Skip to content

Legal

Terms and conditions

The agreement for merchant accounts, the additional clauses that govern agency accounts, and the third parties that process data for us.

In force from
Owner
Martin Clavell
Operated by
BEMATIC ONLINE SAS

At a glance

  • SuiteAnalytics, its software and its code are the work and property of Martin Clavell.
  • A report is a measurement of a sample at one moment — not a certification, and not advice.
  • You may only audit storefronts you own or are authorized to audit.
  • Plans and add-ons are PayPal subscriptions; canceling stops future charges.
  • A verified owner can block agency audits of their domain, with no appeal and no override, and can see which agency accounts audited it.
  • Our liability is capped at the greater of twelve months of fees and €100.00.

01Who we are, and who owns it

The agreement is between the account holder and BEMATIC ONLINE SAS, which operates SuiteAnalytics and is owned by Martin Clavell. Martin Clavell is the author of the system and its code.

SuiteAnalytics — the service, its software, its source code, its checks and rules, its report formats and its documentation — is the work and property of Martin Clavell. These terms give you the right to use the service while your account is in good standing; they transfer no ownership of it and grant no license to its code. The reports it produces for you are yours.

02What the service is

An automated technical analysis of a publicly served SuiteCommerce storefront. We fetch pages the way a search engine and a shopper each receive them, run a fixed set of checks over what we captured, and produce a report that cites the evidence behind every finding.

03What it is not

This section limits what you may rely on, and it is the most important one on the page.
  • Not a certification, and not an assurance. A report is a measurement taken at one moment against one sample of your storefront. It certifies nothing, it is not a penetration test or a security audit, and it is not an accessibility conformance statement under any standard.
  • Not complete. An audit reads a sample bounded by the page budget of the depth you chose. A check that could not run is reported as skipped and is never reported as a pass — but a clean report means the checks that ran found nothing, not that your storefront has no defects.
  • Not advice. Findings and suggested remediations are information. They are not legal, accessibility, security or tax advice, and some are produced by a language model interpreting evidence, which the report labels as such. Verify a finding before you act on it in production.
  • Not a substitute for your own testing. You remain responsible for what you deploy to your storefront.

04Merchant accounts

  • You may request audits of hostnames you have verified, and of no others. Verification is an email address at the registrable domain, a DNS TXT record, or a tag in the Site Management Tools head. It lapses after twelve months and whenever the NetSuite account serving the hostname changes. A sandbox under the same registrable domain as the verified domain it belongs to may inherit that domain’s verification, and lapses with it.
  • An audit makes your NetSuite account regenerate pages. That cost is yours, it is bounded by the page budget of the depth you chose, and the budget is stated before you start.
  • Reports are yours. We use anonymised, de-identified measurements — no hostname, no account — to produce the benchmark a report compares you against.
  • On a paid plan an admin may publish part of a report through a share link. Anyone who has the link can read the sections you chose until it expires — at most 30 days after you create or renew it — or until you revoke it. Only an audit of a hostname you have verified can be shared, except that a partner account may share its own full audit of a client’s site for at most 7 days, carrying the partner’s name, and never once the site’s owner has opted out of agency audits — an opt-out also stops every such link already made. What you publish that way is your decision and your responsibility.
  • We do not fetch anything behind a storefront login, and we do not read order, customer or account data.

