1. Scope
This policy governs the Celeste commerce-platform assessment at runceleste.com — a free, automated tool that suggests a commerce platform based on information you provide. It is separate from, and additional to, Acro Commerce’s general website privacy practices at acrocommerce.com, because Celeste collects different information. By using Celeste you acknowledge this policy.
2. Information we collect
(a) Information you provide
- Assessment inputs: the business details you enter (industry, company size, sales channels, current platform/ERP, pricing/operational complexity, integrations, goals) and the company website URL you submit for assessment.
- Contact details — optional: your name and email, only if you choose to provide them (e.g., to receive the report by email). You can complete an assessment without providing contact details.
(b) Information collected automatically
- Technical data: IP address, browser/device type (user-agent), referring source, pages viewed, and marketing parameters (UTM tags, ad-click identifiers).
- Interaction/analytics data: clicks, scrolling, navigation and funnel steps, via Google Analytics 4, Microsoft Clarity (which provides session replay and heatmaps and masks sensitive on-screen fields by default) and Zoho PageSense. These load only after you consent (Section 4).
- Cookies and similar technologies: for consent state and analytics, set only after consent.
We do not request or knowingly collect payment-card numbers, government IDs, or other sensitive personal information.
3. Why we use it (purposes)
- To generate and deliver your commerce-platform recommendation and operate the assessment.
- To improve Celeste’s accuracy, content, and reliability.
- To assess traffic quality and security — distinguishing genuine visitors from bots/automated and fraudulent traffic, recognizing our own team and partners, and grouping returning visits — so our records and follow-up are accurate.
- To respond to and follow up with you where you provided contact details or where we have a legitimate business interest, and to route genuine opportunities to the appropriate team or partner.
- To measure and improve our marketing.
4. Consent (PIPEDA & CASL)
- Nothing beyond the strictly necessary runs until you choose. Our consent banner asks separately about two things, and both start switched off:
- Analytics — how pages are used, and session replay. Google Analytics, Microsoft Clarity and Zoho PageSense.
- Marketing — identifying the business you are visiting from, and measuring advertising. RB2B, LinkedIn, Reddit, Google Ads and ChatGPT Ads.
- Strictly necessary covers keeping you signed in, security, distinguishing real visitors from automated traffic, and our own count of how many people reached each page. That last one stays inside our own systems and is never shared with any of the companies named below. In the EEA, the UK and Switzerland we do not even do that until you have agreed to analytics.
- Marketing email is separate and express opt-in. Any “keep me informed” option is off by default and is distinct from consent to run the assessment (CASL express consent). Receiving a report you requested by email is a transactional message you asked for, not marketing.
- Where permitted, we may rely on implied consent or legitimate interest for security, fraud/bot detection, and core operation of the tool.
5. Why we capture IP address
We capture the visitor IP at assessment time for security and data-quality purposes: to detect bots, abuse, and fraud; to recognize our own staff and partner traffic so internal testing doesn’t distort our data; and to group repeat visits. In our interface we show a non-identifying visitor label rather than raw IPs to most users. IP addresses are treated as personal information, retained only as long as needed for these purposes (Section 8), and never sold.
6. Service providers we share with
We share the minimum necessary with vendors who process data on our behalf under contract:
- Google Analytics 4 (Google) — usage analytics.
- Microsoft Clarity (Microsoft) — session replay, heatmaps, bot-traffic analysis.
- RB2B (RB2B, Inc.), business-visitor identification. On our public pages, and only after you accept MARKETING specifically, RB2B attempts to match your visit to a work profile and may suggest a name, job title, employer, business email address and LinkedIn profile URL. This is a probabilistic best guess and it can be wrong, including matching the wrong person. We treat it as a suggestion to check, and you may ask us to correct or delete anything it inferred about you. It is used to understand which businesses are evaluating us and to follow up in a business context. It never runs on the client portal or on report pages, and we do not use it to build a profile of your activity away from our own public site.
- HubSpot — CRM, for genuine prospects/opportunities only (not traffic classified as test, spam, or bot).
- Zoho PageSense — on-page experiments, so we can tell whether a change to the page actually helped. Analytics consent only.
- Apollo — working out which company a visitor works for, from the network they are connecting from. Company only: we do not ask it to name individuals, and the plan we are on cannot. With marketing consent, and never on the client portal or on report pages.
- LinkedIn, Reddit, Google Ads and ChatGPT Ads — advertising measurement. With marketing consent, these are told that a step happened — that an assessment was started, or finished — and nothing else. They never receive your email address, your company name, the platforms you selected, any figure you entered, or anything from your answers or your report. They never run on the client portal or on report pages.
- Cloudflare — a background check on arrival that distinguishes a person from an automated script. This is a security and data-quality control rather than analytics, so it runs without consent; it records only whether the check passed, never who you are.
- Postmark — sending the report and related email.
- Vercel — application hosting and delivery.
- Business-data enrichment (e.g., Apollo, BuiltWith) and domain-reputation/fraud screening (IPQualityScore) — to enrich legitimate business records and screen out fake or fraudulent domains.
We do not sell personal information and do not permit these providers to use it for their own purposes.
7. Cross-border transfer
Some providers are located in the United States and elsewhere; your information may be processed outside Canada and may be subject to lawful access requests in those jurisdictions. We use providers that offer appropriate contractual and security safeguards.
8. Retention
We keep assessment and contact data only as long as necessary for the purposes above or as required by law, then delete or de-identify it. Analytics data follows each provider’s retention settings. Submissions classified as bot, spam, or test are pruned routinely.
9. Aggregated / de-identified data
We may create and use aggregated or de-identified data (which does not identify you) for any lawful purpose, including improving Celeste and our recommendations.
10. Security
We apply access controls, encryption in transit, and least-privilege practices appropriate to the sensitivity of the data. No system is perfectly secure, and we cannot guarantee absolute security.
11. Your rights
You may request access to, correction of, or deletion of your personal information, and may withdraw consent for analytics or marketing at any time (subject to legal/contractual limits). Contact our Privacy Officer at privacy@acrocommerce.com. We respond within the timeframes required by PIPEDA. You may also contact the Office of the Privacy Commissioner of Canada.
12. Children
Celeste is a business tool, not directed to children, and we do not knowingly collect their information.
13. Changes
We may update this policy; the “Last updated” date will change and material changes will be highlighted. Continued use after an update constitutes acceptance.
14. Contact
Acro Commerce Inc., British Columbia, Canada. privacy@acrocommerce.com.
See also our Terms of Use.