Skip to content

Legal

Privacy notice

What we collect, what we refuse to collect, where it is kept, when it is purged, and how to make us delete it.

In force from
Owner
Martin Clavell
Operated by
BEMATIC ONLINE SAS

At a glance

  • We never store a secret we find in a storefront’s configuration — only where it is and its shape.
  • We do not train models on your data, and we do not keep the prompts we send.
  • Data is hosted with our providers and is not kept for good: a sweep runs every day and purges what has reached the end of its period.
  • Google Analytics and Microsoft Clarity run on our public pages only if you accept, with form contents hidden. No advertising, and nothing from signed-in pages or reports.
  • A site owner can make us stop and delete what we hold, with or without an account.
  • Questions and requests go to [email protected].

01Who we are

SuiteAnalytics is operated by BEMATIC ONLINE SAS, a company established in Uruguay and owned by Martin Clavell, who is the author of the system and its code. BEMATIC ONLINE SAS is the controller of the personal data this notice describes.

Requests about your data — access, correction, erasure, a copy, or the deletion of a storefront’s audits — go to [email protected].

02The one thing we deliberately do not store

A SuiteCommerce storefront ships its configuration to every visitor, and that configuration often contains third-party API keys. When we find a value that looks like a credential we record where it is, how long it is, which character classes it uses and its entropy — the path, the length, the shape — and we discard the value itself. You get what you need to rotate the key. We never hold a database of other people’s keys, because a database like that is a liability no amount of encryption makes acceptable.

03We do not train models on your data

No model is trained or fine-tuned on anything we hold about you or your storefront. Part of a report is written by a language model, and every one of those calls is inference: we send a slice of the evidence we already collected, the slice is restricted to declared sources and checked for redaction before it leaves, and the answer comes back and is stored in your report. Calls to OpenAI are sent with retention switched off, so the provider is asked to keep nothing beyond answering. We keep the answer, the model and the cost; we do not keep the prompt, only a hash of it. The providers that receive those calls are named in the sub-processor list with what each one can see.

We also compute benchmarks, so a report can tell you where you sit against comparable storefronts. A benchmark point records a release family, a page type, a metric, a value and the month. It carries no hostname, no account and no audit id, so it cannot be traced back to the site it came from — by us or by anyone who obtained the table.

04What we hold about people

Thin by construction: the account holder’s email address and name, the billing details you give us for invoices, and the audit log. Signup also records what an organization says its connection to a storefront is — that it runs one, that it builds them for other companies, or that it is evaluating. That is a fact about a business rather than about a person, it is what we were told rather than anything we checked, and it decides only what we show you next.

The audit log records each sign-in and sign-out and what each member of an organization did on its account — an audit requested, a share link made, a role changed, a billing change asked for — with the network it came from, truncated before it is stored to the first three parts of an IPv4 address or the first three groups of an IPv6 one, and the browser and operating system, never the full address or the raw browser string, and no location. It is kept for 24 months. The owners of an organization can see their own team’s entries, and nobody else’s, so that an agency or a company can see who used its account; other members cannot. Each entry keeps the email address its member had when it was made, so a person who later leaves and changes their address is not followed there by the organization they left.

If you turn on two-step sign-in, we hold your authenticator app’s secret, encrypted, and a one-way hash of each of your recovery codes, until you turn it off or your account is deleted.

Our own page-view record holds the path, the referring host, a viewport bucket and the hour, against a visitor hash salted with a value that rotates daily — so two visits on two days cannot be joined, by us or by anybody who obtained the table.

On the public pages — never on signed-in pages, reports or shared reports — we also use Google Analytics, to see which pages help people. It runs in Google’s Consent Mode: until you accept in the banner it sets no cookie and receives only cookieless measurements of the page viewed. If you accept, it sets its _ga cookies and records the pages you view, the referring page, your device and browser, and an approximate location derived from your IP address. Its advertising features are off whatever you choose. Your choice is kept in your browser, and you can change it at any time with “Cookie settings” at the bottom of every public page. Google is listed with the other sub-processors. There are no advertising cookies on this site.

If you accept, we also load Microsoft Clarity on the public pages. It records how a page is used — clicks, scrolls, mouse movement and the page as you saw it — so we can see where people get stuck, and turns that into heatmaps and session replays. It is not loaded at all until you accept. The contents of our forms — the contact form, the opt-out form and the pre-check — are masked and never recorded, and its advertising storage is never granted. Declining, or changing your choice under “Cookie settings”, tells Clarity consent is withdrawn and it is not loaded again.

