SplitLaunch legal

Privacy Policy

Effective date: July 16, 2026

This Privacy Policy explains how SplitLaunch collects, uses, discloses, stores, and protects information when you use our website, dashboard, APIs, browser pixel, command-line package, documentation, and related services.

SplitLaunch is a package-first A/B testing service. Customers install SplitLaunch in their own websites or applications, use API keys to manage experiments, and use public pixel IDs to collect sessions, exposures, events, and conversions.

SplitLaunch is operated by UXON AI as a separate product under the same parent company. This policy applies to SplitLaunch only unless another UXON AI product links to this policy.

1. Controller and Contact

References to "SplitLaunch", "we", "us", or "our" mean the SplitLaunch product and UXON AI as the parent company operating it. For privacy requests, contact ops@splitlaunch.dev.

Where a customer installs SplitLaunch on its own website or application, that customer is responsible for its relationship with its own visitors and end users. SplitLaunch processes pixel and event data to provide the service to that customer.

2. Information We Collect

Account data
Name, email address, workspace name, authentication details, account settings, billing status, subscription status, API key metadata, support messages, and dashboard activity.
Project and configuration data
Project names, public pixel IDs, whitelisted domains, API key scopes, experiment names, control and variation URLs, traffic allocation, targeting rules, conversion goals, and related configuration.
Pixel and analytics data
Visitor ID, session ID, page URL, page path, referrer, referrer host, timestamp, experiment ID, assigned variant, exposure data, custom event names, conversion values, currency, and custom event metadata.
Acquisition and device metadata
UTM parameters, click IDs such as gclid, gbraid, wbraid, fbclid, msclkid, ttclid, li_fat_id, and twclid, device type, visitor type, timezone, browser language, viewport bucket, country, region, and in-app browser indicators where available.
Technical and log data
IP-derived request context, user agent, API request logs, rate-limit logs, webhook logs, error logs, security logs, and diagnostic data needed to operate and secure the service.
Billing data
Subscription plan, billing customer ID, subscription ID, payment status, invoices, and billing portal activity. Card details are handled by Stripe and are not stored by SplitLaunch.

3. How We Use Information

  • Create and manage accounts, sessions, workspaces, projects, API keys, and pixel IDs.
  • Validate API keys and allow AI agents or users to create, update, launch, pause, and analyse A/B tests.
  • Serve browser pixel scripts, evaluate running experiments, assign visitors, preserve sticky assignments, redirect visitors where configured, and collect exposures, sessions, events, and conversions.
  • Generate usage metrics, enforce plan limits, provide billing and subscription access, and process billing through Stripe.
  • Provide documentation, install instructions, support, account notices, security notices, and onboarding email through providers such as Resend.
  • Monitor, debug, secure, improve, and maintain the website, APIs, pixel infrastructure, package workflows, and dashboard.
  • Comply with legal obligations, enforce our terms, prevent abuse, and protect SplitLaunch, customers, visitors, and third parties.

4. Customer Responsibilities

Customers decide where the SplitLaunch pixel is installed, what experiments are created, what pages are tested, what conversion events are fired, and what custom metadata is sent. Customers are responsible for providing any required notices and obtaining any required consents from their own website visitors and end users.

  • Do not send sensitive personal information, payment card numbers, passwords, health data, government identifiers, or unnecessary personal data through custom events.
  • Keep API keys in trusted server, terminal, or agent environments and never expose private API keys in public browser code.
  • Use public pixel IDs for browser-side tracking and configure whitelisted domains accurately.
  • Make sure your own privacy policy explains your use of A/B testing, analytics, conversion tracking, cookies, local storage, and similar technologies.

5. Cookies, Local Storage, and Similar Technologies

The SplitLaunch browser pixel may use cookies, local storage, or similar technologies to keep visitor assignment consistent, understand sessions, prevent duplicate events, and support experiment delivery. Customers may need to classify and disclose those technologies in their own consent tools or privacy notices.

6. Service Providers and Sharing

We share information only as needed to provide, secure, bill, support, and improve the service. Current infrastructure and service providers may include:

  • Neon for Postgres database hosting.
  • Upstash for Redis caching and rate limiting.
  • Vercel for application hosting and deployment.
  • Stripe for payment processing, subscriptions, invoices, and billing portal access.
  • Resend for transactional email delivery.
  • GitHub for source code hosting and deployment workflows.
  • Cloudflare or DNS providers where domain routing, redirects, or DNS management are configured.

These providers process information according to their own terms, privacy commitments, and security measures. We do not sell personal information.

7. Retention

We retain account, billing, API, project, experiment, and operational records for as long as needed to provide the service, comply with law, resolve disputes, enforce agreements, and maintain security. Pixel, session, exposure, event, conversion, and usage data is retained for the period needed to provide reporting, usage, billing, debugging, and security functions, unless a longer or shorter period is required by law, customer agreement, or operational need.

8. Security

We use technical and organisational measures intended to protect information against unauthorised access, loss, misuse, alteration, and disclosure. No internet service is completely secure. Customers remain responsible for protecting their account credentials, API keys, repository secrets, connected domains, and agent configurations.

9. International Processing

SplitLaunch and its service providers may process information in countries other than the country where a user or visitor is located. Where required, we rely on appropriate contractual, technical, and organisational safeguards for cross-border processing.

10. Privacy Rights

Depending on where you are located, you may have rights to access, correct, delete, export, restrict, or object to processing of your personal information. You may also have the right to lodge a complaint with a privacy or data protection authority.

To make a request, contact ops@splitlaunch.dev. If your request relates to a customer website using SplitLaunch, we may direct you to that customer because they control the tested pages, event configuration, and visitor relationship.

11. Children

SplitLaunch is not intended for children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided personal information to SplitLaunch, contact us so we can review and take appropriate action.

12. Changes to This Policy

We may update this Privacy Policy from time to time. The effective date above indicates when this version became effective. Continued use of SplitLaunch after an update means you accept the updated policy.

These privacy commitments should be read together with our Terms of Service.