Privacy और cookie policy

Hitsteps गोपनीयता और कुकी नीति

Hitsteps website owners के लिए real-time analytics, visitor insights और live support tools provide करता है. यह policy बताती है कि हम क्या collect करते हैं, क्यों collect करते हैं, कितने समय तक रखते हैं और visitors tracking को कैसे control कर सकते हैं.

Hitsteps गोपनीयता नियंत्रण
अंतिम अपडेट 11 August 2026

Default privacy

IP anonymization enabled है, visitor data हर website account तक scoped है, और public report URLs को authentication चाहिए।

सीमित रिटेंशन

Visitor-level analytics data customer plan के अनुसार 30 से 360 दिनों तक retained रहता है, फिर deleted होता है।

कोई क्रॉस-अकाउंट ट्रैकिंग नहीं

हम unrelated customer websites के बीच visitor profiles combine नहीं करते और एक customer का data दूसरे को available नहीं कराते।

विजिटर की पसंद

Visitors Hitsteps इस्तेमाल करने वाली websites पर tracking से opt out कर सकते हैं, और access या deletion request कर सकते हैं।

अवलोकन

यह policy क्या cover करती है

यह privacy policy बताती है कि जब आप Hitsteps सीधे use करते हैं, या आपका browser Hitsteps services use करने वाली website से interact करता है, तब collected information को Hitsteps कैसे use और protect करता है.

Hitsteps website owners और उनके visitors की privacy protect करने के लिए committed है. हम इस page को समय-समय पर update कर सकते हैं, और newest version हमेशा यहाँ published रहेगा.

अकाउंट जानकारी

Hitsteps users से collect की जाने वाली information

जब website owner register करता है, account manage करता है, support request खोलता है, या license purchase करता है, तो हम service provide करने के लिए required information collect कर सकते हैं।

  • Provided होने पर name, email address और telephone number।
  • Hitsteps account ID, login details और hashed password data।
  • Website details, tracking settings, labels और dashboard preferences।
  • जहां applicable हो billing, subscription, invoice और Shopify app installation records।
  • Support tickets, messages और account-related correspondence।

हम यह information accounts create करने, users authenticate करने, dashboards provide करने, billing process करने, abuse prevent करने और support requests का जवाब देने के लिए collect करते हैं।

ब्राउजर extension

Chrome extension डेटा

Hitsteps Chrome extension account owners और authorized operators द्वारा browser toolbar से अपना Hitsteps dashboard monitor करने के लिए इस्तेमाल होता है।

  • Extension user की Hitsteps API key और extension preferences को Chrome local storage में store करता है।
  • Extension visitor counts, pageview counts, dashboard notification status और live support availability updates retrieve करने के लिए API key Hitsteps को भेजता है।
  • Live support presence enabled होने पर extension browser session active या idle है या नहीं भेज सकता है ताकि operator away होने पर available न दिखे।
  • Notifications enabled होने पर extension dashboard events या live support requests के लिए notification titles, descriptions, links और bundled local sound choices receive और display कर सकता है।

Chrome extension browsing history नहीं पढ़ता, websites पर page content inspect नहीं करता, keystrokes collect नहीं करता, mouse movement monitor नहीं करता, या user द्वारा visited pages में tracking code inject नहीं करता।

Google APIs से received information का उपयोग Chrome Web Store User Data Policy, Limited Use requirements सहित, का पालन करेगा।

एनालिटिक्स डेटा

Customer websites के लिए processed information

Hitsteps website owners की ओर से analytics data process करता है ताकि वे समझ सकें कि visitors उनकी sites कैसे use करते हैं। हर website profile अपने authenticated account owner से belong करता है।

सामान्य एनालिटिक्स डेटा

  • Visited pages, referrers, campaigns, links, clicks और navigation paths।
  • Browser, operating system, screen, device और अन्य technical details।
  • Low-accuracy estimated geographic information।
  • Cookies या similar storage enabled होने पर returning visitor identifiers।

विजिटर द्वारा सबमिट डेटा

  • Live chat messages और support details जिन्हें visitors submit करना चुनते हैं।
  • Names, emails, usernames, या phone numbers केवल तब जब visitor द्वारा submitted हों या website owner द्वारा proper consent के साथ configured हों।
  • Opt-out preferences जो Hitsteps को उस browser को track न करने के लिए कहते हैं।

हम cross-site या cross-account tracking allow नहीं करते। एक customer website का data दूसरे customer को available नहीं कराया जाता।

उद्देश्य

हम information कैसे use करते हैं

Collected information को हम केवल Hitsteps operate, secure, improve और support करने से जुड़े purposes के लिए use करते हैं.

  • Real-time analytics, visitor history, live chat, alerts, uptime monitoring और CRM-style follow-up tools provide करना.
  • Website owners को authenticated dashboards में aggregated और visitor-level reports दिखाना.
  • Account records, billing records और customer support history maintain करना.
  • Accounts protect करना, abuse investigate करना, service problems debug करना और reliability improve करना.
  • Important service messages और जहाँ allowed हो product updates भेजना, जिनसे users unsubscribe कर सकें.
शेयरिंग

Information कैसे share होती है

हम personal information को third parties को sell, distribute या lease नहीं करते, जब तक permission न हो, service provide करनी जरूरी न हो, या law require न करे.

