CheckoutWatch Privacy Policy

Effective date: 27 July 2026

Version: 1.1

This policy explains how CheckoutWatch handles personal data when you visit our website, request a free checkout test, create an account, connect a WooCommerce store, use checkout monitoring, contact us, or use an optional integration.

1. Who is responsible for your data

CheckoutWatch is operated by David Mansaray. CheckoutWatch is the data controller for the personal data described in this policy, except where a service provider acts as an independent controller for its own purposes.

Questions, privacy requests, and complaints can be sent to support@checkoutwatch.co.

2. Data we collect

We collect only the data needed to provide, secure, improve, and measure the service.

Website visitors and measurement

Depending on your choices, we may collect:

  • the page or landing path you visited and the referring website's hostname;
  • campaign parameters such as UTM values and a landing-page variant;
  • Google advertising click identifiers only when you allow advertising measurement;
  • consent choices and a limited consent record, which may include the time, policy version, IP address, and browser user agent;
  • optional analytics data such as an opaque browser identifier, page activity, device/browser type, approximate location, and named product events.

We do not send names, email addresses, store URLs, checkout evidence, alert destinations, access tokens, payment details, or free-form error text to our product analytics providers.

Free checkout tests

When you request a free test, we collect:

  • the store URL, your email address, and your stated relationship to the store;
  • the payment method you expect to be visible, if supplied;
  • your confirmation that you own the store, work for it, or have permission to test it;
  • limited campaign/referral data when your measurement choices allow it;
  • public-page test results and temporary evidence, which can include screenshots and technical browser events.

An initial public pre-check may inspect public storefront, product, cart, and checkout pages. After email confirmation, the test may add a product to the cart. It does not submit payment or intentionally create an order.

Free plugin downloads

When you request the free WordPress plugin by email, we collect:

  • your email address and the time of the request;
  • your separate choice about occasional product news and offers; and
  • limited campaign and referral data only when your website measurement choices allow it.

We use the address to send the requested plugin link and three short setup emails. If the separate product-news choice is selected when you submit, we may also send occasional Checkout Watch product updates and offers until you unsubscribe. Clearing that choice does not block the download. Requesting the plugin does not create an application account, team, or trial.

Accounts and connected stores

If you create an account or connect a store, we may collect:

  • your name, email address, sign-in records, workspace role, and business type;
  • team membership and invitation details;
  • the store URL, connection status, test configuration, and encrypted connection credentials;
  • checkout-run status, steps, diagnostics, screenshots, videos, traces, and other evidence;
  • monitoring schedules, incidents, alert settings, and alert recipient email addresses;
  • support messages and operational correspondence.

If you choose Google sign-in, Google provides us with your name and email address. If you connect Slack, we store the workspace, channel, and authorisation information needed to send the alerts you configure.

Billing

Stripe processes card and payment details. CheckoutWatch stores the related customer, subscription, plan, invoice, and payment-status records needed to manage your account, but does not receive or store your full card number.

Security and operations

We process IP addresses, user agents, timestamps, request and authentication records, application logs, and security events where needed to operate the service, prevent abuse, investigate failures, and protect accounts.

3. Why we use data and our legal bases

We use personal data:

  • to provide the service and fulfil our contract, including authentication, requested plugin and setup emails, authorised checkout tests, monitoring, evidence, alerts, support, and billing;
  • with your consent, for optional analytics and advertising measurement. We also rely on your separate marketing choice for occasional product news and offers. You can decline or withdraw these choices without losing core service access or access to the free plugin;
  • for our legitimate interests, where those interests are not overridden by your rights, including service security, fraud and abuse prevention, troubleshooting, reliability, and understanding aggregate service performance; and
  • to meet legal obligations, including accounting, tax, dispute, and regulatory requirements.

We do not sell personal data. We do not use CheckoutWatch analytics data to make solely automated decisions that produce legal or similarly significant effects.

4. Checkout testing and evidence

You must own a store, work for it, or have permission before asking CheckoutWatch to test it. CheckoutWatch is designed to use public buyer-facing pages and limited, authorised store context. Tests must not be used to access customer accounts, private administration areas, or payment credentials.

Evidence is kept private and is available only through authorised report or account access. It can contain storefront content and technical details, so we treat it as sensitive operational data and do not send it to analytics providers.

5. Cookies and measurement choices

CheckoutWatch uses necessary cookies and local storage for security, authentication, consent choices, and core service operation.

Optional measurement is separated by purpose:

  • Analytics helps us understand visits and product use. This may use Google Analytics and, when enabled, PostHog. Optional analytics is not loaded before consent.
  • Advertising measurement lets us retain eligible Google click identifiers and measure whether an ad led to a useful outcome.
  • Advertising personalisation is off for the initial paid-growth release.

You can accept or reject optional purposes in the website banner. Signed-in users can also review or withdraw measurement choices in their account privacy settings, including withdrawal across devices. Withdrawal stops future collection for the affected purpose.

Scope of your choices. A choice made in a browser governs that browser. A signed-in "withdraw on all devices" action applies account-wide: it denies the optional purposes for every browser linked to your account and for the background analytics of accounts you own. An account-level acceptance is never applied silently to a browser that has not made its own choice, so a shared or new browser is asked again; an account-level withdrawal is applied to your browsers, and we tell you once when that happens.

