1. Scope and operator
This Privacy Policy applies to skupeek.com, SkuPeek accounts, dashboards, contact forms, reports, and related services (collectively, the Service). SkuPeek is the operator responsible for the personal data described in this Policy. Privacy questions and requests can be sent to [email protected].
This Policy does not govern third-party websites, store platforms, payment pages, or services that have their own privacy notices. Our Terms of Service govern use of the Service.
2. Personal data we collect
Account and team data
We collect names, business email addresses, password hashes, account and email-verification status, notification preferences, session records, team invitations, workspace roles, accepted Terms and Privacy Policy versions, acceptance method and timestamp, and related account timestamps. We do not store passwords in readable form.
Store, catalog, and workspace data
We collect store names, website URLs and domains, platform, market, country, currency, timezone, and configuration. We process product URLs, uploaded CSV content, product and variant names, identifiers such as SKU, GTIN, MPN, and model, images, categories, prices, stock states, competitor sources and matches, review decisions, job history, analytics settings, saved report snapshots, schedules, and report recipient email addresses. Most catalog data is business or product information rather than personal data, but it may become personal data if it identifies an individual.
Billing data
We process plan, billing interval, subscription and payment status, renewal and cancellation dates, purchased credits, usage, provider customer and subscription identifiers, transaction events, and limited saved-payment-method descriptors such as card brand, last four digits, and expiry when supplied by the payment provider. Payment-card entry is handled by a payment processing and merchant-of-record provider. SkuPeek does not directly receive or store full card numbers or card security codes.
Communications
When you contact us or request a demo, we collect the information you provide, which may include your name, work email, store URL, platform, approximate SKU volume, market, company, team size, and message. We also process support correspondence, transactional email delivery status, and notification preferences.
Technical and activity data
When you use the Service, we may process IP address, request time, browser and device information, requested URLs, authentication and security events, job activity, feature actions, errors, performance data, and operational logs. We also record usage needed to enforce store, SKU, discovery, user, API, and reporting limits.
Across public pages and authenticated customer workspaces, our self-hosted, cookieless analytics records page paths, referring sites, browser and device characteristics, approximate location, and anonymous session, pageview, and configured feature-event data. We exclude URL query strings and fragments and replace dynamic product, competitor, report, and share-token path segments with generic route labels before sending an event. We do not collect or send analytics events from administrator, invitation, unsubscribe, or email-verification flows, and we do not connect analytics sessions to SkuPeek account identities.
3. Sources of personal data
We receive information:
- directly from you when you register, configure a store, upload data, purchase a plan, or contact us;
- from an account owner or team administrator who invites you or configures a workspace;
- automatically from your browser, device, and use of the Service;
- from payment, email, security, infrastructure, and other service providers;
- from public websites, store interfaces, product pages, search results, and other public business sources used for catalog and competitor intelligence; and
- from you when you make a report available through a share link or send it to a recipient.
4. How we use personal data
We use personal data to:
- create accounts, authenticate users, manage sessions, and verify email addresses;
- provide store workspaces, team access, imports, monitoring, discovery, analytics, and reports;
- process subscriptions, credits, payments, renewals, cancellations, and usage limits;
- send verification, invitation, report, service, billing, discovery, and support communications;
- respond to demo, Enterprise, privacy, and support requests;
- detect abuse, protect accounts and infrastructure, debug failures, and maintain availability;
- understand site and product usage and improve landing, registration, conversion, and workspace flows;
- measure and improve Service reliability, extraction quality, matching, and product workflows;
- enforce our Terms, establish or defend legal claims, and comply with legal obligations; and
- create aggregate or de-identified operational statistics that do not reasonably identify a person.
We do not sell personal data, use it for third-party targeted advertising, or use Customer Data to build advertising profiles.
5. Legal bases for processing
Where data-protection law requires a legal basis, we rely on one or more of the following:
- Contract: to create and administer an account, provide requested Service features, process billing, and take steps requested before entering a subscription or Enterprise agreement.
- Legitimate interests: to secure and improve the Service, prevent fraud and abuse, provide support, communicate about requested business services, understand operational performance, and collect and analyze public product information. We balance these interests against the rights of affected individuals.
- Legal obligations: to maintain required financial and compliance records and respond to valid legal process.
- Consent: where we specifically ask for consent. You may withdraw consent at any time without affecting prior processing.
Account, authentication, store, and billing information marked as required is necessary to provide the relevant Service. Without it, we may be unable to create an account, process payment, or provide a feature.
