Privacy
WideAisle processes data to review pilot requests, prepare manually reviewed
business outreach, generate statement drafts, run authorized storefront diagnostics, reconcile payment, control
report access, deliver reports, handle refunds, and operate encrypted backups. WideAisle does not sell personal
information. The categories and operational limits are described below.
What we collect
- Public storefront evidence: when the service is enabled and an authorized scan runs, it retains
automated observations, bounded sanitized element markup, allowlisted computed evidence, and conditional
privacy-screened structural locators. It does not retain full-page or element screenshots.
- Pilot and requester data: agency or business name,
contact name, business email, public storefront domain, requester-supplied project-trigger type and date, and
a timestamped authority attestation. The attestation is recorded and gates checkout; WideAisle does not
independently verify store ownership or authority. Submission does not send a checkout link automatically.
An operator may approve or decline the request and, after a separate review, create and send a private link.
- Public business prospect data: public agency
name, business email, website or social profile, service descriptions, public work examples, source URL,
retrieval date, draft personalization, and outreach or suppression state. A dated directory retrieval is not
evidence that the business has an active client project. Drafts remain unsent until separately reviewed.
WideAisle-generated outreach drafts and report-email bodies do not
contain tracking pixels. Email-provider tracking settings are external configuration and must be verified
before live sending.
- Statement request: store name, storefront
domain, and requester email are stored as an inbound prospect record. An optional feedback email is used to
generate the returned draft. Submitting the statement form does not start a scan, take payment, or send email.
- Payments and refunds: Stripe collects card details on
Stripe-hosted Checkout. The WideAisle application does not collect or store full card numbers. It stores
Stripe Checkout, PaymentIntent, charge, refund, and dispute identifiers and events, together with purchaser
email, storefront, amount, currency, payment state, and refund state needed to reconcile an order.
- Report access and rate limiting: report grant and
session secrets are stored only as hashes. The application transiently processes a network address to derive
a rotating keyed rate-limit identifier; the raw address is not stored in the report-access ledger. Hosting
and security providers may separately process ordinary request metadata.
- Delivery and pilot administration: order and pilot
records contain the delivery address and operator approval or decline state. Delivery ledgers retain a keyed
recipient digest, message digest, provider message and idempotency identifiers, delivery attempts, and
accepted, delivered, bounced, complained, revoked, or refund-related events. A private-pilot acceptance record
stores a hashed confirmation token and the time the recipient explicitly confirms receipt and usability.
Service providers
Stripe hosts Checkout and processes payments and refunds. Resend
processes transactional report and status email; configured business-email providers may be used for separately
reviewed pilot or outreach correspondence. Cloudflare provides DNS, tunnel or hosting services and encrypted R2
backup storage. These providers process the identifiers, contact details, message content, request metadata, or
encrypted backup objects needed for their assigned function under their own terms. A pilot-request submission
does not itself trigger an email or create a Stripe Checkout Session.
Retention & deletion
A v3 report's access grants and sessions expire at the report's
12-month retention boundary. Unless a documented legal hold applies, governed deletion then removes the report
and its report-linked evidence; a content-addressed artifact remains only while another retained report still
references it. Verified encrypted backup bundles receive a
recorded expiry 14 days after creation. The backup-pruning process deletes expired R2 objects and verifies that
they are unavailable; provider or operational failures are retried and can delay physical removal.
Order, payment, refund, dispute, delivery, and acceptance records may
be retained longer for accounting, fraud prevention, dispute handling, and legal obligations. Pilot requests,
statement-request prospect records, public prospect research, and administrative records do not currently have
a promised fixed deletion date; they are retained while needed for evaluation, service administration, abuse
prevention, suppression, or the obligations above. Suppression records are retained to honor opt-outs.
Email
hello@wideaisle.com to request deletion. The
request is reviewed for identity, scope, shared evidence, legal holds, and records that must be retained. Email
hello@wideaisle.com to suppress future WideAisle
outreach to an address or store. An outreach opt-out does not authorize a scan and does not replace the separate,
explicit authority attestation required for any later client preflight.
Email
Prepared outreach drafts include a reply-based opt-out. A recorded email or storefront suppression must be
checked before any initial message or follow-up is sent.
Home · Terms · Refund policy