Findwise Privacy Policy

Last updated October 2, 2026 · Version privacy-2026-10-02-v0.10

This policy explains what Findwise LLC ("Findwise," "we," "us") collects when you use getfindwise.com, scan a store, open or buy a report, or write to us, what we do with it, and the choices you have. We have kept it short and plain on purpose: it describes what the product actually does.

Questions or requests: privacy@getfindwise.com.

1. Who this is for

Findwise is a business tool. It checks how well an online store's public pages answer the questions shoppers and AI shopping assistants ask. It is not meant for children, and it is not used to make decisions about individual people.

2. What we collect

When you use the site

  • The store address you submit for a scan.
  • For free previews: the email address you enter to open a free preview, and whether you agreed to marketing email. We use the address to open that preview on this device and session, and we keep it as a lead record. We also use it, only with your separate consent, for product updates; agreeing is optional and never required to see your preview.
  • If a scan finds that a site is not an online store yet and you ask us to tell you when Findwise covers sites like it: the email address you enter, and whether you agreed to marketing email. We keep the address, and your marketing choice, as a lead record so we can send that one message if Findwise comes to cover sites like yours; that message is not sent yet. We send product updates to it only if you agreed.
  • If you write to us or buy something: your name, email address, phone number if you give one, company, your messages, and what you bought. Card payments are handled by our payment provider, Stripe; we never see or store your card number.

When we scan a store

A scan reads a limited number of a store's public web pages, the way a search engine does, following the rules in our crawl policy at getfindwise.com/bot. We keep what is needed to build the report: page addresses, public page content and markup, product and policy details, and technical facts such as status codes and robots.txt rules. We never log in, add to cart, check out, or get around a block.

Public pages sometimes contain personal details a business chose to publish, such as a founder's name or a reviewer's first name. We use them only as part of the store's report and, where a business publishes a contact address, to offer it a report about its own store; we never build profiles of people.

We also scan stores we choose ourselves, to improve our checks and to offer store owners a report.

Automatically

  • Basic technical data such as IP address, browser, pages viewed, and the page that sent you, used to run and protect the site and to stop abuse.
  • When you start a scan on our site and it is stored as a new scan: a one-way, salted code made from your IP address, when one is available, kept as the record that you accepted our terms. The record holds the code, not your address, and we do not use the code to find out who you are. If the same store was scanned recently, you are shown that earlier scan instead, and we keep no new record of your acceptance. A paid order keeps the same kind of code, when one is available, made from the buyer's email address when Stripe provides one.
  • One essential cookie when you open a scan or private preview: fw_checkout_intent. It holds a random code for up to 36 minutes so repeated purchase clicks can return to the same checkout. It also prevents repeat counts when a private preview reloads. It cannot be read by page scripts, contains no email address, and is not sent to advertising services.
  • One cookie when you open a scan report. It records that that one report was unlocked, expires after 30 days, cannot be read by page scripts, and does not contain your email address.
  • First-party analytics cookies on public and private customer pages: fw_browser holds a random browser code for up to 180 days; fw_session holds a random session code for 30 minutes without a visit; and fw_campaign remembers only an approved code shared by a whole email batch for the same 30 minutes. Each visit restarts these periods. When valid Google Analytics identifiers already exist, we keep that identity; otherwise we create random codes. These cookies contain no email, store identifier, private URL or report token. They let a direct private-preview visit, checkout and payment be counted in the same journey, including when the visitor later opens a public page. They are analytics cookies and operate independently of advertising permission.
  • Analytics from Google. Eligible public pages may set first-party Google Analytics and Google Tag Manager cookies. Our servers may also send events through the Measurement Protocol with pseudonymous client and session identifiers when a scan is accepted, completes with a usable report or fails; when an email address is accepted at a preview or notify form; when a valid free report or current outreach preview is first opened; when checkout begins; and when a purchase settles. They may include only the approved campaign source, medium and name shared by a whole batch, general scan outcome and timing categories, the kind of form or report, and what was bought; a checkout event may include the price and currency, and a purchase may also include the order value, currency and an order reference. When checkout begins, we may also store the same client and session identifiers and the approved shared batch campaign code with the Stripe checkout session so the purchase can be measured when it settles. For scan completion or failure and the first free or outreach-preview open, we use a delivery record keyed by a one-way code made from the event, scan, and pseudonymous client and session identifiers, and send that same code with the event. This helps avoid repeat sends during one visit. If Google's response is missing or the delivery record cannot be finalized, we may retry up to twice, so Google can receive a duplicate. They never include your name or email address, the store URL or domain, the report link, or raw error details. Public page views contain only the public page path and approved campaign codes shared by a whole campaign, with query strings, fragments and referrers removed. Google Tag Manager does not load on /internal, /checkout, /billing, or on /scan, /report or /purchase pages that identify a scan, a report or an order.
  • One cookie if you answer the cookie choices banner or your browser sends Global Privacy Control on our public and private customer pages: fw_ad_consent. It holds your allow/refuse answer or records a Global Privacy Control refusal, including while that refusal is waiting for our server to save it, and expires after 180 days. It changes nothing about Google Analytics, which runs either way.
  • A separate essential cookie, fw_ad_consent_ref, when you answer the banner or Global Privacy Control needs to save a refusal. It holds a random code that our servers use to check your current advertising permission, expires after 180 days, and cannot be read by page scripts. Our database stores the code, whether you allowed or refused advertising measurement or sent Global Privacy Control, and when that choice was made and expires. The code is not sent to Google, Meta or Stripe as a measurement identity; it can accompany checkout metadata at Stripe so we can check your current choice if payment confirms later.
  • Advertising measurement from Meta, only if you allow it and do not send Global Privacy Control. After a stored grant, our servers can establish the random _fbp matching cookie on private customer pages without loading Google or Meta scripts there. A Pixel on eligible public pages receives a fixed public-page address, your browser details and network address, and a random Meta browser code in the first-party _fbp cookie, which lasts up to 90 days. It receives no private-page address or referrer. Our servers can also send accepted and completed scan, accepted lead, eligible free or outreach-preview view, checkout and confirmed purchase events, with that Meta browser code, your consented browser user agent, a fixed public homepage address and a one-way event reference. Checkout and purchase events can include the product type, price and currency. They never include your email address, name, store URL or domain, private report link, raw order code or payment details. A current permission check precedes every server send; absent, expired, refused, Global Privacy Control or unreadable permission prevents it. Rejecting disables Meta in that browser immediately. We mark the withdrawal pending while our server saves it, retry temporary failures automatically, and show it as saved only after acknowledgment. Once saved, it applies to future server sends, including delayed payments; it cannot remove an event Meta already received.