05Plans and add-ons

  • Plans. A paid plan is a PayPal subscription, billed monthly or yearly in advance. A change of plan applies its price from the next payment; an upgrade takes effect when PayPal confirms it and a downgrade when the paid period ends. Canceling stops future charges, and the plan runs to the end of the period already paid for.
  • Partner terms. A Partner term is six months, paid in advance against our invoice. About a month before a term ends we issue the invoice for the next one, due the day the current term ends, and remind your owners as that day approaches. The next term starts when the current one ends, or on the day it is paid if that is later, so paying early never shortens a term. A term invoice may also be paid by bank transfer where we agree it with you, for its full amount; the term then starts as if it had been paid on the day the transfer arrived. If we cancel a term invoice, we issue a credit note for all of it, and nothing is owed on it. Your first term replaces the plan and add-ons the account had: their subscriptions are cancelled when the term starts, and anything still unpaid on them is written off.
  • Unpaid balances. If a payment for a plan or an add-on fails, share links to your reports stop working at once, and 3 days later the account is placed on hold until the payment is made or you cancel the plan instead. The hold does not end on its own, and cancelling a subscription at PayPal does not settle what it owes. You can pay the outstanding balance from your account at any time, or cancel the plan from the same page: the subscription ends, the unpaid amount is written off, and the account moves to the free plan. Once a payment of the balance has been accepted, it can be neither made again nor cancelled instead until PayPal confirms it. The same hold applies when a Partner term invoice is past its due date or the term ends with the invoice for the next one unpaid, while a payment is disputed, and when we suspend a Partner account or place a hold on an account, in which case we tell you why and, where it has one, when it ends. A partner term invoice cannot be cancelled instead: it is held until it is paid. While an account is on hold, audits, reports, domains, PDFs, the API, schedules and alerts are unavailable; billing, settings, the team and support stay available. Nothing is deleted while an account is on hold, and everything is available again as soon as the balance is paid. If you cancel the plan instead, audits beyond what the free plan keeps are removed 30 days after it is cancelled, after we have written to you.
  • Sandboxes. A plan may include sandboxes, as its pricing states: a hostname you verify and link to one of your verified domains as a test copy of the same storefront. A sandbox uses no domain slot, and its audits spend credits as any audit does. A sandbox on a different registrable domain from the domain it belongs to, or whose NetSuite account we cannot match to it, is reviewed by us before its next audit, and we may decline it. A sandbox is covered only while the domain it belongs to is verified and within your plan; one beyond what your plan and add-ons cover is paused, not unlinked.
  • Add-ons. On a paid plan you may add extra domains, extra seats, extra sandboxes and monthly credits (in blocks of 30 credits a month), in any quantity, at the price per unit shown when you buy. Each add-on is its own PayPal subscription, billed monthly or yearly in advance and invoiced separately from the plan.
  • Changing an add-on. A new quantity is billed from the add-on’s next payment, with no proration. More units count as soon as PayPal confirms the change; fewer count from that next payment, because the current period is already paid for. PayPal may ask you to approve a change.
  • Canceling an add-on. Canceling stops future charges; the add-on keeps counting until the end of the period already paid for, and that period is not refunded.
  • When the plan ends. Add-ons count only on a paid plan. If your account returns to the free plan, its add-ons stop counting and we cancel their PayPal subscriptions so that you are not charged for them. Nothing is deleted: domains beyond what the account covers stay verified but are not audited, sandboxes beyond it are paused but stay linked, and teammates beyond its seats are suspended until there is room again.
  • Monthly credits. Credits from a plan or a monthly-credits add-on expire at the end of the period they were granted for; credits bought as a pack keep their own expiry.
  • Complimentary add-ons. We may grant an add-on at no charge. It is shown on your billing page with its note and any end date, and we tell the account’s owners a week before a dated one ends. We may end a complimentary add-on; ending it follows the same rules as a plan ending, and nothing is deleted.
  • Refunds. A full refund of an add-on’s payment ends that add-on at once, and credits it granted are reversed.

06What you promise us

  • Authorization. You warrant that for every hostname you ask us to audit you are the owner, or you are authorized by the owner to request it. Verification is how we check that, and it is a check rather than a substitute for the warranty.
  • Indemnity. You will indemnify us against claims, losses and reasonable costs arising from an audit of a hostname you were not authorized to request, from your use of a report in breach of these terms, or from content you asked us to fetch that infringes somebody’s rights.
  • Acceptable use. No attempt to audit infrastructure you do not control, no probing of our own systems, no circumventing rate or breadth limits, no reselling access, no copying or reverse-engineering the service, and no use of it to build a census of a market.
  • Accuracy. The account and billing details you give us are true, and you keep them current.

