SolutionsUse CasesPricing FAQs Help
Start freeLogin
LoginStart free
‹ All Legal Documents

Privacy Policy

Last updated: 30 June 2026

Split ("we", "us", "our") is operated by Signal Studio Limited. This Privacy Policy explains how we collect, use, and protect information in connection with Split: the dashboard at app.withsplit.com, the Split Webflow Designer Extension, and the split.js client runtime that Split installs on your published Webflow site. For any privacy question, contact us at privacy@withsplit.com.

1. Who This Policy Covers and Our Role

This policy covers two groups:

  • Dashboard users (our customers). For account, billing, and usage data, Signal Studio Limited is the data controller.
  • Visitors to our customers' websites. For the anonymous analytics that split.js collects on a customer's site, Signal Studio Limited acts as a data processor on behalf of that customer, who is the controller. The customer decides whether and how tracking runs, and confirms they have a lawful basis to do so.

2. How Split Works (the published-site runtime)

When you connect a Webflow site, Split installs a lightweight first-party JavaScript runtime (split.js, about 8KB gzipped) on your published site through Webflow's Custom Code API. This runtime is what delivers your A/B and multivariate variants to visitors and records anonymous exposure and conversion events. It is served from Split's own CDN, loads with defer, and communicates only with Split's own endpoints (app.withsplit.com and Split's Supabase project). Split injects no third-party scripts and does not modify any other part of your site's code.

3. Data We Collect

Account data. Email address, password (hashed), name, and, if you use Sign in with Google, your Google account identifier.

Billing data. Handled by Stripe. We never see or store your full card number.

Usage data. Your test configurations (test names, keys, target page paths, variants, goals), dashboard interactions, and support correspondence.

Visitor data (collected by split.js on your published site). Split is built to minimize what it collects about your visitors:

  • An anonymous, randomly generated visitor ID (not linked to any real-world identity).
  • The variant or combination the visitor is assigned to, per test.
  • Conversion events (click, pageview, scroll depth, time on page).
  • A path-only page identifier (for example /pricing). Query strings, hashes, and fragments are stripped before anything is sent.
  • The referrer host only (for example google.com), never the full referring URL.
  • A timestamp for each event.

Split does not collect names, emails, full page URLs, full referrer URLs, query strings, or page fragments from your visitors, and does not track visitors across other websites. Any IP address or user-agent string is used only transiently by our hosting providers for security and abuse prevention, is not stored against a visitor profile, and is auto-deleted with server logs (see Data Retention).

4. How We Use Data

  • To operate the service: assign variants, deliver tests, and compute results.
  • To authenticate your account and authorize access to your connected sites.
  • To install and manage the split.js runtime on your Webflow sites.
  • To display test results and statistical analysis in the dashboard.
  • To process payments and enforce plan limits.
  • To send transactional communications (account verification, sign-in links, billing).
  • To provide support and prevent fraud or abuse.
  • To comply with legal obligations.

We do not sell personal data. We do not use your data, or your visitors' data, for advertising or behavioral profiling.

5. Webflow Integration

Connecting a Webflow site uses OAuth and requests only the scopes needed for A/B testing: reading your site and element structure, and registering the split.js runtime through the Custom Code API. The Designer Extension runs inside Webflow's secure iframe sandbox. It reads the currently selected canvas element (type, ID, custom attributes), writes the Split custom attributes (data-split-test, data-split-variant, data-split-goal) only to elements you explicitly connect, and communicates only with app.withsplit.com using your Webflow ID token. It does not send analytics or data to any third party.

Google API Limited Use Disclosure

Split's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

6. Cookies and Similar Technologies

To keep variant assignment stable and avoid double-counting, split.js stores a small amount of first-party data in the visitor's browser. None of it is sold or shared; it is used only to run your tests and report anonymous, aggregated results.

Where Key Purpose Lifetime
localStorage split_vid Anonymous random visitor ID (not linked to identity) Until cleared
localStorage split_variants Which variant or combination the visitor is assigned to, per test Until cleared
localStorage split_cfg Cached copy of the site's active test config (plus ETag) About 60s, then overwritten
sessionStorage split_session_source Traffic source for the tab session: referrer host only, classified source, and UTM values Tab session
sessionStorage split_exposures De-duplicates exposure events within the tab session Tab session
sessionStorage split_conversions De-duplicates conversion events within the tab session Tab session
Cookie split_vid Backup of the visitor ID for browsers that limit localStorage 30 days
Cookie split_variants Backup of variant assignments 30 days
Cookie split_assignments URL-split tests only: variant and destination needed to redirect returning visitors before paint 30 days

On the dashboard we use cookies for authentication and for first-party product analytics. We do not use advertising cookies or cross-site tracking.

