Table of Contents
Privacy Policy
Terms of Service
Privacy Policy
This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.
We use Your Personal data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.
Interpretation and Definitions
Interpretation
The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
Definitions
For the purposes of this Privacy Policy:
-
Account means a unique account created for You to access our Service or parts of our Service.
-
Business, for the purpose of CCPA/CPRA, refers to the Company as the legal entity that collects Consumers' personal information and determines the purposes and means of the processing of Consumers' personal information, or on behalf of which such information is collected and that alone, or jointly with others, determines the purposes and means of the processing of consumers' personal information, that does business in the State of California.
-
CCPA and/or CPRA refers to the California Consumer Privacy Act (the "CCPA") as amended by the California Privacy Rights Act of 2020 (the "CPRA").
-
Company (referred to as either "the Company", "We", "Us" or "Our" in this Agreement) refers to YuzuTrace.
For the purpose of the GDPR, the Company is the Data Controller.
-
Consumer, for the purpose of the CCPA/CPRA, means a natural person who is a California resident. A resident, as defined in the law, includes (1) every individual who is in the USA for other than a temporary or transitory purpose, and (2) every individual who is domiciled in the USA who is outside the USA for a temporary or transitory purpose.
-
Cookies are small files that are placed on Your computer, mobile device or any other device by a website, containing the details of Your browsing history on that website among its many uses.
-
Country refers to: Canada (Province of Quebec)
-
Data Controller, for the purposes of the GDPR (General Data Protection Regulation), refers to the Company as the legal person which alone or jointly with others determines the purposes and means of the processing of Personal Data.
-
Device means any device that can access the Service such as a computer, a cellphone or a digital tablet.
-
Do Not Track (DNT) is a concept that has been promoted by US regulatory authorities, in particular the U.S. Federal Trade Commission (FTC), for the Internet industry to develop and implement a mechanism for allowing internet users to control the tracking of their online activities across websites.
-
GDPR refers to EU General Data Protection Regulation.
-
Personal Data is any information that relates to an identified or identifiable individual.
For the purposes of GDPR, Personal Data means any information relating to You such as a name, an identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity.
For the purposes of the CCPA/CPRA, Personal Data means any information that identifies, relates to, describes or is capable of being associated with, or could reasonably be linked, directly or indirectly, with You.
-
Service refers to all features and functions of the YuzuTrace platform, including the Website.
-
Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used. For the purpose of the GDPR, Service Providers are considered Data Processors.
-
Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
-
Website refers to YuzuTrace, accessible from https://www.yuzutrace.com
-
You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.
Under GDPR, You can be referred to as the Data Subject or as the User as you are the individual using the Service.
Collecting and Using Your Personal Data
Types of Data Collected
The pool profile you ask for
When you order an audit, you may describe the population you want testing your site: age band, market, language, technical confidence and, where it matters to your audience, gender. A site selling women’s health products, for example, needs women testing it.
These criteria describe a population, not a person. We match them internally against what testers have chosen to tell us about themselves. You never receive a tester’s individual characteristics, only the findings from the sessions. We recruit in good faith on what testers declare, and we do not verify or warrant those characteristics.
The field is free text and optional. Leaving it blank has no effect on your audit.
Personal Data
While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You. Personally identifiable information may include, but is not limited to:
-
Email address
-
First name and last name
-
Address, State, Province, ZIP/Postal code, City
-
Usage Data
Payment information
We do not collect or store payment card details. Payments are handled by Stripe, which collects that information directly through its own hosted pages. We receive only a transaction reference and its status.
Where a payment or a payout requires identity verification, that verification is carried out by Stripe under its own regulatory obligations as a payment institution, not on Our instructions. See When you apply as a tester for how this works for testers.
Usage Data
Usage Data is collected automatically when using the Service.
Usage Data may include information such as Your Device's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data.
When You access the Service by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data.
We may also collect information that Your browser sends whenever You visit our Service or when You access the Service by or through a mobile device.
Tracking Technologies and Cookies
We use Cookies and similar tracking technologies to track the activity on Our Service and store certain information. Tracking technologies used are beacons, tags, and scripts to collect and track information and to improve and analyze Our Service. The technologies We use may include:
- Cookies or Browser Cookies. A cookie is a small file placed on Your Device. You can instruct Your browser to refuse all Cookies or to indicate when a Cookie is being sent. However, if You do not accept Cookies, You may not be able to use some parts of our Service. Unless you have adjusted Your browser setting so that it will refuse Cookies, our Service may use Cookies.
- Web Beacons. Certain sections of our Service and our emails may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that permit the Company, for example, to count users who have visited those pages or opened an email and for other related website statistics (for example, recording the popularity of a certain section and verifying system and server integrity).
Cookies can be "Persistent" or "Session" Cookies. Persistent Cookies remain on Your personal computer or mobile device when You go offline, while Session Cookies are deleted as soon as You close Your web browser.
Here is every cookie the site sets, who sets it, what for and for how long. Analytics and advertising cookies are set only after You agree in the banner, and go away if You withdraw that consent.
| Cookie | Set by | What it is for | Lifetime |
|---|---|---|---|
yuzutrace_cookie_consent | YuzuTrace | Remembers that You made a choice in the banner, so it is not shown again. Always set: it is necessary. | 1 year |
yuzutrace_analytics_consent | YuzuTrace | Remembers Your choice about audience measurement. Always set: it is necessary. | 1 year |
yuzutrace_marketing_consent | YuzuTrace | Remembers Your choice about advertising measurement. Always set: it is necessary. | 1 year |
_GRECAPTCHA | Google (reCAPTCHA) | Tells a person from a bot on the sign-up and application forms. Only on those forms: it is necessary to their security. | 6 months |
_ga, _ga_SEJHSZNX38 | Google Analytics | Counts visits and page views, without identifying You by name. Only after You agree to audience measurement. | 2 years |
_gcl_au | Google Ads | Tells whether a visit that came from an ad led to an order. Only after You agree to advertising measurement. | 90 days |
| OpenAI Ads measurement cookie | OpenAI | Same purpose as the previous one, for our ads on OpenAI, and only on the order confirmation page. Only after You agree to advertising measurement. | Set by OpenAI |
The payment page is Stripe's, on Stripe's domain: the cookies it sets fall under Stripe's policy.
Besides cookies, the site keeps a few items in Your browser's storage. They never leave Your device, are used neither for measurement nor for advertising, and are necessary for the account to work:
- Your client session (Firebase's IndexedDB database), to keep You signed in from one visit to the next, until You sign out;
- The time of Your last sign-in and a session flag (
last_login_time,user_authenticated), until You sign out; - The tester space session (
yt.testerSpace), 30 days at most, or until You sign out; - Markers for the current visit: an anti-request-forgery token, an address awaiting verification, an automatic sign-out message. They are erased when the tab is closed;
- For YuzuTrace staff only, the display preferences of the admin console.
For more information about your choices regarding cookies, please see the “Managing Your Consent” section of this Privacy Policy.
