legal
Privacy policy
This page covers the pixelcapi.com website. How the PixelCapi plugin handles data inside your own store is a separate matter, and is described in the plugin section below.
TODO(owner) — this is a structured draft, not reviewed legal text. It must be reviewed by a professional and dated before launch.
Who is responsible
TODO(owner) — legal entity name, registered address and contact address. The same details belong on the imprint page.
What this website collects
Nothing that identifies you, unless you choose otherwise. There is exactly one optional tool on this site, and it does not load until you say yes.
Before you choose
On your first visit, Google Consent Mode v2 is set to denied for all four
signals — analytics_storage, ad_storage,
ad_user_data and ad_personalization — before any other script
runs. While that is the case:
- Google Analytics is not loaded. No request is made to any Google domain.
- No analytics cookie is set, and no event is recorded or queued for later sending.
- Every page, including the Tracking Checker, works exactly as it would otherwise.
If you accept
Google Analytics 4 is loaded and the four consent signals are set to granted. GA4 sets its own cookies to distinguish one visit from another, and these events are recorded:
page_view— the page you opened.pricing_view— the pricing page was opened.-
checker_run,checker_result_view,checker_cta_click— you ran the Tracking Checker, a report was shown, or you followed a link from one. The checker events record the hostname you checked and the score band, never the full URL or the page contents. docs_search,docs_helpful— a documentation search term, or a yes/no vote on whether an article helped.checkout_start— reserved for when the checkout opens. It cannot fire today, because there is no checkout yet.
We do not send your email address, name or any other personal identifier to Google from this website, and there is no advertising pixel of any kind on it — no Meta pixel, no TikTok pixel, no remarketing tag. Building the honest version of that technology does not require us to run it on visitors who came to read about it.
If you decline
Nothing loads, and we keep a record of one thing: that you declined. Without it the banner would ask again on every page, which is nagging rather than asking.
Where your choice is stored
In your own browser, in localStorage, under the key
pixelcapi-consent-v1, as your choice plus the time you made it. It is
first-party: it is never sent to us or to anyone else, and it stays until you clear your
browser storage or change your mind. The Change my cookie choice link at
the bottom of every page forgets it and asks again.
The v1 in that key is deliberate. If the set of tools on this site ever
changes, the version changes with it, every stored choice becomes void, and you are asked
again — rather than us treating a yes to one thing as a yes to something else.
Google Ads
There is no Google Ads tag on this website today. When advertising begins, the purchase conversion will be recorded server-to-server from the payment provider's webhook rather than from your browser, and this section will name exactly what changed before it does.
The Tracking Checker
The free Tracking Checker fetches a public page you submit and produces a report. What is stored is the URL you submitted, the time of the check, the resulting score and the detections — kept for 30 days so a shared report link keeps working, then deleted automatically. Your IP address is not stored with the report, and no copy of the fetched page is retained.
Your IP address is used for one thing only: a counter that limits how many checks a single visitor can run per hour. That counter holds a count, not a history, and expires within the hour.
Reports are stored in Cloudflare Workers KV. TODO(owner) — confirm the Cloudflare data-processing terms and sub-processor listing with your reviewer.
Purchases
TODO(owner: confirm at Phase 7) — Freemius is the merchant of record for PixelCapi Pro and processes the purchase, including payment details and EU VAT. This section must link to the Freemius privacy policy and state what purchase data reaches us.
The PixelCapi plugin, inside your store
The plugin runs on your own server. Access tokens are stored server-side only and are never written to logs. Personal data is SHA-256 hashed per each platform’s rules before it is sent. IP address, user agent and click IDs are sent raw, because Meta, Google and TikTok require them in that form. Consent gates the browser event and the server event together, and the consent decision is recorded on the order so a send triggered later by a webhook respects it.
When you use the plugin to send conversion data, you decide what is sent and to whom. That makes you the controller for those transfers, and the platforms’ own terms apply. TODO(owner) — confirm this framing with your reviewer.
Your rights
TODO(owner) — the GDPR rights list (access, rectification, erasure, restriction, portability, objection), how to exercise them, and the supervisory authority a complaint can be lodged with.
Contact
TODO(owner) — privacy contact address.