Privacy Policy

Effective date: February 22, 2026  •  Last updated: February 22, 2026

Plain-English summary: We run services that handle your data and your clients' data. We collect only what we need to deliver each product. We do not sell your data or your clients' data to anyone, ever.

1. Who We Are

Radar Commerce ("Radar Commerce," "we," "us," or "our") builds focused software tools for digital agencies, available at radarcommerce.com. Our current products are Radar Monitor (Shopify store monitoring) and Radar Preflight (client asset collection). Additional products may be added in future.

This Privacy Policy explains how we collect, use, and protect personal information when you use our website, platform, or any of our products and services (collectively, "Services").

2. What Information We Collect

Information you provide directly

  • Account registration: your name, email address, and password (stored as a bcrypt hash — we never store your plaintext password).
  • Service configuration: depending on the product — store domains you add for monitoring (Radar Monitor), or project and template details you create (Radar Preflight).
  • Client data you submit on behalf of others: for Radar Preflight, this includes client names, email addresses, and files uploaded through client portals you create. You are responsible for having appropriate authorization to submit this data.
  • Billing information: handled by our payment processor (Stripe). We do not store payment card numbers on our servers.
  • Communications: emails, feedback submissions, or support requests you send us.

Information collected automatically

  • Usage data: pages viewed, features used, and actions taken within the dashboard.
  • Log data: server logs including IP address, browser type, and timestamps. Logs are retained for 30 days for security and debugging purposes.
  • Session cookies: used to keep you signed in (see Section 6).

Information from third parties

If you connect a Shopify store via OAuth (available on Radar Monitor paid plans), we receive an access token scoped to the permissions you approve during the OAuth flow. We request only the minimum scopes necessary to deliver the Service.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and improve the Services.
  • Deliver the core functionality of each product — monitoring store URLs and sending alerts (Radar Monitor), or managing client asset collection projects (Radar Preflight).
  • Send transactional emails — alerts, account notifications, password resets.
  • Send product updates and promotional emails (you can opt out at any time).
  • Respond to your support requests.
  • Detect and prevent fraud, abuse, or security incidents.
  • Comply with legal obligations.

We do not use your data to train machine learning models, sell to advertisers, or share with data brokers.

4. Product-Specific Data

Radar Monitor — store monitoring data

To deliver monitoring, our systems periodically make automated HTTP requests to the Shopify store URLs you configure. These checks access publicly accessible storefront HTML, the /products.json and /cart/add.js endpoints to verify checkout availability, and SSL certificate metadata. We generate snapshots containing response codes, response times, speed scores, a structural hash of the storefront, SSL status, and checkout availability. We do not store full page HTML.

What our monitors do NOT access

  • Customer personal data, order history, or financial data (unless you grant OAuth access to specific admin scopes).
  • Password-protected or private pages — we detect password protection and report it, but we do not attempt to bypass it.

Snapshot retention

Monitoring snapshots are retained according to your plan: Free plan — 7 days; Pro plan — 30 days; Agency plan — unlimited.

Your clients' stores

If you are an agency using Radar Monitor to manage client stores, you are responsible for ensuring you have the right to monitor those stores and, where applicable, to inform your clients about the monitoring. We process this data on your behalf as a data processor.

Radar Preflight — asset collection data

To deliver Preflight, we store project configurations, template definitions, client email addresses associated with projects, and files uploaded by your clients through portals you create. Files are stored in Amazon S3 and are accessible only by you (the agency account holder) and us for the purpose of delivering the Service.

File retention

Uploaded files are retained for the lifetime of the associated project. When you delete a project, associated files are queued for deletion within 30 days. Files are also deleted when you close your account.

Your clients' uploaded data

When your clients upload files through a Preflight portal, they are doing so at your direction. You are the data controller for that client data. We process it on your behalf as a data processor and do not use it for any purpose other than delivering the Service to you.

5. Who We Share Data With

We do not sell your personal information. We share data only in these limited circumstances:

Service providers (sub-processors)

  • Amazon Web Services (AWS): cloud hosting and infrastructure, including the EC2 server and SES email delivery service, located in the us-east-1 region.
  • Stripe: payment processing. Stripe's privacy policy applies to information they collect directly.

All service providers are contractually bound to process data only as we instruct and to maintain appropriate security standards.

Legal requirements

We may disclose information if required by law, regulation, legal process, or governmental request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

Business transfers

If Radar Commerce is acquired, merges with another company, or transfers substantially all of its assets, your information may be transferred as part of that transaction. We will notify you via email or a prominent notice on our website before any such transfer and before your information becomes subject to a different privacy policy.

6. Cookies and Tracking

We use a minimal set of cookies:

  • Session cookie: a secure, HTTP-only cookie used to keep you authenticated. It expires after 24 hours of inactivity or when you sign out.
  • CSRF protection cookie: a small token used to prevent cross-site request forgery attacks.

We do not use third-party advertising cookies, tracking pixels, or cross-site analytics. We do not use Google Analytics or Facebook Pixel on our dashboard.

Our public marketing pages (radarcommerce.com) may use basic, privacy-respecting analytics. If we add any analytics tools, we will update this section and provide opt-out options.

7. Data Retention

We retain your account data for as long as your account is active. If you close your account, we will delete your personal information within 30 days, except where we are required to retain it for legal or regulatory purposes (for example, billing records for up to 7 years in some jurisdictions).

Monitoring snapshots (Radar Monitor) are deleted on the schedule described in Section 4. Store events are retained for the lifetime of your account. Uploaded files (Radar Preflight) are retained for the lifetime of the associated project and deleted when you delete the project or close your account.

8. Security

We take security seriously:

  • Passwords are hashed using bcrypt and are never stored in plaintext.
  • All data in transit is encrypted via TLS/HTTPS.
  • Database access is restricted to the application server; our database is not exposed to the public internet.
  • Session cookies are marked Secure and HttpOnly.
  • OAuth access tokens are stored encrypted at rest.

No method of data transmission or storage is 100% secure. If you believe your account has been compromised, please contact us immediately at contact us.

9. Your Rights

Depending on where you are located, you may have the following rights regarding your personal data:

  • Access: request a copy of the personal data we hold about you.
  • Correction: request that we correct inaccurate or incomplete data.
  • Deletion: request that we delete your personal data ("right to be forgotten").
  • Portability: request your data in a structured, machine-readable format.
  • Objection / Restriction: object to or request restriction of certain processing activities.
  • Withdraw consent: where we process data based on your consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, email us at contact us. We will respond within 30 days. We may need to verify your identity before fulfilling a request.

If you are located in the European Economic Area, United Kingdom, or California, you may also have the right to lodge a complaint with your local data protection authority.

10. Children's Privacy

The Service is not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that a child under 16 has provided us with personal information, we will delete it promptly. If you believe we have collected information from a minor, please contact us at contact us.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page.
  • Send an email notification to all registered account holders at least 14 days before the changes take effect.
  • Where required by law, ask for your consent.

Your continued use of the Service after changes take effect constitutes acceptance of the updated policy. If you do not agree with the changes, you may close your account before the effective date.

12. Contact Us

For privacy-related questions, data requests, or concerns, please get in touch. For security issues, include "Security" in your message subject.