Privacy Policy
What data PreTraffic collects, why we process it, who we share it with, how long we keep it, and your GDPR rights.
1. Controller
The controller for the personal data described here, within the meaning of the EU General Data Protection Regulation (GDPR), is:
AI Quantum Ventures LLC (operating as PreTraffic)
United States
Email: privacy@pretraffic.ai
We operate from the United States. Where we process personal data of individuals in the EU/EEA or the UK, we do so in line with the GDPR and UK GDPR, using appropriate safeguards (including Standard Contractual Clauses) for international transfers.
2. What we collect
a) Data you give us
- Email address — to deliver your report link, send transactional and account email, run magic-link sign-in for the subscriber portal, and (if you opt in) send product updates or waitlist news.
- Store URLs you submit for audit — the URL itself, plus the pages our engine walks from it.
- Account details — for admin and portal users: email, authentication identifiers, and role.
- Support messages — anything you send us by email.
b) Data generated when we run an audit
- Page content, HTML, prices and copy read from the storefront you submitted.
- Screenshots of the pages walked, stored in a private bucket and served through a signed application route.
- Performance measurements (Core Web Vitals) for the pages walked.
- The generated report: personas, verdicts, quotes, findings, scorecard and recommendations.
c) Payment data
Card numbers never reach our servers. Checkout is hosted by Stripe. We receive from Stripe only the identifiers and metadata needed to fulfil and support the order: a customer and session/subscription identifier, the email used at checkout, amount, currency, country, payment status, and the card brand and last four digits. Shopify merchants who buy through the embedded app are billed via Shopify Billing, and we receive the equivalent charge status from Shopify.
d) Technical data
Server logs (IP address, user agent, timestamps, requested route) generated when you use the site, kept for security, abuse prevention and debugging. Essential cookies and local storage are used to keep you signed in and to remember an audit in progress.
3. Why we use it, and our legal basis
- Running audits and delivering reports — performance of a contract (Art. 6(1)(b) GDPR), or pre-contractual steps for free audits you request.
- Payments, invoicing, refunds and fraud prevention — contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)).
- Transactional email (report ready, run failed, refund issued, receipt, magic link) — contract (Art. 6(1)(b)).
- Marketing email, waitlist and nurture sequences — consent (Art. 6(1)(a)), withdrawable at any time via the unsubscribe link in every such email.
- Security, abuse prevention, service reliability and improving the engine — legitimate interests (Art. 6(1)(f)) in running a safe, working product.
- Bookkeeping and tax records — legal obligation (Art. 6(1)(c)) under German commercial and tax law.
4. Who we share it with
We do not sell personal data and we do not share it for third-party advertising. We use the following processors and service providers:
- Stripe (payments, refunds, subscription billing) — Stripe acts as an independent controller for payment processing.
- Shopify — only for merchants who install the PreTraffic embedded app: shop domain, install status and billing state.
- Supabase — database, authentication and file storage for accounts, audits and screenshots.
- Resend — transactional and marketing email delivery.
- Our audit engine and its AI/model infrastructure — the store URL, page content captured from it, and the run's parameters are sent to our audit engine and to the model providers it uses to generate shopper reactions and findings. Your email address is not sent to model providers as part of the audit prompt. We use providers under terms that prohibit training their foundation models on our submitted content.
- Hosting and infrastructure providers that run the application and its edge network.
We may also disclose data where legally required, or to establish, exercise or defend legal claims.
5. International transfers
Some of these providers process data in the United States or other countries outside the EEA. Where that happens, transfers are covered by the European Commission's Standard Contractual Clauses, and where applicable the EU–US Data Privacy Framework, together with supplementary technical measures such as encryption in transit and at rest. You can request a copy of the transfer safeguards at privacy@pretraffic.ai.
6. How long we keep it
- Audit reports and screenshots — kept while your report link is intended to remain permanent, and for as long as your account or subscription is active. Free-tier audits and their screenshots are deleted 24 months after the run.
- Account and portal data — until you ask us to delete it, then removed within 30 days.
- Marketing contacts — until you unsubscribe or ask for deletion; suppression records are kept afterwards so we do not email you again.
- Order, invoice and tax records — up to 10 years, as required by German commercial and tax law.
- Server and security logs — up to 90 days.
7. Your rights
Under the GDPR you have the right to: access your data (Art. 15); correct it (Art. 16); have it deleted (Art. 17); restrict processing (Art. 18); receive it in a portable format (Art. 20); object to processing based on legitimate interests (Art. 21); and withdraw consent at any time without affecting processing already carried out (Art. 7(3)). You also have the right to lodge a complaint with the data protection supervisory authority where you live or work.
To exercise any right, email privacy@pretraffic.ai. We respond within one month and may ask you to confirm control of the email address on the account. There is no charge for a reasonable request.
8. Automated decision-making
PreTraffic reports are generated automatically by AI. They evaluate a storefront, not a person, and they do not produce legal or similarly significant effects on individuals within the meaning of Art. 22 GDPR. We do not use automated decision-making to profile you as an individual.
9. Cookies and local storage
We use only what the site needs to work: an authentication session cookie/token, a magic-link session, and local storage that remembers an audit you started so you can return to it. We do not run third-party advertising or cross-site tracking cookies.
10. Security
Data is encrypted in transit (TLS) and at rest. Screenshots live in a private bucket that is not publicly listable and is served only through our application. API keys and OAuth tokens are stored encrypted server-side and are never exposed to the browser. Access to production data is limited to the operators who need it.
11. Children
The Service is for businesses and is not directed at children under 16. We do not knowingly collect their data.
12. Changes
We may update this policy. Material changes are announced by updating the effective date and, for active customers, by email.
13. Contact
AI Quantum Ventures LLC
United States
Privacy: privacy@pretraffic.ai
General: support@pretraffic.ai