What this policy covers
This privacy policy describes how Hitsteps uses and protects information collected when you use Hitsteps directly, or when your browser interacts with a website that uses Hitsteps services.
Hitsteps is committed to protecting the privacy of website owners and their visitors. We may update this page from time to time, and the newest version will always be published here.
Information we collect from Hitsteps users
When a website owner registers, manages an account, opens a support request, or purchases a license, we may collect information needed to provide the service.
- Name, email address, and telephone number if provided.
- Hitsteps account ID, login details, and hashed password data.
- Website details, tracking settings, Segment definitions, and dashboard preferences.
- Billing, subscription, invoice, and Shopify app installation records where applicable.
- Support tickets, messages, and account-related correspondence.
We collect this information to create accounts, authenticate users, provide dashboards, process billing, prevent abuse, and respond to support requests.
Chrome extension data
The Hitsteps Chrome extension is used by account owners and authorized operators to monitor their own Hitsteps dashboard from the browser toolbar.
- The extension stores the user's Hitsteps API key and extension preferences in Chrome local storage.
- The extension sends the API key to Hitsteps to retrieve visitor counts, pageview counts, dashboard notification status, and live support availability updates.
- When live support presence is enabled, the extension may send whether the browser session is active or idle so the operator is not shown as available while away.
- When notifications are enabled, the extension may receive and display notification titles, descriptions, links, and bundled local sound choices for dashboard events or live support requests.
The Chrome extension does not read browsing history, inspect page content on websites, collect keystrokes, monitor mouse movement, or inject tracking code into pages visited by the user.
Our use of information received from Google APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.
Information processed for customer websites
Hitsteps processes analytics data on behalf of website owners so they can understand how visitors use their sites. Each website profile belongs to its authenticated account owner.
Typical analytics data
- Visited pages, referrers, campaigns, links, clicks, and navigation paths.
- Browser, operating system, screen, device, and other technical details.
- Low-accuracy estimated geographic information.
- Returning visitor identifiers when cookies or similar storage are enabled.
Visitor-submitted data
- Live chat messages and support details visitors choose to submit.
- Names, emails, usernames, or phone numbers only when submitted by the visitor or configured by the website owner with the proper consent.
- Opt-out preferences that tell Hitsteps not to track that browser.
We do not allow cross-site or cross-account tracking. Data for one customer website is not made available to another customer.
How we use information
We use collected information only for purposes connected to operating, securing, improving, and supporting Hitsteps.
- Provide real-time analytics, visitor history, live chat, alerts, uptime monitoring, and CRM-style follow-up tools.
- Show website owners aggregated and visitor-level reports inside authenticated dashboards.
- Maintain account records, billing records, and customer support history.
- Protect accounts, investigate abuse, debug service problems, and improve reliability.
- Send important service messages and, where allowed, product updates that users can unsubscribe from.
How information is shared
We do not sell, distribute, or lease personal information to third parties unless we have permission, need to provide the service, or are required by law.
- Customer website data is visible only to authenticated users who are allowed to access that website profile.
- We may use infrastructure, security, email, payment, analytics, and support providers to operate Hitsteps.
- We may disclose information when required to comply with law, enforce our terms, prevent fraud, or protect our users and service.
Our website and customer dashboards may contain links to other websites. Those websites are not governed by this privacy policy, and you should review their own privacy policies.
Hitsteps AI and OpenAI
Hitsteps AI is an optional dashboard feature. An account owner or administrator must enable it for the account, and each dashboard user must review a one-time disclosure before sending a first message. The account owner or an account administrator can disable Hitsteps AI later from website settings.
When a dashboard user sends a Hitsteps AI message, Hitsteps sends the user’s question, a bounded number of recent chat messages, and the Hitsteps analytics or account information needed to answer to OpenAI through its API. Confirmed account actions may also send the proposed action and the information needed to perform it. Users should avoid entering unnecessary sensitive or special-category personal information.
