Privacy Policy
Last updated 9 August 2026
Janus is a popup app for Shopify stores. This policy explains what data the app handles, why, who else sees it, how long we keep it, and how to have it deleted. It is written to be read, not to be survived.
1. Who this covers
Janus is operated by Janus Inc. ("Janus", "we"). Two different groups of people appear in this policy, and the difference matters:
- Merchants — the Shopify store owners who install Janus. You are our customer.
- Shoppers — the people who visit a merchant's store and see a popup. You are not our customer; you are the merchant's.
For shopper data, the merchant is the data controller and Janus is the processor. We handle that data on the merchant's instructions. If you are a shopper asking about your data, the store you signed up with is the right first contact, and we will help them answer you.
2. What we collect from merchants
- Your myshopify domain and primary storefront domain.
- An access token Shopify issues at install, so the app can act on your store.
- Your plan and subscription status, kept in sync by Shopify.
- Install and uninstall dates.
- Anything you type into the app: campaign designs, settings, and any API keys you connect.
We do not receive or store your payment details. Billing runs entirely through Shopify.
3. What we collect from shoppers
Only what a merchant's popup is built to ask for, plus the analytics needed to report on whether it worked.
| Category | Fields | Why |
|---|---|---|
| Sign-up details | Email, phone, first name, date of birth — only the fields the merchant's popup asks for | To deliver the offer and pass the sign-up to the merchant's email or SMS tool |
| Consent record | Whether email and SMS consent was given, the exact wording shown, the IP address it was given from, and the timestamp | Proof of consent, which marketing law requires the merchant to hold |
| Quiz and survey answers | The options selected in a popup's questions | To recommend products and to report answers back to the merchant |
| Analytics events | An anonymous session identifier, which popup and step was seen, page URL, referrer, UTM parameters, device type, browser, operating system, language, and approximate location (country, region, city) derived from the network connection | To count views and opt-ins and to show the merchant what is working |
| Order attribution | Order number, total, the discount code used, and the time of the order | To tell the merchant which sales came from a popup sign-up |
We never receive payment card details, passwords, or Shopify account credentials. We do not buy data about you, and we do not sell yours.
4. Cookies and local storage
The popup stores a small identifier in the shopper's browser. It is what stops the same popup from reappearing on every page, and it is what honours a frequency setting like "once per day". It is not used to track anyone across other websites.
5. Who else sees the data
We use a small number of service providers, and we share only what each one needs.
| Provider | Role | Where |
|---|---|---|
| Shopify | The platform Janus runs on; source of store, order, and billing data | Global |
| Render | Application hosting and database | United States (Oregon) |
| Cloudflare R2 | Storage for images uploaded to the popup builder | United States |
| Sentry | Error monitoring, so faults get fixed. Configured not to send personal data | United States |
Destinations the merchant chooses. If a merchant connects an email or SMS tool — Klaviyo, Postscript, Mailchimp, Omnisend, Attentive, Sendlane, Privy, or similar — sign-ups are sent there using credentials the merchant supplies. Once the data arrives, that tool's own privacy policy applies alongside the merchant's.
We disclose data otherwise only when the law requires it, or to protect the rights and safety of people using the service.
6. Where data is stored
Janus runs in the United States. If you are in the United Kingdom, the European Economic Area, or another region with data-transfer rules, using the app involves transferring data to the United States. We rely on the standard contractual protections our providers offer for those transfers.
7. How long we keep it
- Analytics events — 400 days. Long enough to compare this year to last, then deleted automatically by a daily job.
- Game outcome records — 90 days once claimed, 180 days maximum.
- Sign-ups and consent records are kept until the merchant deletes them, a deletion request is received, or the store's data is erased after uninstall.
8. Deletion and your rights
Janus implements Shopify's three mandatory privacy endpoints. They run automatically, without anyone at Janus touching them:
- Shopper data request — we return everything we hold about that person to the merchant, who passes it on.
- Shopper deletion — we delete that person's sign-up records and any discount codes issued to them.
- Store deletion — 48 hours after a store uninstalls Janus, Shopify asks us to erase that store's data, and we do.
Depending on where you live you may also have the right to access, correct, port, or object to the processing of your data. Shoppers should contact the store they signed up with, since the merchant holds those obligations. If you cannot reach them, write to us at hello@getjanus.co and we will help.
9. What happens when a merchant uninstalls
The access token is revoked immediately and the app stops collecting anything. Store data is erased when Shopify sends the store deletion request, which is 48 hours later.
10. Security
All traffic is encrypted in transit with TLS. Each store's data is isolated at the database level, so one merchant's queries cannot reach another's rows. API keys merchants connect are stored server-side and are never sent back to the browser in full. No system is perfectly secure, and we do not claim otherwise.
11. Children
Janus is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child's data has reached us through a popup, tell us and we will delete it.
12. Changes
If this policy changes in a way that matters, we will update the date at the top and notify merchants in the app or by email. Continuing to use Janus after a change means accepting it.
13. Contact
Janus Inc. — hello@getjanus.co
Shoppers: please contact the store you signed up with first. They hold your data and can act on it fastest.