Privacy policy
Dernière mise à jour : September 5, 2026
Who is responsible
YIAASK, Inc., a Delaware C Corporation, [business address]. For any question about your data: [email protected].
What we collect
Buying an audit requires two pieces of information, and we collect little beyond them:
- Your order: the email address you give us and the URL of the store to audit.
- Audit results: the agents’ execution traces, screenshots of public pages of the audited store, scores and frictions.
- Payment: the Stripe session and payment identifiers. No card data ever passes through our servers.
- Security: IP address and user-agent of requests, and rate-limiting logs.
No account is created and no password is stored: the report is reached through a secret link.
What we never collect
Our agents never enter a password, payment details, or real personal data on the sites they test. They never create an account, and they only reach publicly accessible pages. No internal merchant data is ever read.
Why we process it
- To perform the contract: run the audit you paid for and deliver the report.
- Legitimate interest: security, abuse prevention, and aggregated statistics used to improve the product.
- Legal obligation: keeping records required for accounting and tax purposes.
Service providers
- Google (Gemini API) — runs the shopping agents. What is transmitted is the content of public pages of the store being audited.
- Stripe — payment processing.
- Hostinger — hosting of the application and the database, on a server located in Boston, Massachusetts, United States.
- [SMTP provider] — delivery of transactional email.
This list names the providers actually in use. If the model provider changes, this page is updated before the change takes effect.
How long we keep it
- Orders and reports: kept so your link keeps working; deleted on request.
- Screenshots and execution traces: kept with the report they document.
- Rate-limiting logs and expired sessions: purged automatically within 7 to 30 days.
- Billing records: for the period required by applicable tax law.
Your rights
Write to the contact address above to access, correct, or delete your data, or to obtain a copy of it. We answer every request, whatever your jurisdiction.
California residents. Under the CCPA/CPRA you may request disclosure of the personal information we collect, request its deletion, and correct it. We do not sell or share personal information as those terms are defined by that law, and we do not discriminate against anyone for exercising these rights.
Visitors in the European Economic Area and the United Kingdom. Where the GDPR or UK GDPR applies to you, you have rights of access, rectification, erasure, restriction, objection, and portability, and you may lodge a complaint with your supervisory authority. Our representative under Article 27 GDPR: [EU representative — name and address]. Because our servers are in the United States, your data is transferred there; the safeguard we rely on is [standard contractual clauses or other safeguard].
Cookies
Buying an audit and reading a report require no cookie at all. The application sets a single strictly necessary cookie only if you sign in to an account. No advertising cookie and no third-party tracker is ever set.