Use of Your Personal Data
Main purposes of data collection
We collect and use your personal information mainly to:
- Provide and deliver the requested audit services and manage your account;
- Process payments and comply with legal/fiscal obligations;
- Protect the website and your data against fraud and attacks (e.g., via reCAPTCHA);
- Improve the website through analytics tools such as Google Analytics or Firebase (enabled only with your consent).
The detailed purposes below remain applicable and expand on these main categories:
The Company may use Personal Data for the following purposes:
-
To provide and maintain our Service, including to monitor the usage of our Service.
-
To manage Your Account: to manage Your registration as a user of the Service. The Personal Data You provide can give You access to different functionalities of the Service that are available to You as a registered user.
-
For the performance of a contract: the development, compliance and undertaking of the purchase contract for the products, items or services You have purchased or of any other contract with Us through the Service.
-
To contact You: To contact You by email, telephone calls or other equivalent forms of electronic communication regarding updates or informative communications related to the functionalities, products or contracted services, including the security updates, when necessary or reasonable for their implementation.
-
To provide You with news, special offers and general information about other goods, services and events which we offer that are similar to those that you have already purchased or enquired about unless You have opted not to receive such information.
-
To manage Your requests: To attend and manage Your requests to Us.
-
For business transfers: We may use Your information to evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Data held by Us about our Service users is among the assets transferred.
-
For other purposes: We may use Your information for other purposes, such as data analysis, identifying usage trends, determining the effectiveness of our promotional campaigns and to evaluate and improve our Service, products, services, marketing and your experience.
We may share Your personal information in the following situations:
- With Service Providers: We may share Your personal information with Service Providers to monitor and analyze the use of our Service, for payment processing, to contact You.
- For business transfers: We may share or transfer Your personal information in connection with, or during negotiations of, any merger, sale of Company assets, financing, or acquisition of all or a portion of Our business to another company.
- With Your consent: We may disclose Your personal information for any other purpose with Your consent.
Retention of Your Personal Data
The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use Your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.
The Company will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of Our Service, or We are legally obligated to retain this data for longer time periods.
Transfer of Your Personal Data
Your information, including Personal Data, is processed at the Company's operating offices and in any other places where the parties involved in the processing are located.
It means that this information may be transferred to and maintained on computers located outside your state, province, country, or other governmental jurisdiction, where data protection laws may differ from those in your jurisdiction.
Your consent to this Privacy Policy followed by Your submission of such information represents Your agreement to that transfer.
The Company will take all steps reasonably necessary to ensure that Your data is treated securely and in accordance with this Privacy Policy and no transfer of Your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of Your data and other personal information.
Delete Your Personal Data
You have the right to delete or request that We assist in deleting the Personal Data that We have collected about You.
Our Service may give You the ability to delete certain information about You from within the Service.
You may update, amend, or delete Your information at any time by signing in to Your Account, if you have one, and visiting the account settings section that allows you to manage Your personal information. You may also contact Us to request access to, correct, or delete any personal information that You have provided to Us.
Please note, however, that We may need to retain certain information when we have a legal obligation or lawful basis to do so.
Disclosure of Your Personal Data
Business Transactions
If the Company is involved in a merger, acquisition or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy.
Law enforcement
Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).
Other legal requirements
The Company may disclose Your Personal Data in the good faith belief that such action is necessary to:
- Comply with a legal obligation
- Protect and defend the rights or property of the Company
- Prevent or investigate possible wrongdoing in connection with the Service
- Protect the personal safety of Users of the Service or the public
- Protect against legal liability
Security of Your Personal Data
The security of Your Personal Data is important to Us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While We strive to use commercially acceptable means to protect Your Personal Data, We cannot guarantee its absolute security.
Detailed Information on the Processing of Your Personal Data
The Service Providers We use may have access to Your Personal Data. These third-party vendors collect, store, use, process and transfer information about Your activity on Our Service in accordance with their Privacy Policies.
Analytics
We may use third-party Service providers to monitor and analyze the use of our Service.
-
Google Analytics
Google Analytics is a web analytics service offered by Google that tracks and reports website traffic. Google uses the data collected to track and monitor the use of our Service. This data is shared with other Google services. Google may use the collected data to contextualize and personalize the ads of its own advertising network.
You can opt-out of having made your activity on the Service available to Google Analytics by installing the Google Analytics opt-out browser add-on. The add-on prevents the Google Analytics JavaScript (ga.js, analytics.js and dc.js) from sharing information with Google Analytics about visits activity.
For more information on the privacy practices of Google, please visit the Google Privacy & Terms web page: https://policies.google.com/privacy
-
Advertising measurement (Google Ads, OpenAI Ads)
When You accept marketing cookies, two measurement tags may load: Google Ads and OpenAI Ads. They serve one purpose: telling whether a visit that came from an ad led to an order, so We can measure what Our campaigns return. The OpenAI tag loads on the order confirmation page only. No advertising profile is built, ad personalization is denied in the signals We send to Google, and You are not followed onto other sites. Without Your consent, neither tag loads.
-
Firebase
Firebase is an analytics service provided by Google Inc.
You may opt-out of certain Firebase features through your mobile device settings, such as your device advertising settings or by following the instructions provided by Google in their Privacy Policy: https://policies.google.com/privacy
We also encourage you to review the Google's policy for safeguarding your data: https://support.google.com/analytics/answer/6004245
For more information on what type of information Firebase collects, please visit the How Google uses data when you use our partners' sites or apps webpage: https://policies.google.com/technologies/partner-sites
Payments
We may provide paid products and/or services within the Service. In that case, we may use third-party services for payment processing (e.g. payment processors).
We will not store or collect Your payment card details. That information is provided directly to Our third-party payment processors whose use of Your personal information is governed by their Privacy Policy. These payment processors adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of payment information.
-
Stripe
Their Privacy Policy can be viewed at https://stripe.com/us/privacy
When You use Our Service to pay a product and/or service via bank transfer, We may ask You to provide information to facilitate this transaction and to verify Your identity.
Usage, Performance and Miscellaneous
We may use third-party Service Providers to maintain and improve our Service.
-
Invisible reCAPTCHA
We use an invisible captcha service named reCAPTCHA. reCAPTCHA is operated by Google.
The reCAPTCHA service may collect information from You and from Your Device for security purposes.
The information gathered by reCAPTCHA is held in accordance with the Privacy Policy of Google: https://www.google.com/intl/en/policies/privacy/
Testing and Recording Providers
Testers record their own screen and voice using standard screen-recording tools and send us the file. These recordings are stored on servers located in the European Union and are deleted thirty days after the report is delivered. They are never used to train any automated system.
Email Delivery
We use trusted third-party email services to send transactional and service-related messages, such as order confirmations, password resets, and account notifications.
- SendGrid (Twilio SendGrid) – our primary provider for sending transactional and service-related emails. Data may be processed and stored on SendGrid’s servers, primarily located in the United States.
- Microsoft 365 (Microsoft Corporation) – hosts the mailbox we use for business correspondence with clients. Data may be processed on Microsoft servers, including outside Québec.
These services process only the data necessary to send emails (e.g., your email address, name, and message content) and follow their own privacy policies and security standards.
