Effective date: 27 July 2026
Version: 1.1
This policy explains how CheckoutWatch handles personal data when you visit our website, request a free checkout test, create an account, connect a WooCommerce store, use checkout monitoring, contact us, or use an optional integration.
CheckoutWatch is operated by David Mansaray. CheckoutWatch is the data controller for the personal data described in this policy, except where a service provider acts as an independent controller for its own purposes.
Questions, privacy requests, and complaints can be sent to support@checkoutwatch.co.
We collect only the data needed to provide, secure, improve, and measure the service.
Depending on your choices, we may collect:
We do not send names, email addresses, store URLs, checkout evidence, alert destinations, access tokens, payment details, or free-form error text to our product analytics providers.
When you request a free test, we collect:
An initial public pre-check may inspect public storefront, product, cart, and checkout pages. After email confirmation, the test may add a product to the cart. It does not submit payment or intentionally create an order.
When you request the free WordPress plugin by email, we collect:
We use the address to send the requested plugin link and three short setup emails. If the separate product-news choice is selected when you submit, we may also send occasional Checkout Watch product updates and offers until you unsubscribe. Clearing that choice does not block the download. Requesting the plugin does not create an application account, team, or trial.
If you create an account or connect a store, we may collect:
If you choose Google sign-in, Google provides us with your name and email address. If you connect Slack, we store the workspace, channel, and authorisation information needed to send the alerts you configure.
Stripe processes card and payment details. CheckoutWatch stores the related customer, subscription, plan, invoice, and payment-status records needed to manage your account, but does not receive or store your full card number.
We process IP addresses, user agents, timestamps, request and authentication records, application logs, and security events where needed to operate the service, prevent abuse, investigate failures, and protect accounts.
We use personal data:
We do not sell personal data. We do not use CheckoutWatch analytics data to make solely automated decisions that produce legal or similarly significant effects.
You must own a store, work for it, or have permission before asking CheckoutWatch to test it. CheckoutWatch is designed to use public buyer-facing pages and limited, authorised store context. Tests must not be used to access customer accounts, private administration areas, or payment credentials.
Evidence is kept private and is available only through authorised report or account access. It can contain storefront content and technical details, so we treat it as sensitive operational data and do not send it to analytics providers.
CheckoutWatch uses necessary cookies and local storage for security, authentication, consent choices, and core service operation.
Optional measurement is separated by purpose:
You can accept or reject optional purposes in the website banner. Signed-in users can also review or withdraw measurement choices in their account privacy settings, including withdrawal across devices. Withdrawal stops future collection for the affected purpose.
Scope of your choices. A choice made in a browser governs that browser. A signed-in "withdraw on all devices" action applies account-wide: it denies the optional purposes for every browser linked to your account and for the background analytics of accounts you own. An account-level acceptance is never applied silently to a browser that has not made its own choice, so a shared or new browser is asked again; an account-level withdrawal is applied to your browsers, and we tell you once when that happens.
Withdrawal also deletes. When you withdraw analytics consent we delete all of the analytics event records we gathered under that consent, whether or not they had already been sent to an analytics provider. Nothing is kept in a reduced or "anonymised" form. What remains is the minimal record of the withdrawal itself, described below. Where records had already been sent, we first note the identifiers involved so we can raise an internal task to have the corresponding data deleted at the provider, which we complete within 30 days using our documented procedure; that note is itself time-limited and deleted once the task is done. Team-level background analytics is the account's data rather than yours personally, and is handled by team or account deletion.
Suppression records. When you withdraw or decline, we keep a minimal record of that decision itself — the purpose, the choice, the time, and the policy and copy version you were shown. We keep it so we can prove and honour your choice, and so a later visit is not treated as if you had never decided. We cannot delete this record along with the rest: without it we would have no way to respect the objection. The lawful basis is compliance with our legal obligations, including the obligation to respect your objection and to demonstrate that consent choices were honoured. It contains no analytics identifier, and it is not used to profile you.
Google Analytics is not permitted to receive personally identifiable information from CheckoutWatch. PostHog, when enabled, will receive only explicit named events and opaque identifiers: broad autocapture and session replay are off at launch.
We disclose data only where needed to operate the service, follow your instructions, protect CheckoutWatch and its users, or comply with law. Providers may include:
These providers may process data under their own privacy notices as well as contracts with CheckoutWatch. We do not give the Hermes distribution agent customer-level analytics, store URLs, evidence, or unrestricted analytics access; its planned reporting interface is aggregate-only.
CheckoutWatch and its providers may process data in the United Kingdom, United States, and other countries. When personal data is transferred outside the UK or European Economic Area, we rely on an applicable adequacy decision or contractual protections such as the UK International Data Transfer Addendum and EU Standard Contractual Clauses, where required.
The planned PostHog project uses PostHog Cloud in the United States. Google may process Analytics data internationally; use of a regional collection endpoint does not mean all Analytics processing remains in Europe.
Provider details:
We keep data only for as long as needed for the purpose described, subject to legal, security, backup, and dispute requirements.
| Data | Typical retention |
|---|---|
| Unconfirmed free-test request | Up to 72 hours |
| Confirmed free-test report and evidence | Up to 14 days |
| Plugin-download contact | Through the requested setup series; longer only while an ongoing marketing choice remains active or a minimal suppression record is needed to honour an unsubscribe |
| Connected-store evidence | Until the expiry shown for the run or under the applicable account/plan setting |
| Operational application logs | Typically up to 14 days |
| Browser analytics context | Up to 13 months |
| Google Analytics user- and event-level data | Intended maximum of 14 months; aggregate reports may remain longer |
| PostHog event data, when enabled | Up to the active project-plan retention, currently planned as a maximum of one year |
| Account, subscription, and business records | While the account is active and afterwards where needed for legal, accounting, security, or dispute purposes |
| Consent and withdrawal records | The current record for each purpose is kept while it applies; a superseded record is kept up to 6 years |
| Provider deletion task snapshot (account deletion or consent withdrawal) | Up to 45 days while deletion is completed and verified |
Backups may retain deleted data for a limited additional period until they rotate out. We isolate backup data from ordinary use and restore it only for recovery or security purposes.
We use technical and organisational controls designed to protect data, including encrypted network transport, access controls, private evidence storage, secret-management practices, data minimisation, and logging. No internet service is completely secure, but we review and improve these controls as the service develops.
Please protect your sign-in links and account sessions, grant store access only to trusted people, and contact us promptly if you suspect unauthorised use.
Depending on where you live, you may have rights to:
To exercise a right, email support@checkoutwatch.co. We may need to verify your identity and may retain limited records where the law requires it. You can also delete your CheckoutWatch account from your account settings.
If you are in the United Kingdom, you may complain to the Information Commissioner's Office. Please contact us first if you are comfortable doing so; we would like the opportunity to resolve the issue.
CheckoutWatch is a business service and is not directed to children. Do not use the service if you are not old enough to enter a binding contract in your country.
We may update this policy as the product, providers, or legal requirements change. We will publish the new version and effective date here and provide additional notice where a change materially affects your choices.
Email: support@checkoutwatch.co