Friction Privacy Policy

Effective date: August 11, 2026

This Privacy Policy explains how Friction collects, uses, stores, shares, and deletes information when merchants install or use the Friction Shopify app, when shoppers visit a Shopify storefront where Friction is enabled, or when someone contacts us through our website, app, or support channels.

For privacy questions, requests, or legal notices, contact us at: rohith@usefriction.com

1. Who We Are

Friction is a Shopify app that helps merchants preserve and restore anonymous shopping carts when browser storage is unreliable, expired, unavailable, or cleared.

Friction is designed to support functional cart continuity. It is not designed for advertising retargeting, email capture, marketing attribution, cross-store advertising, or the sale of shopper data.

In this policy, “Friction,” “we,” “us,” and “our” refer to the developer and operator of the Friction Shopify app and related services.

2. Our Role

When Friction processes shopper and cart information on behalf of a Shopify merchant, Friction generally acts as a service provider or processor for that merchant. The merchant is usually the business, controller, or party responsible for its relationship with shoppers and for determining the lawful basis for using Friction on its storefront.

When Friction processes merchant account information, billing and usage records, support requests, security logs, or app operations data, Friction may act as an independent business or controller for those limited purposes.

Shoppers who have questions about a specific store’s use of Friction should generally contact the merchant whose storefront they visited. Merchants may contact Friction at rohith@usefriction.com.

3. What Friction Does

Friction helps Shopify merchants keep anonymous cart intent intact.

When a shopper adds products to a cart but does not log in or check out, the cart can sometimes disappear because of browser storage limits, privacy controls, cookie expiration, Safari ITP behavior, local storage clearing, or similar conditions. Friction mirrors anonymous cart state in server-side storage and may restore the prior cart when the shopper returns, but only when the app determines that restoration is appropriate.

Friction is designed to restore a cart only when:

  • The shopper can be matched to a prior anonymous cart with sufficient confidence.
  • The current Shopify cart is empty.
  • The stored cart is still within the configured restore window.
  • The merchant’s Friction settings and billing status allow the runtime to operate.
  • The session is not treated as private/incognito or otherwise unsafe for restoration.

Friction does not change checkout, does not process payment details, does not send abandoned-cart emails, and does not show discounts or marketing popups.

4. Information We Collect From Merchants

When a merchant installs, configures, or uses Friction, we may collect and process:

  • Shopify shop domain and shop identifiers.
  • Shopify app installation identifiers.
  • OAuth/session records required to authenticate the app.
  • App configuration, feature settings, billing settings, runtime status, and theme app extension setup state.
  • Shopify app proxy configuration and app lifecycle records.
  • Shopify subscription, plan, billing period, usage, and App Events metering information.
  • Non-unique visitor usage counts used for plan limits, billing controls, and usage reporting.
  • Support requests, contact details, messages, and related communication history.
  • Enterprise inquiry details submitted by a merchant or prospective merchant.
  • Technical logs, errors, diagnostic information, audit records, and security records.
  • Product, variant, cart, and storefront information needed to operate cart restoration through Shopify APIs.

Friction does not intentionally collect merchant bank account details or payment card numbers. Shopify handles Shopify app billing and related payment flows.

5. Information We Collect From Shoppers

When a shopper visits a Shopify storefront where Friction is enabled, we may collect and process information needed to provide anonymous cart persistence and restoration, including:

  • Anonymous cart state, such as product or variant IDs, quantities, cart item keys, item titles, item images, prices, currency, cart totals, and cart token or cart state returned by Shopify cart APIs.
  • Pseudonymous visitor identifiers used to associate a returning browser or session with a prior anonymous cart.
  • Cookie and local storage identifiers used for functional cart continuity, including Friction visitor identifiers.
  • Session and visit-window identifiers used to avoid double-counting usage during a short period.
  • Browser storage reliability signals, such as whether cookies or local storage appear available or reliable.
  • Browser/runtime signals used to make restoration safer, such as browser family, locale, storefront path, referrer host, timing data, restore state, and restore result.
  • Private/incognito-mode indicators where available, used to suppress restoration rather than to identify a shopper.
  • FingerprintJS request IDs, hashed FingerprintJS visitor identifiers, confidence or diagnostic signals, and related device/browser intelligence when device recognition is used for supported restoration flows.
  • Non-unique visitor usage counters used for product analytics, billing controls, and merchant dashboards.
  • Hashed Shopify customer identifiers when a shopper logs in and the storefront flow provides an association needed for privacy redaction, cart merge support, or operational integrity.

