Scanning policy
What a scan does
Version 1.0 · 2026-09-07
Exactly what our browser does to a site, so nobody has to guess. If a scan of your store ever does something not on this list, that is a bug and we want to hear about it.
Every scan
- Requests public pages over HTTPS with an ordinary desktop browser user agent, from a United States address.
- Sends the Global Privacy Control and Do Not Track headers, because the visitor we are imitating is one who has already opted out.
- Uses a fresh browser context per page, with no cookies and no history.
- Observes each page for about four seconds and records outbound requests, cookies, and local storage keys.
- Refuses to scan any address that resolves to a private network.
Never
- Logs in, or attempts to. There is no credential handling anywhere in the scanner.
- Submits a form, enters an email address, or places an order.
- Probes for vulnerabilities, enumerates paths, or requests anything not linked from the pages it was given.
- Bypasses a paywall, a password, a robots directive on a disallowed path, or any other access control.
- Retains the page content. We keep the request log and the cookie inventory, not your pages.
The one write
A paid scan of a store adds one item to a cart, which is the only way a checkout page can be reached. It is the same request a shopper's browser makes when they press Add to cart. Nothing is purchased, no contact details are entered, and because Shopify creates an abandoned-checkout record only once contact details exist, none is created. The cart is discarded with the browser context at the end of the scan.
The free homepage scan performs no writes at all.
Load
A full scan is a handful of page loads spread over about a minute: less traffic than one curious visitor, and far less than any search engine crawler. Free scans are rate limited per address. If you operate a site and want us to stop scanning it, say so and we will block the domain.
Reporting a problem
If a scan caused something unexpected on your site, tell us with the date and time and we will find it in the logs and fix it: hello@snitch.example.