GapStudy / Service information
Data processing
Updated 19 September 2026. This operational notice requires owner and legal review before paid launch. It is not a certification or a negotiated data-processing agreement.
Data and purpose
GapStudy processes submitted website URLs, selected competitor URLs, captured public text and HTML structure, evidence hashes, generated findings and report preferences to prepare and store requested studies. Accounts, existing workspace records and waitlist email addresses support access and service operations.
Infrastructure
This application uses Vercel for hosting and server requests, and Supabase for authentication and database storage. The currently connected Supabase database is in the US East (Ohio) region. Processing locations and contractual terms require owner review before paid launch.
Retention
Study records remain until deleted; no automatic study-expiry promise is made. Guest access cookies expire after 30 days. Rate-limit records contain hashed identifiers and are removed after 30 days during subsequent scan admission. Waitlist records remain until an owner fulfils a removal request.
User controls
A study owner can delete a completed or failed study, including its evidence and active share link. This does not erase copies a recipient already downloaded. Database backups and infrastructure logs follow provider retention settings; immediate backup erasure is not promised.
Before processing client data
Only submit public pages you are permitted to inspect. Do not include private credentials, access tokens or sensitive query parameters. Review evidence before sharing because public pages may contain personal contact details. This page is an operational description, not a signed DPA.
Questions or data requests: hello@clientflow.app