Law 25 – Protection of Personal Information (Quebec)
YuzuTrace is a business established in Quebec, Canada. The processing of Your personal information is governed by the Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1), as modernised by Law 25. The competent supervisory authority is the Commission d’accès à l’information du Québec (CAI).
Privacy Officer
Privacy Officer – YuzuTrace, contact@yuzutrace.com, 300-204 rue du Saint-Sacrement, Montreal (QC) H2Y 1W8, Canada.
Your rights under Law 25
- Access: obtain the personal information We hold about You.
- Rectification: have inaccurate, incomplete or ambiguous information corrected.
- Withdrawal of consent: withdraw Your consent at any time, subject to applicable legal or contractual restrictions.
- Portability: since 22 September 2024, receive the information You provided to Us in a structured, commonly used technological format, or have it communicated to a third party.
- Cessation of dissemination and de-indexing: require that the dissemination of personal information cease, or that any hyperlink giving access to it be de-indexed, where such dissemination contravenes the law or a court order.
We answer any request within 30 days of receiving it. If Our answer does not satisfy You, You may file a complaint with the Commission d’accès à l’information du Québec.
Confidentiality incidents
We maintain a register of confidentiality incidents. Where an incident presents a risk of serious injury to You, We promptly notify both the Commission d’accès à l’information and the individuals concerned, and We take reasonable measures to reduce the risk and prevent recurrence.
Automated processing
Some operations of Our Service are automated:
- calculating the price of an order;
- temporarily locking an account after repeated failed sign-in attempts;
- capping the number of tester applications accepted from one network, to prevent automated form filling;
- comparing the country a tester application reaches Us from with the market the applicant declared;
- computing reliability indicators for a tester from their session history: replies to invitations, deadlines met, sessions accepted and never delivered, and the quality mark given to each delivered session.
None of these operations alone produces legal effects concerning You without the possibility of human review. No application is refused, and no tester is removed from the pool, on the strength of a calculation alone: the decision is made by a person. The report delivered to a client is written by hand, from the sessions observed.
You may at any time ask to be informed of the information used to render such a decision and submit Your observations to a member of Our team.
Data hosting and transfers outside Quebec
Your personal information is stored outside Quebec. We state this expressly, as required by section 17 of the Act respecting the protection of personal information in the private sector.
- Database, files, session recordings and application processing: Google Cloud data centres located in Belgium (europe-west1 region), subject to the European Union General Data Protection Regulation.
- Payments: Stripe, in the United States.
- Email delivery: SendGrid (Twilio), in the United States.
- Business mail: Microsoft, in the United States and the European Union.
- Site delivery: Firebase Hosting (Google), served over Fastly’s global network.
Before communicating personal information outside Quebec, We assess whether it will receive adequate protection there, in light of generally recognised personal information protection principles. That assessment considers the sensitivity of the information, the purposes for which it is used, the contractual and technical safeguards in place, and the legal framework applicable in the territory concerned.
Our agreements with these providers require that the information be processed solely on Our instructions, for the purposes described in this Policy only, and that it be protected by appropriate security measures.
Our governance policies (Law 25, s. 3.2)
Quebec law requires Us to establish policies governing Our handling of personal information, and to publish detailed information about them in clear terms. Here they are. They describe what Our system actually does, not what it would be desirable for it to do.
1. Retention and destruction
Personal information is destroyed or anonymised once the purpose for which it was collected has been achieved. The periods below are applied by automated jobs, with no human step.
| Information | Period |
|---|---|
| Recording of a test session (a tester’s screen and voice) | 30 days after the report is delivered, and 90 days at the outside in every case |
| Language test (thirty seconds of a tester’s voice, per declared language) | Until the language is confirmed; deleted immediately after |
| Technical reading of a session (browser, system, screen and window size). The raw user agent string is never kept | with the recording it describes |
| Sign-in details a client provides for their own site | destroyed 30 days after the audit deadline |
| Invitation link sent to a tester | stops working 3 days after the audit deadline |
| Unpaid order | archived after 7 days |
| Completed order | archived after 60 days |
| Database backups | 30 days |
| Tester application | refused: twelve months after the decision; accepted: while the tester is in the pool, then deleted with their file |
| Confidentiality incident register | 5 years from the day the incident became known |
| Accounting records and invoices | 6 years (tax obligation) |
| Information used to make a decision | at least 1 year (section 11 of the Act) |
Deleting a client account triggers irreversible anonymisation: what must be kept for accounting reasons can no longer be tied to a person. Deleting a tester destroys their file and their recordings, and leaves only a trace carrying no personal information, attesting that the erasure took place, which the law requires Us to be able to prove.
2. Roles and responsibilities of Our staff
The person with the highest authority is responsible by law for the protection of personal information. They approve these policies, are consulted at the outset of any project touching personal information, take part in assessing any incident, and answer for the decisions made.
Access to files is restricted to what the role requires. Administrative access is not obtained by editing a field in the database: it depends on an authorisation issued by the authentication system and verified server-side on every call. Administrative actions on a client file are logged.
Session recordings are never handed to the client; they are watched only while writing their report, which may carry, when a finding calls for it, a short silent image of the screen showing the problem met and nothing but the site under test. If a client disputes that a session took place, extracts may be shown to them in a meeting, without sound, without a copy and without the tester’s name. Viewing one goes through a signed link, minted on demand and valid for two hours; none is ever publicly accessible, at any point.
Sign-in details a client entrusts to Us are encrypted before storage, with a key held outside the database. They are never sent by email.
Everyone who works for Us, in-house or outside, is bound to confidentiality in writing. Testers sign an agreement forbidding them to share, publish or capture what they saw during a session, and requiring them to delete any file downloaded during a test.
3. Handling complaints and requests
Any request for access, rectification, withdrawal of consent, portability or de-indexing, and any complaint about the protection of personal information, goes to the Privacy Officer at contact@yuzutrace.com, or by post to the address given in the previous section.
- Acknowledgement. We confirm that we have received your request.
- Identity check. We have to be sure We are answering the right person. This protects You: the main way to disclose information to a stranger is to answer an access request too quickly.
- Answer within 30 days of receipt, free of charge.
- If We refuse, in whole or in part, Our answer is written and reasoned. It states the precise provision of the law the refusal rests on, Your right to ask the Commission d’accès à l’information du Québec to review that decision, and the 30-day period to do so. This is what section 34 of the Act requires.
- If Our answer does not satisfy You, you may complain to the Commission d’accès à l’information du Québec, independently of Us.
These policies are reviewed at least once a year, and on any significant change to Our system or Our providers.
GDPR Privacy
Legal Basis for Processing Personal Data under GDPR
We may process Personal Data under the following conditions:
- Consent: You have given Your consent for processing Personal Data for one or more specific purposes.
- Performance of a contract: Provision of Personal Data is necessary for the performance of an agreement with You and/or for any pre-contractual obligations thereof.
- Legal obligations: Processing Personal Data is necessary for compliance with a legal obligation to which the Company is subject.
- Legitimate interests: Processing Personal Data is necessary for the purposes of the legitimate interests pursued by the Company.
