Privacy Policy
Last updated: August 4, 2026
StoreRoast ("we", "us", "our") provides an AI-powered UI audit tool for e-commerce stores, along with optional automations (Back in Stock alerts, competitor tracking) merchants can activate. This policy explains what personal data we collect, why, how it's protected, and the rights you have over it.
1. Who this applies to
This policy covers two kinds of people: merchants who create a StoreRoast account, and storefront visitors — the merchant's own customers who interact with a widget StoreRoast powers (e.g. leaving an email for a Back in Stock alert). We act as the data controller for merchant account data, and as a data processor on the merchant's behalf for storefront visitor data collected through a widget the merchant chose to install.
2. What we collect
- Account data — your email and authentication details, handled by Supabase Auth.
- Store data — the URL(s) you submit for audit, screenshots we capture of those pages, and text scraped from the page (titles, headings, CTAs, meta tags). Raw screenshots and scraped page data are working data, automatically deleted 48 hours after the audit runs — only the final report (score, issues, suggestions) is kept longer, tied to your account. If you connect a store (Shopify, WooCommerce, BigCommerce, Wix, Squarespace), we store the connection credentials needed to read products/orders and install the on-site widget.
- Audit results — the AI-generated report (score, issues, suggestions) tied to your account.
- Integration keys — if you connect Mailchimp, Klaviyo, Google Analytics, or Google Search Console, we store your API key or OAuth token encrypted at rest (AES-256-GCM); the decryption key is never stored alongside it. We never see or log the plaintext key after the initial connection check.
- Storefront visitor data — if you install our Back in Stock widget, we collect the email addresses your own customers submit to be notified, solely to send that notification.
- Billing data — subscription and payment details are handled directly by Stripe; we store your plan and Stripe customer ID, never your card details.
- Usage and log data — basic technical logs (timestamps, error traces, IP address at request time) kept for security and debugging.
3. Cookies
We use only what's strictly necessary to run the service: a session cookie from Supabase Auth to keep you signed in, and a short-lived cookie (auto-expires in 10 minutes) set only during a Google OAuth connection to prevent CSRF attacks. We don't use third-party advertising or cross-site tracking cookies. If we later add product analytics (e.g. Vercel Analytics), it will be privacy-respecting and cookie-light, and this section will be updated accordingly.
4. Legal basis for processing (EEA/UK users)
We process account and store data under contractual necessity — it's required to deliver the service you signed up for. Billing data is processed under a mix of contractual necessity and legal obligation (invoicing, tax). Where you connect an optional integration, processing is based on your explicit action and consent to activate it. You can withdraw that consent at any time by disconnecting the integration.
5. How we use it
To run the audit you request (screenshots and scraped text are sent to Anthropic's Claude API for analysis), to operate features you activate, to bill your subscription, to secure the service against abuse, and to operate and improve the product. We do not sell your data, and we don't use your store's content to train third-party AI models beyond what's needed to generate your own audit in that single request.
6. Automated processing
Your audit report is generated by an AI model (Claude, by Anthropic) based on screenshots and text you submit. This is a business analytics tool, not a decision made about you as an individual — it doesn't produce any legal or similarly significant effect on a person, so it falls outside GDPR Article 22's automated-decision-making protections. You're always free to disregard or act on the suggestions as you see fit.
7. Google user data
If you connect Google Analytics or Google Search Console, StoreRoast's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request only the minimum read-only scope needed to power the features you activate. Google Analytics traffic and funnel numbers are shown in your dashboard, and — because that's the feature you're activating it for — are also included as text in the audit prompt sent to Anthropic's Claude API, so Roast audits can weigh issues against your real conversion data instead of guessing. Search Console ranking data (positions, clicks, impressions) is shown in your dashboard and is not sent to any AI model.We never use Google user data to serve ads, never sell it, never share it with third parties for their own independent purposes, and never use it to train AI models. You can revoke StoreRoast's access at any time from your Google Account's third-party permissions, or by disconnecting the integration inside StoreRoast — either immediately deletes the stored token.
8. Who we share it with
- Anthropic (Claude API) — screenshots and page text, to generate your audit; and, if Google Analytics is connected, your traffic/funnel summary, so the audit can be prioritized against your real conversion data.
- Screenshotone — to capture screenshots of the URLs you submit.
- Supabase — database and authentication hosting.
- Stripe — payment processing.
- Resend — transactional email delivery (reports, notifications).
- Vercel — application hosting.
- Mailchimp / Klaviyo / Google Analytics / Search Console — only if you explicitly connect them under Integrations; your data flows through them only for the feature you activated.
Each of these processes data under their own privacy terms as our sub-processors, scoped strictly to the function above. We don't share your data with anyone for their own independent marketing purposes.
9. International data transfers
Our sub-processors operate infrastructure in the United States and/or the EU. Where personal data of EEA/UK users is transferred outside those regions, it's done under those providers' own standard contractual clauses or equivalent safeguards.
10. Data retention
Raw screenshots and scraped page data captured to run an audit are working data — automatically deleted 48 hours after capture, regardless of account status. The audit report itself (score, issues, suggestions — no images) is kept for as long as your account is active, plus a reasonable period afterward to comply with legal/tax obligations (e.g. billing records). Integration keys (Mailchimp, Klaviyo, Google Analytics, Search Console) are deleted immediately when you disconnect them, and your store connection can be removed at any time from Settings — both delete the stored credential immediately, not just the display. Storefront visitor emails (Back in Stock leads) can be cleared by the merchant at any time from their dashboard, and are automatically deleted along with the rest of the store's data if the merchant deletes their account. Deleting your account deletes account data, audit reports, integration credentials, store connection, and collected leads, without a recovery window. You can request full deletion of your own account data at any time.
11. Security
Third-party API keys and OAuth tokens (Mailchimp, Klaviyo, Google Analytics, Search Console, Shopify) are encrypted at rest (AES-256-GCM) and are never written to your browser's local storage or sent from your browser to our server — the server resolves them itself, server-side, from the encrypted copy, so they're never in a place a browser-based attack (like XSS) could read them. Database access outside your own account uses server-only credentials — your data is never queried directly from a browser. If we become aware of a data breach affecting your personal data, we'll notify you without undue delay as required by applicable law.
12. Your rights
Depending on where you live, you may have the right to access, correct, export, delete, or restrict the processing of your personal data, and to object to or withdraw consent for certain processing. Most of these you can exercise directly from your dashboard settings; for anything else, contact us below and we'll respond within the timeframe required by applicable law.
If you're in the EEA/UK, you also have the right to lodge a complaint with your local data protection authority. If you're a California resident, you have equivalent rights under the CCPA/CPRA, including the right to know what personal information we collect and to request its deletion — we do not sell personal information.
13. Children's privacy
StoreRoast is a business tool intended for merchants and is not directed at children. We don't knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we'll delete it.
14. Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected by updating the date at the top of this page; continued use of StoreRoast after a change means you accept the update.
15. Contact
Questions about this policy, or to exercise any of your rights: storeroast@gmail.com
This policy describes our actual data practices in plain language. It isn't a substitute for tailored legal advice — if you need a formal GDPR/CCPA compliance opinion for your jurisdiction, have it reviewed by a lawyer.