Policy
Data retention and security
The Sync Health Audit starts with exports, not system credentials. This page describes how those files are handled.
Last updated September 10, 2026
Private upload path
Files are uploaded to a private Supabase Storage bucket using short-lived, server-issued signed upload URLs. The bucket is not public, direct anonymous database access is disabled, and server credentials are kept out of browser code. We do not request write access or production credentials for this audit.
Retention
Our operating policy is to delete uploaded audit files and related working copies within 30 days after receipt. Lead and payment records may be retained longer when needed for transaction records, support, fraud prevention, or legal obligations. Until automated cleanup is in place, deletion is completed and recorded as an operations task.
What not to upload
Do not upload passwords, API keys, access tokens, production credentials, or unrelated personal data. Upload only the exports needed for the selected audit issue. Contact us promptly if you upload something by mistake.
Security questions
No online service can guarantee absolute security. If you have a security or deletion request, email hello@commercegaplabs.com. We will verify the request before discussing customer data.