  • Customer website data केवल authenticated users को दिखता है जिन्हें उस website profile का access allowed है.
  • Hitsteps operate करने के लिए हम infrastructure, security, email, payment, analytics और support providers use कर सकते हैं.
  • Law comply करने, terms enforce करने, fraud prevent करने या users और service protect करने के लिए required होने पर information disclose कर सकते हैं.

हमारी website और customer dashboards में other websites के links हो सकते हैं. वे इस privacy policy से governed नहीं हैं; उनकी अपनी policies review करें.

Optional AI feature

Hitsteps AI and OpenAI

Hitsteps AI is an optional dashboard feature. An account owner or administrator must enable it for the account, and each dashboard user must review a one-time disclosure before sending a first message. The account owner or an account administrator can disable Hitsteps AI later from website settings.

When a dashboard user sends a Hitsteps AI message, Hitsteps sends the user’s question, a bounded number of recent chat messages, and the Hitsteps analytics or account information needed to answer to OpenAI through its API. Confirmed account actions may also send the proposed action and the information needed to perform it. Users should avoid entering unnecessary sensitive or special-category personal information.

  • Provider and purpose: OpenAI Ireland Ltd. and applicable OpenAI affiliates process the data to generate answers, invoke authorized Hitsteps tools, provide security, and prevent abuse.
  • Model training: OpenAI states that API inputs and outputs are not used to train or improve its models by default unless the API customer explicitly opts in. Hitsteps does not opt in to model-training data sharing for this feature.
  • Provider retention: under OpenAI’s default API controls, abuse-monitoring logs may contain prompts and responses and are retained for up to 30 days, subject to stated legal and safety exceptions. Hitsteps sends Responses API requests with response storage disabled, but that setting does not by itself remove OpenAI’s separate abuse-monitoring logs.
  • Hitsteps records: Hitsteps does not normally store AI prompts or answers on its servers. It stores limited account, dashboard-user, website, request, model/tool-usage, confirmation, and categorized safety-event metadata for access control, usage limits, security, audits, and abuse prevention. AI usage and safety metadata is normally retained for 90 days. A limited conversation can remain in the user’s browser tab for up to 24 hours and can be cleared with New chat.
  • International transfers: OpenAI and its infrastructure or moderation providers may process data outside the EEA, including in the United States. Hitsteps uses the data-processing and transfer safeguards in its provider agreement, including the European Commission’s Standard Contractual Clauses where required, and applies data minimization, access control, encryption in transit, bounded history, and pseudonymous safety identifiers as supplementary measures.

See the Hitsteps subprocessor list for provider details and links to OpenAI’s current data-control and subprocessor information.

रिटेंशन

हम information कितने समय तक रखते हैं

हम information केवल उतने समय तक रखते हैं जितना इस policy में described purposes के लिए needed हो, जब तक legal, accounting, security या dispute-resolution reasons से longer period required न हो.

  • Account information customer account active और used रहने तक रखी जाती है.
  • Inactive customer accounts 720 days inactivity के बाद suspend और delete हो सकते हैं.
  • Visitor-level analytics data customer purchased plan के आधार पर 30 से 360 days तक retained रहता है.
  • Aggregated statistics, जैसे total pageviews या visitor counts, customer active account रहने तक रह सकते हैं.
सुरक्षा

हम information कैसे protect करते हैं

हम unauthorized access, disclosure, alteration या destruction से बचाने के लिए technical और organizational safeguards use करते हैं.

  • Dashboard access authentication require करता है, और website data अब public report URLs से share नहीं होता.
  • Passwords salted और hashed हैं; cleartext passwords store नहीं होते.
  • Hitsteps service access को default रूप से HTTPS पर redirect करता है ताकि transit में data encrypted रहे.
  • Production data access authorized staff तक limited है, और development work जहाँ possible हो separated या dummy data use करता है.
  • Servers firewall controls से protected हैं और security updates तथा operational monitoring से maintained हैं.
विकल्प

Access, deletion और opt-out choices

Website owners consent, anonymization और tracking options सहित कई privacy-related settings अपने Hitsteps dashboard से manage कर सकते हैं.

Visitors को पहले उस website owner से contact करना चाहिए जहाँ information collect हुई. अगर website owner seven days में reply न दे, तो visitors हमसे contact करें और website address तथा match locate करने के लिए पर्याप्त information provide कर सकते हैं.

Visitors हमारे ट्रैकिंग ऑप्ट-आउट फॉर्म.

जिन customers को DPA चाहिए, उनके लिए request पर DPA forms available हैं.

कुकी नीति

हम cookies कैसे use करते हैं

Cookies users को logged in रखने, dashboard preferences याद रखने, service problems diagnose करने, returning visitors समझने और opt-out choices respect करने में मदद करती हैं. Login और security के लिए necessary dashboard cookies Hitsteps के अंदर disable नहीं की जा सकतीं. Tracking cookies केवल website owner settings और visitor consent requirements से permitted होने पर use होती हैं.

Cookie storage browser control करता है. Browser settings से cookies remove कर सकते हैं, लेकिन इससे आप log out हो सकते हैं या preferences reset हो सकती हैं.

अपडेट

इस policy में changes

Product, security, legal या operational changes reflect करने के लिए हम इस privacy policy को update कर सकते हैं. Material changes होने पर हम page के top पर date update करेंगे और appropriate होने पर additional notice दे सकते हैं.

इस policy के questions हमारे संपर्क पेज.