Friction does not intentionally collect shopper payment card numbers, full payment details, passwords, shipping addresses, email addresses, phone numbers, or marketing consent preferences as part of its cart-restoration runtime.

Standard infrastructure logs may include request metadata such as IP address, request URL, user agent, timestamp, response status, and similar security or diagnostic information.

6. Cookies, Local Storage, And Similar Technologies

Friction uses first-party cookies, local storage, session storage, and similar technologies to support functional cart continuity.

These technologies may be used to:

  • Remember an anonymous visitor/cart identifier.
  • Maintain a short-lived session identifier.
  • Prevent duplicate usage counting within a visit window.
  • Coordinate an in-progress restore attempt.
  • Remember whether a restore was already attempted.
  • Queue runtime events when the browser is temporarily offline.
  • Improve reliability when Shopify cart changes happen before network requests complete.

Examples of Friction browser storage keys may include fr_aid, fr_sid, fr_visit_window_v1, fr_restore_state_v2, friction_outbox_v1, and related operational keys. The exact keys may change as the app evolves.

These identifiers are used for cart functionality and app operations. Friction does not use them to build advertising audiences or retarget shoppers.

7. Device Recognition And FingerprintJS

Friction may use FingerprintJS Pro to help recognize a returning browser or device when ordinary browser storage is unreliable, unavailable, expired, or cleared.

FingerprintJS may process browser and device signals such as browser type, device characteristics, IP address, approximate location, request identifiers, visitor identifiers, and device intelligence signals. Depending on configuration and availability, this may include signals related to private/incognito mode, bot behavior, VPN/proxy/relay indicators, tampering, high activity, or similar fraud and reliability signals.

Friction uses FingerprintJS for functional cart continuity, restore safety, abuse prevention, diagnostics, and billing-related usage controls. Friction does not use FingerprintJS to create advertising audiences, run behavioral advertising, retarget shoppers, sell shopper data, or perform cross-store marketing attribution.

Where possible, Friction stores FingerprintJS visitor identifiers in a shop-scoped hashed form before using them as durable Friction visitor keys. This helps reduce direct identifiability in Friction’s own systems. FingerprintJS request IDs and related diagnostic signals may still be processed where needed to operate, debug, or measure the device-recognition flow.

FingerprintJS may be loaded through a first-party Shopify app proxy path to improve reliability. If that first-party proxy path is unavailable, Friction may fall back to FingerprintJS’s direct endpoint.

More information about FingerprintJS privacy and compliance is available at: https://fingerprint.com/legal/

8. Consent And Merchant Responsibilities

Merchants are responsible for ensuring that their storefront privacy notices, cookie banners, consent tools, and legal bases cover their use of Friction where required by applicable law.

Friction’s core purpose is functional cart persistence. In some regions, ordinary cart cookies and storage used to remember basket contents may be treated as necessary for a shopper-requested ecommerce service. However, device recognition and browser fingerprinting may require separate notice, consent, or opt-out rights depending on the shopper’s location and the merchant’s compliance approach.

Merchants should not classify Friction as advertising or retargeting technology unless they independently use Friction data for those purposes, which Friction itself is not designed to do.

Where applicable, merchants should disclose that Friction may use:

  • Functional cookies and local storage.
  • Anonymous cart identifiers.
  • Server-side cart mirroring.
  • Device recognition technology for cart continuity when browser storage is unreliable.
  • Service providers such as Shopify, Google Cloud/Firebase, and FingerprintJS.

If a merchant uses a consent management platform or Shopify’s customer privacy features, the merchant is responsible for configuring those tools appropriately. In regions that require prior consent for device recognition or similar technologies, merchants should ensure Friction is used only after the required consent is obtained, unless the merchant has determined that a legal exemption applies.

