Privacy by product design

We review the storefront. We never enter the back office.

The initial free report reads public storefront evidence only. It needs no Shopify Admin access, order or customer records, account, or email.

Public pages onlyNo login or app installNo store changes
Public storefrontEvidence visible to a shopper
Private back officeAdminOrdersCustomers
Public evidence may support a report. Private business data never enters the scan path.

The access boundary

Public evidence can cross. Private data cannot.

The scanner is read-only and receives no permission to change the storefront.

Readable

Public storefront

  • Rendered page content
  • Public links and metadata
  • Public structured data
  • Public image markup
  • Public response behavior
Blocked

Private merchant data

  • Shopify Admin
  • Orders and customers
  • Revenue and conversion
  • Private analytics and apps
  • Private theme source
The initial free report needs no account or email and never receives permission to change the store.

What may be retained

Enough evidence to explain the report—not an indefinite scanner archive.

Public page evidence may be retained so a report can show what supported each finding. Proposed launch limits are 30 days for completed reports, 14 days for partial reports, and 7 days for failed or canceled records. Operational records also have bounded limits. These values still require owner approval before any production canary.

Read the email-access, cookie, example, and deletion boundaries

If you request the alternate report, the normalized email address, report-access request, separate marketing-consent choice and timestamp, saved-access capability hash, next free-scan eligibility time, and bounded transactional delivery state are retained with that report only until its report boundary. Exact-scan deletion removes that co-located record. The browser receives a bounded HttpOnly report-access cookie; neither the report page address nor the email address authorizes another browser. Transactional delivery is disabled by default and, when separately configured, sends the non-authorizing report page address; it does not add the address to a marketing list.

Saved examples are separate, curated snapshots and do not inherit live-scan time limits. A Netlify Forms copy of a report-access or service-request lead is separately governed outside scanner deletion and requires its own deletion handling.

Saved example

Already captured

Clearly labeled snapshot. Opening it sends no storefront request.

Public scan

Evidence for the report

Address, sampled public pages, observations, timestamps, state, and safety outcomes may be retained.

Policy boundary

No invented timeline

No universal retention or deletion period is claimed.

Orders, customer records, private analytics, and Shopify Admin data are not collected by the public scan.

How evidence is labeled

Measured facts, scenarios, and unknowns stay separate.

Technical detail is available when needed, without turning a comparison into a performance claim.

ObservedRetained public evidenceScenarioEntered assumptionsVerifiedSame-rule recheckUnavailableNot zero or pass
Image transfer comparison
Measured current transfer6.80 MB
Validated candidate3.25 MB
Measured difference3.55 MB
How measured comparisons work

The supplied calculator case compares 6.80 MB with a 3.25 MB validated candidate, a 3.55 MB measured difference. MB is decimal and exact integer bytes are stored. This does not predict LCP, PageSpeed, conversion, orders, or revenue.

How confidence is interpreted

Confidence describes how directly retained evidence supports a finding. It does not guarantee business impact or grade the whole storefront.

How changes are verified

Keep the baseline, make one reversible change, and repeat the same rule against the same evidence boundary.

Baseline

Keep the proof

Same page, scope, date, rule, and limits.

Controlled change

Edit one thing

Use a duplicate theme or safe branch.

Same-rule recheck

Run it again

Compare against the retained baseline.

Possible resultVerifiedUnchangedRegressedInconclusive
The result stays unknown until the same evidence check runs again.

Analytics and cookies

Google Analytics is disabled by default.

The site includes dormant GA4 support that loads only when the owner explicitly enables it on the canonical production hostname. If enabled later, GA4 may receive clean page paths and coarse interaction events to understand aggregate site usage. It does not receive entered store URLs, merchant domains, form contents, email addresses, affected-page URLs, report or scan IDs, evidence, prompt content, query strings, or URL fragments.

Default configurationAnalytics request not loaded

Store URLs, report IDs, evidence, form content, and email addresses stay outside the dormant analytics path.

What this does and does not promise

No consent mechanism, cookie behavior, retention period, anonymization claim, subprocessor list, or legal right is asserted here. Consent-management requirements remain to be decided before analytics is enabled where applicable.

Limits of public evidence

Public pages cannot answer private business questions.

A public observation can support a storefront finding. It cannot prove a business outcome.

  • Revenue
  • Conversion
  • Orders
  • Customer behavior
  • Private configuration
  • Search demand
  • App value
  • Guaranteed business impact

Method and requests

Read the evidence method and current service boundary.

Sampling, confidence, limitations, and verification are documented.

Open the methodology

No verified privacy-request contact is currently published, so self-service deletion is not available. A protected intake and scan-link verification process must be configured before launch; it will never require Shopify credentials or customer or order data.

Security limits on a public scan

Public scans use HTTPS, URL normalization, DNS and redirect revalidation, private-address blocking, and fixed request, page, byte, parser, redirect, and time budgets. The browser scan does not execute storefront JavaScript.