Privacy & security

What we collect

Only what you send — and exactly what the website tag and Shopify pixel send.

Before you connect anything, it’s fair to ask what Crunch will actually see. The short answer: only what you send it. Here is what each way of connecting sends, so you can check it against your own privacy policy and tell your customers with confidence.

Website tag

The website tag is a small piece of code on your site that sends events — things visitors do, like viewing a page or submitting a form — to Crunch. It sends only the events your site pushes with event: 'bb_event', along with the page, the referrer (the page the visitor came from), campaign parameters and any fields you add. Nothing else on the page is read.

Tip: user IDs can be hashed in the browser first, so the raw ID never leaves the visitor’s browser.

Shopify pixel

The Shopify pixel sends the store’s standard events — views, carts and checkouts — with an anonymous Shopify client ID. It asks Shopify for no customer identity.

Uploads and linked tables

The files you upload and the tables you link are read only to answer your questions.

On-prem sync

Only the columns your rules let out, in the form the rules set. See Keep sensitive data inside your network for how those rules work.

Good to know

Events are accepted only from domains you have verified. Verifying a domain means proving the website address is really yours, so events claiming to come from anywhere else are not accepted. See Domains.

Still stuck? support@bumbleb.co

🐝 BumbleB Crunch™ — the AI analyst that investigates Sign up free