9. How We Use Information

We use the information described in this policy to:

  • Provide the Friction Shopify app.
  • Authenticate merchants and operate the embedded Shopify admin experience.
  • Mirror anonymous cart state in server-side storage.
  • Restore eligible anonymous carts when a shopper returns.
  • Suppress restoration when it may be unsafe, inaccurate, or inappropriate.
  • Avoid restoring carts in private/incognito sessions where the app detects that restoration should not occur.
  • Sync cart changes from the storefront to Friction’s backend.
  • Maintain merchant configuration, feature controls, runtime status, and setup state.
  • Count non-unique visitor usage for plan limits, overage controls, merchant analytics, and Shopify App Events usage reporting.
  • Debug runtime behavior and storefront compatibility.
  • Detect, prevent, investigate, and respond to abuse, security issues, fraud, errors, outages, and reliability problems.
  • Process support requests and enterprise inquiries.
  • Comply with Shopify app requirements, mandatory privacy webhooks, contractual obligations, and applicable law.
  • Enforce our terms and protect our rights, users, merchants, shoppers, and services.

We may also use aggregated or de-identified information for analytics, product improvement, forecasting, debugging, and business operations. Aggregated or de-identified information does not identify a specific shopper.

10. What We Do Not Do

Friction does not:

  • Sell shopper personal information.
  • Share shopper personal information for cross-context behavioral advertising.
  • Use shopper cart data for advertising retargeting.
  • Build marketing audiences from Friction runtime data.
  • Send abandoned-cart emails, SMS messages, or other shopper marketing messages.
  • Collect shopper payment card numbers.
  • Intentionally collect shopper passwords.
  • Intentionally collect precise geolocation.
  • Use Friction runtime data to profile shoppers across unrelated merchants for advertising purposes.

11. How We Share Information

We share information only as needed to provide, secure, support, bill, and operate Friction.

We may share information with:

  • Shopify: for app authentication, Shopify app proxy requests, cart APIs, product or variant APIs where applicable, app billing, Shopify App Pricing, App Events, mandatory privacy webhooks, and app platform operations.
  • Google Cloud and Firebase: for hosting, Firestore database storage, Firebase Functions, Cloud Run, Cloud Tasks, logging, secret management, infrastructure security, and related cloud services.
  • FingerprintJS: for device recognition, browser identification, request IDs, visitor IDs, and related device/browser intelligence when Friction invokes FingerprintJS.
  • Communication and support providers: such as email, notification, support, or messaging tools used to respond to merchant support requests or enterprise inquiries.
  • Professional and legal advisors: where needed for accounting, tax, legal, compliance, security, or business purposes.
  • Authorities or third parties where legally required: when necessary to comply with law, respond to lawful requests, enforce agreements, protect rights, prevent harm, or investigate security issues.
  • Business transfer recipients: if Friction is involved in a merger, acquisition, financing, reorganization, sale of assets, or similar transaction, information may be transferred as part of that transaction subject to appropriate protections.

We require service providers to process information only for authorized purposes and subject to appropriate confidentiality, security, and data-processing obligations.

12. Shopify App Usage Reporting

Friction may report merchant-level usage to Shopify for billing and App Events.

This usage reporting is based on non-unique visitor units, billing periods, plan limits, and overage settings. Friction does not need to send shopper cart contents to Shopify for App Events usage billing.

Shopify app billing and subscription management are handled through Shopify.

13. Retention

Friction keeps information only for as long as reasonably needed for the purposes described in this policy, unless a longer period is required or permitted by law.

Current retention practices include:

  • Raw operational shopper/cart records are generally retained for up to 365 days.
  • Visitor records, cart records, raw restore/event records, visit-window records, FingerprintJS call records, fingerprint transport diagnostics, identity alias records, and billing-period usage records are generally retained for up to 365 days.
  • Short-lived restore coordination records are retained for a much shorter period, currently about 20 minutes.
  • Merchant installation, configuration, billing, support, audit, and account records may be retained while the app remains installed and for as long as reasonably needed for billing, accounting, tax, legal, compliance, security, support, or dispute-resolution purposes.
  • Aggregated or de-identified metrics may be retained for longer because they do not identify a specific shopper.

When a merchant uninstalls Friction, we disable runtime behavior for that shop and schedule deletion of shop data after the applicable uninstall grace period, unless Shopify sends a shop/redact webhook or another verified request requires earlier deletion.

14. Shopify Privacy Webhooks And Deletion

Friction is designed to support Shopify’s mandatory privacy webhooks:

  • customers/data_request
  • customers/redact
  • shop/redact

When Shopify sends a customer data request webhook, Friction records and responds to the request as required by Shopify’s app requirements.

When Shopify sends a customer redaction webhook, Friction deletes or redacts matching customer-associated data where it can be matched to Friction visitor or cart records.

