StoreAuditLab sells one audit through a website with no customer login or on-site account area. One guide offers a worksheet by email and a separate, optional signup for occasional ecommerce SEO notes.
The audit itself is performed on public pages only. We never ask for your store admin credentials, your Search Console, or your analytics accounts, because the work does not use them.
The site is delivered and measured through the services listed below, payment is handled entirely by Stripe, and email uses Cloudflare and Brevo. Each one is named here rather than described in general terms.
What this site loads
These are the third-party requests the pages actually make. Nothing else is embedded.
| Service | Where it runs | What it involves |
|---|---|---|
| Cloudflare | Every page | Hosts and delivers the site, enforces the canonical domain and security headers, and produces Cloudflare's own delivery and traffic analytics. Serving any page means Cloudflare processes the request, including your IP address, user agent, and the URL you asked for. |
| Google Analytics 4 | Every page | Loaded by the site's one script with the measurement ID G-M4NGW7MS4H. It records page views and a checkout-click event, and it sets Google Analytics cookies in your browser. |
| Google Fonts | Every page | Typefaces are requested from fonts.googleapis.com and fonts.gstatic.com, which means Google receives the request for those files. |
| Stripe | Only when you check out | Every checkout button sends you to a Stripe-hosted payment page. Card details are entered on Stripe, not here, and this site never receives or stores them. |
| Brevo | After a confirmed order, or when you request a worksheet or email signup | Stores paid buyers in a StoreAuditLab customer list and sends the welcome and intake email. Customer records are separate from the marketing subscriber list. If you separately check an optional marketing box, Brevo sends a double-opt-in confirmation and adds the address to the marketing list only after confirmation. Transactional delivery records can remain in Brevo's email logs. |
| Fiverr | Only if you follow the link | An optional external marketplace where the same audit can be ordered. Following that link puts you on Fiverr, under Fiverr's own terms and privacy handling. |
The attribution data attached to checkout
The site's one script does something worth stating plainly rather than burying.
- It stores a small attribution record in your browser's session storage under the key sal_attribution_v1. That record holds campaign values (utm_source, utm_medium, utm_campaign, utm_term, utm_content) and the path you landed on. Session storage is cleared by your browser when the tab closes.
- If you arrived without campaign values, it infers a coarse source from the referring domain, such as google and organic, or direct. The referring host is reduced to a short token rather than kept in full.
- When you click a checkout button, those values plus a generated reference are appended to the checkout route so an order can be matched to the page it came from. A launch-offer button can pass through a same-site, offer-gated redirect before Stripe. That redirect accepts only the listed attribution fields and can redirect only to the configured Stripe host. The reference is assembled from a timestamp, the attribution tokens, the button location, and random characters. It contains nothing about you personally.
You can check all of this yourself: the script is served uncompressed at /site.js.
Payment
Checkout is processed through a Stripe payment link. Standard buttons link to Stripe directly. A time-bounded offer can use a same-site redirect that opens only when that exact offer and Stripe destination are configured. Stripe collects and processes whatever it needs to take the payment, including your email address, store URL, and card details. Stripe is the party that holds the card data and issues the receipt for a completed payment. StoreAuditLab never sees your card number.
After Stripe confirms a paid order, StoreAuditLab receives the buyer email, name when provided, store URL, order reference, amount, timestamp, and checkout attribution. The email and order details are stored in the StoreAuditLab customer list in Brevo so the welcome and intake message can be sent. A private local customer registry mirrors the same limited operational fields. It is excluded from the public website and from Git.
Being stored as a customer does not add you to the marketing subscriber list. Marketing signup remains separate and requires its own confirmation. Questions about an order can be sent to hello@storeauditlab.com. If you order through Fiverr instead, Fiverr is the payment processor and its own terms and privacy handling apply.
Worksheet delivery and optional emails
The duplicate-content guide asks for an email address to deliver its printable worksheet. That address is sent to Brevo for the requested one-time delivery. It is not added to a marketing list merely because you requested the file.
A separate checkbox offers occasional practical ecommerce SEO notes. It is unchecked by default. If you select it, Brevo sends a confirmation email; the address is added to the marketing list only after you use that confirmation link. Future marketing emails must include Brevo's unsubscribe link. You can also ask hello@storeauditlab.com to remove the address.
If delivery is not configured or temporarily fails, the guide shows a direct download link instead of silently taking the address. The form does not send the email address to analytics.
Direct email
Mail sent to hello@storeauditlab.com is received through Cloudflare's mail routing and forwarded to a private mailbox operated by the studio. Replies are sent using an authenticated third-party email delivery service.
What arrives in that mailbox is whatever you put in the message, typically a store URL, a platform, a product count, a target country, and an SEO concern. The audit needs nothing more. Writing to us directly does not subscribe you to marketing.
Never send credentials by email. We do not ask for store admin logins, passwords, Search Console access, or analytics accounts, and the audit has no use for them. If anyone claiming to be StoreAuditLab requests account access, it is not us.
Meta lead forms
StoreAuditLab may use a Meta instant form on Facebook or Instagram to answer a specific request about audit fit. The form can collect the contact name and email address associated with your Meta account, your public store URL, ecommerce platform, operating country, whether you sell or plan to sell to United States customers, and the SEO issue you select.
Meta processes the form under its own privacy terms and makes the submitted fields available to StoreAuditLab. StoreAuditLab uses them only to assess the fixed audit's fit and reply to that request. Submitting the form does not create an order and does not add the address to the StoreAuditLab marketing list. Do not submit store credentials, analytics access, customer information, or payment details through the form.
What we do not do
- We do not ask for store admin, Search Console, or analytics access.
- We do not add a worksheet requester to marketing without the separate checkbox and confirmation.
- We do not add a Meta lead-form requester to marketing merely because they asked about audit fit.
- We do not run an account system or login on this site.
- We do not run advertising retargeting pixels beyond the services named in the table above.
- We do not publish, name, or hint at any customer, and the sample report is redacted and illustrative rather than a customer case study.
Your options
The controls that genuinely exist are your own, so here they are without overstating them.
- Browser and extension controls. Blocking scripts or third-party requests stops Google Analytics from loading. The site works without it.
- Google's own opt-out. Google publishes a Google Analytics opt-out browser add-on that applies across sites, not only this one.
- Clearing session storage. Closing the tab clears the attribution record described above.
- Email controls. Ignore the double-opt-in message and no marketing subscription is created. If you confirm, every marketing message must include an unsubscribe link.
- Asking us. Email hello@storeauditlab.com with a question about your data, or a request to delete correspondence, and we will answer it directly.
Not covered on this page
This page describes only what can be verified from the site as it stands today. It deliberately does not state retention schedules, legal bases, compliance certifications, or a formal request process, because publishing commitments we have not established would be the same kind of unsupported claim the audit is built to catch.
This site currently shows no cookie banner and offers no consent tool. If you have a question about how your data is handled, email us and you will get a direct answer rather than a form.
Questions about any of this
Write to hello@storeauditlab.com. The contact page explains what to send, and the terms page sets out exactly what the $100 audit covers.