Split ("we", "us", "our") is operated by Signal Studio Limited. This Privacy Policy explains how we collect, use, and protect information in connection with Split: the dashboard at app.withsplit.com, the Split Webflow Designer Extension, and the split.js client runtime that Split installs on your published Webflow site. For any privacy question, contact us at privacy@withsplit.com.
This policy covers two groups:
split.js collects on a customer's site, Signal Studio Limited acts as a data processor on behalf of that customer, who is the controller. The customer decides whether and how tracking runs, and confirms they have a lawful basis to do so.When you connect a Webflow site, Split installs a lightweight first-party JavaScript runtime (split.js, about 8KB gzipped) on your published site through Webflow's Custom Code API. This runtime is what delivers your A/B and multivariate variants to visitors and records anonymous exposure and conversion events. It is served from Split's own CDN, loads with defer, and communicates only with Split's own endpoints (app.withsplit.com and Split's Supabase project). Split injects no third-party scripts and does not modify any other part of your site's code.
Account data. Email address, password (hashed), name, and, if you use Sign in with Google, your Google account identifier.
Billing data. Handled by Stripe. We never see or store your full card number.
Usage data. Your test configurations (test names, keys, target page paths, variants, goals), dashboard interactions, and support correspondence.
Visitor data (collected by split.js on your published site). Split is built to minimize what it collects about your visitors:
/pricing). Query strings, hashes, and fragments are stripped before anything is sent.google.com), never the full referring URL.Split does not collect names, emails, full page URLs, full referrer URLs, query strings, or page fragments from your visitors, and does not track visitors across other websites. Any IP address or user-agent string is used only transiently by our hosting providers for security and abuse prevention, is not stored against a visitor profile, and is auto-deleted with server logs (see Data Retention).
split.js runtime on your Webflow sites.We do not sell personal data. We do not use your data, or your visitors' data, for advertising or behavioral profiling.
Connecting a Webflow site uses OAuth and requests only the scopes needed for A/B testing: reading your site and element structure, and registering the split.js runtime through the Custom Code API. The Designer Extension runs inside Webflow's secure iframe sandbox. It reads the currently selected canvas element (type, ID, custom attributes), writes the Split custom attributes (data-split-test, data-split-variant, data-split-goal) only to elements you explicitly connect, and communicates only with app.withsplit.com using your Webflow ID token. It does not send analytics or data to any third party.
Split's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
To keep variant assignment stable and avoid double-counting, split.js stores a small amount of first-party data in the visitor's browser. None of it is sold or shared; it is used only to run your tests and report anonymous, aggregated results.
On the dashboard we use cookies for authentication and for first-party product analytics. We do not use advertising cookies or cross-site tracking.
Split gives the site owner control over how visitor tracking starts, mirroring Webflow's own Analyze and Optimize tracking options:
In every mode, Split:
Variant delivery still works regardless of the tracking mode. Only the analytics events are gated.
We use the following third-party services to operate Split. Each has its own privacy policy, which we recommend reviewing. We give 30 days' notice before adding a new subprocessor.
All data is stored in Supabase (PostgreSQL) with row-level security enforced on every table, so each user can access only data belonging to their own connected sites. API endpoints validate authentication and site ownership on every request. Traffic is encrypted in transit with TLS. The Designer Extension communicates over HTTPS with a locked CORS origin. Webflow OAuth tokens are stored encrypted and used only for authorized API calls. We notify affected customers within 72 hours of becoming aware of a personal data breach.
Depending on your jurisdiction, you have the right to access, rectify, erase, port, object to, or restrict the processing of your personal data. You can access and export your data from the dashboard, disconnect Webflow sites at any time (which revokes our access), and request account deletion. For any request, contact privacy@withsplit.com and we will respond within 30 days.
For website visitors: because Split processes visitor analytics on behalf of our customer (the site owner), please direct access or deletion requests to the site owner, who is the controller. We support them in fulfilling those requests.
Signal Studio Limited operates from New Zealand. Where we transfer personal data from the EEA or the UK, we rely on Standard Contractual Clauses or another lawful transfer mechanism.
A Data Processing Agreement is available on request and is recommended for customers with visitors in the EEA, the UK, or California. Contact privacy@withsplit.com.
Split is not directed at, and is not intended for use by, anyone under the age of 18. We do not knowingly collect personal information from children.
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or an in-app notice. The "Last updated" date above reflects the most recent revision.
Signal Studio Limited
Email: privacy@withsplit.com
Website: app.withsplit.com
If you are in New Zealand and are not satisfied with our response, you may contact the Office of the Privacy Commissioner. If you are in the EEA or the UK, you may lodge a complaint with your local supervisory authority.