In any case, the Company will gladly help to clarify the specific legal basis that applies to the processing, and in particular whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract.
Your Rights under the GDPR
The Company undertakes to respect the confidentiality of Your Personal Data and to guarantee You can exercise Your rights.
You have the right under this Privacy Policy, and by law if You are within the EU, to:
- Request access to Your Personal Data. The right to access, update or delete the information We have on You. Whenever made possible, you can access, update or request deletion of Your Personal Data directly within Your account settings section. If you are unable to perform these actions yourself, please contact Us to assist You. This also enables You to receive a copy of the Personal Data We hold about You.
- Request correction of the Personal Data that We hold about You. You have the right to have any incomplete or inaccurate information We hold about You corrected.
- Object to processing of Your Personal Data. This right exists where We are relying on a legitimate interest as the legal basis for Our processing and there is something about Your particular situation, which makes You want to object to our processing of Your Personal Data on this ground. You also have the right to object where We are processing Your Personal Data for direct marketing purposes.
- Request erasure of Your Personal Data. You have the right to ask Us to delete or remove Personal Data when there is no good reason for Us to continue processing it.
- Request the transfer of Your Personal Data. We will provide to You, or to a third-party You have chosen, Your Personal Data in a structured, commonly used, machine-readable format. Please note that this right only applies to automated information which You initially provided consent for Us to use or where We used the information to perform a contract with You.
- Withdraw Your consent. You have the right to withdraw Your consent on using your Personal Data. If You withdraw Your consent, We may not be able to provide You with access to certain specific functionalities of the Service.
Exercising of Your GDPR Data Protection Rights
You may exercise Your rights of access, rectification, cancellation and opposition by contacting Us. Please note that we may ask You to verify Your identity before responding to such requests. If You make a request, We will try our best to respond to You as soon as possible.
You have the right to complain to a Data Protection Authority about Our collection and use of Your Personal Data. For more information, if You are in the European Economic Area (EEA), please contact Your local data protection authority in the EEA.
CCPA/CPRA Privacy Notice (California Privacy Rights)
This privacy notice section for California residents supplements the information contained in Our Privacy Policy and it applies solely to all visitors, users, and others who reside in the State of California.
Categories of Personal Information Collected
We collect information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular Consumer or Device. The following is a list of categories of personal information which we may collect or may have been collected from California residents within the last twelve (12) months.
Please note that the categories and examples provided in the list below are those defined in the CCPA/CPRA. This does not mean that all examples of that category of personal information were in fact collected by Us, but reflects our good faith belief to the best of Our knowledge that some of that information from the applicable category may be and may have been collected. For example, certain categories of personal information would only be collected if You provided such personal information directly to Us.
-
Category A: Identifiers.
Examples: A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, driver's license number, passport number, or other similar identifiers.
Collected: Yes.
-
Category B: Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)).
Examples: A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver's license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. Some personal information included in this category may overlap with other categories.
Collected: Yes.
-
Category C: Protected classification characteristics under California or federal law.
Examples: Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information).
Collected: No.
-
Category D: Commercial information.
Examples: Records and history of products or services purchased or considered.
Collected: Yes.
-
Category E: Biometric information.
Examples: Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data.
Collected: No.
-
Category F: Internet or other similar network activity.
Examples: Interaction with our Service or advertisement.
Collected: Yes.
-
Category G: Geolocation data.
Examples: Approximate location inferred from IP address (we do not collect precise GPS-level location).
Collected: Yes.
-
Category H: Sensory data.
Examples: Audio, electronic, visual, thermal, olfactory, or similar information.
Collected: No.
-
Category I: Professional or employment-related information.
Examples: Current or past job history or performance evaluations.
Collected: No.
-
Category J: Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)).
Examples: Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records.
Collected: No.
-
Category K: Inferences drawn from other personal information.
Examples: Profile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
Collected: No.
-
Category L: Sensitive personal information.
Examples: Account login and password information.
Collected: Yes.
Under CCPA/CPRA, personal information does not include:
- Publicly available information from government records
- Deidentified or aggregated consumer information
- Information excluded from the CCPA/CPRA's scope, such as:
- Health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the California Confidentiality of Medical Information Act (CMIA) or clinical trial data
- Personal Information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (FRCA), the Gramm-Leach-Bliley Act (GLBA) or California Financial Information Privacy Act (FIPA), and the Driver's Privacy Protection Act of 1994
Sources of Personal Information
We obtain the categories of personal information listed above from the following categories of sources:
- Directly from You. For example, from the forms You complete on our Service, preferences You express or provide through our Service, or from Your purchases on our Service.
- Indirectly from You. For example, from observing Your activity on our Service.
- Automatically from You. For example, through cookies We or our Service Providers set on Your Device as You navigate through our Service.
- From Service Providers. For example, third-party vendors to monitor and analyze the use of our Service, third-party vendors for payment processing, or other third-party vendors that We use to provide the Service to You.
Use of Personal Information
We may use or disclose personal information We collect for "business purposes" or "commercial purposes" (as defined under the CCPA/CPRA), which may include the following examples:
- To operate our Service and provide You with Our Service.
- To provide You with support and to respond to Your inquiries, including to investigate and address Your concerns and monitor and improve our Service.
- To fulfill or meet the reason You provided the information. For example, if You share Your contact information to ask a question about our Service, We will use that personal information to respond to Your inquiry. If You provide Your personal information to purchase a product or service, We will use that information to process Your payment and facilitate delivery.
- To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations.
- As described to You when collecting Your personal information or as otherwise set forth in the CCPA/CPRA.
- For internal administrative and auditing purposes.
- To detect security incidents and protect against malicious, deceptive, fraudulent or illegal activity, including, when necessary, to prosecute those responsible for such activities.
- Other one-time uses.
Please note that the examples provided above are illustrative and not intended to be exhaustive. For more details on how we use this information, please refer to the "Use of Your Personal Data" section.
If We decide to collect additional categories of personal information or use the personal information We collected for materially different, unrelated, or incompatible purposes, We will update this Privacy Policy.
Disclosure of Personal Information
We may use or disclose and may have used or disclosed in the last twelve (12) months the following categories of personal information for business or commercial purposes:
- Category A: Identifiers
- Category B: Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e))
- Category D: Commercial information
- Category F: Internet or other similar network activity
Please note that the categories listed above are those defined in the CCPA/CPRA. This does not mean that all examples of that category of personal information were in fact disclosed, but reflects our good faith belief to the best of our knowledge that some of that information from the applicable category may be and may have been disclosed.
When We disclose personal information for a business purpose or a commercial purpose, We enter a contract that describes the purpose and requires the recipient to both keep that personal information confidential and not use it for any purpose except performing the contract.
Share of Personal Information
We may share, and have shared in the last twelve (12) months, Your personal information identified in the above categories with the following categories of third parties:
- Service Providers
- Payment processors
- Third party vendors to whom You or Your agents authorize Us to disclose Your personal information in connection with products or services We provide to You
Sale of Personal Information
As defined in the CCPA/CPRA, "sell" and "sale" mean selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a Consumer's personal information by the Business to a third party for valuable consideration. This means that We may have received some kind of benefit in return for sharing personal information, but not necessarily a monetary benefit.
