What is collected
Shopper IP addresses are processed transiently at the edge to resolve country, region, and city and to apply rate limiting. The address itself is not stored with events or in application logs.
Retention while your store is active
Retention windows are applied per store and are not extended by request. If your compliance program needs a shorter window for shopper events, contact support@uselayers.com.
After you uninstall
Uninstalling the Layers app starts a 30-day grace period. During this period your data is retained but sync activity stops, so you can reinstall and pick up where you left off. The process is documented in full under App uninstallation and data retention. At the end of the grace period:- Your store record and all associated data are permanently deleted from Layers’ primary databases. This includes the catalog mirror, configuration, embeddings, aggregated analytics, and any shopper events or request logs that have not already expired.
- Per-store analytics storage is decommissioned.
- Access tokens issued to your storefront and dashboard users stop working.
Backups
Layers takes automated backups of its primary databases for disaster recovery. Backups are encrypted at rest and are only restored to recover the service after an infrastructure failure. They are not used to serve traffic or to restore an individual store’s data after the grace period has ended.- Backup rotation window: 30 days. A backup taken on the day your data is deleted from primary storage is itself deleted no later than 30 days afterwards.
- Combined timeline: your data is fully gone from Layers systems no later than 60 days after uninstall (30-day grace period plus the 30-day backup rotation window).
- Shopper events and request logs live in per-store analytics storage that is decommissioned at the end of the grace period and is not included in long-lived backups.
Data subject requests
Layers processes Shopify’s mandatory privacy webhooks automatically:- Customer data request: when a shopper asks you for their data through Shopify, Layers compiles the search queries tied to that customer ID and a count of matching records in each data store, and makes them available to you in the dashboard.
- Customer redact: when Shopify sends a redaction request for a customer, Layers removes or anonymizes the customer ID in analytics tables, request logs, search feedback, derived affinities, and quiz responses linked to the customer’s sessions, and anonymizes the customer’s earlier privacy request records. Copies of the customer ID that may exist in application logs or observability traces are not individually redacted. They expire according to the retention of the vendors on the sub-processors page.
- Shop redact: when Shopify sends a shop redaction request after uninstall, Layers queues the store for deletion on the same schedule as the grace period above.
Next steps
- AI & your data for how model providers fit into this picture.
- Infrastructure & Sub-processors for where data is hosted.
- Incident response overview for how Layers handles a security or availability incident.