What shipped
- 01Versioned hosted JavaScript with no private credential
- 02UTM, referral and Google click identifier capture
- 03First-party opaque acquisition ID
- 04Explicit browser events marked as non-authoritative
- 05Server-only install, trial, paid, cancellation, churn and refund events
- 06Exact-origin restriction, deduplication and rate limiting
- 07Recent verification events and 180-day raw retention
- 08Public-key and private-key rotation plus revocation
Honest Shopify handoff
Marlo does not assume query parameters survive the App Store, Shopify-managed installation or an OAuth redirect. App developers retain the opaque ID in their own signed session and associate it only after Shopify authentication succeeds. Marlo never replaces the OAuth state/nonce.
Set it up
Follow the acquisition tracking setup guide for browser, Shopify Remix, Next.js and direct HTTP examples.
Use the method on your own data