✓ PromiseCheck
PromiseCheck crawler
Updated October 6, 2026
PromiseCheck is operated by David Gutierrez under Shop Promise. It monitors merchant-authorized Shopify storefronts for inconsistent customer promises and problems with supported shopping controls. Live QA uses owner-authorized development stores.
Identity
The User-Agent is PromiseCheck/1.0 (+https://promisecheck-dg.fly.dev/crawler). The robots.txt product token is PromiseCheck. Storefront pages, product data, theme resources, cart calls and robots.txt requests carry Web Bot Auth signatures when signing is configured. Signatures are restricted to the confirmed storefront origin; app proxies and other origins do not receive storefront signatures.
The Signature-Agent identity is https://promisecheck-dg.fly.dev. Our public signing-key directory is available for verification. Registration and signatures do not override a site’s crawler rules or guarantee access.
Requests and crawler rules
Scans sample representative homepage, product and policy pages, supported widgets, and isolated cart journeys where permitted. They use desktop and mobile browser sessions without customer accounts. PromiseCheck does not open checkout, submit payments or create orders.
Before requesting HTTP pages or resources, the crawler reads that origin’s public robots.txt without visitor cookies or passwords. It honors Allow and Disallow rules and Crawl-delay, including for assets, cart calls, password form submissions and redirect targets. Page and cart requests are spaced at least 1.8 seconds apart. Pacing is shared by processes using the app’s database.
On the storefront of the merchant who connected PromiseCheck, it acts on that merchant’s request, so it follows only robots.txt groups that name PromiseCheck, as Google’s AdsBot does. Shopify’s default User-agent: * rules are written for search engines and disallow the cart, store policies and a script every page loads. On every other site, PromiseCheck follows that site’s applicable rules, including User-agent: *.
Policies are cached for up to 15 minutes, shortened by cache directives. Missing policies (404 or 410) permit crawling. Denied, unavailable, challenged, oversized or unusable policies prevent requests to that site. Blocked embedded resources are skipped and disclosed; they do not cancel unrelated page reads. A missing dependency prevents a negative UI result from being confirmed as a storefront defect. Assets with no Crawl-delay use bounded parallel downloads. Delays above 30 seconds or queues that cannot be served within the check’s time budget stop checks rather than shorten the required delay. Blocked checks are reported as untested.
Opt out and contact
Site operators, including connected merchants, can disallow PromiseCheck in their robots.txt. For a complete opt-out, use:
User-agent: PromiseCheck Disallow: /
Connected merchants can also pause scheduled scans or uninstall the app. Contact davidcgutierrez93@gmail.com for access, coverage or opt-out questions. Do not send passwords or signing keys.
Data use
Sampled wording, results and redacted screenshots provide evidence to the merchant. Fly.io hosts the app and database; Tigris holds encrypted recovery backups. Enabled Brevo email alerts may send finding summaries, quoted wording and source links to merchant-selected recipients. Data is not sold or used for advertising. See our privacy and data-use policy for retention and deletion details.