Privacy Policy
This placeholder policy describes how Checkout Monitor collects, uses, and protects information when you use our website and monitoring service. Replace this copy with your reviewed legal text before publishing.
1. Information we collect
We collect information you provide directly, information collected automatically, and information from the stores you connect for monitoring.
- Account information — your name, work email, and (when applicable) billing details.
- Store configuration — the base URL, shared secret, and per-store settings you provide to enable the signed checkout tests.
- Usage data — pages viewed, features used, and diagnostic logs from the dashboard.
2. How we use your information
We use the information we collect to operate the monitoring service, run scheduled signed Store API checkouts, deliver alerts, provide support, and improve the product.
3. Store & checkout data
To monitor your checkout we run signed WooCommerce Store API test purchases using the bot-only test payment gateway installed by the companion WordPress plugin. We do not process real payments and the test orders created are automatically suppressed from your admin list, transactional emails, and analytics by the plugin. Every run's step-by-step result is stored so you can diagnose failures.
4. Cookies & tracking
We use essential cookies to keep you signed in and a limited set of analytics cookies to understand product usage. You can control non-essential cookies through your browser or our preferences panel.
5. Sharing & sub-processors
We do not sell your personal information. We share data only with the service providers required to run Checkout Monitor — hosting, email delivery, and any alert channels (Slack webhooks, SMS provider) you configure — under contract and only as needed.
6. Data retention
We retain account information for as long as your account is active and run history according to your plan (7 days on Free, 90 days on Pro, 1 year on Agency). You can request deletion at any time, subject to legal and accounting obligations.
7. Security
Store shared secrets and configured Slack webhook URLs are AES-encrypted at rest via Laravel's encrypted cast — they never appear in API responses or logs. Every request between our runner and your plugin is HMAC-SHA256 signed with a timestamp and one-time nonce; the plugin fails-closed on any missing header, stale timestamp, replay attempt, or signature mismatch.
8. Your rights
Depending on your location, you may have the right to access, correct, export, or delete your personal information, and to object to certain processing. To exercise these rights, contact us using the details below.
9. Changes to this policy
We may update this policy from time to time. When we make material changes we will notify you by email or an in-app notice and update the "last updated" date above.
10. Contact us
Questions about this policy or your data? Reach us at privacy@checkoutmonitor.app or through our contact page.
Have your counsel review and replace every section before this policy goes live. Nothing here is legal advice.