We do not sell your personal information for monetary compensation. However, under the CCPA/CPRA, sharing data with analytics or advertising partners (such as Google Analytics) may be legally defined as a 'sale' or 'sharing'.
Under this broad definition, we may have 'shared' the following categories of personal information in the last twelve (12) months:
- Category A: Identifiers
- Category B: Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e))
- Category D: Commercial information
- Category F: Internet or other similar network activity
Please note that the categories listed above are those defined in the CCPA/CPRA. This does not mean that all examples of that category of personal information were in fact sold, but reflects our good faith belief to the best of Our knowledge that some of that information from the applicable category may be and may have been shared for value in return.
Personal Information of Minors
We do not knowingly collect personal information from minors under the age of 18 through our Service, although certain third party websites that we link to may do so. These third-party websites have their own terms of use and privacy policies and We encourage parents and legal guardians to monitor their children's Internet usage and instruct their children to never provide information on other websites without their permission.
We do not sell or share the personal information of individuals We know to be under 18 years of age.
If You have reason to believe that a minor has provided Us with personal information, please contact Us with sufficient detail to enable Us to delete that information.
Your Rights under the CCPA/CPRA
The CCPA/CPRA provides California residents with specific rights regarding their personal information. If You are a resident of California, You have the following rights:
- The right to notice. You have the right to be notified which categories of Personal Data are being collected and the purposes for which the Personal Data is being used.
- The right to know/access. Under CCPA/CPRA, You have the right to request that We disclose information to You about Our collection, use, sale, disclosure for business purposes and share of personal information. Once We receive and confirm Your request, We will disclose to You:
- The categories of personal information We collected about You
- The categories of sources for the personal information We collected about You
- Our business or commercial purposes for collecting or selling that personal information
- The categories of third parties with whom We share that personal information
- The specific pieces of personal information We collected about You
- If we sold Your personal information or disclosed Your personal information for a business purpose, We will disclose to You:
- The categories of personal information categories sold
- The categories of personal information categories disclosed
- The right to say no to the sale or sharing of Personal Data (opt-out). You have the right to direct Us to not sell Your personal information. To submit an opt-out request, please see the "Do Not Sell My Personal Information" section or contact Us.
- The right to correct Personal Data. You have the right to correct or rectify any inaccurate personal information about You that We collected. Once We receive and confirm Your request, We will use commercially reasonable efforts to correct (and direct our Service Providers to correct) Your personal information, unless an exception applies.
- The right to limit use and disclosure of sensitive Personal Data. You have the right to request to limit the use or disclosure of certain sensitive personal information We collected about You, unless an exception applies. To submit, please see the "Limit the Use or Disclosure of My Sensitive Personal Information" section or contact Us.
- The right to delete Personal Data. You have the right to request the deletion of Your Personal Data under certain circumstances, subject to certain exceptions. Once We receive and confirm Your request, We will delete (and direct Our Service Providers to delete) Your personal information from our records, unless an exception applies. We may deny Your deletion request if retaining the information is necessary for Us or Our Service Providers to:
- Complete the transaction for which We collected the personal information, provide a good or service that You requested, take actions reasonably anticipated within the context of our ongoing business relationship with You, or otherwise perform our contract with You.
- Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities.
- Debug products to identify and repair errors that impair existing intended functionality.
- Exercise free speech, ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law.
- Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et. seq.).
- Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information's deletion may likely render impossible or seriously impair the research's achievement, if You previously provided informed consent.
- Enable solely internal uses that are reasonably aligned with consumer expectations based on Your relationship with Us.
- Comply with a legal obligation.
- Make other internal and lawful uses of that information that are compatible with the context in which You provided it.
- The right not to be discriminated against. You have the right not to be discriminated against for exercising any of Your consumer's rights, including by:
- Denying goods or services to You
- Charging different prices or rates for goods or services, including the use of discounts or other benefits or imposing penalties
- Providing a different level or quality of goods or services to You
- Suggesting that You will receive a different price or rate for goods or services or a different level or quality of goods or services
Exercising Your CCPA/CPRA Data Protection Rights
Please see the "Do Not Sell My Personal Information" section and "Limit the Use or Disclosure of My Sensitive Personal Information" section for more information on how to opt out and limit the use of sensitive information collected.
Additionally, in order to exercise any of Your rights under the CCPA/CPRA, and if You are a California resident, You can contact Us:
-
By email: contact@yuzutrace.com
-
By visiting this page on our website: https://www.yuzutrace.com/#contact
Only You, or a person registered with the California Secretary of State that You authorize to act on Your behalf, may make a verifiable request related to Your personal information.
Your request to Us must:
- Provide sufficient information that allows Us to reasonably verify You are the person about whom We collected personal information or an authorized representative
- Describe Your request with sufficient detail that allows Us to properly understand, evaluate, and respond to it
We cannot respond to Your request or provide You with the required information if We cannot:
- Verify Your identity or authority to make the request
- And confirm that the personal information relates to You
We will disclose and deliver the required information free of charge within 45 days of receiving Your verifiable request. The time period to provide the required information may be extended once by an additional 45 days when reasonably necessary and with prior notice.
Any disclosures We provide will only cover the 12-month period preceding the verifiable request's receipt.
For data portability requests, We will select a format to provide Your personal information that is readily usable and should allow You to transmit the information from one entity to another entity without hindrance.
Do Not Sell My Personal Information
As defined in the CCPA/CPRA, "sell" and "sale" mean selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a Consumer's personal information by the Business to a third party for valuable consideration. This means that We may have received some kind of benefit in return for sharing personal information, but not necessarily a monetary benefit.
We do not sell your personal information for monetary compensation. However, under the CCPA/CPRA, sharing data with analytics or advertising partners (such as Google Analytics) may be legally defined as a 'sale' or 'sharing'.
You have the right to opt-out of the sale of Your personal information. Once We receive and confirm a verifiable consumer request from You, we will stop selling Your personal information. To exercise Your right to opt-out, please contact Us.
The Service Providers we partner with (for example, our analytics or advertising partners) may use technology on the Service that sells personal information as defined by the CCPA/CPRA law. If you wish to opt out of the use of Your personal information for interest-based advertising purposes and these potential sales as defined under CCPA/CPRA law, you may do so by following the instructions below.
Please note that any opt out is specific to the browser You use. You may need to opt out on every browser that You use.
Website
If applicable, click "Privacy Preferences", "Update Privacy Preferences" or "Do Not Sell My Personal Information" buttons listed on the Service to review Your privacy preferences and opt out of cookies and other technologies that We may use. Please note that You will need to opt out from each browser that You use to access the Service.
Additionally, You can opt out of receiving ads that are personalized as served by our Service Providers by following our instructions presented on the Service:
- The NAI's opt-out platform: http://www.networkadvertising.org/choices/
- The EDAA's opt-out platform http://www.youronlinechoices.com/
- The DAA's opt-out platform: http://optout.aboutads.info/?c=2&lang=EN
- Processing agreement
- What we capture during a session
The opt out will place a cookie on Your computer that is unique to the browser You use to opt out. If you change browsers or delete the cookies saved by Your browser, You will need to opt out again.
