Privacy Policy
This policy explains how Douglas Anthony Silkstone, trading as Benson ("Benson", "we") handles personal data. Benson is a service for online stores; it plays two different roles, and this policy covers both.
Who is responsible#
- We're the controller for this website (trybenson.com), for people who join the waitlist or preview their store here, and for the accounts of the businesses that use Benson.
- We're a processor for storefront data: when a store uses Benson, the store decides what Benson measures on its site, and processes it under our Data Processing Agreement. If you shopped on a store that uses Benson, contact that store first; we'll help them answer you.
Contact: [email protected]. Address: Nademlejnská 600/1, 198 00 Prague – Hloubětín, Czech Republic.
What we collect#
From visitors to this website#
- We measure this site with Benson itself using a session-only id. If you allow optional analytics, PostHog and Google Analytics also measure page views and product actions using cookies and browser storage. You can change this choice through Analytics preferences. See the Cookie Policy.
- If you join the waitlist: your email address, the store address you enter, campaign (UTM) tags from the link you arrived by, and whether you asked for product news. Sign-ups made before 28 September 2026 may also hold the result of our scan of that store's homepage.
- If you preview your store: the store address you enter. We fetch that store's homepage and icon to show them to you, keep the result for a day so we don't fetch it again, and don't link it to you.
From businesses that use Benson#
- Account details: name, email address, password (stored as a salted hash), two-factor settings, the workspaces you belong to, and your email choices (product news, and set-up tips).
- Billing details: handled by Stripe or Shopify. We keep the plan, status and invoice references, not card numbers.
- Support emails and messages you send us.
- With optional analytics consent: account and workspace identifiers, product actions, and subscription events. We do not send email addresses, form contents, report contents, or shared-report tokens to PostHog or Google Analytics.
From storefronts (as a processor)#
- Events about shopping sessions: pages viewed, which extensions were detected (and, where the store turns it on, which were installed), what Benson hid, widget views and codes applied, and a random session id. Storefront events contain no names, email addresses, postal addresses or phone numbers.
- IP addresses are used transiently, to estimate the country and to rate-limit traffic, and are never stored. No identifier is derived from an IP address.
- Order data from Shopify or the store's platform: order totals, discount codes used and the Benson session id, without customer contact details.
- Email addresses shoppers give the store's widget to unlock a code, when the store turns that on.
Installed-extension check#
Stores can let Benson check whether a shopper has one of a short list of coupon and cashback browser extensions installed, even before the extension shows anything on the page.
- What it does. Each listed extension makes a few of its own files public to every website. Benson asks the browser for one such file per extension. If the file loads, that extension is installed. Nothing is read from the file.
- Which extensions. Only coupon, cashback and shopping-assistant extensions. The current list:
- Avast SafePrice
- Capital One Shopping
- Cently
- Coupert
- CouponBirds
- CouponCabin
- Karma
- Klarna
- PayPal Honey
- Rakuten
- RetailMeNot
- SwagButton
- TopCashback
- Where it runs. Only in desktop Chrome and Microsoft Edge, at most once per visit, and never on checkout pages. Other browsers don't allow the check.
- Legal basis. The check reads information from your device, so in the EEA, the UK and Switzerland it runs only after you consent (the same analytics consent the store's banner asks for). Elsewhere, where the store shows no consent banner, it runs only when we can tell you're outside those regions; if we can't tell, it doesn't run. Each store chooses whether the check is off, automatic, or only with consent.
- What's kept. Only the names of matched extensions, as part of the visit's events. Extensions that aren't installed aren't recorded, and the results are never combined into an identifier for you or your device.
- How long. The same as other storefront events (see How long we keep it).
Why we use it#
| Purpose | Data | Legal basis |
|---|---|---|
| Providing the service to businesses | Account, billing, storefront data | Contract; for storefront data, the store's instructions |
| Sending waitlist emails | Email, store address | Your request (steps before a contract) |
| Tips to help you set up and get value from Benson | Email (Loops) | Legitimate interests; opt out at sign-up, in settings or in any email |
| Product news, if you tick the box | Email (Loops) | Consent, which you can withdraw any time in settings or in any email |
| Security, abuse prevention and rate limits | Request metadata, transient IP | Legitimate interests |
| Optional website and product analytics | Page views, product actions, account and workspace identifiers | Consent |
| Improving Benson | Aggregated, de-identified statistics | Legitimate interests |
| Tax, accounting and legal obligations | Billing records | Legal obligation |
We don't sell personal data, and we don't use storefront data for advertising.
How long we keep it#
These periods come straight from the retention settings our deletion jobs use, so this table and the system can't drift apart.
| Data | Kept for |
|---|---|
| Raw storefront events and session summaries | 90 days |
| Hourly analytics summaries | 35 days |
| Daily analytics summaries | 25 months |
| Order records and order summaries | 25 months |
| Discount code summaries | 25 months |
| Attribution records | 25 months |
| Edge traffic summaries | 25 months |
| Experiment assignments | 180 days after the experiment ends |
| Email delivery log | 90 days |
| Workspace audit log | 2 years |
| Staff access log | 2 years |
| Workspace deletion records | 2 years |
| Shopify privacy requests | 2 years |
| Waitlist sign-ups (leads) | 24 months, unless you create an account |
| Widget email subscribers after deletion | 30 days |
| Store scans from setup | 90 days |
| Data export files | 24 hours |
| Report export files | 7 days |
Account data is kept while your account is active and deleted when a workspace is deleted, apart from records we must keep by law.
#
We use these subprocessors to run Benson:
| Subprocessor | Purpose | Data | Location |
|---|---|---|---|
| Railway Corporation | Application hosting, databases and queues | All service data (accounts, workspace settings, storefront events, orders) | EU (Netherlands data centre); US company |
| Cloudflare, Inc. | DNS, content delivery of the storefront script, file storage | Request metadata (IP address transiently), the public script, exports | Global edge network; US company |
| Resend (Plus Five Five, Inc.) | Transactional and notification email | Recipient email address, email content | US |
| Loops, Inc. | Lifecycle and product email (set-up tips, product news) | Account holder name and email, workspace name and role, plan and set-up progress | US (standard contractual clauses) |
| Stripe Payments Europe, Ltd.Workspaces that pay by card | Card payments and invoicing | Billing contact, payment details (held by Stripe), invoices | EU and US |
| Shopify International LimitedStores that install the Shopify app | App platform and billing for Shopify-installed stores | Shop domain, app subscription, order and discount data you let the app read | Ireland; global |
For optional analytics on our own website and app, we use PostHog (EU project) and Google Analytics. These providers receive the analytics data described above only when you allow optional analytics.
We may also disclose data to professional advisers, to a buyer if the business is sold (under the same protections), or where the law requires.
International transfers#
Our main hosting is in the EU. Some subprocessors are based in, or can access data from, the United States. Where data leaves the UK or EEA we rely on adequacy decisions (including the UK–US data bridge and the EU–US Data Privacy Framework where the provider is certified) or on standard contractual clauses with the UK addendum.
Your rights#
Depending on where you live, you can ask to access, correct, delete or export your personal data, object to or restrict how we use it, and withdraw consent. Email [email protected]. We'll reply within one month. If you're unhappy with our answer, you can complain to the UK Information Commissioner's Office (ico.org.uk) or your local data protection authority.
Security#
Sensitive fields are encrypted at rest, all traffic is encrypted in transit, access is limited to the people who need it and logged, and we test our controls regularly. See the security section of our Terms.
Changes#
We'll post updates here with a new version date, and tell account holders about material changes.

