Commerce Gap Labs

Policy

Data retention and security

The Sync Health Audit starts with exports, not system credentials. This page describes how those files are handled.

Last updated September 10, 2026

Private upload path

Files are uploaded to a private Supabase Storage bucket using short-lived, server-issued signed upload URLs. The bucket is not public, direct anonymous database access is disabled, and server credentials are kept out of browser code. We do not request write access or production credentials for this audit.

Retention

Our operating policy is to delete uploaded audit files and related working copies within 30 days after receipt. Lead and payment records may be retained longer when needed for transaction records, support, fraud prevention, or legal obligations. Until automated cleanup is in place, deletion is completed and recorded as an operations task.

What not to upload

Do not upload passwords, API keys, access tokens, production credentials, or unrelated personal data. Upload only the exports needed for the selected audit issue. Contact us promptly if you upload something by mistake.

Security questions

No online service can guarantee absolute security. If you have a security or deletion request, email hello@commercegaplabs.com. We will verify the request before discussing customer data.