Privacy notice

What we hold, who sees it, how long it stays, and how to ask for an export or an erasure.

Last updated 17 September 2026.

Tagnovo operates tagnovo.com and the Tagnovo hosts that serve the product. This notice is how those services handle personal data. It is not legal advice. Write towe.care@tagnovo.com if a sentence does not match what you see in the product.

What we hold

A public scan you started

The storefront address, the pages we loaded (home, collection, product, cart), the requests those pages made, the scripts we saw, the findings, and a shareable report at a/sr_… URL. The report is readable by anyone who has the link. We do not add anything to a cart and we do not submit a form.

Before a capture is stored we strip cookies, authorization headers, POST bodies, and visitor identifiers on collection URLs. The same rule applies to finding evidence.

A free public reading of a host that already produced a usable result is reused for 24 hours. Five new hosts per address per day is the ceiling. We count distinct hosts per address for that ceiling; the address is not kept as a customer record.

An account

Email, a password hash or a one-time link, an authenticator secret if you enrol one, the workspace name, the people you invite, the stores you add, verification proofs, alert destinations (email, Slack, a webhook URL you set), and the actions those people take.

We send transactional mail only: confirm an address, sign in, reset a password, tell you a check finished or an alert opened. If you asked to be told when a public report changes, that address sits on a suppressible list. It is not a marketing list.

Billing

Paid amounts come from the live catalog. Stripe holds the card. We keep the customer and subscription identifiers we need to match a webhook to a workspace, not the card number.

The Manifest tag

From real visitors the tag reports script host and path, transfer size, a content hash when the browser can read the file, the security headers the page sent, a presence id for that page view, and the install key. Sampling is 100% on the payment-path patterns you set, and 5% elsewhere unless you change it.

The tag never reads form fields, card numbers, names, addresses, or anything typed into the payment session. It does not record the screen, the mouse, or the page contents. It fails silent and does not block the page.

On WordPress the plugin can send the heartbeat from your site so a browser shield does not treat it as a third-party tracker.

A name on a payment-page decision

When someone authorises a script or attests a period, we store the name, role and email they typed. That is the merchant's compliance record, not our marketing data. See erasure below.

What we do not collect

  • Card numbers, CVCs, or the contents of a payment form.
  • Heatmaps, session video, clicks, or scrolling.
  • Visitor identifiers that belong to the store's own tags, once a capture is scrubbed.
  • A marketing cookie on tagnovo.com. We do not run our own analytics tag here.

Cookies we set

Cookies Tagnovo sets
NameWhyHow long
tg_sessionSigned-in workspace. Opaque token; we store a hash of it.30 days, or until you sign out.
tg_staffStaff console only. Signing out of admin leaves the workspace cookie.8 hours, or until staff sign out.
tg_themeLight or dark. Preference only.One year.

A bot check runs on the public scan, sign-up, and one-time-link forms. Stripe Checkout, if you pay, sets Stripe's own cookies on Stripe's origin.

Who sees it

  • Cloudflare — hosting, DNS, and the bot check on public forms.
  • Stripe — payment and the customer portal.
  • Resend — transactional email.
  • A destination you connected — Slack or a webhook URL you pasted. We send what that alert contains, to the place you named.
  • Staff, when you ask for help — a support session is opened with a reason, is time-bounded, and cannot sign a Manifest authorisation.
  • Anyone with a public report link — a free scan is a public page. Do not paste a link that should stay inside the workspace.

We do not sell personal data. Corpus pages name script hosts, not stores. A host is published only after it has been seen on twenty distinct stores. A G- or GTM-value is never published.

How long it stays

  • Unverified recurring watch: artefacts for 7 days. Cadence no faster than once a day.
  • Verified recurring watch: artefacts for 13 months.
  • A public scan that nobody claimed: the 24-hour reuse lock, then ordinary expiry.
  • Payment-page authorisation and attestation: for the period the requirement asks the merchant to hold the record. Those names are not erased with an account.
  • Billing records: as long as tax and the payment processor require.

Export, erasure, and the exception

Write to we.care@tagnovo.com. Four cases actually arrive:

  • Stop mailing this address. We write a suppression and set unsubscribed.
  • Delete this report. We delete the scan row and its artefacts.
  • Do not scan this host again. Recurring paths honour arobots.txt disallow for tagnovoscanner, and a host can be put on the denylist. Steps are on the scanner page. A one-shot scan someone started themselves is still their request.
  • Erase this account. The user row is never hard-deleted. We blank the display name, replace the email with a non-routable placeholder, and set deleted. The id stays so every approval and baseline it is cited by remains intact. The address is released for a later sign-up.

A request to erase approver_name, approver_email,actor_name, attester_name, attester_role orattester_email is refused in part. The person who authorises a script on a payment page is signing something. Signatures are meant to persist. The reason and the retention period are written on the request and sent back to you.

Stores you do not own

Loading a public page once is what any browser does. Watching it on a cadence, keeping a change log, and exporting a branded pack is not. Recurring cadence, retention and export require verification. That line is also in the terms.

Children

Tagnovo is for people who run or look after storefronts. It is not directed at children.

Changes

A material change gets a new date at the top of this page. The facts that feed it live in one place in the product; this page is updated when those facts change, not the other way around.

Contact

we.care@tagnovo.com. Scanner identity and opt-out:/bot.