07Availability, suspension and termination

The service is provided as it stands and as it is available. We offer no uptime commitment and no service credits, and we may change, suspend or withdraw a feature. We may suspend or close an account immediately where we reasonably believe it is being used to audit hostnames without authorization, to probe our systems, or in breach of the acceptable use above; and on notice for non-payment. You may close your account at any time. A paid term already invoiced is not refunded on early termination, because the remainder is already paid.

08Limits on our liability

Nothing in these terms limits or excludes liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for anything else that the applicable law does not permit to be limited. If you contract as a consumer, your statutory rights are unaffected by anything below. Liability owed directly to a data subject under data protection law is owed to that person and is not affected by any term agreed between us and a customer.

Subject to that paragraph, and to the extent the applicable law permits:

  • We give no warranty that the service will be uninterrupted, that a report will be complete or free of error, or that acting on a finding will produce any particular result. All warranties, conditions and terms implied by statute or common law are excluded so far as the law allows.
  • We are not liable for loss of profit, revenue, business, goodwill, anticipated savings, search ranking or data, nor for any indirect or consequential loss, however arising.
  • We are not liable for loss arising from your acting on a finding without verifying it, from a defect in your storefront that an audit did not detect, or from a change a third party made to your NetSuite account or your theme.
  • Our total liability arising out of or in connection with the service, whether in contract, tort including negligence, or otherwise, is capped in aggregate at the greater of the fees you paid us in the twelve months before the claim arose and €100.00.

09Agency and vendor accounts

A partner account may audit a storefront it has not verified. These six clauses are what stands in for the merchant’s consent, and they are why partner accounts are approved by hand rather than by card.

  1. Legitimate interest. Each domain audited is a client or a prospect you have a genuine commercial interest in. Building a market census is not one.
  2. No resale. A report may be shown to the merchant it describes and used in your own engagements. It may not be sold, syndicated or published as a dataset. Aggregate commentary is fine; findings attributed to a named merchant are not.
  3. Breadth limits are contractual. 5 new distinct domains per day and 40 per rolling thirty days for paid audits, within a fair-use credit pool. The first paid audit of a domain you have never paid to audit costs 3 times the usual credits. Your own active sandbox of a domain you already audit is not a new domain. Quick audits are free, within fair use: up to 50 a day, each site once every 6 hours (its www, bare and subdomain addresses count as one site), and up to 25 sites a day you have not audited before. Free audits are fair use: past any of those numbers an audit is refused until its window reopens, never charged, and a free audit waits behind paid ones. Weekly scheduled audits cover at most 10 of your client sites at once, and a schedule of a site whose owner opts out of agency audits is switched off. Circumventing the limits with multiple accounts or shared credentials ends the contract without refund.
  4. Term. Six months minimum, paid upfront by invoice. Early termination refunds nothing, because the remainder is already paid.
  5. Add-ons on a term. Add-ons are sold beside a term as beside a plan, except extra domains and extra sandboxes: a term’s domains and its sandboxes per domain are unlimited, so they would count for nothing. When the term ends, its add-ons stop counting and we cancel their PayPal subscriptions so that you are not charged for them.
  6. Opt-out is absolute. A verified owner may block partner audits of their domain — of one hostname, or of every hostname under the domain where their verification covers it, and of the sandboxes they link to it — and anybody who proves they control a site may ask us to stop auditing it. There is no appeal path through support, and no account tier that overrides either. The owner may also refuse one partner account while allowing the rest, or allow one while refusing the rest; an allowance never overrides a request somebody proved, or a block. An opt-out or a refusal stops new audits and switches off your weekly audits of the site, and we tell you so without naming the owner. The reports you already made of the site stay with you.
  7. Audit. Every partner audit is logged with the domain, the user and the report id, and we disclose that log to the merchant who owns the domain: an owner who verified the domain sees, for every site under it, which partner accounts audited it, when, how often and how deeply, and how many of their attempts were refused. We show partner account names to an owner who verified with a DNS record or a tag in the page head and is not a partner account; to other owners we show counts. We tell the owner the first time each partner account audits their site, naming it on the same terms.