When Shopify sends a shop redaction webhook, Friction deletes shop-level app data from Friction systems, subject to legal, security, accounting, or compliance retention obligations where applicable.

Because Friction primarily processes anonymous or pseudonymous cart identifiers, not directly identifying shopper contact information, some requests may not be matchable unless Shopify or the merchant provides an identifier that can be connected to Friction’s records.

15. Privacy Rights

Depending on location, merchants and shoppers may have rights to:

  • Request access to personal information.
  • Request deletion of personal information.
  • Request correction of inaccurate information.
  • Object to or restrict certain processing.
  • Withdraw consent where processing is based on consent.
  • Opt out of sale, sharing, targeted advertising, or profiling where applicable.
  • Request portability of certain information.
  • Appeal a decision about a privacy request where applicable.

Shoppers should generally submit requests to the merchant whose storefront they visited, because the merchant controls the storefront relationship and may be better able to identify the shopper.

Merchants may contact Friction at rohith@usefriction.com for help processing requests related to Friction data.

We may need to verify a request before acting on it. We may also decline or limit requests where permitted by law, such as when we cannot verify identity, cannot reasonably match the request to Friction records, must retain information for legal or security reasons, or act only as a processor/service provider for a merchant.

16. Regional Privacy Information

European Economic Area, United Kingdom, and Switzerland: Where GDPR, UK GDPR, or similar laws apply, the merchant generally determines the lawful basis for processing shopper data through Friction. Depending on the context, relevant lawful bases may include performance of a contract, legitimate interests, consent, or compliance with legal obligations. Device recognition, cookies, local storage, and similar technologies may require consent unless an exemption applies, such as where the technology is strictly necessary to provide a service requested by the shopper.

United States: Friction does not sell shopper personal information or share it for cross-context behavioral advertising. Friction uses shopper-related data to provide functional cart persistence, app operations, security, diagnostics, support, and billing-related usage controls.

California and similar US state laws: Friction acts primarily as a service provider or processor for shopper data processed on behalf of merchants. Friction does not use shopper data collected through the app for targeted advertising or sale/share as those terms are commonly used in US state privacy laws.

Canada, Brazil, Quebec, and other consent-sensitive regions: Merchants should provide clear notice and obtain consent where required before enabling technologies such as device recognition, unless the merchant determines that a legal exemption or other lawful basis applies.

17. Security

Friction uses technical, administrative, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure.

These safeguards may include:

  • Encrypted network transport.
  • Cloud provider security controls.
  • Firestore security rules and server-side access controls.
  • Environment-separated infrastructure for development, preview, and production.
  • Secret management for sensitive credentials.
  • Restricted Shopify app scopes where practical.
  • Access controls for operational systems.
  • Logging and monitoring for reliability and security.
  • Data minimization and retention limits.

No method of transmission or storage is perfectly secure. We cannot guarantee absolute security, but we work to protect Friction systems and data.

18. International Transfers

Friction and its service providers may process and store information in countries other than the country where a merchant or shopper is located, including the United States.

Where required, Friction and its service providers rely on appropriate safeguards for international transfers, such as data processing agreements, standard contractual clauses, service provider terms, or other lawful transfer mechanisms.

19. Subprocessors And Service Providers

Friction may use subprocessors and service providers to operate the app. Current or expected providers include:

  • Shopify, for the Shopify platform, app authentication, app proxy, billing, cart APIs, App Events, and privacy webhooks.
  • Google Cloud and Firebase, for hosting, database, serverless functions, tasks, logs, and infrastructure.
  • FingerprintJS, for device recognition and browser/device intelligence used in cart continuity flows.
  • Email, notification, and support providers used to respond to merchant support requests or enterprise inquiries.

We may update our providers as the service evolves. Merchants can contact rohith@usefriction.com with questions about subprocessors or data processing terms.

20. Children’s Privacy

Friction is not directed to children. Friction operates on Shopify storefronts selected by merchants. We do not knowingly collect personal information from children through Friction. If you believe a child has provided personal information to Friction, contact us at rohith@usefriction.com.

21. Changes To This Policy

We may update this Privacy Policy from time to time as Friction, Shopify requirements, legal requirements, or our operations change.

When we make material changes, we will update the effective date and provide additional notice where required by law.

22. Contact Us

For privacy questions, requests, legal notices, data processing questions, or concerns about Friction’s use of data, contact:

Friction
Email: rohith@usefriction.com

Support