Legal

Privacy statement

Auditor exists to keep an honest record of what happened in a store. That only works if we are equally plain about what we hold, why we hold it, and who else touches it.

Last updated 30 July 2026 · Version 1.0

Before you publish this page. This statement is written to match how Auditor actually works, but it is a starting draft, not legal advice — I'm not a lawyer. Have a qualified privacy lawyer in your jurisdiction review it, and fill in every bracketed placeholder, before it goes live. BigCommerce also reviews an app's privacy statement during listing approval.

1. Who we are and what this covers

Auditor ("Auditor", "we", "us") is operated by [Legal entity name], registered at [registered address], [country]. We publish the Auditor app for BigCommerce stores and the website at [auditorapp.com].

This statement covers:

  • this website, including the pricing, help and contact pages;
  • the Auditor app and its dashboard, as installed in a BigCommerce store;
  • emails, alerts and support conversations connected to either.

It does not cover BigCommerce itself, the store that installed Auditor, or any other app in that store. Those are governed by their own privacy notices.

2. Our two roles

This is the most important thing to understand about Auditor, because it decides who you should contact about what.

We are the controller of the information about the merchant relationship — the account that installs the app, the person who signs up, support emails, billing records and website analytics. We decide how that information is used, and this statement explains it.

We are a processor of the audit history recorded from a store. That history belongs to the merchant. It may include personal information about their staff and their shoppers, because a log entry naturally names the person who made a change and the record they changed. We only handle it on the merchant's instructions, under our terms of service and, where required, a data processing agreement. We do not use it for our own purposes, we do not sell it, and we do not use it to train models.

If you are a shopper or a staff member and want your information removed from a store's audit history, the merchant decides that, not us. See section 11.

3. Information we collect

3.1 Merchant and account information — we control this

  • Store name, store hash or ID, store domain and BigCommerce plan.
  • Name, work email address and role of the person who installs Auditor and of any colleague they invite.
  • Chosen plan, subscription status, and the billing reference BigCommerce gives us. We never receive your card number — BigCommerce takes the payment.
  • Alert recipient addresses you configure.

3.2 Store audit data — the merchant controls this, we process it

When an event happens in the store, BigCommerce notifies us and we record a normalised entry. Depending on the event, an entry can contain:

Field Example May identify a person
event product.updated No
occurred_at 2026-07-12T09:15:44Z No
actor Staff account, app name or API token Yes — a staff member
source_ip Where BigCommerce provides it Yes
resource Order #10429, SKU AW-2291, Customer #88214 Sometimes
previous_value The value before the change Sometimes — e.g. an old email or address
new_value The value after the change Sometimes
store_id Which store the entry belongs to No

What we deliberately do not record. Auditor holds read-only permissions and requests only the scopes it needs. We do not receive or store full payment card numbers, CVVs, bank details, or store or staff passwords. Where BigCommerce sends us a field we have no use for, it is dropped before the entry is written.

3.3 Website and support information — we control this

  • What you type into the contact form: your name, email, store address, and your message.
  • Emails you send to our support, billing, security or privacy addresses.
  • Standard server records for this website: IP address, browser and operating system, pages requested, and the time of the request.

3.4 Service records

We keep technical logs of our own systems — request timings, error traces, delivery status of alert emails, and which dashboard features are used. These help us keep the app working and occasionally contain an IP address or a store ID.

4. How we use it

Purpose Information used Our lawful basis (UK/EU GDPR)
Recording, storing and displaying the audit history Store audit data Performance of our contract with the merchant; the merchant relies on its own basis for the underlying personal data
Sending the alerts a merchant switches on Audit data, alert recipients Performance of contract
Creating your account, applying your plan, taking payment through BigCommerce Merchant and account information Performance of contract
Answering support, billing and privacy requests Contact form, emails, account information Performance of contract; legitimate interests in supporting our users
Keeping the service secure and investigating abuse Service records, IP addresses Legitimate interests in protecting our systems and our users
Fixing faults and improving the app Service records, aggregated usage counts Legitimate interests in maintaining a reliable product
Sending service notices — trial ending, allowance reached, breaking changes Account contact details Performance of contract
Sending occasional product news, if you opt in Name, email Consent — withdraw it from any such email
Meeting tax, accounting and legal obligations Billing records Legal obligation

We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use store audit data to train machine learning models. Anomaly detection runs on a single store's own data, for that store only.

No decision that has a legal or similarly significant effect on you is made about you by automated means. Auditor's alerts flag patterns for a human to look at; they do not act on anyone.

5. Cookies on this website

This website sets only what it needs to work: a cookie that remembers your cookie choice, and a session cookie if you sign in to the dashboard. We do not run advertising or cross-site tracking cookies.

