Shopify stores
Production Shopify themes use Shopify Customer Privacy as the canonical processing authority. Compatible consent apps must synchronize shopper choices to Shopify before 100 Rocks mounts behavior measurement.
Shoppers who decline analytics still contribute audience-tier events where permitted; behavior events require explicit analytics consent.
Web Pixel checkout events are gated by the pixel's Customer privacy settings in Shopify admin (Required + Analytics purpose).
Custom sites
The bundled 100 Rocks consent banner collects opt-in before behavior measurement. Limited audience measurement may run before consent where lawful; behavior data remains consent-gated. Analytics, Preferences, and Marketing toggles align with Shopify purpose categories for future parity.
Legal documents
Storefront visitor processing is covered by our Data Processing Addendum, accepted when an authorized merchant creates or connects a store.
See Privacy policy and Terms of service for controller/processor roles and retention.
Storefront privacy notice — copy and adapt
Add the following section under “Analytics” in your storefront privacy policy. Review it for your jurisdictions and enabled features before publishing.
Analytics. We use 100 Rocks (Karen Charykov EI, France) as our analytics provider. 100 Rocks processes page views, navigation and commerce events, device and browser information, approximate location, and pseudonymous identifiers on our behalf to measure and improve our storefront. Where permitted by law, limited audience measurement may operate before consent. Behavior data remains consent-gated: with your analytics consent, 100 Rocks also measures scrolling, clicks, pointer movement, and hesitation to produce aggregated heatmaps. Raw events are retained for 90 days, sessions and session metrics for 12 months, daily aggregate rollups and page-layout references for 24 months, and consent records for 25 months. Generated heatmap versions follow the merchant's plan quota rather than a 24-month retention period.
Cookie and browser storage disclosure
Also add these entries to your cookie or browser-storage table when the relevant storage is enabled.
| Name | Type and purpose | Duration |
|---|---|---|
| adaptive.analytics.session_key.{counter ID} | Session storage — pseudonymous identifier used to associate events within one browser tab | Until the tab is closed |
| adaptive_visitor_id | Local storage — pseudonymous returning-visitor identifier created after analytics consent | Up to 13 months |
| adaptive_analytics_consent | Local storage — remembers the overall custom-site analytics consent decision | Until the visitor changes or clears the decision |
| adaptive_analytics_purpose_consent | Local storage — remembers custom-site Analytics, Preferences, and Marketing purpose choices | Until the visitor changes or clears the choices |
| rocks_session_key | First-party Shopify cookie — associates storefront activity with consented Web Pixel commerce events for one visit | Up to 30 minutes |