Skip to main content
CartVigil
ProductMagentoAgenciesPricingSecurity
Log inStart free

Provider-review draft

Privacy notice

The intended privacy notice for CartVigil account, billing, support, and public-store monitoring data.

Draft — legal review required before commercial launch

This page documents the intended product policy and commercial flow. It is not a representation that counsel has approved final wording or that a legal entity has been inserted where still required.

Draft updated: 8 August 2026

1. Controller and contact

The final data-controller legal name, registered address, registration identifiers, and representative details must be inserted after legal review. Privacy questions can be sent to privacy@cartvigil.com.

2. Information we expect to process

  • Account identity, work email, authentication, workspace, and role data.
  • Billing plan and normalized payment status; CartVigil does not store card data.
  • Authorized public store URLs, configuration, run results, incidents, and redacted evidence.
  • Contact messages, support correspondence, audit records, security events, and service logs.

3. Why information is used

Information is used to provide and secure accounts, operate authorized monitoring, deliver transactional notices, support billing, answer requests, prevent abuse, maintain auditability, and meet legal obligations. The final lawful-basis mapping requires counsel review.

4. Monitoring boundaries

CartVigil uses public storefront pages and synthetic guest data. It does not require Magento Admin, analytics, customer databases, payment credentials, or production logs. Captured target-site text is escaped and evidence is redacted before display.

5. Service providers and transfers

Expected infrastructure and providers include DigitalOcean for hosting, WayForPay for billing, and Resend for transactional email once each integration passes its release gate. Final processor identities, locations, transfer safeguards, and data-processing terms must be verified before launch.

6. Retention

Successful temporary screenshots are deleted within 24 hours by default; failed screenshots within 30 days; traces and general logs within 14 days; and critical incident evidence within 90 days unless a configured or legal requirement applies. Account, billing, webhook, audit, and legal records follow separate documented schedules.

7. Security

CartVigil uses TLS, server-side secrets, isolated browser contexts, workspace-scoped access, protected administration, structured redaction, and bounded evidence policies. No system can promise absolute security.

8. Your choices and rights

Depending on applicable law, you may have rights to access, correct, delete, restrict, object, or receive certain personal information. Verification, exceptions, complaint routes, response timing, and supervisory-authority details require final jurisdiction-specific review.

9. Cookies and analytics

Authentication may require essential session storage. CartVigil records a bounded first-party signup funnel, selected plan, campaign parameters, referral code, and referrer hostname without third-party scripts or cross-site tracking. Names, email addresses, full referrer paths, and monitored-store URLs are excluded from the aggregate funnel. Optional third-party marketing analytics are not selected; any future optional analytics must follow applicable consent requirements before loading.

10. Changes

Material changes should be dated and communicated through an appropriate service or account notice. The effective-date and notice procedure must be finalized before launch.

CartVigil

Automated Magento purchase-flow monitoring.

Know when customers can’t buy.

Product

How it worksMagento monitoringFor agenciesPricing

Company

SecurityFAQContactSupport

Legal

TermsPrivacyRefund policySystem status

© 2026 CartVigil. English only.

Monitoring stops before placing an order.