Mobile Devices
Your mobile device may give You the ability to opt out of the use of information about the apps You use in order to serve You ads that are targeted to Your interests:
- "Opt out of Interest-Based Ads" or "Opt out of Ads Personalization" on Android devices
- "Limit Ad Tracking" on iOS devices
You can also stop the collection of location information from Your mobile device by changing the preferences on Your mobile device.
Limit the Use or Disclosure of My Sensitive Personal Information
If You are a California resident, You have the right to limit the use and disclosure of Your sensitive personal information to that use which is necessary to perform the services or provide the goods reasonably expected by an average consumer who requests such services or goods.
We collect, use and disclose sensitive personal information in ways that are necessary to provide the Service. For more information on how We use Your personal information, please see the "Use of Your Personal Data" section or contact us.
"Do Not Track" Policy as Required by California Online Privacy Protection Act (CalOPPA)
Our Service does not respond to Do Not Track signals.
However, some third party websites do keep track of Your browsing activities. If You are visiting such websites, You can set Your preferences in Your web browser to inform websites that You do not want to be tracked. You can enable or disable DNT by visiting the preferences or settings page of Your web browser.
Your California Privacy Rights (California's Shine the Light law)
Under California Civil Code Section 1798 (California's Shine the Light law), California residents with an established business relationship with us can request information once a year about sharing their Personal Data with third parties for the third parties' direct marketing purposes.
If you'd like to request more information under the California Shine the Light law, and if You are a California resident, You can contact Us using the contact information provided below.
California Privacy Rights for Minor Users (California Business and Professions Code Section 22581)
Our Service is strictly intended for adults and we do not knowingly register anyone under 18. Should a California resident under 18 nonetheless have registered, California Business and Professions Code Section 22581 allows California residents under the age of 18 who are registered users of online sites, services or applications to request and obtain removal of content or information they have publicly posted.
To request removal of such data, and if You are a California resident, You can contact Us using the contact information provided below, and include the email address associated with Your account.
Be aware that Your request does not guarantee complete or comprehensive removal of content or information posted online and that the law may not permit or require removal in certain circumstances.
Children's Privacy
Our Service is strictly intended for individuals who are 18 years of age or older. We do not knowingly collect personally identifiable information from anyone under the age of 18. If You are a parent or guardian and You are aware that Your minor child has provided Us with Personal Data, please contact Us so we can remove that information from Our servers.
If We need to rely on consent as a legal basis for processing Your information and Your country requires consent from a parent, We may require Your parent's consent before We collect and use that information.
Links to Other Websites
Our Service may contain links to other websites that are not operated by Us. If You click on a third party link, You will be directed to that third party's site. We strongly advise You to review the Privacy Policy of every site You visit.
We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.
Responsible for Personal Information
YuzuTrace has designated the following person to oversee compliance with privacy obligations in Québec:
- Privacy Officer: Privacy Officer – YuzuTrace
- Email: contact@yuzutrace.com
- Mailing address: 300-204 rue du Saint-Sacrement, Montréal (QC) H2Y 1W8, Canada
You may contact the Privacy Officer at any time to:
- Request access to or correction of your personal information;
- Withdraw consent for the use of your personal information (subject to legal or contractual restrictions);
- Ask questions about how YuzuTrace collects, uses, or discloses personal data.
Managing Your Consent
You can change or withdraw your consent at any time. For analytics and advertising cookies and trackers (such as Google Analytics), use the Manage cookies link in the footer of every page. For our promotional newsletters, click the unsubscribe link included in any promotional email, or contact us.
Changes to this Privacy Policy
We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page.
We will let You know via email and/or a prominent notice on Our Service, prior to the change becoming effective and update the "Last updated" date at the top of this Privacy Policy.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
Terms of Service and Refund Policy
Agreement to Terms
By accessing or using the services of YuzuTrace at https://www.yuzutrace.com (the “Service”), you agree to these Terms of Service and Refund Policy (“Terms”). If you do not agree, you may not use the Service. These Terms form a binding agreement between you (“you”, “your”) and YuzuTrace (“we”, “us”, “our”). Please read them carefully.
Definitions
- Report: the document delivered at the end of the audit, as a PDF.
- Content: anything you submit for an audit, including the address of the site, the journeys to be tested, your notes, and any test credentials you choose to provide.
- Service: all features and functions of the YuzuTrace platform, including the Website.
Services Provided
YuzuTrace provides user research and technical quality assurance for websites, including but not limited to:
- Unmoderated user testing of one or more journeys on your website, carried out by real testers recruited and paid by us, working on their own devices without a facilitator present.
- A written report of the obstacles encountered, ranked by severity, with a recommended fix for each.
- Written excerpts and verbatim quotes, with the timestamp of the moment observed. Session recordings themselves are never shared, in keeping with the undertakings given to our testers.
- Optional technical QA: bug hunting across the tested journey, with device, browser, steps to reproduce and severity.
- Testing in English, French and Spanish. Testers are recruited in Canada and are assigned only to audits in a language they are fluent in. Recruitment in another country is possible by prior written agreement and may affect price and delivery time.
The findings reflect what the testers encountered on the dates of the study. They are observations, not an exhaustive audit of your website, and they do not constitute legal, accessibility or security certification.
Eligibility
You must be at least 18 years old and legally able to enter a binding contract. If you act on behalf of an organization, you confirm you have authority to bind that organization.
An account comes before an order. You create it with your email address and nothing else: we send a six-digit code and a sign-in link, and using either one both opens your session and confirms that the address is yours. There is no password to choose and none to lose. You accept these terms at that moment, and we record the date together with the version of the text you accepted.
Your name and company are optional. You may add them at any time from your profile, and we ask for them at the moment they become useful, which is when you order.
Authority over the website. By placing an order you confirm that you own the website to be audited or are duly authorised to commission its audit. We carry out no verification of ownership and accept no liability for an order placed without that authority. Where this condition is not met, we may decline or stop the audit; if testers have not yet been recruited, the order is refunded in full.
Business use. The Service is intended for businesses and professionals. If you order as a consumer, mandatory consumer protection provisions applicable to you continue to apply and prevail over any conflicting term of this agreement.
Your Content & Rights
- Ownership: you keep full ownership of your website, your brand and anything you send us.
- Licence to us: you grant us a limited right to access your website and any test credentials you provide, solely to carry out the audit you ordered.
- Test credentials: where a journey sits behind a login, you undertake to provide credentials for a test account. We never ask for, and you must never provide, access to real customer data.
- Responsibility: you are solely responsible for ensuring that the website submitted does not infringe third-party rights or break the law.
- Acceptable use: you may not order an audit for the purpose of harming a third party, nor use our findings to attack a competitor’s website.
Report License
Upon full payment, YuzuTrace grants you a worldwide, perpetual, non-exclusive and royalty-free licence to use the delivered report and its excerpts for your own business purposes.