10If you are a merchant we audited

You do not need an account to stop us. Our crawler page explains how to block the user agent outright. Verifying your domain also lets you see which partner accounts audited it, switch off partner audits for it permanently or for one partner account at a time, and you may ask us to delete what we hold about your storefront — the privacy notice says what that covers, what survives it and how long it takes.

11Sub-processors

The third parties that process data on our behalf, what each is for, and what each can see. The list is generated from the same module the product calls, so a provider added to the code and not to this list is a test failure rather than an omission you discover. Data is hosted with them and purged on the schedule in the privacy notice.

Customers are notified before a sub-processor is added. Enterprise customers may object.
Sub-processorPurposeWhat it can see
RailwayHosting, PostgresEverything the application holds, at the infrastructure level
Cloudflare R2Object storage: HTML, DOM dumps, screenshots, bundles, PDFsStored objects
PayPalPaymentsThe payer’s PayPal account and payment instrument, and what is being paid for. We never see card data
ResendTransactional emailRecipient address and the body of our own emails
SentryError monitoringStack traces and request metadata, allowlist-scrubbed
OpenAIclassifier, analyst and writer model rolesRedacted evidence slices only
AnthropicSecond adapter for the same roles, switchable per role by configurationRedacted evidence slices only
GeneratePDFPDF renderingThe report Markdown we send it, for an account entitled to a PDF, from our API service only
Google (Google Analytics)Website analytics on our public pages, behind a consent bannerPages viewed, referrer, device, browser and approximate location on public pages; a cookie identifier only after you accept. Never signed-in pages or reports
Microsoft (Clarity)Session recordings and heatmaps of our public pages, only after you acceptHow a public page was used — clicks, scrolls, mouse movement and the page as shown — with form contents masked. Never signed-in pages or reports
Google (reCAPTCHA)Telling people from bots on the sign-in, sign-up, contact, opt-out and pre-check forms and the admin sign-inOn those pages only: your IP address, browser and device details and how the page was used, to produce a score. Not used for advertising

What the two model providers receive. Only the evidence slice for the dimension being analyzed: extracted facts — titles, canonical URLs, header names, configuration paths, module ids, timings, accessibility rule ids, catalog counters — and the storefront text the evidence pack already carries, which is titles, meta descriptions, og: values, headings and category and item names. The pack holds no page body text and no item description. A redaction check runs on the rendered block before any call, and no account holder’s email, name, address or billing detail can reach a slice: there is no code path that puts an account row into an evidence pack.

Both providers are configured for zero or minimum retention and no training on our traffic. That is a setting in each provider’s console rather than something our code can prove, so it is verified by a person before the first production call and re-verified at each security review.

Notice and objection. Customers are notified before a sub-processor is added. Enterprise customers may object. The data processing addendum attaches this list as its schedule. Objections and questions about it go to [email protected].

12Governing law and disputes

These terms, and any dispute or claim arising out of or in connection with them or the service, are governed by the laws of the Oriental Republic of Uruguay. The the courts of Montevideo, Uruguay have exclusive jurisdiction to settle any such dispute.

If you contract as a consumer, this does not take away the protection of the mandatory consumer law of the country where you live, and you may also bring a claim in the courts there.

13Changes, and the rest

We may change these terms; the version in force is the one on this page, with its date at the top, and we will tell account holders by email before a change that materially reduces what they get. If a clause is held unenforceable the rest stands. Failing to enforce a term is not a waiver of it. These terms and the documents they link to are the whole agreement. Questions about them go to [email protected].

14Your data

What we hold, where it is hosted and for how long is in the privacy notice; who processes it is in the sub-processors section above. Enterprise and Partner accounts can sign the data processing addendum.