Withdrawal also deletes. When you withdraw analytics consent we delete all of the analytics event records we gathered under that consent, whether or not they had already been sent to an analytics provider. Nothing is kept in a reduced or "anonymised" form. What remains is the minimal record of the withdrawal itself, described below. Where records had already been sent, we first note the identifiers involved so we can raise an internal task to have the corresponding data deleted at the provider, which we complete within 30 days using our documented procedure; that note is itself time-limited and deleted once the task is done. Team-level background analytics is the account's data rather than yours personally, and is handled by team or account deletion.

Suppression records. When you withdraw or decline, we keep a minimal record of that decision itself — the purpose, the choice, the time, and the policy and copy version you were shown. We keep it so we can prove and honour your choice, and so a later visit is not treated as if you had never decided. We cannot delete this record along with the rest: without it we would have no way to respect the objection. The lawful basis is compliance with our legal obligations, including the obligation to respect your objection and to demonstrate that consent choices were honoured. It contains no analytics identifier, and it is not used to profile you.

Google Analytics is not permitted to receive personally identifiable information from CheckoutWatch. PostHog, when enabled, will receive only explicit named events and opaque identifiers: broad autocapture and session replay are off at launch.

6. Service providers and sharing

We disclose data only where needed to operate the service, follow your instructions, protect CheckoutWatch and its users, or comply with law. Providers may include:

  • DigitalOcean for application hosting, databases, and private evidence storage;
  • Stripe for billing and payment processing;
  • Google for optional sign-in and, with consent, Analytics and advertising measurement;
  • PostHog, when enabled, for consented product analytics;
  • our dedicated, self-hosted Mautic system for plugin-download contacts, preferences, campaigns, and suppression;
  • Amazon SES for delivery of plugin, setup, and opted-in marketing email;
  • Slack, only when you connect it for alerts;
  • email-delivery and operational service providers needed to send sign-in links, reports, alerts, and support messages; and
  • professional advisers, authorities, or a successor organisation where legally required or as part of a properly managed business transaction.

These providers may process data under their own privacy notices as well as contracts with CheckoutWatch. We do not give the Hermes distribution agent customer-level analytics, store URLs, evidence, or unrestricted analytics access; its planned reporting interface is aggregate-only.

7. International transfers

CheckoutWatch and its providers may process data in the United Kingdom, United States, and other countries. When personal data is transferred outside the UK or European Economic Area, we rely on an applicable adequacy decision or contractual protections such as the UK International Data Transfer Addendum and EU Standard Contractual Clauses, where required.

The planned PostHog project uses PostHog Cloud in the United States. Google may process Analytics data internationally; use of a regional collection endpoint does not mean all Analytics processing remains in Europe.

Provider details:

8. How long we keep data

We keep data only for as long as needed for the purpose described, subject to legal, security, backup, and dispute requirements.

Data Typical retention
Unconfirmed free-test request Up to 72 hours
Confirmed free-test report and evidence Up to 14 days
Plugin-download contact Through the requested setup series; longer only while an ongoing marketing choice remains active or a minimal suppression record is needed to honour an unsubscribe
Connected-store evidence Until the expiry shown for the run or under the applicable account/plan setting
Operational application logs Typically up to 14 days
Browser analytics context Up to 13 months
Google Analytics user- and event-level data Intended maximum of 14 months; aggregate reports may remain longer
PostHog event data, when enabled Up to the active project-plan retention, currently planned as a maximum of one year
Account, subscription, and business records While the account is active and afterwards where needed for legal, accounting, security, or dispute purposes
Consent and withdrawal records The current record for each purpose is kept while it applies; a superseded record is kept up to 6 years
Provider deletion task snapshot (account deletion or consent withdrawal) Up to 45 days while deletion is completed and verified

Backups may retain deleted data for a limited additional period until they rotate out. We isolate backup data from ordinary use and restore it only for recovery or security purposes.

9. Security

We use technical and organisational controls designed to protect data, including encrypted network transport, access controls, private evidence storage, secret-management practices, data minimisation, and logging. No internet service is completely secure, but we review and improve these controls as the service develops.

Please protect your sign-in links and account sessions, grant store access only to trusted people, and contact us promptly if you suspect unauthorised use.

10. Your rights

Depending on where you live, you may have rights to:

  • access and receive a copy of your personal data;
  • correct inaccurate data;
  • request deletion or restriction;
  • object to processing based on legitimate interests;
  • receive portable data you supplied to us;
  • withdraw consent at any time; and
  • complain to a data-protection authority.

To exercise a right, email support@checkoutwatch.co. We may need to verify your identity and may retain limited records where the law requires it. You can also delete your CheckoutWatch account from your account settings.

If you are in the United Kingdom, you may complain to the Information Commissioner's Office. Please contact us first if you are comfortable doing so; we would like the opportunity to resolve the issue.

11. Children

CheckoutWatch is a business service and is not directed to children. Do not use the service if you are not old enough to enter a binding contract in your country.

12. Changes to this policy

We may update this policy as the product, providers, or legal requirements change. We will publish the new version and effective date here and provide additional notice where a change materially affects your choices.

13. Contact

Email: support@checkoutwatch.co