Privacy policy
13 September 2026
We read your store’s public pages, nothing more, and the rest fits on one page.
What this site does not do
It sets no advertising cookie, no analytics cookie and no third-party cookie. It sets two at most: the one that remembers the language you picked, and your session cookie if you open an account. Both are described below.
It runs no analytics, no advertising pixel, no heatmap and no session recording.
It loads nothing from an outside server: the typefaces ship with the site, and there is no third-party script or image. When you run a store analysis, our server reads that store's public pages, never your browser.
It asks for no email address and no phone number to run the diagnostic. The list of findings shows without an account. Only the estimate in hours requires a free account, because it exposes how we price an intervention.
What happens to your store address
The address you type goes to our server, which reads the store's public pages, the ones any visitor already sees. We sign in to no account, we touch no order and no customer data, and nothing on your store is changed.
We hold the result of that read in memory for thirty minutes at most, so that the same store is not fetched twice in a row. After that it is gone. The address is written to no database and to no log, unless you ask for a repair plan.
Your answers to the diagnostic questions stay in your browser and disappear when you close the tab. They are written to no cookie, no local storage and no server.
If you open a repair file, the store address is kept there, since it is the very subject of the work.
If you open an account
The account exists to follow a repair: the quote, the work log and the proof of restored tracking are filed there. It is never required to run the diagnostic, which stays free and anonymous.
We then keep your email address and the date the account was opened. Nothing else. The password is not stored in clear: our authentication host keeps only an irreversible hash that nobody, ourselves included, can read back.
A session cookie is set when you sign in. It only keeps you identified from one page to the next, it tracks nothing and it never leaves this site. It is a strictly necessary cookie under Quebec's Law 25 and the GDPR, so it is exempt from consent. Signing out removes it.
Account data is hosted by Supabase on infrastructure located in Canada, Canada Central region. It does not leave the country.
You can ask for the account to be closed and its contents erased at any time, by email.
If you write to us
The button that requests a repair plan opens your own mail client with a message you review before sending. Nothing is transmitted until you press send, in your own mail software.
We then keep your message and your address to handle the request, for the duration of the commercial relationship. You can ask for deletion at any time by replying to any of our messages.
We never sell, rent or share an address.
Why there is no consent banner
A consent banner exists to collect your agreement before trackers are set. This site sets none. There are only two cookies, and neither is a tracker: the session cookie, without which a sign-in would not survive a page change, and the one that remembers the language you picked, without which your choice would be forgotten on your next visit. Neither carries an advertising identifier, neither leaves this site, and the law files both among the cookies exempt from consent.
If we ever added a measurement tool, that banner would appear, and this page would be updated first.
Your rights
Under Quebec's Law 25 and the General Data Protection Regulation, you may request access, correction, deletion or portability of any personal information we hold about you.
Requests are made by email and answered within thirty days.
The person responsible for personal information protection is reachable at the same address as commercial contact.
Hosting and security
The site is served over strict HTTPS, with a content security policy that forbids any external script, and headers that prevent it from being framed by another site.
What you paste into the old scripts field never reaches a server: that reading happens entirely in your browser, so nothing can leak. The store address you enter is the only diagnostic data sent to the server. It is used to fetch that store's public pages, held in memory for half an hour so the store is not fetched twice, and written to the database only if you request a quote.
The account database is protected by row level security, enabled by default on every table: a signed-in person can read only their own records, and a signed-out visitor can read nothing at all.