6. Automated crawling, matching, and AI
SkuPeek uses automated systems to retrieve public product pages and search results, extract catalog fields, suggest competitor matches, compare price and stock signals, and prepare analytics and reports. Some extraction and matching tasks may send relevant page content, URLs, and catalog fields to AI infrastructure and model providers. We do not intentionally send account passwords or full payment-card details to those providers.
These systems make product and market recommendations, not decisions about individuals that produce legal or similarly significant effects. Customers can review suggested matches and approve, reject, or remap them. Automated outputs may be inaccurate and should be reviewed.
8. International data transfers
SkuPeek and its providers may process data in countries other than the country where you are located. Those countries may have different data-protection laws. Where required, we rely on legally recognized transfer mechanisms and contractual or organizational safeguards. You may contact us for information about safeguards relevant to your data.
10. Data retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy. Retention depends on the type of data, the account and subscription lifecycle, workspace instructions, security and support needs, contractual commitments, legal recordkeeping, and potential disputes.
- Account, workspace, catalog, and report data is generally retained while the account or relevant workspace is active and for a reasonable period afterward to support recovery, export, and dispute handling.
- Session, usage analytics, security, crawl, extraction, job, and diagnostic records are retained for operationally appropriate periods based on measurement, security, reliability, and troubleshooting needs.
- Billing events, subscription records, audit logs, and transaction information may be kept longer where needed for tax, accounting, fraud-prevention, compliance, and legal claims.
- Legal-acceptance records are retained as an append-only contract and compliance history and may remain after account closure where needed to establish or defend legal claims.
- Contact and support correspondence is retained while the request is handled and afterward as reasonably needed for follow-up and records.
- Deletion from active systems may not immediately remove encrypted or disaster-recovery backups; backup copies are isolated and expire or are overwritten according to backup schedules unless longer retention is legally required.
11. Security
We use reasonable technical and organizational measures designed to protect personal data, including access controls, hashed passwords and session tokens, encrypted network transport, restricted internal services, and backup controls. No internet transmission or storage system is completely secure, so we cannot guarantee absolute security.
Keep credentials confidential, use secure devices, remove team access that is no longer needed, and contact us promptly if you suspect an account or data-security incident.
12. Your privacy rights
Depending on where you live and subject to legal exceptions, you may have rights to request access to or a copy of personal data, correction, deletion, restriction, objection, portability, or withdrawal of consent. You may also have the right to complain to the data-protection authority where you live or work or where you believe a violation occurred.
Send a request to [email protected] from the email associated with your account and describe the right you want to exercise. We may ask for information reasonably necessary to verify your identity and authority. We will not discriminate against you for exercising a privacy right. You can disable competitor-discovery emails in Profile settings or through the unsubscribe link in those emails.
If your account belongs to a business customer, we may direct a request about Customer-controlled workspace data to that customer. Some data may be retained where an exception applies, including security, billing, legal-compliance, and claims records.
13. California privacy disclosures
To the extent California privacy law applies, the categories described in Section 2 correspond to identifiers; customer records and commercial information; internet or electronic activity; professional or employment-related information; approximate location derived from IP; and inferences about store and product activity. We collect them from the sources in Section 3, use them for the purposes in Sections 4 and 6, and disclose them to the recipient categories in Section 7 for business purposes.
SkuPeek does not sell personal information or share it for cross-context behavioral advertising, and has not done so in the preceding 12 months. We do not knowingly sell or share the personal information of anyone under 16. We do not use or disclose sensitive personal information to infer characteristics or for purposes that require a right to limit under California law.
California residents may request to know, access, correct, or delete covered personal information and may exercise applicable opt-out or limitation rights without discriminatory treatment. Submit requests to [email protected]. An authorized agent may submit a request, but we may require proof of the agent's authority and verification with the resident.
14. Customer-controlled personal data
For account, billing, security, and direct relationship data, SkuPeek generally determines why and how the data is processed. If a business customer submits personal data to a workspace for SkuPeek to process only on its instructions, that customer is responsible for its own notices, legal basis, instructions, and responses to individuals, and SkuPeek acts as its service provider or processor as applicable.
The Service is intended for product, catalog, and business intelligence. Customers should not upload end-customer records or sensitive personal data. Businesses that require a separate data-processing agreement may contact us before submitting personal data beyond ordinary account and business-contact information.
15. Children
The Service is for business users aged 18 or older and is not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact us so we can review and delete it where appropriate.
16. Changes and contact
We may update this Policy to reflect changes to the Service, providers, or legal requirements. We will post the updated Policy, change the effective date, and provide additional notice of material changes when appropriate. Prior versions may be requested by email.
Contact
For privacy questions, rights requests, or complaints, email [email protected]. You may also lodge a complaint with the privacy or data-protection authority available in your location.