Privacy
What Stackpeek reads, and what it never does.
Stackpeek is a Shopify theme and app detector. It looks at the store page you are already viewing and reports the theme, the apps, and the tracking pixels it can identify. This page describes exactly what that involves.
What the extension reads
When you open the side panel on a store, Stackpeek reads the public markup of the page in your active tab — the same HTML, script URLs and JavaScript globals any visitor's browser receives — and the store's public product endpoints when you ask for a catalogue export. It reads nothing on any other tab.
What leaves your browser
Detection signals are sent to our server so that fingerprints can be matched against the catalogue and improved over time: the store's domain, the script URLs present on the page, the JavaScript globals it defines, and the theme metadata the storefront publishes about itself.
Your browsing history is not collected. Pages on non-Shopify sites are not read, not sent, and not recorded. Detections are not linked to you: the observation records our server keeps carry the store, not the install that reported it, so a list of the stores you have looked at is not something we hold.
What we store about a person
If you ask to be told when the paid tier ships, we store the email address you typed and nothing else — no name, no company, no source page. It is used for exactly one message and then it has done its job. Ask us at any time and we will delete it.
The anonymous install ID is not browser-only either. Each detection updates a matching row on our server — the ID, a count of detections, and the timestamps of the first and the most recent one. It is a counter, not a profile: no store list is attached to it, because detection signals no longer carry the install ID that reported them. What happens to that row over time is covered under Seeing or deleting what we hold, below.
The CSV export
Product exports are assembled in your browser from the store's own public catalogue endpoints and written straight to a file on your machine. Product data is not sent to our server and we keep no copy of it.
The four permissions
activeTab— lets the extension read the page you are looking at, and only when you click the icon. It lapses when you move to another tab.scripting— runs the detection routine inside that page so it can see the storefront's own JavaScript globals, which are invisible from outside it.sidePanel— draws the results panel where Stackpeek reports its findings.storage— remembers one anonymous install ID on your machine, used to count unique detections without tracking you. The same ID is also held server-side as a counter, described above.
The extension also requests network access to Stackpeek's own servers
(https://api.stackpeek.app) so that detection signals can be sent
and fingerprints matched against the catalogue.
There is no tabs permission and no history
permission, which is why a list of the sites you visit is not something
Stackpeek could assemble even if it wanted to.
Retention
Raw detection signals are deleted after 90 days — long enough to correct and re-check the fingerprint catalogue, short enough that the log does not become an archive. Aggregate counts — how many stores run a given app — outlive the individual observations they were derived from, because they no longer describe any single store.
Who runs this, and where the data sits
Stackpeek is operated by Stackpeek L.C., registered in Andorra. The detection signals described above are stored on a server we rent from DigitalOcean in New York, in the United States. DigitalOcean is the only company that processes those signals on our behalf. There is no advertising network and no data broker anywhere in the path, and nothing here is sold.
This website
Separately from the extension, these pages count visits with Cloudflare Web Analytics, so Cloudflare processes that count for us. It is cookieless: it stores nothing on your machine and builds no profile that could follow you to another site. What it records is which page loaded, the page that linked to it, your browser and the country the request came from, and how long the page took to render. It runs on this website only — it is not in the extension, it never sees a store you inspect, and it is not joined to the detection signals above.
If you are in Europe
Then the signals leave the European Economic Area, because the server is in New York. That transfer relies on the protections in DigitalOcean's published data processing agreement. Andorra, where we are registered, holds an adequacy decision from the European Commission of its own, so the leg that reaches us needs no separate mechanism. That decision says nothing about the American hosting, which is why both facts are here instead of only the flattering one.
Seeing or deleting what we hold
Write to hello@stackpeek.app and we will tell you what is there and delete it. Two honest caveats about what that can mean. If you signed up to be notified, your email address is deletable and we will delete it. Detection signals are not deletable on request in any meaningful sense — not because we refuse, but because they are not linked to you: they record that a store was seen running an app, with no identifier for whoever saw it. There is nothing there to look up by person. Uninstalling the extension clears the anonymous install ID from your browser immediately; the matching counter on our server is deleted automatically after 90 days without activity.
Children
Stackpeek is a tool for people who run or research online shops. It is not directed at children and we do not knowingly collect anything from them.
Google APIs and the Chrome Web Store
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
In practice that means what the rest of this page already says: the data is used to run and improve the one thing this extension does, it is never sold, and it is never used to target advertising. People on our side do read detection signals — that is how the fingerprint catalogue gets built and corrected — but only as ordinary catalogue work, never to find out anything about the person who triggered a detection. The store policy permits reading web activity only for a user-facing feature described prominently — that feature is the detection panel, and describing it prominently is what this page is for.
Questions
Write to hello@stackpeek.app.
This page describes how Stackpeek behaves today, in ordinary language rather than the language of a contract. When the behaviour changes, this page changes with it.
Last updated August 07, 2026.