[If you add analytics, name the tool here, say whether it is cookie-based, and describe how visitors can refuse it. If you use a consent banner, link it here.]

6. Who we share it with

We share information only with the organisations that help us run Auditor, and only with what they need. Each is bound by a written contract that limits them to our instructions.

Who What they do for us Where
Google Cloud Platform Hosts the application and background processing [region]
[Database provider] Stores the audit history [region]
[Email provider] Delivers alerts and service emails [region]
[Error monitoring] Reports faults so we can fix them [region]
BigCommerce Sends us store events and handles your subscription payment See BigCommerce's own notice

We also disclose information when the law requires it — a valid court order, a regulator's demand, or to establish or defend a legal claim. Where we are allowed to tell the affected merchant first, we do.

If Auditor is ever sold or merged, information may transfer to the buyer. We would tell merchants before that happened and the buyer would be bound by this statement or one no less protective.

7. Where it is stored

Auditor runs in [region] on Google Cloud Platform. Some of the providers above may access information from another country, including the United States.

When information leaves the UK or the European Economic Area, we rely on an approved safeguard — the UK International Data Transfer Addendum or the European Commission's Standard Contractual Clauses — together with a transfer risk assessment. Ask us and we will describe the safeguard that applies to a given provider.

8. How long we keep it

Information Kept for
Audit history The retention window of the merchant's plan — 90 days, 13 months, or up to 7 years
Audit history after uninstalling 30 days so the merchant can export it, then deleted. Earlier on request
Account and subscription records For the life of the account, then as long as tax and accounting law requires
Support conversations 24 months from the last message
Service and security logs 90 days, unless one is part of an open investigation
Website server records [e.g. 30 days]

Audit entries are append-only while they exist: nobody, including our own staff, can quietly change or remove a single entry. That is the point of an audit log. Deletion happens by whole retention window, or on a documented request from the merchant.

9. How we protect it

  • Read-only access. Auditor requests read scopes only and makes no write calls to a store.
  • Encryption. In transit with TLS, and at rest on our hosting and database providers.
  • Verified events. Every incoming event is checked against BigCommerce's signature before it is written, so a forged entry cannot enter the record.
  • Separation. Each store's history is scoped to its own credentials and cannot be queried by another store.
  • Least privilege. Our staff access production only when a support or reliability task requires it, through individual accounts with multi-factor authentication, and that access is itself logged.
  • Backups. Encrypted, with restores tested [frequency].

No system is perfect. If a breach affects your personal information and is likely to put you at risk, we will notify the relevant supervisory authority within 72 hours of becoming aware, and tell affected merchants without undue delay.

10. Your rights

Depending on where you live, you may have the right to:

  • Know and access what we hold about you, and get a copy.
  • Correct anything inaccurate.
  • Delete it, where no legal reason requires us to keep it.
  • Restrict or object to a use we base on legitimate interests.
  • Portability — receive it in a machine-readable form.
  • Withdraw consent at any time, where consent was our basis.
  • Not be discriminated against for exercising any of these rights.

Write to privacy@auditorapp.com. We answer within one month, and will tell you if we need longer. We may ask a question or two to confirm who you are — never more than we need. You can use an authorised agent.

If we hold your information only as a processor for a merchant, we will point you to that merchant rather than act on the request ourselves, and we will tell you that we have.

If you are unhappy with our response, you can complain to your data protection authority. In the UK that is the Information Commissioner's Office (ico.org.uk); in the EU it is the authority for the country you live in. We would rather hear from you first.

11. Shoppers and staff of a store using Auditor

You may have reached this page because a merchant told you they use Auditor. Here is what that means for you.

  • Auditor keeps a record of changes made in that store. If you are a staff member, entries will name you as the person who made a change. If you are a shopper, an entry may reference your order or customer record, and may hold a value as it was before it was changed.
  • The merchant decides what is recorded, how long it is kept, and who at the store can see it. They are the controller.
  • So requests about that data — access, correction, deletion — go to the merchant. If you have sent one and heard nothing, write to us at privacy@auditorapp.com and we will help you reach the right person and support the merchant in acting on it.

12. Children

Auditor is a business tool and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child's information has reached us through a store's audit history, tell us and we will work with the merchant to remove it.

13. Changes to this statement

When we change this statement we update the version and date at the top. For a change that materially affects how we handle information, we email the account contact of every store with Auditor installed at least 30 days before it takes effect. Previous versions are available on request.

14. How to reach us

Privacy questions and rights requests

privacy@auditorapp.com

Security disclosures

security@auditorapp.com

By post

[Legal entity name]
[Street address]
[City, State, Postcode]
[Country]

Data protection officer or representative

[Name and contact details, if you are required to appoint one, or an EU/UK representative if you have no establishment there.]

Terms of service · Contact us · Help centre