3. How we use it

  • To run scans, build and deliver reports, and take payment.
  • To reply when you write to us.
  • To send a message you asked us for, such as the note about a site that is not a store yet, once we start sending it (see section 2); and, only if you agreed, product updates.
  • To contact a business about a report on its own public store, and to honour any request not to be contacted again.
  • To understand which pages work, to measure cost and quality, and to improve our checks.
  • To keep the site secure and stop abuse.

Reports are produced by automated checks. An optional AI step tags what kind of site was scanned and what it sells; it does not write any of the report. AI processing runs on Cloudflare Workers AI, inside the same Cloudflare account that hosts Findwise. We do not send your information to any other AI provider, we do not let any provider train its models on it, and we do not use paid reports to train models.

4. Who we share it with

We do not sell personal information. We share it with the services below for the purposes described above; advertising measurement with Meta happens only with your consent:

  • Cloudflare: hosting, storage, security and AI processing.
  • Stripe: payments and the consent reference and consented browser information needed to measure a payment when it confirms.
  • Google: site analytics, and our business email (Google Workspace), which receives and stores the messages you send to our @getfindwise.com addresses and the replies we send you.
  • Resend: sending the email we owe you, when email delivery is on.
  • Meta: advertising measurement, only with your consent.

We also share information when the law requires it, to protect Findwise or others from fraud or abuse, or with a buyer if Findwise is ever sold. Before we add a new kind of service that receives personal information, we update this policy.

Some US state laws treat advertising measurement with Meta as "sharing" for targeted advertising. We allow it only if you say yes, and a Global Privacy Control signal counts as no.

5. Reports

Report links are long and unguessable, and report pages are kept out of search engines. We treat paid reports as private to the buyer. We do not publish a report about a named store, or use a customer's name or logo, without permission.

6. How long we keep things

  • Raw copies of scanned pages: up to 30 days for scans started on our public site, meaning the free scan we run when a store is entered there; and up to 180 days for other scans, such as a paid rescan or a scan we start ourselves.
  • Reports, scores and the evidence behind them: for as long as the report is offered, so it can still be opened and compared with a later scan.
  • Leads, purchases and messages: as long as they are useful to run the business, or longer where tax or accounting rules require it.
  • Records that an analytics event was sent to Google (the one-way code described in section 2, which scan and event it was about, when it was tried, whether it was delivered, how many attempts it took and any error): as long as they help avoid repeat sends, with the retries described in section 2.
  • Current advertising permission: the choice expires after 180 days; we periodically remove expired permission records.
  • Records of Meta milestone delivery: one-way event references, the scan and event involved, attempt times and coarse outcomes; records older than 180 days are eligible for periodic removal. They hold no email or browser user agent.
  • Do-not-contact records: as long as needed to honour them.

7. Your choices

  • Ask to see, correct or delete your information, or to stop marketing email: write to privacy@getfindwise.com. We may need to check it is really you.
  • Block or delete cookies in your browser. The report cookie is needed to reopen a report on that device.
  • Allow or refuse Meta advertising measurement and cookies at any time with the Cookie choices link at the foot of public and private customer pages. They are off until you allow them, and a Global Privacy Control signal from your browser counts as refusing.
  • Store owners can ask us to limit or stop scanning their site, correct or remove a report, or not contact them again, at legal@getfindwise.com.

We will not treat you differently for using any of these choices.

8. Security

We use reasonable safeguards such as encrypted connections, access controls and rate limits. No system is perfectly secure. Findwise never asks for your store's passwords or admin access.

9. Outside the United States

Findwise is run from the United States, and information is processed there and wherever our service providers operate. If you need something specific for your country, write to us.

10. Changes

When what we do changes, we update this page first, change the date and version above, and, for a significant change, say so on the site. We will not start using information in a new way that this page does not describe.

11. Contact

Findwise LLC

Privacy requests: privacy@getfindwise.com

Store owners and legal notices: legal@getfindwise.com

Mailing address: Available upon request, or as listed in formal customer order documents.