本政策涵盖的内容
本隐私政策说明当你直接使用 Hitsteps,或当你的浏览器与使用 Hitsteps 服务的网站互动时,Hitsteps 如何使用并保护所收集的信息。
Hitsteps 致力于保护网站所有者及其访客的隐私。我们可能会不时更新本页面,最新版本始终会发布在这里。
我们从 Hitsteps 用户收集的信息
当网站所有者注册、管理账户、提交支持请求或购买许可证时,我们可能会收集提供服务所需的信息。
- 姓名、电子邮件地址,以及在提供时的电话号码。
- Hitsteps 账户 ID、登录详情和经过哈希处理的密码数据。
- 网站详情、追踪设置、标签和仪表盘偏好。
- 在适用时的账单、订阅、发票和 Shopify 应用安装记录。
- 支持工单、消息和账户相关通信。
我们收集这些信息用于创建账户、验证用户、提供仪表盘、处理账单、防止滥用,以及回应支持请求。
Chrome 扩展数据
Hitsteps Chrome 扩展由账户所有者和授权操作员使用,用于从浏览器工具栏监控自己的 Hitsteps 仪表盘。
- 该扩展会在 Chrome 本地存储中保存用户的 Hitsteps API 密钥和扩展偏好。
- 该扩展会把 API 密钥发送给 Hitsteps,以获取访客数量、浏览量数量、仪表盘通知状态和实时支持可用性更新。
- 启用实时支持在线状态时,扩展可能会发送浏览器会话是活跃还是空闲,以免操作员离开时仍显示为可用。
- 启用通知时,扩展可能会接收并显示仪表盘事件或实时支持请求的通知标题、描述、链接和打包的本地声音选项。
Chrome 扩展不会读取浏览历史、检查网站页面内容、收集按键、监控鼠标移动,也不会向用户访问的页面注入追踪代码。
从 Google API 接收的信息的使用将遵守 Chrome Web Store User Data Policy,包括 Limited Use 要求。
为客户网站处理的信息
Hitsteps 代表网站所有者处理分析数据,使他们能够了解访客如何使用其网站。每个网站档案都属于已验证的账户所有者。
常见分析数据
- 访问页面、推荐来源、广告活动、链接、点击和导航路径。
- 浏览器、操作系统、屏幕、设备和其他技术详情。
- 低精度估计地理信息。
- 在启用 Cookie 或类似存储时的回访访客标识符。
访客提交的数据
- 访客选择提交的实时聊天消息和支持详情。
- 只有在访客提交,或网站所有者在具备适当同意的情况下配置时,才会包含姓名、电子邮件、用户名或电话号码。
- 告诉 Hitsteps 不追踪该浏览器的退出偏好。
我们不允许跨站点或跨账户追踪。一个客户网站的数据不会提供给另一个客户。
我们如何使用信息
我们只会将收集的信息用于与运营、保护、改进和支持 Hitsteps 相关的目的。
- 提供实时分析、访客历史、实时聊天、告警、可用性监控和类似 CRM 的跟进工具。
- 在已验证仪表盘内向网站所有者显示汇总和访客级报表。
- 维护账户记录、账单记录和客户支持历史。
- 保护账户、调查滥用、调试服务问题并提高可靠性。
- 发送重要服务消息,并在允许时发送用户可取消订阅的产品更新。
信息如何共享
除非我们获得许可、需要提供服务,或法律要求,否则我们不会向第三方出售、分发或出租个人信息。
- 客户网站数据只对允许访问该网站档案的已验证用户可见。
- 我们可能使用基础设施、安全、邮件、支付、分析和支持提供商来运营 Hitsteps。
- 在需要遵守法律、执行条款、防止欺诈或保护用户和服务时,我们可能披露信息。
我们的网站和客户仪表盘可能包含指向其他网站的链接。这些网站不受本隐私政策管辖,你应查看它们自己的隐私政策。
Hitsteps AI and OpenAI
Hitsteps AI is an optional dashboard feature. An account owner or administrator must enable it for the account, and each dashboard user must review a one-time disclosure before sending a first message. The account owner or an account administrator can disable Hitsteps AI later from website settings.
