hedlyte records how visitors move through your store — where they click, scroll, hesitate, and leave. That's sensitive work, and we treat it that way. This page explains what we collect, what we never touch, and where your data lives. No dark patterns, no fine print surprises.
The whole page in four lines.
When a visitor is on your store, our script records the session: pages viewed, clicks, scrolls, device type, browser, screen size, and rough location (country/region). That's what powers everything — funnels, leak detection, verification.
Install is two lines of script — the same mechanism as your analytics or ad pixel. It doesn't slow your store down, doesn't change anything a visitor sees, and doesn't touch your theme beyond the snippet. Sessions upload from the visitor's browser to our servers, where the analysis runs.
hedlyte is AI plus two founders, deliberately. Kam and Mike review findings before they reach your dashboard. That means real people at hedlyte can view session replays from your store — that's the product working, not a breach. It also means a person you can name is accountable for how your data is handled. Access is limited to the two of us.
We keep session data for as long as you're a customer, because the verification loop compares today's sessions against history — that's how we tell you a fix worked, or quietly broke again. Cancel and we delete your data within 30 days of your request.
Selling to EU shoppers? Here's how hedlyte fits your GDPR obligations. Short version: you're the controller, we're a processor, we minimize what we touch, and we put it in writing.
| Who | Role | What that means |
|---|---|---|
| Your store | Data controller | You decide why visitor data is processed. |
| hedlyte | Data processor | We process session data on your instructions, for one purpose: finding and fixing where your funnel leaks. |
We'll sign a Data Processing Agreement (DPA) with any customer who needs one.
GDPR asks companies to collect the minimum data needed for the purpose. That's not a burden for us — it's our architecture. We analyze behavior patterns, not people: no names, no emails, no payment data, no cross-site tracking of individuals.
If your store shows a consent banner (it should, for EU traffic), hedlyte should load in the analytics/statistics category — recording only after the visitor consents. We'll help you or your agency wire that up during install; it's a standard integration, not a special case.
One paragraph, roughly:
“We use hedlyte to understand how visitors use our store (pages viewed, clicks, scrolls) so we can improve the shopping experience. hedlyte processes this on our behalf, does not identify individual visitors, and does not sell or share data. See hedlyte.com/security.”
We'll give you copy matched to your store's language.
EU visitors can ask you for access to or deletion of their data. Because sessions aren't tied to identities, there's usually nothing to look up — but where a request applies, we support deletion within 30 days. Route requests to us and we handle our side.
On our own Canadian servers. Data is encrypted in transit. Each store's recordings live in a separate storage bucket, and the bucket is always determined by our server from your install token — never by anything a browser sends.
For an EU store this is an international transfer, and Canada holds a partial adequacy decision from the European Commission. If your DPO needs transfer terms in writing, contact us before you install.
We record how visitors move through the funnel — and then, unlike recordings you'd watch yourself, our system finds the drop-offs, prices them, and verifies fixes. You get answers, not tapes.
We see that a checkout started. The checkout page itself is sealed off from us — no payment data, ever.
The two founders. Nobody else.
Remove the script, request deletion, done in 30 days.
No. Cross-store learning is about which fixes work — patterns, never your sessions, numbers, or shoppers.
Ask us anything about this page: security@hedlyte.com. If we don't know the answer, we'll say so and find out. That's the policy.
Try the free store audit — no account, no snippet, nothing installed on your store.