Legal

Privacy Policy

Last updated: January 2, 2026Effective: January 2, 2026

This placeholder policy describes how Checkout Monitor collects, uses, and protects information when you use our website and monitoring service. Replace this copy with your reviewed legal text before publishing.

1. Information we collect

We collect information you provide directly, information collected automatically, and information from the stores you connect for monitoring.

  • Account information — your name, work email, and (when applicable) billing details.
  • Store configuration — the base URL, shared secret, and per-store settings you provide to enable the signed checkout tests.
  • Usage data — pages viewed, features used, and diagnostic logs from the dashboard.

2. How we use your information

We use the information we collect to operate the monitoring service, run scheduled signed Store API checkouts, deliver alerts, provide support, and improve the product.

3. Store & checkout data

To monitor your checkout we run signed WooCommerce Store API test purchases using the bot-only test payment gateway installed by the companion WordPress plugin. We do not process real payments and the test orders created are automatically suppressed from your admin list, transactional emails, and analytics by the plugin. Every run's step-by-step result is stored so you can diagnose failures.

4. Cookies & tracking

We use essential cookies to keep you signed in and a limited set of analytics cookies to understand product usage. You can control non-essential cookies through your browser or our preferences panel.

5. Sharing & sub-processors

We do not sell your personal information. We share data only with the service providers required to run Checkout Monitor — hosting, email delivery, and any alert channels (Slack webhooks, SMS provider) you configure — under contract and only as needed.

6. Data retention

We retain account information for as long as your account is active and run history according to your plan (7 days on Free, 90 days on Pro, 1 year on Agency). You can request deletion at any time, subject to legal and accounting obligations.

7. Security

Store shared secrets and configured Slack webhook URLs are AES-encrypted at rest via Laravel's encrypted cast — they never appear in API responses or logs. Every request between our runner and your plugin is HMAC-SHA256 signed with a timestamp and one-time nonce; the plugin fails-closed on any missing header, stale timestamp, replay attempt, or signature mismatch.

8. Your rights

Depending on your location, you may have the right to access, correct, export, or delete your personal information, and to object to certain processing. To exercise these rights, contact us using the details below.

9. Changes to this policy

We may update this policy from time to time. When we make material changes we will notify you by email or an in-app notice and update the "last updated" date above.

10. Contact us

Questions about this policy or your data? Reach us at privacy@checkoutmonitor.app or through our contact page.

This is placeholder text.

Have your counsel review and replace every section before this policy goes live. Nothing here is legal advice.