US Privacy Notice
Last updated: September 5, 2026
This notice covers the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"), and applies alongside the Privacy Policy. Where the two differ for a California resident, this one governs.
It is written for two audiences, and the distinction matters throughout:
- If you are a business using StorePilot on your website — you are the Business under the CCPA. The obligations to your consumers are yours. §2 tells you what we do and do not do with the data, so you can write your own notice accurately.
- If you are a visitor to a website that uses StorePilot — the website you visited is the Business, and your rights run against them. §6 explains how to reach them and us.
1. We do not sell or share personal information
StorePilot does not sell personal information, and does not share it for cross-context behavioral advertising, as "sell" and "share" are defined in Cal. Civ. Code §1798.140(ad) and (ah). We have not done so in the preceding twelve months.
We are not a data broker and are not registered as one, because we have no relationship of that kind with any consumer.
This is why you will not find a "Do Not Sell or Share My Personal Information" link on our site. That link is required of businesses that sell or share; publishing one where nothing is sold would misdescribe what we do. If our practices ever change, the link will appear before the practice does.
2. Our role: Service Provider
We process personal information as a Service Provider under §1798.140(ag), on behalf of the business whose website collects it. As required by §1798.100(d), we contract — in the Data Processing Agreement, which incorporates this section — that we shall not:
- sell or share the personal information;
- retain, use or disclose it for any purpose other than the specific purpose of performing the services set out in the Terms of Service, including retaining, using or disclosing it for a commercial purpose other than those services;
- retain, use or disclose it outside the direct business relationship between us and the business;
- combine it with personal information received from, or on behalf of, any other person, or collected from our own interactions with a consumer, except as §1798.145(ah)(4) permits.
We certify that we understand these restrictions and will comply with them. We further undertake to comply with all obligations applicable to service providers under the CCPA and its regulations, including 11 C.C.R. §7051, and to provide personal information in our care the same level of privacy protection as the CCPA requires of businesses.
We will notify the business if we determine we can no longer meet these obligations, and we grant the business the right to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.
3. Categories collected
Collected on behalf of the business operating the website, in the statutory categories of §1798.140(v):
| Statutory category | What it is here | Collected always? |
|---|---|---|
| Identifiers (B) | A first-party browser identifier (sp_vid), a session identifier, IP address, and — where the website has logged-in areas — its own user ID | Yes |
| Customer records (C) | Name, email address, telephone number, and city/state/country, where a form or checkout collects them. Street address and postcode are refused at collection and never stored. | Only with lead capture enabled |
| Commercial information (D) | Cart contents, cart totals, order identifiers and amounts | Only with lead capture enabled |
| Internet or network activity (F) | Pages viewed, time on page, referrer, clicks, scroll depth, rage and dead clicks, session recordings, error diagnostics | Yes |
| Customer records (C) | Chat transcripts, where the business connects a chat provider — the messages as typed, plus the name and email the provider reported | Only with a chat provider connected |
| Geolocation data (G) | Country only, derived from the IP address. We do not collect or derive precise geolocation. | Yes |
| Inferences (K) | An "interest score" per session — a number derived from engagement and frustration signals, used to order the recordings list | Yes |
Not collected: personal characteristics (E), biometric information (H), professional or employment information (I), education information (J), and audio or visual recordings other than the DOM-based session replay described above. Camera, microphone and canvas capture are switched off in the recorder.
Sources. Directly from the consumer's browser, and from the website's own server where the website enriches a record (its user ID, cart contents, and the IP address it observed).
Business purposes (§1798.140(e)): providing the analytics, monitoring and replay services; detecting and debugging errors; security and fraud prevention; and quality assurance.
Disclosure. To the business whose website collected it, and to the sub-processors engaged under the Data Processing Agreement §4, whose current list is available on request. Disclosure for a business purpose is not a sale or a share.
Retention. Each category has a defined period, published in the Privacy Policy §4 and enforced nightly.
4. Sensitive personal information
We do not intentionally collect sensitive personal information as defined in §1798.140(ae). In particular:
- No precise geolocation. Country resolution only.
- Account credentials. Every form input is masked in session recordings,
passwordfields are never captured by the lead collectors, and fields whose name is credential-shaped are dropped before storage. - Contents of communications. A message typed into a contact form is stored, because delivering that message to the business is the service the business asked for. It is not disclosed to anyone else.
We do not use or disclose sensitive personal information for the purpose of inferring characteristics about a consumer. Under §1798.121(d) the right to limit its use therefore does not apply to our processing.
Sensitive information can nevertheless reach the Service through a business's own pages — a health retailer's product names, a form field asking something we did not anticipate. Businesses should exclude such pages under Settings → Privacy → Excluded URLs. Consumer-health-data laws — Washington's My Health My Data Act and Nevada's SB 370 — define "consumer health data" broadly enough that a wellness or supplements shop's browsing trail can qualify; a business in their scope should treat the pages that reveal it the same way: exclude them, or gate collection on consent.
5. Opt-out preference signals — Global Privacy Control
We honour Global Privacy Control, and we honour it without any configuration.
There is no setting, on any site, that turns this off. It is enforced in two independent places:
- In the browser. Our collectors check
navigator.globalPrivacyControlbefore doing anything at all — before writing an identifier, before starting a recording, before sending a request. A visitor with GPC enabled has nothing written to their device. - On the request. The Platform refuses to store anything arriving with a
Sec-GPC: 1header, whatever the site's settings say and even if the page has explicitly asserted consent. This covers the paths our JavaScript never touches — most importantly a contact-form submission, which the website's own server forwards to us with no script of ours involved.
DNT: 1 is not treated the same way and is ignored. Do Not Track is not a universal opt-out mechanism under any US state privacy law: the W3C discontinued the specification in 2019, and browsers that still send it describe it as advisory. GPC, above, is the signal these laws recognise, and it is the one we honour.
Because we neither sell nor share personal information, GPC does not have a sale to stop. We treat it as a request not to be tracked and stop collecting, which is more than the signal strictly requires of a service provider in our position.
6. Your rights, and where to exercise them
A California resident has the right to know, to delete, to correct, to opt out of sale or sharing, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of them.
Exercise these rights with the website you visited, not with us. As a Service Provider we hold no direct relationship with you, and we have no way to verify that a request concerns you rather than someone else. The business that operates the website can identify you and is obliged to respond within 45 days.
If you cannot identify or reach that business, contact us at contact@store-pilot.net and we will identify the relevant business where we can, or forward your request to them. We will not act on it directly, and we will not use anything you send us for any purpose other than processing that request.
Businesses using StorePilot may exercise a consumer's rights through the dashboard: the visitor detail page shows everything held, and a single erasure action removes it. See the DPA §8.
Authorized agents. An agent acting for a consumer should approach the business. Where an agent contacts us, we will ask for written authorisation and forward the request as above.
Minors. We do not knowingly collect personal information from anyone under 16, and — since we neither sell nor share — the opt-in requirements of §1798.120(c) do not arise. Businesses must not use the Service to collect data from children in breach of the Terms of Service or of COPPA.
7. Other US state privacy laws
Comparable laws in Virginia, Colorado, Connecticut, Utah, Texas and elsewhere use different terms — "processor" rather than "service provider", "targeted advertising" rather than "sharing" — for substantially the same arrangement. Our position under each is the one described above: we process on a business's documented instructions, we do not sell personal data, we do not process it for targeted advertising or profiling with legal effects, and we honour universal opt-out signals including GPC.
Contact: contact@store-pilot.net