Security & GDPR

Monitor checkout without hoarding customer data.

CashFlowCanary focuses on minimal read-only signals, filtered proof and explicit actions. The service watches useful conversion signals without collecting card data or customer cart contents.

What CashFlowCanary deliberately limits

The value comes from checkout signal, not broad data collection.

No card data

CashFlowCanary does not collect or store card numbers. Payments are handled by the configured payment provider.

No customer cart contents

Technical proof is filtered to focus on status, page, error and action.

No public third-party tracking

The public website stays free from third-party scripts and external CDN dependencies.

Shareable proof

Reports are designed to be useful, not intrusive.

A CashFlowCanary proof should help an agency, merchant or developer understand the incident without exposing an end customer.

  • Read-only noindex proof links
  • PDF/CSV by plan with filtered technical data
  • Revocation and expiry for public proof links
Filtered CashFlowCanary incident proof

Processed data

The service processes the data required for monitoring: user account, monitored site, plan configuration, check status, incidents, sent alerts and generated reports.

Data not collected

  • Card numbers and sensitive payment data.
  • Detailed end-customer cart contents.
  • Full screenshots or payloads containing unnecessary personal data.
  • Advertising scripts or third-party trackers on the public website.

Application security

  • Sensitive forms use session, CSRF, trusted origin and rate limiting.
  • Exports and proof pages are no-store or noindex where appropriate.
  • Secrets stay server-side and never in public assets.
  • Payments and webhooks are activated server-side after verification.

Retention and deletion

Proof, reports, public links and sessions are intended to stay bounded in time. The duration depends on the plan and purpose: incident operations, contractual proof, security or legal obligations.

GDPR rights

You can request access, correction, limitation, objection, export or deletion via the contact page.