Privacy policy for Shopify Theme Detector & Apps — Stackpeek
Shopify Theme Detector & Apps — Stackpeek by Anton Kopylov
Stackpeek is a Shopify theme and app detector. It looks at the store page you
are already viewing and reports the theme, the apps, and the tracking pixels it
can identify. This page describes exactly what that involves.
When you open the side panel on a store, Stackpeek reads the public markup of
the page in your active tab — the same HTML, script URLs and JavaScript globals
any visitor's browser receives — and the store's public product endpoints when
you ask for a catalogue export. It reads nothing on any other tab.
Detection signals are sent to our server so that fingerprints can be matched against the catalogue and improved over time: the store's URL, without query strings, the script URLs present on the page, the JavaScript globals it defines, and the theme metadata the storefront publishes about itself.
Your browsing history is not collected. Deciding whether a page is a Shopify store means reading its script URLs and JavaScript globals and sending them to our API to match. If it is not a Shopify store, nothing about the page is stored: no URL, no domain, no observation of any kind. The anonymous install counter described below still ticks, because it counts detections and knows nothing about what was detected. Detections are not linked to you: the observation records our server keeps carry the store, not the install that reported it, so a list of the stores you have looked at is not something we hold.
If you ask to be told when the paid tier ships, we store the email address
you typed and nothing else — no name, no company, no source page. It is used
for exactly one message and then it has done its job. Ask us at any time and
we will delete it.
The anonymous install ID is not browser-only either. Each detection updates
a matching row on our server — the ID, a count of detections, and the
timestamps of the first and the most recent one. It is a counter, not a
profile: no store list is attached to it, because detection signals no longer
carry the install ID that reported them. What happens to that row over time
is covered under Seeing or deleting what we hold, below.
Product exports are assembled in your browser from the store's own public
catalogue endpoints and written straight to a file on your machine. Product data
is not sent to our server and we keep no copy of it.
Four permissions in Chrome and three in Firefox — the difference is
that Firefox needs no permission at all to draw a sidebar.
activeTab— lets the extension read the page you are looking
at, and only when you click the icon. It lapses when you move to another tab.scripting— runs the detection routine inside that page so it
can see the storefront's own JavaScript globals, which are invisible from
outside it.sidePanel(Chrome only) — draws the results panel where
Stackpeek reports its findings. The Firefox build draws the same panel throughsidebar_action, which requires no permission, so it does not appear
in that build's manifest.storage— remembers one anonymous install ID on your machine,
used to count unique detections without tracking you. The same ID is also
held server-side as a counter, described above.
On Firefox the install ID is an optional grant
(
technicalAndInteraction), which Firefox asks you about at install andwhich you can withdraw at any time. Decline it and no identifier is written to your
machine: each session sends an identifier generated in memory and discarded when
the panel closes, which the detector needs in order to rate-limit itself but which
cannot be joined to any other session. The page content the extension reads is
declared separately and is required, because reading the page is what the extension
does.
The extension also requests network access to Stackpeek's own servers
(
https://api.stackpeek.app) so that detection signals can be sentand fingerprints matched against the catalogue.
There is no
tabs permission and no historypermission, which is why a list of the sites you visit is not something
Stackpeek could assemble even if it wanted to.
Raw detection signals are deleted after
— long enough to correct
and re-check the fingerprint catalogue, short enough that the log does not
become an archive. Aggregate counts — how many stores run a given app —
outlive the individual observations they were derived from, because they no
longer describe any single store.
The
detection signals described above are stored on a server we rent from
DigitalOcean in New York, in the United States. DigitalOcean is the only
company that processes those signals on our behalf. There is no advertising
network and no data broker anywhere in the path, and nothing here is sold.
Separately from the extension, these pages count visits with Cloudflare
Web Analytics, so Cloudflare processes that count for us. It is cookieless:
it stores nothing on your machine and builds no profile that could follow
you to another site. What it records is which page loaded, the page that
linked to it, your browser and the country the request came from, and how
long the page took to render. It runs on this website only — it is not in
the extension, it never sees a store you inspect, and it is not joined to
the detection signals above.
Then the signals leave the European Economic Area, because the server is
in New York. That transfer relies on the protections in DigitalOcean's
published data processing agreement. Andorra, where we are registered,
holds an adequacy decision from the European Commission of its own, so the
leg that reaches us needs no separate mechanism. That decision says nothing
about the American hosting, which is why both facts are here instead of
only the flattering one.
Write to hello@stackpeek.app (mailto:hello@stackpeek.app) and
we will tell you what is there and delete it. Two honest caveats about what
that can mean. If you signed up to be notified, your email address is
deletable and we will delete it. Detection signals are not deletable
on request in any meaningful sense — not because we refuse, but
because they are not linked to you: they record that a store was seen
running an app, with no identifier for whoever saw it. There is nothing
there to look up by person. Uninstalling the extension clears the
anonymous install ID from your browser immediately; the matching counter
on our server is deleted automatically after
without activity.
Stackpeek is a tool for people who run or research online shops. It is not
directed at children and we do not knowingly collect anything from them.
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
In practice that means what the rest of this page already says: the data
is used to run and improve the one thing this extension does, it is never
sold, and it is never used to target advertising. People on our side do read
detection signals — that is how the fingerprint catalogue gets built and
corrected — but only as ordinary catalogue work, never to find out anything
about the person who triggered a detection. The store policy permits reading
web activity only for a user-facing feature described prominently — that
feature is the detection panel, and describing it prominently is what this
page is for.
Write to hello@stackpeek.app (mailto:hello@stackpeek.app).
This page describes how Stackpeek behaves today, in ordinary language
rather than the language of a contract. When the behaviour changes, this
page changes with it.
Last updated August 18, 2026.