When a dashboard user sends a Hitsteps AI message, Hitsteps sends the user’s question, a bounded number of recent chat messages, and the Hitsteps analytics or account information needed to answer to OpenAI through its API. Confirmed account actions may also send the proposed action and the information needed to perform it. Users should avoid entering unnecessary sensitive or special-category personal information.
- Provider and purpose: OpenAI Ireland Ltd. and applicable OpenAI affiliates process the data to generate answers, invoke authorized Hitsteps tools, provide security, and prevent abuse.
- Model training: OpenAI states that API inputs and outputs are not used to train or improve its models by default unless the API customer explicitly opts in. Hitsteps does not opt in to model-training data sharing for this feature.
- Provider retention: under OpenAI’s default API controls, abuse-monitoring logs may contain prompts and responses and are retained for up to 30 days, subject to stated legal and safety exceptions. Hitsteps sends Responses API requests with response storage disabled, but that setting does not by itself remove OpenAI’s separate abuse-monitoring logs.
- Hitsteps records: Hitsteps does not normally store AI prompts or answers on its servers. It stores limited account, dashboard-user, website, request, model/tool-usage, confirmation, and categorized safety-event metadata for access control, usage limits, security, audits, and abuse prevention. AI usage and safety metadata is normally retained for 90 days. A limited conversation can remain in the user’s browser tab for up to 24 hours and can be cleared with New chat.
- International transfers: OpenAI and its infrastructure or moderation providers may process data outside the EEA, including in the United States. Hitsteps uses the data-processing and transfer safeguards in its provider agreement, including the European Commission’s Standard Contractual Clauses where required, and applies data minimization, access control, encryption in transit, bounded history, and pseudonymous safety identifiers as supplementary measures.
See the Hitsteps subprocessor list for provider details and links to OpenAI’s current data-control and subprocessor information.
我们保留信息多久
除非出于法律、会计、安全或争议解决原因需要更长时间,否则我们只在本政策所述目的需要时保留信息。
- 账户信息会在客户账户处于活跃并被使用期间保留。
- 不活跃的客户账户可能会在 720 天不活跃后被暂停并删除。
- 访客级分析数据会根据客户购买的套餐保留 30 到 360 天。
- 汇总统计,例如总浏览量或访客数量,可能会在客户拥有活跃账户期间保留。
我们如何保护信息
我们使用旨在保护信息免遭未经授权访问、披露、变更或销毁的技术和组织保障措施。
- 仪表盘访问需要身份验证,网站数据不再通过公开报表 URL 共享。
- 密码会加盐并哈希处理;不会以明文存储密码。
- Hitsteps 默认将服务访问重定向到 HTTPS,以加密传输中的数据。
- 生产数据访问仅限授权员工,开发工作会在可行时使用分离数据或虚拟数据。
- 服务器受到防火墙控制保护,并通过安全更新和运行监控进行维护。
访问、删除和退出选择
网站所有者可以从 Hitsteps 仪表盘管理许多与隐私相关的设置,包括同意、匿名化和追踪选项。
访客应首先联系收集其信息的网站所有者。如果网站所有者七天内没有回复,访客可以 联系我们,并提供网站地址以及足够信息,以便我们定位匹配记录。
访客也可以使用我们的 追踪退出表单.
需要数据处理协议的客户可按请求获取 DPA 表单。
我们如何使用 Cookie
Cookie 帮助我们让用户保持登录、记住仪表盘偏好、诊断服务问题、理解回访访客并尊重退出选择。登录和安全所必需的仪表盘 Cookie 无法在 Hitsteps 内停用。追踪 Cookie 只会在网站所有者设置和访客同意要求允许时使用。
浏览器控制 Cookie 存储。你可以在浏览器设置中删除 Cookie,但这样做可能会让你退出登录或重置偏好。
本政策的变更
我们可能更新本隐私政策,以反映产品、安全、法律或运营变化。当我们作出重大变更时,会更新本页面顶部日期,并在适当时提供额外通知。
关于本政策的问题可以通过我们的 联系页面.