StoreAuditLab sells one audit through a website with no customer login, newsletter signup, or on-site account area.
The audit itself is performed on public pages only. We never ask for your store admin credentials, your Search Console, or your analytics accounts, because the work does not use them.
The site is delivered and measured through the services listed below, payment is handled entirely by Stripe, and email reaches us through Cloudflare. Each one is named here rather than described in general terms.
What this site loads
These are the third-party requests the pages actually make. Nothing else is embedded.
| Service | Where it runs | What it involves |
|---|---|---|
| Cloudflare | Every page | Hosts and delivers the site, enforces the canonical domain and security headers, and produces Cloudflare's own delivery and traffic analytics. Serving any page means Cloudflare processes the request, including your IP address, user agent, and the URL you asked for. |
| Google Analytics 4 | Every page | Loaded by the site's one script with the measurement ID G-M4NGW7MS4H. It records page views and a checkout-click event, and it sets Google Analytics cookies in your browser. |
| Google Fonts | Every page | Typefaces are requested from fonts.googleapis.com and fonts.gstatic.com, which means Google receives the request for those files. |
| Stripe | Only when you check out | Every checkout button sends you to a Stripe-hosted payment page. Card details are entered on Stripe, not here, and this site never receives or stores them. |
| Fiverr | Only if you follow the link | An optional external marketplace where the same audit can be ordered. Following that link puts you on Fiverr, under Fiverr's own terms and privacy handling. |
The attribution data attached to checkout
The site's one script does something worth stating plainly rather than burying.
- It stores a small attribution record in your browser's session storage under the key sal_attribution_v1. That record holds campaign values (utm_source, utm_medium, utm_campaign, utm_term, utm_content) and the path you landed on. Session storage is cleared by your browser when the tab closes.
- If you arrived without campaign values, it infers a coarse source from the referring domain, such as google and organic, or direct. The referring host is reduced to a short token rather than kept in full.
- When you click a checkout button, those values plus a generated reference are appended to the Stripe link so an order can be matched to the page it came from. That reference is assembled from a timestamp, the attribution tokens, the button location, and random characters. It contains nothing about you personally.
You can check all of this yourself: the script is served uncompressed at /site.js.
Payment
Checkout is a Stripe payment link. Stripe collects and processes whatever it needs to take the payment, including your email address and card details, and Stripe is the party that holds that data. Stripe also issues the receipt for a completed payment. StoreAuditLab sees the order and the email address Stripe passes on, and never sees your card number.
Payment records and transaction processing stay in Stripe. Questions about an order can be sent to hello@storeauditlab.com. If you order through Fiverr instead, Fiverr is the payment processor and its own terms and privacy handling apply.
Email is the only channel this site publishes, and nothing is collected from you unless you choose to write. Mail sent to hello@storeauditlab.com is received through Cloudflare's mail routing and forwarded to a private mailbox operated by the studio. Replies are sent using an authenticated third-party email delivery service.
What arrives in that mailbox is whatever you put in the message, typically a store URL, a platform, a product count, a target country, and an SEO concern. The audit needs nothing more. There is no mailing list on this site, so writing to us does not subscribe you to anything.
Never send credentials by email. We do not ask for store admin logins, passwords, Search Console access, or analytics accounts, and the audit has no use for them. If anyone claiming to be StoreAuditLab requests account access, it is not us.
What we do not do
- We do not ask for store admin, Search Console, or analytics access.
- We do not run a newsletter, an account system, or a login on this site.
- We do not run advertising retargeting pixels beyond the services named in the table above.
- We do not publish, name, or hint at any customer, and the sample report is redacted and illustrative rather than a customer case study.
Your options
The controls that genuinely exist are your own, so here they are without overstating them.
- Browser and extension controls. Blocking scripts or third-party requests stops Google Analytics from loading. The site works without it.
- Google's own opt-out. Google publishes a Google Analytics opt-out browser add-on that applies across sites, not only this one.
- Clearing session storage. Closing the tab clears the attribution record described above.
- Asking us. Email hello@storeauditlab.com with a question about your data, or a request to delete correspondence, and we will answer it directly.
Not covered on this page
This page describes only what can be verified from the site as it stands today. It deliberately does not state retention schedules, legal bases, compliance certifications, or a formal request process, because publishing commitments we have not established would be the same kind of unsupported claim the audit is built to catch.
This site currently shows no cookie banner and offers no consent tool. If you have a question about how your data is handled, email us and you will get a direct answer rather than a form.
Questions about any of this
Write to hello@storeauditlab.com. The contact page explains what to send, and the terms page sets out exactly what the $100 audit covers.