Security FAQ

1. Will this script be placed on all pages? If the answer is yes, how is PII data prevented from being sent to vendor sites?

The Da Vinci Tracking script tag is added to webpages of the client’s choice. For the Tracking script product to function, Movable Ink uses a unique identifier to associate event-level data collected by the script tag with the user triggering these events. This unique identifier is a pseudonymous identifier assigned to each known user. Movable Ink maintains a mapping of the pseudonymous identifier to a hashed value of the user’s email address.

2. What is the Domain to which this JS sends data if it captures data?

track.coherentpath.com

3. Is the JS going to stub/remove PII data during information?

The script tag only collects information needed for Movable Ink to provide its Da Vinci tracking service. This includes a hash of the user’s email address which may be considered “personal data” or “PII” under specific regulatory frameworks.

4. If the customer uses a tag manager, will the JS deploy in our environment or be called dynamically from the vendor’s environment?

The JS is hosted server-side by Movable Ink and is managed using Tealium or another tag manager.

5. What are the data that will be collected by JavaScript? How does the vendor server handle this data?

Data collected by the Signal script tag will include the following:

  • A hash of the user’s email address
  • A unique user identifier
  • A browser ID
  • A session ID

Additionally, event-level data will be collected, for example:

  • Product Page Event:
    • Product ID
    • Price
  • Search page Event:
    • Search term
    • Page View Event:
    • URL
    • Order Confirmation
    • Order ID
    • Order Revenue
  • Order Items

Data is used strictly to provide our services and is stored in Movable Ink’s secure GCP environment. Data is encrypted in transit and at rest using industry-standard encryption algorithms.

6. Once the data is collected, will it be stored in any vendor's database? If the answer is yes, what would be the data retention policy?

Yes, data is retained for 2 years to enable us to provide our services and to enable clients to conduct year-over-year analytics. Data is stored in Movable Ink’s secure GCP environment, encrypted in transit and at rest.

7. If there is a new version of JavaScript available, how will the upgrade be handled and who will have access to upgrade or update?

Major version upgrades require the client to upgrade. Minor upgrades are handled transparently by Movable Ink.

8. Is there documentation on the JS implementation that we can look at and review

Yes, refer to the Javascript SDK documentation.

9. In the test environment is there an experience editor switch we need to toggle to be able to see these JavaScripts?

No, there is no interaction with an experienced editor required.

10. Can we get a list of all the JS files that would be loaded after adding the CJ tag?

https://track.coherentpath.com/v1/track.js

Was this article helpful?

/