No checkout, cart, account, payment, customer, private-order, or admin data in a default scan.
Default scan boundary
GradeMY reads public storefront pages and public metadata. Typical evidence includes product detail pages, product cards, structured Product and Offer data, sitemap and robots signals, visible product content, image information, and public policy or contact links.
Data not collected by default
GradeMY does not request passwords, payment information, checkout sessions, cart contents, customer accounts, private customer records, private orders, analytics, or private admin screens during a default public scan. It does not modify products or place orders.
Scan and report records
A scan record may contain the submitted URL, email used to identify the report, optional shopping request, captured public evidence, normalized report data, timestamps, operational metadata, and the artifacts emitted by the scan.
Optional connections
Where explicitly offered, a merchant may choose an optional read-only connection for deeper catalog validation. It is not required for the public scan. Any such capability must be presented with its current permissions and revocation path; it is not implied by this page.
Operational controls
Scans are bounded to public product-evidence evaluation and must not be used for abusive crawling, access-control bypassing, or private data collection.
Security contact
Report a concern to matt@grademy.store.