1. Information We Collect
When you use StoreVitals, we collect:
- Account information: Email address provided during sign-up.
- Store data: URLs you submit for scanning. We crawl publicly accessible pages only.
- Scan results: Health scores, issues found, and page metadata from scans you initiate.
- Usage data: IP addresses (for rate limiting), browser type, and interaction data to improve our service.
- Payment data: Processed securely by Stripe. We never store your credit card details.
2. How We Use Your Information
- To provide and improve the StoreVitals service
- To send scan reports and service notifications
- To process payments and manage subscriptions
- To prevent abuse and enforce rate limits
- To communicate important service updates
3. Data Storage & Security
Your data is stored on Supabase (hosted on AWS) and Vercel's infrastructure. We use industry-standard security practices including:
- Encryption in transit (TLS/HTTPS)
- Row-level security on database tables
- Secure authentication via magic links (no passwords stored)
- Payment processing through Stripe (PCI DSS compliant)
4. Data Sharing
We do not sell, rent, or share your personal information with third parties except:
- Service providers: Stripe (payments), Supabase (database), Vercel (hosting), Resend (email delivery).
- Legal requirements: When required by law or to protect our rights.
- Shareable reports: Scan reports you choose to share via public links are accessible to anyone with the URL.
5. Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your account and all associated data
- Export your scan data
- Opt out of non-essential communications
6. Cookies & Tracking
We use essential cookies for authentication and session management. We do not use third-party advertising trackers. Analytics, if any, are privacy-respecting and anonymized.
7. Data Retention
Scan results are retained for as long as your account is active. Anonymous (free) scan data may be retained for up to 90 days. When you delete your account, all associated data is permanently removed within 30 days.
8. Changes to This Policy
We may update this policy from time to time. Significant changes will be communicated via email.