To keep bots out, the sign-in, sign-up, contact, opt-out and pre-check forms — and our own staff sign-in — use Google reCAPTCHA. On those pages only, Google receives your IP address, details of your browser and device and how the page was used, and gives us a score of how likely the visitor is a person. It is a security measure rather than analytics, so it runs without the cookie choice; Google does not use it for advertising. It is listed with the other sub-processors.

We may add or replace analytics tools. A new one is described here and added to the sub-processors before it runs, and it runs under the same consent: nothing until you accept.

If you write to us from our contact page, or ask us to stop auditing a site, we keep the address you gave us — and, for a message, what you wrote — encrypted at rest, and use it only to answer you. A request to stop auditing a site is kept for as long as it stands, because it is our record of why we do not crawl that site.

05What we crawl

Only what a storefront serves publicly to an anonymous visitor. Nothing behind a login is fetched, and no order, customer or account data is read — that is a scope decision, not a setting. Our crawler identifies itself on every request and says what it honors and how to turn it away.

The crawler carries no cookie jar. Every request is made as a first-time anonymous visitor, and a Set-Cookie a storefront sends back is discarded: we record the cookie’s name and its flags, never its value. So we hold no session from any storefront we have read, which is the part of this that would matter if we were ever breached.

06Why we are allowed to

Account data, and audits of a domain whose owner verified it and asked for them, rest on our contract with that customer. Audits requested by an agency account, and the anonymous pre-check somebody runs from our home page, rest on a legitimate interest in auditing a publicly served commercial website — balanced by the things that make it bearable for the site being read: a crawler that names itself on every request and links to a page explaining how to refuse it, rate budgets small enough that a storefront built for shoppers does not notice, an owner opt-out that no account tier overrides, and a blocklist that refuses a hostname before a request is made. That balancing test is written down and reviewed at each security review rather than assumed. Part of it is that the site’s verified owner can see who audited it: if you use an agency account, the verified owner of a storefront you audit can see your account’s name — where they verified the domain with a DNS record or a tag in the page head and are not an agency themselves — with when, how often and how deeply you audited it, and we tell them the first time you do. The reports you made stay in your account if they then opt out.

07Where your data lives, and when it is purged

Everything we hold is hosted with our providers: the application and its database on Railway, and the files an audit captures — pages, DOM snapshots, screenshots, PDFs — in Cloudflare R2 object storage. Both are named, with what each can see, in the sub-processor list.

The operator is established in Uruguay, which the European Commission recognizes as providing an adequate level of protection for personal data (Decision 2012/484/EU, confirmed in its 2024 review), so personal data transferred to us from the European Economic Area needs no further safeguard. Where a sub-processor processes personal data outside the region it came from — most of ours are established in the United States — the transfer relies on that provider’s certification under the EU–U.S. Data Privacy Framework where it holds one, and otherwise on the Standard Contractual Clauses in its data processing terms.

Nothing an audit captures is kept for good. Every item has a retention period, set by your plan, and a sweep that runs every day at 03:00 UTC purges what has reached the end of its period — the database rows first, then the stored files they pointed at.

08How long we keep it

Depends on your plan

  • Raw HTML, DOM dumps, screenshots, environment dumps

    Free
    90 days
    Pro
    12 months
    Enterprise
    24 months
    Partner
    24 months
  • Evidence pack

    Free
    90 days
    Pro
    12 months
    Enterprise
    24 months
    Partner
    24 months
  • Page snapshots, findings, reports

    Free
    The 2 most recent audits of each domain
    Pro
    12 months
    Enterprise
    24 months
    Partner
    24 months
  • Whether you found a finding useful

    Free
    The 2 most recent audits of each domain
    Pro
    12 months
    Enterprise
    24 months
    Partner
    24 months
  • Audit progress events

    Free
    30 days
    Pro
    30 days
    Enterprise
    90 days
    Partner
    90 days

The same on every plan

Audit log
24 months
Webhook delivery records
Deleted 30 days after the delivery; a record holds its status and the receiver's HTTP status, never its answer
Support tickets
What you wrote is removed 18 months after the ticket closes; when it was opened, who answered and how long it took are kept. An open ticket is never swept
Sessions and sign-in links
Deleted once they expire
Sign-in history and team activity
24 months, in the audit log; the network address is truncated before it is stored
An invitation nobody accepted
The address is deleted 30 days after the invitation expires
An alert e-mail address nobody confirmed
Deleted when its confirmation link expires, 7 days after the last confirmation e-mail
Payment events from PayPal
Contents removed 90 days after processing; the event id and type are kept
Credit ledger
Kept for the life of the account and deleted with it
Invoices and credit notes
Kept for the statutory period, including after the account is deleted; never changed once issued

When a plan ends or a payment fails, your history is kept on the old plan's terms for 30 days before the new plan's shorter window applies, so a card that fails on a Friday does not delete a year of reports on Saturday.

