1. Scope
Auditario is currently a prelaunch information site with a contact-only waitlist. This notice describes the data handled by that site. It does not describe a merchant application, secure document workspace, Shopify app, or billing service because none of those services is available today.
2. What the waitlist collects
The waitlist accepts one required field and four optional business-context fields.
| Field | Required? | Why it is collected |
|---|---|---|
| Email address | Yes | To record and respond to your early-access interest. It is normalized to lowercase before storage. |
| Shopify store URL | No | To understand the store associated with the request. Providing it does not connect Auditario to Shopify. |
| Current 3PL | No | To understand provider interest and future format demand. |
| Monthly 3PL spend band | No | To understand which prelaunch use cases may be a fit. |
| Plan interest | No | To understand interest in the planned flat-price tiers. It is not an order or price reservation. |
The waitlist record also contains the time it was first created, the time it was most recently updated, and the version of the waitlist consent notice in effect when it was submitted. A hidden anti-bot field is checked but is not stored with a valid submission.
3. How the submission is processed
- Your browser sends the waitlist fields as JSON to Auditario's /api/waitlist endpoint.
- A Cloudflare Pages Worker validates the request, rejects oversized or invalid input, normalizes the email address, checks Cloudflare Turnstile, and applies a submission rate limit.
- The handler derives a one-way hash of the email address for the storage key. The record itself still contains the email address and any optional fields you supplied.
- The record is stored in the Auditario WAITLIST Cloudflare KV namespace with an automatic expiry.
- If the same email is submitted again, Auditario updates that record rather than creating a second one.
Cloudflare provides the site delivery, bot verification, request processing, and KV storage used by this waitlist. Like other web infrastructure providers, Cloudflare receives routine network request information, such as an IP address and user agent, to deliver and protect the service under its own platform practices. Auditario's waitlist record does not include those network fields. Separately, the Worker stores a one-way hash derived from the requesting IP address with a daily submission counter for abuse prevention; the raw address is not written to that record and the counter expires automatically within two days.
The waitlist handler does not email the submission anywhere. Its application error records contain operational information such as the request method, path, and error message—not the submitted waitlist field values.
4. How Auditario uses the information
Auditario uses waitlist information only to:
- record and de-duplicate early-access interest;
- contact you about availability, qualification, or relevant product research;
- understand aggregate interest by provider, spend band, store, or planned tier; and
- maintain and protect the waitlist service.
Waitlist information is not used to run an invoice audit, create a merchant account, connect a Shopify store, calculate a discrepancy, authorize a dispute, or train an auditing model.
5. Retention and deletion
Each waitlist record has a maximum Cloudflare KV time-to-live of 180 days from its most recent submission. A repeat submission refreshes that expiry and updates the record while preserving its original creation time. Cloudflare KV removes the record after the expiry.
You can request earlier deletion by emailing hello@auditario.com with the email address used for the waitlist. Auditario may ask for enough information to verify that the requester controls that address before deleting the record.
Deletion from the waitlist means removing the corresponding KV record. There is no merchant account, source-document archive, audit output, or billing record associated with a waitlist submission.
6. What this site does not collect
- Documents
- No contracts, invoices, rate cards, spreadsheets, PDFs, or document links are accepted through the waitlist.
- Shopify data
- No OAuth connection exists, and the optional store URL does not grant Auditario store access.
- Payments
- No card, bank, subscription, or billing information is requested or processed.
- Cookies
- The current site does not set first-party marketing, preference, authentication, or analytics cookies.
- Analytics
- Auditario does not enable a visitor analytics or advertising service on the current site. The site's Content Security Policy blocks page-level analytics scripts and beacons; Cloudflare still processes routine edge-delivery metrics as infrastructure provider.
7. Your choices and contact
Every business-context field is optional. You may join using only an email address, ask what is stored, correct a submitted field by resubmitting the form, or request deletion before the automatic expiry.
For an access, correction, deletion, or privacy question, contact hello@auditario.com. If this site begins collecting a materially different category of data, this notice will be updated before that collection begins and the effective date above will change.