7. How and When Split Tracks Visitors

Split gives the site owner control over how visitor tracking starts, mirroring Webflow's own Analyze and Optimize tracking options:

  • Track all visitors (default). Once the site owner authorizes tracking and confirms a lawful basis, Split records anonymous analytics on all pages. Split still waits for a supported cookie banner to grant consent on pages where one is present.
  • Don't track by default (owner enables it). Split records analytics only on pages where a supported consent manager is present and grants consent. Pages with no banner are not tracked. A consent management solution is required for this mode.

In every mode, Split:

  • Honors Do Not Track and Global Privacy Control. These always block tracking, including CCPA opt-outs.
  • Automatically detects supported consent managers (Finsweet Cookie Consent, Cookiebot, OneTrust, Cookie Yes, Osano) and waits for their consent, and also reads IAB TCF v2.2 consent where present.
  • Never tracks until the site owner has explicitly authorized tracking in the dashboard (Site, then Tracking and cookies), with a lawful-basis confirmation.

Variant delivery still works regardless of the tracking mode. Only the analytics events are gated.

8. Subprocessors

We use the following third-party services to operate Split. Each has its own privacy policy, which we recommend reviewing. We give 30 days' notice before adding a new subprocessor.

Service Purpose Data shared
Supabase Database, authentication, file storage Account info, test data, anonymous visitor events
Vercel Application hosting Request logs (IP, user-agent), auto-deleted after 90 days
Stripe Payment processing Email and plan selection; Stripe handles all card data
Webflow Site integration (OAuth and Custom Code API) Site ID, script registration
Google Sign in with Google, and Google Analytics 4 on the dashboard only Authentication identifier; GA4 is not embedded by split.js

9. Data Retention

  • Account data: retained while your account is active, deleted within 30 days of account closure.
  • Billing records: retained for 7 years to meet tax and accounting obligations.
  • Test data: retained while the test exists, deleted when you delete the test.
  • Visitor event data: retained for 12 months after collection, then automatically purged. First-party visitor cookies default to 30 days.
  • Server logs: auto-deleted after 90 days.
  • Webflow OAuth tokens: revoked and deleted when you disconnect a site or delete your account.

10. Security

All data is stored in Supabase (PostgreSQL) with row-level security enforced on every table, so each user can access only data belonging to their own connected sites. API endpoints validate authentication and site ownership on every request. Traffic is encrypted in transit with TLS. The Designer Extension communicates over HTTPS with a locked CORS origin. Webflow OAuth tokens are stored encrypted and used only for authorized API calls. We notify affected customers within 72 hours of becoming aware of a personal data breach.

11. Your Rights

Depending on your jurisdiction, you have the right to access, rectify, erase, port, object to, or restrict the processing of your personal data. You can access and export your data from the dashboard, disconnect Webflow sites at any time (which revokes our access), and request account deletion. For any request, contact privacy@withsplit.com and we will respond within 30 days.

For website visitors: because Split processes visitor analytics on behalf of our customer (the site owner), please direct access or deletion requests to the site owner, who is the controller. We support them in fulfilling those requests.

12. International Transfers

Signal Studio Limited operates from New Zealand. Where we transfer personal data from the EEA or the UK, we rely on Standard Contractual Clauses or another lawful transfer mechanism.

13. Data Processing Agreement

A Data Processing Agreement is available on request and is recommended for customers with visitors in the EEA, the UK, or California. Contact privacy@withsplit.com.

14. Children's Privacy

Split is not directed at, and is not intended for use by, anyone under the age of 18. We do not knowingly collect personal information from children.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or an in-app notice. The "Last updated" date above reflects the most recent revision.

16. Contact

Signal Studio Limited
Email: privacy@withsplit.com
Website: app.withsplit.com

If you are in New Zealand and are not satisfied with our response, you may contact the Office of the Privacy Commissioner. If you are in the EEA or the UK, you may lodge a complaint with your local supervisory authority.

A/B testing built for Webflow. Honest statistics. No code required.

Product

FeaturesPricingFAQChangelog

Resources

Help CenterBlog Coming soonCRO Guide Coming soonStatistics Explainer Coming soon

Company

About Coming soonContactTwitterComing soonLinkedInComing soon
© 2026 Split. All rights reserved.
Privacy PolicyTerms of Use