- Permitted uses: reading, copying, adapting and circulating the report inside your organisation, and sharing it with the contractors working on your website.
- Restrictions: you may not resell the report as a product, nor present it as the work of a third party.
Pricing & Payment
- Currency. All prices are in USD.
- Taxes. Prices are exclusive of taxes. Any applicable sales taxes are added at checkout and shown before payment.
- Payment. Payment in full is due before production begins. We accept major credit and debit cards through our secure processor (Stripe).
- Processor fees. Where a refund is issued, payment processor fees may be deducted to the extent permitted by law.
- Welcome credit. Any welcome credit applies to a first order only, once per account, and cannot be combined with any other offer or promotional code. It expires on the date shown in your dashboard. Creating multiple accounts to obtain more than one credit voids the credit and may lead to suspension of the accounts concerned.
- Rush option. Where offered, the rush option is confirmed before the order is placed and depends on tester availability. It carries the surcharge stated at the time of confirmation.
- Purchases made by testers. Where a journey ends in a payment, you undertake to provide test cards or a sandbox mode. If neither is available and a tester must complete a real purchase, the terms are agreed in writing before work begins and the exact amount is invoiced back to you. No real purchase is made without your prior agreement.
Delivery
The report is delivered as a PDF you download from your YuzuTrace dashboard. You are notified by email when it is ready.
Delivery time is seven (7) business days for the functional check and seven (7) to ten (10) business days for the fixed-price audits, from the moment we receive a complete brief. For a custom engagement, the delivery date is agreed in writing before work begins. The applicable date is shown in your dashboard.
What a business day means here. In this policy a business day is a day from Monday to Friday, excluding the statutory holidays applicable in Canada, 24 June included. Every time limit stated in business days is counted in Eastern Time (America/Toronto).
Where the brief is incomplete (missing URL, missing test credentials, undefined task), the countdown starts when the missing element reaches us.
Late delivery. Where we exceed the applicable delivery time for reasons attributable to us, you receive a credit of 20% of the price of the order concerned. This credit is your sole and exclusive remedy for late delivery.
The report remains available in your dashboard for as long as your account is open. Session recordings are deleted thirty days after delivery.
We notify you promptly in the event of any unexpected delay.
Acceptance of the Report
An audit is an observation, not a production task: what the testers encountered cannot be rewritten on request. There is therefore no revision cycle. What we do correct, at no charge, is any factual error in the report: a misattributed severity, a wrong timestamp, a quotation attributed to the wrong tester, a fix that does not match the obstacle described.
- Reporting an error. Corrections must be requested in writing within fourteen (14) days of the delivery notification. We correct and reissue the report at no cost.
- Material shortfall. If, within the same fourteen days, you demonstrate in writing that the audit delivered does not correspond to what was ordered — for example, fewer testers than the plan provides, or a journey other than the one briefed — we re-run the affected part of the audit with new testers, once, at no charge. This re-run is your sole and exclusive remedy in such a case.
- Acceptance. The report is deemed accepted where no correction has been requested and no material shortfall has been reported in writing within those fourteen days.
Refund Policy
- Cancellation before work starts. You receive a full refund if you cancel before we begin recruiting testers. Once recruitment has started, testers are paid whatever happens, and the amount already committed is deducted.
- Website altered during the study. Where the website is modified during the study and the observations are no longer usable, the sessions already carried out remain payable, since the testers have been paid. We will re-run the affected journey at 50% of its price. Where the modification was made at our request or resulted from our own error, the re-run is free of charge.
No refund is available for:
- A change of mind after the report has been delivered.
- Requests submitted after the fourteen-day window, the report being then deemed accepted.
- Results considered insufficient, where the audit was carried out as ordered. The number and severity of obstacles found are not guaranteed; a report with no critical obstacle is a valid outcome.
Approved refunds are issued to the original payment method and may take 5–10 business days. Nothing in this policy limits rights you may have under applicable consumer protection law that cannot be waived by agreement.
Warranties & Disclaimers
- We warrant that the testers are real people, recruited and paid by us, selected against the population described in your brief, on the basis of what testers have declared about themselves, and that the report faithfully reflects what was observed during the sessions.
- We do not warrant any commercial outcome. An audit identifies obstacles; it does not guarantee an increase in conversions, traffic or revenue, which depend on the fixes you choose to apply.
- Findings describe what the testers encountered on the dates of the study. They are not an exhaustive inventory of every possible bug on your website.
- Apart from this limited warranty, the Service is provided “AS IS”.
Limitation of Liability
Our total aggregate liability to you, for all claims arising out of or relating to a given order, is capped at the amount you actually paid for that order.
We are not liable for indirect or consequential damages (lost profits, lost data, business interruption, and the like), nor for the consequences of applying or not applying our recommendations, except where prohibited by law or in cases of our gross negligence or intentional misconduct.
Indemnification
You agree to defend, indemnify, and hold harmless YuzuTrace, its owners, employees, and contractors from any claims, liabilities, damages, losses, and expenses (including reasonable legal fees) arising out of: (a) the content you submit and the site you ask us to test, including any claim that such content or site infringes the intellectual property, privacy, or other rights of a third party; (b) your violation of these Terms; or (c) your violation of any applicable law.
Termination
You may stop using the Service or request account deletion at any time (we keep some records where required by law or for tax purposes).
We may suspend or terminate access if you breach these Terms, fail to pay, or abuse the Service. Except in cases of fraud or unlawful use, we give you thirty (30) days’ notice before closing your account, so that you can download the reports you have paid for.
Licences granted for reports already delivered remain permanently valid, whatever becomes of the account. The file stays available for download on your dashboard for as long as your account is open. We recommend keeping your own copy.
Force Majeure
YuzuTrace is not liable for any delay or failure to perform resulting from causes beyond its reasonable control, including outages or failures of third-party providers (such as hosting, storage or content-delivery networks), internet or power failures, acts of God, natural disasters, epidemics, strikes, government actions, or the sudden and widespread unavailability of testers in the language concerned. In such cases, delivery timelines are suspended for the duration of the event, and we will resume performance as soon as reasonably practicable.
Where recruitment proves impossible within a reasonable time, we inform you and refund the order in full.
Language
A French version of these Terms is available at yuzutrace.com/fr/legal and is presented before any other language version. Where you have expressly chosen to be bound by the English version after being presented with the French version, the English version applies. Otherwise, the French version prevails.
Governing Law
These Terms are governed by the laws of Quebec and Canada. Any disputes not resolved amicably may be brought before the competent courts in Quebec, unless consumer protection laws require otherwise.
Contact
Questions or requests:
- Email: contact@yuzutrace.com
- Website: YuzuTrace
Processing agreement
This section applies whenever we handle personal data on your behalf. It is written to satisfy Article 28 of the General Data Protection Regulation and forms part of our agreement with you. You do not need to send us a separate document.
Roles
For any personal data reached through your website, you are the controller and YuzuTrace is the processor. For the data of our own testers and of your account with us, YuzuTrace is the controller.
