Privacy Policy

Last updated 28 September 2026 · Version 2026-09-28

This policy explains how Douglas Anthony Silkstone, trading as Benson ("Benson", "we") handles personal data. Benson is a service for online stores; it plays two different roles, and this policy covers both.

Who is responsible#

  • We're the controller for this website (trybenson.com), for people who join the waitlist or preview their store here, and for the accounts of the businesses that use Benson.
  • We're a processor for storefront data: when a store uses Benson, the store decides what Benson measures on its site, and processes it under our Data Processing Agreement. If you shopped on a store that uses Benson, contact that store first; we'll help them answer you.

Contact: [email protected]. Address: Nademlejnská 600/1, 198 00 Prague – Hloubětín, Czech Republic.

What we collect#

From visitors to this website#

  • We measure this site with Benson itself using a session-only id. If you allow optional analytics, PostHog and Google Analytics also measure page views and product actions using cookies and browser storage. You can change this choice through Analytics preferences. See the Cookie Policy.
  • If you join the waitlist: your email address, the store address you enter, campaign (UTM) tags from the link you arrived by, and whether you asked for product news. Sign-ups made before 28 September 2026 may also hold the result of our scan of that store's homepage.
  • If you preview your store: the store address you enter. We fetch that store's homepage and icon to show them to you, keep the result for a day so we don't fetch it again, and don't link it to you.

From businesses that use Benson#

  • Account details: name, email address, password (stored as a salted hash), two-factor settings, the workspaces you belong to, and your email choices (product news, and set-up tips).
  • Billing details: handled by Stripe or Shopify. We keep the plan, status and invoice references, not card numbers.
  • Support emails and messages you send us.
  • With optional analytics consent: account and workspace identifiers, product actions, and subscription events. We do not send email addresses, form contents, report contents, or shared-report tokens to PostHog or Google Analytics.

From storefronts (as a processor)#

  • Events about shopping sessions: pages viewed, which extensions were detected (and, where the store turns it on, which were installed), what Benson hid, widget views and codes applied, and a random session id. Storefront events contain no names, email addresses, postal addresses or phone numbers.
  • IP addresses are used transiently, to estimate the country and to rate-limit traffic, and are never stored. No identifier is derived from an IP address.
  • Order data from Shopify or the store's platform: order totals, discount codes used and the Benson session id, without customer contact details.
  • Email addresses shoppers give the store's widget to unlock a code, when the store turns that on.

Installed-extension check#

Stores can let Benson check whether a shopper has one of a short list of coupon and cashback browser extensions installed, even before the extension shows anything on the page.

  • What it does. Each listed extension makes a few of its own files public to every website. Benson asks the browser for one such file per extension. If the file loads, that extension is installed. Nothing is read from the file.
  • Which extensions. Only coupon, cashback and shopping-assistant extensions. The current list:
  • Avast SafePrice
  • Capital One Shopping
  • Cently
  • Coupert
  • CouponBirds
  • CouponCabin
  • Karma
  • Klarna
  • PayPal Honey
  • Rakuten
  • RetailMeNot
  • SwagButton
  • TopCashback
  • Where it runs. Only in desktop Chrome and Microsoft Edge, at most once per visit, and never on checkout pages. Other browsers don't allow the check.
  • Legal basis. The check reads information from your device, so in the EEA, the UK and Switzerland it runs only after you consent (the same analytics consent the store's banner asks for). Elsewhere, where the store shows no consent banner, it runs only when we can tell you're outside those regions; if we can't tell, it doesn't run. Each store chooses whether the check is off, automatic, or only with consent.
  • What's kept. Only the names of matched extensions, as part of the visit's events. Extensions that aren't installed aren't recorded, and the results are never combined into an identifier for you or your device.
  • How long. The same as other storefront events (see How long we keep it).

Why we use it#

PurposeDataLegal basis
Providing the service to businessesAccount, billing, storefront dataContract; for storefront data, the store's instructions
Sending waitlist emailsEmail, store addressYour request (steps before a contract)
Tips to help you set up and get value from BensonEmail (Loops)Legitimate interests; opt out at sign-up, in settings or in any email
Product news, if you tick the boxEmail (Loops)Consent, which you can withdraw any time in settings or in any email
Security, abuse prevention and rate limitsRequest metadata, transient IPLegitimate interests
Optional website and product analyticsPage views, product actions, account and workspace identifiersConsent
Improving BensonAggregated, de-identified statisticsLegitimate interests
Tax, accounting and legal obligationsBilling recordsLegal obligation

We don't sell personal data, and we don't use storefront data for advertising.

How long we keep it#

These periods come straight from the retention settings our deletion jobs use, so this table and the system can't drift apart.

DataKept for
Raw storefront events and session summaries90 days
Hourly analytics summaries35 days
Daily analytics summaries25 months
Order records and order summaries25 months
Discount code summaries25 months
Attribution records25 months
Edge traffic summaries25 months
Experiment assignments180 days after the experiment ends
Email delivery log90 days
Workspace audit log2 years
Staff access log2 years
Workspace deletion records2 years
Shopify privacy requests2 years
Waitlist sign-ups (leads)24 months, unless you create an account
Widget email subscribers after deletion30 days
Store scans from setup90 days
Data export files24 hours
Report export files7 days

Account data is kept while your account is active and deleted when a workspace is deleted, apart from records we must keep by law.

Who we share it with#

We use these subprocessors to run Benson:

SubprocessorPurposeDataLocation
Railway CorporationApplication hosting, databases and queuesAll service data (accounts, workspace settings, storefront events, orders)EU (Netherlands data centre); US company
Cloudflare, Inc.DNS, content delivery of the storefront script, file storageRequest metadata (IP address transiently), the public script, exportsGlobal edge network; US company
Resend (Plus Five Five, Inc.)Transactional and notification emailRecipient email address, email contentUS
Loops, Inc.Lifecycle and product email (set-up tips, product news)Account holder name and email, workspace name and role, plan and set-up progressUS (standard contractual clauses)
Stripe Payments Europe, Ltd.Workspaces that pay by cardCard payments and invoicingBilling contact, payment details (held by Stripe), invoicesEU and US
Shopify International LimitedStores that install the Shopify appApp platform and billing for Shopify-installed storesShop domain, app subscription, order and discount data you let the app readIreland; global

For optional analytics on our own website and app, we use PostHog (EU project) and Google Analytics. These providers receive the analytics data described above only when you allow optional analytics.

We may also disclose data to professional advisers, to a buyer if the business is sold (under the same protections), or where the law requires.

International transfers#

Our main hosting is in the EU. Some subprocessors are based in, or can access data from, the United States. Where data leaves the UK or EEA we rely on adequacy decisions (including the UK–US data bridge and the EU–US Data Privacy Framework where the provider is certified) or on standard contractual clauses with the UK addendum.

Your rights#

Depending on where you live, you can ask to access, correct, delete or export your personal data, object to or restrict how we use it, and withdraw consent. Email [email protected]. We'll reply within one month. If you're unhappy with our answer, you can complain to the UK Information Commissioner's Office (ico.org.uk) or your local data protection authority.

Security#

Sensitive fields are encrypted at rest, all traffic is encrypted in transit, access is limited to the people who need it and logged, and we test our controls regularly. See the security section of our Terms.

Changes#

We'll post updates here with a new version date, and tell account holders about material changes.

Find out what's leaking. 14 days of Own, no card.