hedlyte
What it findsHow it works
Log inRequest early access
Security & Privacy

We watch shoppers so you don't have to. Here's exactly what that means.

hedlyte records how visitors move through your store — where they click, scroll, hesitate, and leave. That's sensitive work, and we treat it that way. This page explains what we collect, what we never touch, and where your data lives. No dark patterns, no fine print surprises.

Last updated 28 July 2026Applies to hedlyte.com and the hedlyte recorder

On this page

  1. The principles
  2. What we collect
  3. What we never collect
  4. How it runs on your store
  5. The humans in the loop
  6. Retention & deletion
  7. GDPR — roles, plainly
  8. Data minimization
  9. Consent & your cookie banner
  10. What to put in your privacy policy
  11. Visitor rights
  12. Where data lives
  13. FAQ

The principles

The whole page in four lines.

  • We collect behavior, not identities. We need to know a shopper hesitated at your size selector — we don't need to know who they are.
  • We never see payment data. By design, not policy. Checkout pages on Shopify are sealed off from scripts like ours — we couldn't record a credit card if we tried.
  • Your data works for your store only. We don't sell it, we don't share it with advertisers, and we don't use one store's sessions to serve another store. What we learn across stores are patterns about fixes — never your shoppers, never your numbers.
  • Leave anytime, take nothing to untangle. Remove two lines of script and we're gone. Ask us to delete your data and we do.

What we collect

When a visitor is on your store, our script records the session: pages viewed, clicks, scrolls, device type, browser, screen size, and rough location (country/region). That's what powers everything — funnels, leak detection, verification.

What we never collect

  • Payment details, card numbers, checkout form contents — the checkout page is invisible to us.
  • Passwords or account credentials.
  • Anything a visitor types into forms, unless you explicitly ask us to measure a specific field's completion (never its contents).
  • Names, emails, or profiles of your visitors. Sessions are behavioral, not personal.

How it runs on your store

Install is two lines of script — the same mechanism as your analytics or ad pixel. It doesn't slow your store down, doesn't change anything a visitor sees, and doesn't touch your theme beyond the snippet. Sessions upload from the visitor's browser to our servers, where the analysis runs.

The humans in the loop

hedlyte is AI plus two founders, deliberately. Kam and Mike review findings before they reach your dashboard. That means real people at hedlyte can view session replays from your store — that's the product working, not a breach. It also means a person you can name is accountable for how your data is handled. Access is limited to the two of us.

Retention & deletion

We keep session data for as long as you're a customer, because the verification loop compares today's sessions against history — that's how we tell you a fix worked, or quietly broke again. Cancel and we delete your data within 30 days of your request.

GDPR — roles, plainly

Selling to EU shoppers? Here's how hedlyte fits your GDPR obligations. Short version: you're the controller, we're a processor, we minimize what we touch, and we put it in writing.

WhoRoleWhat that means
Your storeData controllerYou decide why visitor data is processed.
hedlyteData processorWe process session data on your instructions, for one purpose: finding and fixing where your funnel leaks.

We'll sign a Data Processing Agreement (DPA) with any customer who needs one.

Data minimization (our favorite article)

GDPR asks companies to collect the minimum data needed for the purpose. That's not a burden for us — it's our architecture. We analyze behavior patterns, not people: no names, no emails, no payment data, no cross-site tracking of individuals.

Consent & your cookie banner

If your store shows a consent banner (it should, for EU traffic), hedlyte should load in the analytics/statistics category — recording only after the visitor consents. We'll help you or your agency wire that up during install; it's a standard integration, not a special case.

What to put in your privacy policy

One paragraph, roughly:

“We use hedlyte to understand how visitors use our store (pages viewed, clicks, scrolls) so we can improve the shopping experience. hedlyte processes this on our behalf, does not identify individual visitors, and does not sell or share data. See hedlyte.com/security.”

We'll give you copy matched to your store's language.

Visitor rights

EU visitors can ask you for access to or deletion of their data. Because sessions aren't tied to identities, there's usually nothing to look up — but where a request applies, we support deletion within 30 days. Route requests to us and we handle our side.

Where data lives

On our own Canadian servers. Data is encrypted in transit. Each store's recordings live in a separate storage bucket, and the bucket is always determined by our server from your install token — never by anything a browser sends.

For an EU store this is an international transfer, and Canada holds a partial adequacy decision from the European Commission. If your DPO needs transfer terms in writing, contact us before you install.

FAQ

Is this like session recording tools?

We record how visitors move through the funnel — and then, unlike recordings you'd watch yourself, our system finds the drop-offs, prices them, and verifies fixes. You get answers, not tapes.

Can hedlyte see what my customers buy?

We see that a checkout started. The checkout page itself is sealed off from us — no payment data, ever.

Who at hedlyte can see my data?

The two founders. Nobody else.

What happens if we cancel?

Remove the script, request deletion, done in 30 days.

Do you use my store's data to help my competitors?

No. Cross-store learning is about which fixes work — patterns, never your sessions, numbers, or shoppers.

Questions

Ask us anything about this page: security@hedlyte.com. If we don't know the answer, we'll say so and find out. That's the policy.

Try the free store audit — no account, no snippet, nothing installed on your store.

hedlyte
How it worksWhat it findsFree auditSecurity & privacyLog in
© 2026 hedlyte · the intelligence layer