On this page
Privacy Policy
How Candler handles information about the people who use it: store owners, their teams, and anyone reading this site. If a store records your visit with Candler, that part is further down.
The short version.
- This site doesn't track you.
- No cookies, no analytics and no ad pixels on candleranalytics.com.
- We don't sell information.
- Not yours, and not the visit data stores collect with Candler.
- Card details go to Stripe.
- We never see or store your full card number.
- Stores control their visitors' data.
- We record visits for the store, on its instructions. Ask the store, or ask us and we'll pass it on.
Who we are.
Candler Analytics ("Candler", "we", "us") runs Candler at candleranalytics.com and app.candleranalytics.com. We decide how the information in this policy is used, so we're its controller. Reach us at hello@candleranalytics.com or 3278 Deer Ln, Kirbyville, MO 65679.
What we collect.
When you or your team use Candler
- Account details: your name, email address and password. The password is stored only as a one-way hash we can't reverse.
- Store details: store name and address, timezone and currency.
- Team details: the name, email address and role of everyone on the account, including people you invite before they accept.
- Billing details: your plan, billing period and subscription status, and the ID Stripe gives your account. Stripe collects your card and billing address. We can see your card's brand, last four digits and expiry date, your billing address and any tax ID, but never the full card number.
- Sign-ins: a random sign-in token (stored only as a hash), your browser's user agent, and when you were last active.
- A security log: sign-ins, failed sign-ins and changes to settings, keys and team members. It stores a salted hash of the IP address, never the address itself.
- Server logs: our web server records requests to the app, including the IP address, the address requested and the browser's user agent.
- Messages: anything you send us by email.
When you read this site
Nothing. candleranalytics.com sets no cookies, runs no analytics or ad pixels, loads its fonts from our own server, and our server keeps no log of visits to it. Cloudflare, which runs our DNS and can carry traffic to our servers, processes your IP address to deliver the page and protect it from attacks.
How we use it.
- To run your account and the Service, and sign you in.
- To bill you through Stripe and keep the records tax law requires.
- To send emails the Service needs: signup and password reset links, invitations, receipts, security alerts, and notice of changes to prices, terms or this policy.
- To answer you when you write to us.
- To keep Candler secure, stop abuse and fix errors.
- To see, in aggregate, which features get used, so we know what to improve.
- To meet legal obligations and enforce our terms.
If we ever send product news, every email will have a one-click unsubscribe.
Our legal bases in the EU and UK.
- Contract: running your account, billing, and service emails.
- Legitimate interests: security, preventing abuse, fixing errors and improving the product. You can object to these.
- Legal obligation: tax and accounting records, and answering lawful requests.
- Consent: anything we ask your permission for. You can withdraw it at any time.
Who we share it with.
Only the providers that help us run Candler, each under a contract that limits them to that job:
| Provider | What they do | Where |
|---|---|---|
| Hetzner Online GmbH | Servers, storage and backups | Germany |
| Cloudflare, Inc. | DNS and network protection | United States, global network |
| Stripe, Inc. | Payments, invoices and tax | United States |
| Email delivery service | Sends account emails | Named here before we start using one |
We also share information when the law requires it, to protect people from harm, with professional advisers under confidentiality, or with a buyer if Candler is sold, who would then be bound by this policy.
We don't sell personal information, and we don't share it for cross-context behavioral advertising. We haven't done either in the last 12 months.
If a store records your visit with Candler.
Stores and other websites use Candler to understand how people use them. When they do, the store decides what's collected and why. The store is the controller, and we process the data on its behalf under the Data Processing Addendum. The store's own privacy policy applies to it.
What Candler can record for a store:
- The pages you view, your clicks, how far you scroll, and your mouse position on a computer, about once a second.
- A replay of how the pages looked and changed during your visit.
- Your device type, browser, screen size, language and timezone, the country you're in (from Cloudflare, not stored IP addresses), and the site or campaign that sent you.
- Carts and orders: products, amounts and the order number.
- A random ID in a cookie that recognizes you when you come back. The cookies page lists every one.
- If store staff add them, your name, email, phone and notes about you.
What it doesn't record: anything you type into a form is masked in your browser before it's sent, and payment card fields aren't recorded at all. Your IP address isn't stored with your visits.
How long it's kept depends on the store's plan and settings. Recordings are kept between 14 and 180 days.
Opting out. Browsers that send the Global Privacy Control signal aren't tracked. A store's opt-out link, its address with ?candler_optout=1 added, turns Candler off in that browser for that store. Clearing your cookies resets your ID.
Your rights over that data. Contact the store. If you contact us instead, we'll pass your request to the store and help it respond. We can't act on that data without the store's instructions.
How long we keep it.
| Information | How long |
|---|---|
| Account, store and team details | While the account is open. Deleted within 30 days of closing it, and from backups within a further 30 days. |
| Billing and tax records | 7 years, as tax law requires. Stripe keeps its own records under its policy. |
| Sign-in sessions | Until they expire, at most 14 days, or 30 days after last use. |
| Signup and password reset links | Until they expire: 24 hours and 60 minutes. |
| Team invitations | 30 days after they expire. |
| Security log | 400 days. |
| Error reports | 90 days. |
| Server logs | Only as long as needed for security and troubleshooting, then deleted. |
| Emails with us | Up to 3 years after the conversation ends. |
Where it's stored.
Candler's servers, database and backups are in Nuremberg, Germany. We're based in the United States and work on the Service from there, and Stripe and Cloudflare are US companies. When personal data from the EU, the UK or Switzerland goes to the US, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum and Swiss changes), or on the provider's certification under the EU-US Data Privacy Framework.
How we protect it.
Connections are encrypted with HTTPS. Passwords are hashed with scrypt. Sign-in tokens, reset links and API keys are stored only as hashes. Each account's data is kept apart from every other's, and access inside an account follows the roles its owner sets. Our servers only accept web traffic and key-based administrator logins, and they install security updates automatically. The security annex has the full list.
Found a security problem? Email hello@candleranalytics.com. Please give us a chance to fix it before telling anyone else.
Your rights.
Wherever you live, you can ask us for a copy of your information, to correct it, or to delete it. You can change most account details yourself in Settings. For anything else, email hello@candleranalytics.com from the address on your account.
EU, UK and Switzerland. You also have the right to object to processing based on legitimate interests, to restrict processing, to receive your data in a portable format, and to complain to your data protection authority.
US states with privacy laws, including California, Colorado, Connecticut, Virginia, Utah, Texas and Oregon. You have the right to know what we collect and why, to get a copy, to correct it and to delete it. You can also opt out of the sale or sharing of personal information and of targeted advertising, though we do neither. We won't treat you differently for using these rights. An authorized agent can make a request for you. We verify requests by matching them to the email address on the account.
For Californians, the categories we collect are: identifiers (name, email, IP address in server logs), commercial information (plan and billing history), internet activity (how you use the dashboard), and account login details. We use them for the purposes in How we use it, and disclose them only to the providers in Who we share it with.
We answer requests within 30 days, or 45 days where US state law allows it, and tell you if we need longer. If we turn down a request, you can appeal by replying to our answer with "appeal". We'll respond within 60 days, and if you're still not satisfied, you can contact your state's attorney general.
Children.
Candler is for businesses and isn't meant for anyone under 18. We don't knowingly collect children's information. Stores may not use Candler on sites aimed at children, under our Acceptable Use Policy.
Changes to this policy.
When we change this policy, we update the date at the top. If a change matters, we'll email account owners before it takes effect.
How to reach us.
Email hello@candleranalytics.com, or write to Candler Analytics, 3278 Deer Ln, Kirbyville, MO 65679.