StoreProof Public Beta Privacy Notice
StoreProof is a public-beta service from RXR Code for testing public storefronts. This notice explains the information StoreProof currently processes when someone starts or receives a scan.
Information StoreProof processes
When you submit a storefront, StoreProof records the submitted URL, normalized URL, domain, scan timestamps and status, scan results, findings, scores, and related technical evidence. Evidence can include screenshots of public storefront pages, browser console or page errors, and failed network request URLs and status codes.
StoreProof also uses request IP information for rate limiting. The IP address is used in short-lived Redis rate-limit keys rather than stored in the scan record itself. If you choose to email a report, the recipient email address is sent to the configured email-delivery provider for that request; the StoreProof scan database does not persist that email address.
If you sign in with Google, StoreProof stores your Google account identifier, verified email address, workspace membership, storefront domains and cadence preferences, and manual authorization records. A necessary HTTP-only cookie maintains your session for up to seven days; signing out revokes that session. Google processes sign-in under its own privacy terms. Adding a storefront does not make public reports private or start scheduled monitoring.
If you choose to join the founding beta, StoreProof stores the email address and role you provide, plus any optional store count, storefront domain, monitoring frequency, feature interests, and the source report. This information is used only to evaluate and contact people about the StoreProof founding beta; the form does not opt you into unrelated marketing.
Cookies and analytics
StoreProof has no third-party analytics or advertising integration and does not intentionally set analytics or advertising cookies. It records a small set of first-party product events—such as scan, report, finding, Verify Fix, sharing, monitoring-CTA, and founding-beta form actions—using a random browser-session identifier. These events do not include storefront evidence, form email addresses, or request IP addresses. Hosting and infrastructure providers may process ordinary request metadata needed to operate and protect the service. Public storefronts loaded by the scanner may set their own cookies inside the isolated browser session used for the scan.
Infrastructure and service providers
StoreProof relies on hosting and operational infrastructure including a PostgreSQL database, Redis-backed queue and rate limiting, artifact storage that may be local or S3-compatible depending on deployment, and Resend when a user requests email delivery. These providers may process the information necessary to provide those services under their own terms and privacy practices.
Retention
StoreProof automatically removes scan reports after the configured retention period. The production retention period is published by the service operator and is configured through a deployment-only setting. Cleanup runs asynchronously: an expired report is made unavailable first, its screenshots/artifacts are removed, and its associated scan data is then deleted. A temporary artifact-storage failure keeps the report unavailable and is retried by a later cleanup run. Rate-limit keys expire after their configured window.
Public storefronts and deletion requests
StoreProof is intended for public storefront testing. Do not submit private environments or URLs that expose confidential information. To ask a privacy question or request deletion of StoreProof scan data, contact RXR Code at contact@rxrcode.dev. Include enough information to identify the relevant scan or report.
StoreProof now has a protected founder-operated process for locating and deleting a founding-beta interest record by email. When that record contains a linked first-party event-session identifier, the operator can also delete events associated with that session. This beta-lead operation is separate from deleting public scan data and does not itself delete scans, findings, screenshots, or artifacts.
StoreProof processes publicly accessible storefront pages and does not require Shopify Admin access for a public scan. During the public beta, any third party can submit a publicly reachable storefront; we do not verify merchant ownership before every scan.
A report may be manually deleted through protected founder operations. A verified storefront owner may also request manual deletion of all StoreProof scan data for one exact hostname, or blocking of that exact hostname from future public StoreProof scans. These requests are handled manually throughcontact@rxrcode.dev during beta after reasonable ownership verification, such as DNS, a temporary site marker, business-domain email plus review, or documented business verification. Subdomains and sibling hostnames are handled separately.
Manual report deletion, verified exact-host deletion, and verified exact-host blocking remain available in addition to automatic retention.
