1. Scope and roles
Pickora provides product recommendation quiz tools to SHOPLINE merchants. For merchant account, installation, security, and service-operation data, Pickora acts as the service provider responsible for operating the app. For shopper information collected through a merchant-created quiz, the merchant determines why the quiz is used and which optional fields are collected; Pickora processes that information to provide the quiz service on the merchant’s behalf.
A merchant may have its own privacy notice for its storefront and customer relationships. Shoppers should review the merchant’s privacy notice in addition to this policy.
2. Information we process
- Merchant and store information: SHOPLINE store handle, store identifier, store name, primary domain, language preferences, installation/authorization timestamps, OAuth scopes, and encrypted access credentials required to call authorized SHOPLINE APIs.
- Quiz configuration: quiz titles, descriptions, questions, answers, conditional-flow rules, recommendation paths, selected products, fallback products, display rules, storefront entry settings, auto-trigger settings, lead-capture settings, discount configuration, and experiment configuration.
- Product information: product and variant identifiers, titles, images, handles/URLs, prices, publication status, variant availability metadata, and other catalog details needed to build and validate recommendations.
- Shopper quiz submissions: answers, recommended product identifiers, matched recommendation paths, quiz completion state, and timestamps.
- Optional lead information: a shopper’s first name, last name, email address, and/or phone number only when the merchant enables Lead Capture and chooses those fields. Email collection is separate from email-marketing consent; Pickora records marketing consent only when the merchant enables a consent prompt and the shopper actively selects it.
- Usage and diagnostic information: quiz views, starts, question answers, completions, product clicks, add-to-cart events, discount views/copies, locale, page URL, referrer, request identifiers, API usage counters, error diagnostics, and service-health events.
- Browser storage: Pickora may store a randomly generated storefront visitor identifier, first-seen timestamp, new/returning-session state, auto-trigger state, and a completed-quiz submission identifier in localStorage or sessionStorage so targeting, one-time triggers, and result restoration work correctly.
3. Why we process information
- Authenticate merchants and keep the embedded SHOPLINE admin experience available.
- Create, save, publish, duplicate, preview, and operate quizzes.
- Read SHOPLINE catalog data and validate whether configured recommendation products are still deliverable.
- Evaluate quiz answers against merchant-defined recommendation rules and return product results.
- Provide optional lead capture, discount rewards, conditional flows, targeting, automatic triggers, and A/B experiments.
- Generate analytics such as starts, completion rate, question drop-off, product clicks, and add-to-cart activity.
- Protect the service, troubleshoot failures, monitor reliability, prevent abuse, and improve product performance.
- Comply with applicable legal obligations and respond to lawful requests.
4. SHOPLINE permissions
Pickora requests only the SHOPLINE permissions currently needed for its published features: read_products, read_discounts, and write_discounts. Product permissions support catalog search and recommendation delivery checks. Discount permissions support validating and creating/connecting Quiz Reward discount codes. Pickora does not request payment-card access and does not process card numbers.
5. How information is shared
We do not sell personal information. Information may be shared with infrastructure, hosting, database, security, monitoring, and other service providers only as needed to operate Pickora. Information is also exchanged with SHOPLINE when Pickora calls authorized SHOPLINE APIs or when storefront features interact with SHOPLINE product/cart functionality.
If a merchant connects Klaviyo, Pickora may send shopper contact identifiers, quiz-completion events, answers, recommendation context, and related properties to that merchant’s Klaviyo account according to the integration settings. Pickora only requests an email-marketing subscription when the shopper has actively provided email-marketing consent through the merchant-configured Quiz consent prompt.
Operational monitoring may include store identifiers, app/version/environment information, aggregated API usage counters, and error diagnostics. Shopper lead fields are not required for operational monitoring.
6. Cookies and browser storage
The Pickora admin uses an HTTP-only session cookie named quiz_session after SHOPLINE authorization. In production it is sent securely and is configured for a limited session duration.
The storefront runtime primarily uses localStorage/sessionStorage for a random visitor identifier, new-versus-returning visitor logic, one-time auto-trigger suppression, debug preference when manually enabled, and restoration of a recently completed quiz. Merchants are responsible for presenting any cookie/storage consent notice required by the laws that apply to their storefront.
7. Data retention and deletion
We retain information for as long as reasonably necessary to provide and secure Pickora, maintain merchant configurations and analytics, meet legal obligations, and resolve disputes. Retention may vary by data type and operational requirement.
Deleting a quiz configuration does not necessarily remove historical submission or analytics records immediately. Merchants that need store, shopper, submission, or analytics data deleted should contact Pickora support with sufficient store and request details. We may retain limited information where required for security, fraud prevention, legal compliance, or backup integrity.
8. Security
Pickora uses safeguards designed for the type of information it processes, including encrypted storage of SHOPLINE access tokens, HTTPS in production, HTTP-only admin session cookies, scoped SHOPLINE permissions, input validation, and service-health monitoring. No system can guarantee absolute security, and merchants should protect access to their SHOPLINE admin accounts.
9. International processing
Pickora and its service providers may process information in countries or regions different from the merchant or shopper. Where required, merchants remain responsible for providing storefront notices and obtaining consents or implementing transfer safeguards applicable to their customer relationships.
10. Privacy rights and requests
Depending on applicable law, individuals may have rights to access, correct, delete, restrict, or object to certain processing. Because shopper information is collected in the context of a merchant’s storefront, shoppers should normally contact that merchant first. Merchants can contact Pickora support for assistance with requests involving data stored by Pickora.
11. Children
Pickora is a merchant tool and is not designed specifically for children. Merchants are responsible for deciding whether their products, quizzes, and data-collection practices are appropriate for their audience and for obtaining any legally required parental consent.
12. Changes to this policy
We may update this Privacy Policy when Pickora’s features, data practices, or legal requirements change. The “Last updated” date on this page identifies the current published version.
13. Contact
For privacy, data-deletion, or security questions, Use the developer support channel shown on the Pickora Quiz listing in the SHOPLINE App Store..