Privacy
Privacy boundaries for a training-only product.
This page summarizes the current beta data boundaries for ShoppableLab. It is written to match the product implementation and should be reviewed again before a broader public launch.
What ShoppableLab collects
- Email addresses submitted for Free Creator Testing Kit lead capture, ShoppableLab Starter Pack checkout, Mission Pack checkout when privately enabled, or fresh access-link requests.
- Anonymous browser IDs used to connect mock drill starts, completions, and safe result records.
- Mock drill context such as route, drill type, selected mock product IDs, score, scenario IDs, and safe option IDs.
- Free Creator Testing Kit route opens and PDF button clicks.
- Private purchase and access records needed for hosted checkout, delivery, and duplicate purchase prevention.
Payments and hosted checkout
- ShoppableLab Starter Pack checkout uses a hosted payment page when checkout is enabled.
- The ShoppableLab Starter Pack is a one-time downloadable PDF purchase with no subscription.
- ShoppableLab stores private purchase, payment-event, and access-delivery records only as needed to deliver the ShoppableLab Starter Pack.
- Private Mission Pack checkout, when enabled, reuses the same purchase and entitlement system with a separate product configuration.
- ShoppableLab does not store card numbers, card last four, card scheme, issuer bank, payment instruments, or raw payment-provider responses.
Private Mission access
- Mission access links are short-lived and single-use. ShoppableLab stores only a cryptographic hash of the link token.
- A confirmed link creates an opaque HttpOnly browser cookie. Only its cryptographic hash, normalized entitlement email, absolute expiry, and bounded access timestamps are stored server-side.
- Every protected Mission request rechecks the active entitlement. Expired, revoked, malformed, or unverifiable access fails closed.
- Valid recovery requests always receive the same generic browser response, whether or not the email has access.
Analytics
- Product analytics are limited to broad usage events that help improve the training flow.
- Analytics events are limited to safe funnel context such as route, drill type, source, status, mock product ID, selected count, and mock scores.
- PostHog analytics must not include email, payment details, private access links, provider references, secrets, transcript text, or other raw user-entered text.
Mission attempts in this browser
- The latest five Mission attempts are stored in this browser's local storage. Each attempt can include its deterministic event log, score, red flags, submitted transcript, and structured AI evaluation metadata.
- The Device Check itself is camera-only and does not request audio. ShoppableLab does not persist raw audio or camera frames.
- Answer aloud is optional. If you choose it later in the Mission, the browser may request microphone access for one response of up to 20 seconds, and browser or vendor speech recognition may process that audio.
- After the run, the transcript you submit is sent to ShoppableLab's server-side DeepSeek evaluator. ShoppableLab does not make claims here about the provider's retention policy.
- Transcript text is not included in PostHog analytics, and neither is other raw user-entered text.
- The Mission Library provides a Clear local mission data control. You can also clear site data through your browser controls.
- Milestone 1 has no remote account copy of a Mission attempt. Clearing browser data, using another browser, or losing local storage can make an attempt unavailable.
Getting the PDF again
- Fresh-link requests ask for the email used at checkout and always return a generic success response for valid email submissions.
- If the email has the ShoppableLab Starter Pack, ShoppableLab sends a fresh short-lived download link.
- If the email does not have the ShoppableLab Starter Pack, the browser response stays the same to protect purchase privacy.
Storage boundaries
- Private production records are stored in server-side systems, not in public browser storage.
- Free drill and lead records are kept separate from payment and access records.
- Payment records are used only for checkout, delivery, support, and duplicate purchase prevention.
Marketplace data
- ShoppableLab is independent educational software and is not affiliated with, endorsed by, or sponsored by TikTok, TikTok Shop, or any marketplace platform.
- The product uses mock training data and does not use real TikTok Shop data, marketplace scraping, official platform data access, official screenshots, logos, or official UI assets.