Be clear about what the sweep reaches, because “we delete it after N months” would be too strong. What expires on the periods above is the raw artefacts — the captured pages, the DOM dumps, the screenshots, the evidence pack and the PDF — together with the findings, the reports, the per-page snapshots and the progress feed. What does not expire is the record that an audit ran and what it scored, the list of URLs we have seen on the domain, the catalog and category rows, and the model output stored against a report. Those persist until the organization is deleted, because the score history and the trend line are read from them. Deleting the organization removes all of it.

09Who else touches it

The providers that process data on our behalf are listed in the terms, with what each one is for and what each one can see. Enterprise and Partner accounts can sign the data processing addendum, which attaches that list as its schedule.

If an admin of your account publishes a share link, the sections they chose are readable by anyone who holds the link until it expires or is revoked. Those pages are marked so search engines do not index them. When somebody opens one we count the view and note when; we do not record who they are, where they came from or which browser they used.

10If you own a storefront we audited

You do not need an account with us, and you do not need to have asked for the audit. If you control the domain, you can tell us to delete what we hold about it and we will, within 30 days of confirming you control it. We will ask you to prove that the same way a customer does — an email at the domain, a DNS record, or a tag in the site’s head — because otherwise the request is an instruction from a stranger to destroy somebody else’s records.

What we delete:

  • Every stored audit of that hostname and everything under it — the captured pages and headers, the DOM snapshots, the screenshots, the bundle evidence, the findings, the reports and their PDFs, and the comparisons between them.
  • Whatever a language model was sent about the site, as it is stored inside those reports and nowhere else.

What survives, and why each one:

  • The record that the audit happened. The audit log keeps the domain, the account that requested it and when. That entry exists to protect you rather than us — it is what lets us tell you who audited your storefront — and it is kept for the period in the schedule above.
  • Benchmark points. They carry no hostname, no account and no audit id, so there is nothing in them to identify as yours and nothing to remove. That is the same property that makes them safe to hold at all; we are not declining, we genuinely cannot find them.
  • The instruction itself. If you also ask us never to fetch the domain again, we keep the hostname on a blocklist, because forgetting it is how we would crawl you again next month. Asking us to stop takes the same proof, and works without an account.

You can also stop us before there is anything to delete. Our crawler page explains how to refuse the user agent, and verifying the domain lets you see which agency accounts audited it and switch off agency audits of it permanently — or for one agency at a time — with no appeal path and no account tier that overrides it.

11Deleting an account

Ask us and we delete the organization. That removes its audits, snapshots, findings, reports, comparisons, alerts, schedules, destinations, memberships, sessions and credit ledger, and queues a purge of the stored files those rows pointed at — the raw HTML, the DOM dumps, the screenshots and the PDFs. Each purge lists its storage prefix empty before it reports itself finished, so “the files are gone” is something we check rather than something we assume.

Three things survive it, deliberately. The audit log stays with the organization detached from it, because it is the record that an audit of somebody else’s domain happened. Invoices and credit notes are kept for the statutory period, because the law requires the seller to keep them; each holds the billing details as they were when it was issued. And a person’s user row survives if they belong to another organization — deleting one customer should not sign them out of another.

It is run by an operator rather than by a button in your settings, and it refuses while a PayPal subscription is still live — cancel first, or we would leave the processor billing a customer that no longer exists.

12Your rights, and complaining about us

Where data protection law applies to you, you have the right to ask what we hold about you, to have it corrected, to have it erased, to get a copy in a portable form, to object to processing we base on a legitimate interest, and to complain to your supervisory authority. As the operator is established in Uruguay, Law No. 18.331 on the protection of personal data applies to what we hold, and its authority is the Unidad Reguladora y de Control de Datos Personales (URCDP). Ask at [email protected]; we answer within one month, and we do not charge for it. Where we must notify a personal data breach, the General Data Protection Regulation sets that at 72 hours after we become aware of it, and we will tell you directly where it is likely to be a high risk to you.