Terms of use

What you may use Tagnovo for, what a public scan is not, and where a recurring watch needs proof you control the store.

Last updated 17 September 2026.

These terms apply when you use tagnovo.com, the API, the Manifest tag, or a Tagnovo installer. The privacy notice is the companion page. Creating a workspace, starting a scan, or installing the tag is agreement. If a sentence here and a sentence in the product disagree, the product behaviour wins and this page is updated.

The service

Tagnovo sells two things, independently. Tracewatches analytics and marketing tags on public storefront pages. Manifest is an approved list of scripts on pages that take a card, plus change detection as the shopper's browser received them.

Tagnovo is not a Qualified Security Assessor and does not certify compliance with PCI DSS or anything else. Manifest produces the inventory, the named approval, and the dated checks an assessor asks to be shown. Whether requirements 6.4.3 and 11.6.1 apply is decided by the acquiring bank. The SAQ page is a walkthrough, not a determination.

Accounts and workspaces

A workspace owns the stores, alerts and exports. You keep the password or the authenticator to yourself. You are responsible for the people you invite and for the destinations you point alerts at. Staff can open a support session when you ask; they cannot be the named person on a Manifest authorisation.

A public scan

Anyone may ask us to load a public storefront once. We identify ourselves asTagnovoScanner/1.0. We do not add to a cart and we do not submit a form. The result is a public page. Turnstile and a per-address host ceiling exist so the free scanner is not used as crawling infrastructure. Private ranges, credentials in the URL, and redirects into private space are rejected.

A one-shot scan that a person started from tagnovo.com does not honour robots.txt. A scheduled or batch scan does. How to allow or refuse the scanner is on/bot.

Recurring watch, and the line we will defend

Loading a public page once is what any browser does. Watching it every hour for a year, with a change log and a branded export, is not. Recurring cadence faster than once a day, thirteen-month retention, white-label export, and Manifest all require verification that you control the host. Unverified stores can still be added and read; they cannot be used as a standing watch on someone else's shop.

You must not:

  • Use the scanner as a general crawler or to map a third party at scale.
  • Point recurring monitoring at a store you do not control, hoping verification never lands.
  • Flood a Manifest install with forged beacons so the authorisation queue is unusable.
  • Probe private addresses, or ask us to follow a redirect into one.
  • Circumvent Turnstile, the host ceiling, or a denylist entry.

The Manifest tag

Manifest needs a first-party script on the pages you declare. A scan from the outside cannot see hosted checkout, and a skimmer that fingerprints automation will stay quiet for a driven browser. The tag reports script URLs, hashes and headers. It does not read the payment form.

You keep the key, the payment-path patterns, and the consent / optimizer settings on your origin. Do not install the tag only through Google Tag Manager — the monitor must not depend on the thing it watches. The WordPress plugin is the first-party path for WooCommerce.

A beacon is untrusted input. It can create a pending inventory row. Pending never alerts and never appears in an evidence pack as authorised. The named approval is the product.

Evidence you export

A pack carries a checksum so a later reader can see it was not edited after the stamp. You are responsible for who you show it to and for the names you put on an approval. Tagnovo does not stand behind a pack whose signatory was not the person who typed the name.

Amounts are the live catalog on /pricing. This page does not quote a dollar figure. Billing runs through Stripe. If a card fails we keep checking and keep alerting for seven days, then the catalog's own rules apply. Switching monthly and yearly is described on the pricing page. We do not invent a refund window here.

Availability

The scanner, the tag ingest, and the site can fail. A finding is what we observed, at that time, with that control. A page whose control was not satisfied is unobservable, not broken. We do not promise that a check will catch every silent tag or every skimmer.

Your content

You grant us the right to load the public pages you ask us to load, to store the capture long enough to produce the report, and to show that report to people who have the link. For a store you have verified, you grant us the right to repeat that on the cadence you set.

Our content

The site, the scanner, the tag, and the installers are Tagnovo's, except the WordPress plugin which is GPLv2 or later as shipped. You may not imply that Tagnovo certified a store.

If something goes wrong

Tagnovo is provided as observed. We are not liable for a card brand fine, a lost sale, or a decision you made from a report. This does not limit liability that the law does not allow to be limited.

We have not published a registered office on this page. When one exists, it will be named here. Until then, write to we.care@tagnovo.com and we will answer from the operator of these hosts.

Changes

A material change gets a new date at the top. Continued use after that date is agreement to the new text, except where the law requires a fresher consent.

Contact

we.care@tagnovo.com. Privacy:/privacy. Scanner: /bot.