Security and data use

Public storefront evidence. Read only.

Default GradeMY scans do not require a store login and do not access private commerce or customer systems.

Last updated August 30, 2026

No checkout, cart, account, payment, customer, private-order, or admin data in a default scan.

Default scan boundary

GradeMY reads public storefront pages and public metadata. Typical evidence includes product detail pages, product cards, structured Product and Offer data, sitemap and robots signals, visible product content, image information, and public policy or contact links.

Data not collected by default

GradeMY does not request passwords, payment information, checkout sessions, cart contents, customer accounts, private customer records, private orders, analytics, or private admin screens during a default public scan. It does not modify products or place orders.

Scan and report records

A scan record may contain the submitted URL, email used to identify the report, optional shopping request, captured public evidence, normalized report data, timestamps, operational metadata, and the artifacts emitted by the scan.

Optional connections

Where explicitly offered, a merchant may choose an optional read-only connection for deeper catalog validation. It is not required for the public scan. Any such capability must be presented with its current permissions and revocation path; it is not implied by this page.

Operational controls

Scans are bounded to public product-evidence evaluation and must not be used for abusive crawling, access-control bypassing, or private data collection.

Security contact

Report a concern to matt@grademy.store.