What we actually process, and what we do not
This is deliberately narrow. Our testers use their own details or fictitious ones. We do not ask you for access to your customer records, we do not import your databases, and we do not need production credentials to run an audit.
Personal data reaches us in two ways only. A tester may enter their own details into your forms. A screen may briefly display something we did not ask for, such as a notification or an address in the browser bar. Anything of that second kind is removed before the report is written.
Instructions
We process personal data only on your documented instructions, which are the brief you submit when you order. If we believe an instruction breaches data protection law, we will tell you and will not carry it out.
Confidentiality
Everyone who handles your data, employees and testers alike, is bound to confidentiality in writing before they are given access.
Security
Data is encrypted in transit and at rest. Access is limited to the people who need it for your audit. Session material is held in the European Union and deleted thirty days after the report is delivered.
Sub-processors
Three sub-processors have access to the data we process on your behalf, and we tell you before adding a fourth.
- Google Ireland Limited: hosting, database and email delivery infrastructure. Data stored in the Belgian region (europe-west1).
- Stripe Payments Europe Limited: payment processing. We never see or store your card number.
- Twilio SendGrid: transactional email.
Other providers are involved without processing that data on our behalf: Microsoft 365 for our business mailbox, Google reCAPTCHA, and a content-delivery network for a few static libraries. One measurement tool, Google Analytics, loads only after you consent to analytics cookies. One advertising pixel, OpenAI Ads (OpenAI, OpCo, LLC), loads only after you consent to advertising cookies and is used to measure our ads.
Your rights, and helping you honour them
If one of your customers exercises a right of access, correction or erasure and the data is with us, we assist you within five business days at no charge.
Breaches
We notify you without undue delay and in any event within forty-eight hours of becoming aware of a personal data breach affecting your data, with what we know at that point.
Return and deletion
Session material is deleted on the schedule stated above. Everything else is deleted or returned at your request when our agreement ends, unless a law requires us to keep it.
Audits
On reasonable notice, and no more than once a year, we will answer written questions about how we meet these obligations.
Transfers outside the European Union
YuzuTrace is established in Québec, Canada. Where personal data is transferred outside the European Economic Area, it is covered by the European Commission's standard contractual clauses.
When you apply as a tester
This section is written for testers: what we collect at each step, why, who sees it, how long we keep it, and what you can do about it. The next section covers the session itself.
The application form
The form asks for your first and last name, your email address, the languages you speak, the market you live in (and your country if it is neither Canada nor the United States), the devices you could test with and the operating system of each, your age bracket, how often you buy online and what you last bought, how comfortable you are with technology, and a few written lines about your languages. Gender is asked as an open field, and it is optional: some clients need testers who reflect their own customers. Once accepted, you can add your province from your account; it is optional and serves the tax slip if your payments pass CA$500 in a year. All of this serves one purpose, deciding which sessions to invite you to. It is seen by the people who run YuzuTrace, never by a client.
One thing you do not type: when the form is sent, we record the country your connection comes from, and a shortened form of your IP address that stops at the network rather than the machine. We compare that country with the market you selected. This is not proof of anything and a VPN defeats it; it exists because a client who pays for testers in one country is entitled to testers who are actually there. If the two disagree, we may ask you about it. We do not reject an application on that alone.
When the form is sent, you receive a receipt by email and we receive a note that an application is waiting. An application we do not accept is deleted twelve months after the decision. An accepted one becomes your tester file and is kept while you are in the pool.
The language test
Once accepted, you record thirty seconds to one minute of speech in each language you declared, from your portal. Those clips are listened to by the person who confirms your languages, never by a client, and never passed through an automated system. They are permanently deleted as soon as your language is confirmed.
The agreement
Before your first session, we ask you to accept a services and confidentiality agreement. At the moment you tick the box, we record the date and time, the version of the text you read, the language it was shown in, your full IP address, and your browser identifier. Those last two exist for one reason: to tell a ticked box apart from a box ticked by you. They serve nothing else, are never passed to a client, and disappear with your file if you ask for it to be deleted. When the text changes, you are asked to accept the new version, and the earlier acceptance is kept: the sessions you ran under it remain governed by it.
How you are paid
Payments go through Stripe. When you set up your payment, you are taken to a page hosted by Stripe, where you enter your legal name, your date of birth, your address, your phone number and your bank details. Depending on your country and the amounts involved, Stripe may also ask for an identity document.
This information is collected by Stripe and never passes through YuzuTrace. We do not see it, do not keep it, and cannot look at it. Your account is a Stripe Connect Express account, and what reaches us is limited to five things: the account identifier, whether transfers are allowed, whether you have finished Stripe’s form, whether Stripe is still verifying something, and the list of items Stripe is still waiting for. On that last one we see the names of the items, never their contents. Stripe holds everything else in the United States, under its own legal identity-verification obligations, and you can view or correct it from the Stripe dashboard it gives you access to.
If you live in Canada and we pay you more than CA$500 in a calendar year, the law requires us to issue a tax slip. We then ask for your Social Insurance Number or Business Number through a secure form, use it for the slip, and keep only the fact that it was received, never the number itself. Never send it by email, and never when signing the agreement.
Your portal
Your tester portal has no password. You enter your email address, we send a six-digit code, and the code opens a session that lasts thirty days on that browser. A code or a session is refused once it has expired and erased within a day of expiring, and we count failed attempts to slow down anyone guessing. The portal is where you accept invitations, sign the agreement, set up your payment, record your language test, download a copy of your data or ask for its deletion.
Your record
Working with you produces a record of its own: the invitations you answered and the ones you did not, the deadlines you met, the sessions you accepted and never delivered, and for each delivered session a quality mark given by the person who wrote the report. From this we compute a reliability indicator over the last twelve months. Declining an invitation is an answer like any other and does not enter it; what matters is answering every invitation and delivering what you accepted. It decides how often you are invited and can lead us to end the agreement; it is never shown to a client, and you can ask us what yours is.
Keeping and deleting
Your file is kept while you are in the pool so we can invite you to future tests that match your profile. You can download a copy of everything we hold, or ask for its deletion, at any time from your portal or by writing to contact@yuzutrace.com. Deletion removes your file, your language test and your recordings; what accounting and tax law require us to keep (the payments made to you and the slips issued) is kept for the prescribed period, without being linked back to anything else.
What we capture during a session
A tester records their screen and their voice. We never record their face, and we never ask for camera access. Nothing in our method requires it.
Two things follow from this. A voice identifies a person, so a recording is personal data and is treated as such. And a screen can briefly show something nobody intended to capture, such as an incoming notification, another open tab or an address in the browser bar. The agreement says so and the session page repeats it before recording starts: testers are asked to close anything private beforehand, and anything of that kind that still appears is removed before we write the report.
Recordings are stored in the European Union, seen by the YuzuTrace team, and deleted thirty days after delivery. They are never sold, never used to train a model, and never published. We deliver findings and short quotations, not session footage.
A tester may withdraw their consent at any time and we delete their material. If the report has already been delivered, the findings drawn from it remain valid; the recording is destroyed and the quotation is anonymised.
Last Updated: September 2026
We may update these policies periodically. We'll notify you of significant changes.