On this page
Acceptable Use Policy
What you can and can't do with Candler. It applies to everyone on a Candler account and is part of the Terms of Service. Recording visits is powerful, so most of it is about the people being recorded.
Only record sites you're allowed to.
Install Candler only on websites you own or control, or where the owner has authorized you in writing. Don't send data to someone else's tracking ID.
Tell visitors, and get consent where it's required.
Every site running Candler needs a privacy policy that discloses session recording and analytics. Where the law requires consent before recording or setting analytics cookies, use Candler's consent mode or an equivalent. The cookies page explains both.
Keep sensitive data out.
Don't use Candler to collect any of the following. Don't install it on pages where visitors enter or see it, unless it's masked or blocked so it never reaches Candler:
- health information, including protected health information under HIPAA. Candler isn't built for HIPAA and won't sign a business associate agreement;
- full payment card numbers, bank account numbers or security codes;
- government ID numbers, such as Social Security, passport or driver's license numbers;
- passwords, security questions or one-time codes;
- biometric or genetic data, or precise geolocation;
- information about racial or ethnic origin, religion, political opinions, union membership, sex life, sexual orientation, immigration status or criminal records;
- information about children. Don't use Candler on sites or pages aimed at children under 13, or under 16 in the EU and the UK.
Don't switch off the masking defaults, mark fields as safe, or send custom event properties unless you're sure no personal information appears there.
Don't use recordings against people.
- Don't use Candler to stalk, harass, threaten or discriminate against anyone.
- Don't use it to make decisions about anyone's credit, employment, housing, insurance or education.
- Don't sell recordings or visit data, or share them outside your business and its advisers.
- Don't try to identify anonymous visitors by combining Candler data with other sources, except customers who've given you their details, such as by placing an order.
- Don't record your own employees or contractors without telling them.
Don't abuse the Service.
- Don't copy, resell or sublicense Candler, or reverse engineer it, except where the law allows that regardless of this policy.
- Don't get around plan limits, for example with extra free accounts.
- Don't probe, scan or load test Candler, or try to get past its security. If you've found a vulnerability, email hello@candleranalytics.com before testing further.
- Don't send malware, junk data or more traffic than your sites really produce.
- Don't share logins or API keys with anyone outside your business, or use Candler to build a competing product.
Follow the law.
Use Candler in line with the laws that apply to you and your visitors, including privacy, consumer protection, intellectual property, export control and sanctions laws.
What happens if this policy is broken.
We can remove data collected in breach of this policy, suspend the account or end the agreement, as the terms describe. Where we reasonably can, we'll tell you first and give you a chance to fix it.
To report misuse of Candler, email hello@candleranalytics.com.