Technologies (Salesforce, Inc.) | Internal communication and Slack Connect channels with Services clients | Information shared in shared channels, including reports and account context | United States |
| Twilio SendGrid | Transactional and product email delivery | Name, email address, email content | United States |
| Close (Elastic Inc.) | Sales CRM and outreach | Account and prospect contact details and communication history. Does not receive connected-store customer data | United States |
| Stripe, Inc. | Payment processing and subscription billing | Billing contact and payment data | United States |
| GitHub, Inc. | Source code repository and management | Source code; no Merchant Data in the ordinary course | United States |
Notification of changes and right to object
Customers with a Data Processing Agreement in place may subscribe to be notified of new sub-processors before we authorize them to process personal data. To subscribe, email support@funnelytics.io with your customer name, address, and an executed copy of the DPA.
A customer with a DPA in place may object to a new sub-processor by notifying us in writing within ten (10) business days of our notice. If the objection is not unreasonable, we will use reasonable efforts to make available a change in the applicable Service, or recommend a commercially reasonable change in configuration, to avoid processing by the objected-to sub-processor without unreasonably burdening you. If we cannot make such a change within thirty (30) days, you may terminate the affected Service by giving written notice.
12. Security & Compliance
We take practical, layered steps to protect the data we hold on your behalf. The controls below are what we operate today; we continue to invest in our security programme as the platform grows. We do not currently hold a SOC 2 or ISO 27001 certification, and we will say so plainly rather than imply otherwise.
- Encryption in transit and at rest — all personal data is encrypted while moving between systems and while stored in our databases.
- Least-privilege access — access to store and customer data is restricted to personnel who need it to operate the Service, and is reviewed periodically.
- Strong authentication — we require strong, unique credentials for internal systems, use multi-factor authentication where supported, and maintain access logs.
- Read-only integrations — the Shopify data connection and advertising platform connections are read-only. Funnelytics cannot create, edit, or delete anything in your store or your ad accounts through them.
- Data segregation — connected-store customer data and behavioural analytics data are kept separate from our support and sales systems, with regional isolation between analytics data (US East / N. Virginia) and tracking data (Canada Central).
- Trusted infrastructure — hosted on Amazon Web Services and ClickHouse Cloud.
- Contracted sub-processors — every sub-processor in Section 11 is engaged under contract with confidentiality and data protection obligations, and personnel are bound by confidentiality.
- Incident response — we maintain a documented security-incident and breach-response policy. Where a breach affects Merchant Data, we will notify affected customers without undue delay and in any event within seventy-two (72) hours of becoming aware, with the information available to us at the time, and will keep you updated as we investigate.
- International transfers — where personal data moves out of the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses.
Reporting a vulnerability. Email support@funnelytics.io with enough detail to reproduce the issue. We will acknowledge and investigate. We ask that you give us a reasonable opportunity to remediate before public disclosure, and that you do not access, modify, or exfiltrate data belonging to others while testing. We will not pursue action against good-faith security research conducted in line with this request.
13. Contact
For any question about these terms, our privacy practices, or how we handle your Shopify data — or to make a data access or deletion request — please contact us.
Email: support@funnelytics.io
Funnelytics Inc.
© 2026 Funnelytics Inc. All rights reserved.