- Provider and purpose: OpenAI Ireland Ltd. and applicable OpenAI affiliates process the data to generate answers, invoke authorized Hitsteps tools, provide security, and prevent abuse.
- Model training: OpenAI states that API inputs and outputs are not used to train or improve its models by default unless the API customer explicitly opts in. Hitsteps does not opt in to model-training data sharing for this feature.
- Provider retention: under OpenAI’s default API controls, abuse-monitoring logs may contain prompts and responses and are retained for up to 30 days, subject to stated legal and safety exceptions. Hitsteps sends Responses API requests with response storage disabled, but that setting does not by itself remove OpenAI’s separate abuse-monitoring logs.
- Hitsteps records: When encrypted support-history retention is enabled, Hitsteps stores questions, bounded recent chat context, AI replies, and proposed or confirmed action details for 30 days to investigate failures and improve reliability. The content is encrypted with separately managed keys. Staff review requires an exact account and request, conversation, or action reference, a named reviewer, a ticket or incident reason, a time-limited production authorization, and an access-audit record written before decryption. Hitsteps deletes the encrypted content automatically after 30 days and retains the content-access audit for 365 days. Enabling this mode requires users to review the updated Hitsteps AI disclosure. Separately, Hitsteps retains limited account, dashboard-user, website, request, model/tool-usage, confirmation, and categorized safety-event metadata for 90 days. A limited conversation can also remain in the user’s browser tab for up to 24 hours and can be cleared with New chat.
- International transfers: OpenAI and its infrastructure or moderation providers may process data outside the EEA, including in the United States. Hitsteps uses the data-processing and transfer safeguards in its provider agreement, including the European Commission’s Standard Contractual Clauses where required, and applies data minimization, access control, encryption in transit, bounded history, and pseudonymous safety identifiers as supplementary measures.
See the Hitsteps subprocessor list for provider details and links to OpenAI’s current data-control and subprocessor information.
How long we keep information
We keep information only as long as it is needed for the purposes described in this policy, unless a longer period is required for legal, accounting, security, or dispute-resolution reasons.
- Account information is kept while the customer account is active and being used.
- Inactive customer accounts may be suspended and deleted after 720 days of inactivity.
- The Free plan includes 14 days of detailed visitor history; paid plans offer 30–360 days. Visitor profiles are aged from their most recent activity, and expired records are removed in scheduled batches.
- Aggregated statistics, such as total pageviews or visitor counts, may remain while the customer has an active account.
How we protect information
We use technical and organizational safeguards designed to protect information from unauthorized access, disclosure, alteration, or destruction.
- Dashboard access requires authentication, and website data is no longer shared through public report URLs.
- Passwords are salted and hashed; cleartext passwords are not stored.
- Hitsteps redirects service access to HTTPS by default to encrypt data in transit.
- Production data access is limited to authorized staff, and development work uses separated or dummy data where possible.
- Servers are protected with firewall controls and maintained with security updates and operational monitoring.
Access, deletion, and opt-out choices
Website owners can manage many privacy-related settings from their Hitsteps dashboard, including consent, anonymization, and tracking options.
Visitors should first contact the website owner where their information was collected. If the website owner does not reply within seven days, visitors may Contact us and provide the website address plus enough information for us to locate a match.
Visitors can also opt out from being tracked on customer websites by using our tracking opt-out form.
DPA forms are available upon request for customers who need one.
How we use cookies
Cookies help us keep users logged in, remember dashboard preferences, diagnose service problems, understand returning visitors, and respect opt-out choices. Dashboard cookies that are necessary for login and security cannot be disabled inside Hitsteps. Tracking cookies are used only when permitted by the website owner's settings and visitor consent requirements.
Browsers control cookie storage. You can remove cookies in your browser settings, but doing so may log you out or reset preferences.
Changes to this policy
We may update this privacy policy to reflect product, security, legal, or operational changes. When we make material changes, we will update the date at the top of this page and may provide additional notice when appropriate.
Questions about this policy can be sent through our contact page.