Privacy Policy
This policy explains what personal data SKUmio holds, why, who else sees it, how long it is kept and what you can require of us. It covers the website and application at skumio.com and the emails we send.
Contents
- Who we are
- What the service does, in privacy terms
- What we collect about you
- Where it comes from
- Why we hold it, and on what basis
- Data about people other than you
- If you sign in with Facebook
- Cookies, analytics and advertising tags
- Who else processes it
- International transfers
- Security
- How long we keep it
- Your rights
- If you are in California or another US state
- Email you receive from us
- Automated decisions
- Children
- Mobile apps
- Changes
- Contact
1. Who we are
SKUmio is operated by Observa Systems, LLC, a Delaware limited liability company with its registered office at 131 Continental Dr, Suite 305, Newark, DE 19713, New Castle County, Delaware, USA. For the personal data described here we are the controller: we decide what is collected and why.
Write to [email protected] about anything in this policy, including to exercise a right under section 13.
2. What the service does, in privacy terms
SKUmio observes publicly available product listings on e-commerce websites its customers choose, and estimates how much those shops sell by watching how their published stock numbers change over time.
We collect product data, not people data. We do not read, buy or receive the personal data of those shops' customers. We do not place a tracker on any shop's website, we do not follow individuals around the web, and we build no profile of any shopper. Our readers request pages as any visitor can, and never sign in as a shop's customer.
So the personal data in this policy is of two kinds only, and they are kept separate: data about you, the account holder (sections 3 to 5), and a small amount of data about other people that shops and public registers publish themselves (section 6).
3. What we collect about you
- Your sign-in identity. Your email address, your display name and the user identifier issued by the provider you signed in with. Authentication is handled by Google Firebase Authentication; we never see or store a password.
- Your settings. Interface language, display currency, the shops you have chosen to monitor, how often you want them checked, your notification preferences per shop, and what you have exported or reported on.
- Your payment records. The top-ups you have made, your balance, what it was spent on and which run each charge belongs to, plus invoices. Card details are entered on Stripe's own payment form and never reach our servers; we hold only Stripe's identifiers for your customer record and saved payment method, and the card's brand, last four digits and expiry so we can show it to you and warn you before it expires.
- What you send us. Messages through the contact form or by email, requests to have a shop checked by a person, and anything you choose to include in them.
- Technical logs. IP address, browser user agent, the pages and interfaces you requested and when, and error traces. Kept so we can find faults, keep the service available and detect abuse.
- Email delivery events. Whether a message we sent you was delivered, bounced or was marked as spam, so we can stop writing to an address that does not work.
We do not ask you for, and you should not send us, special categories of data: health, race, political opinions, religion, trade union membership, biometrics, or anything similar.
4. Where it comes from
- From you, when you register, configure the service, write to us or pay.
- From your sign-in provider (Google, or another supported provider), which passes us your name, email address and identifier.
- From Stripe, which tells us that a payment succeeded or failed and describes the card, without giving us its number.
- From your use of the service, which produces the logs and records above.
5. Why we hold it, and on what basis
| Purpose | Basis |
|---|---|
| Creating and running your account, monitoring the shops you chose, showing you the data | Performance of our contract with you |
| Charging for the service, taking payment, issuing invoices, chasing a debt | Contract, and our legitimate interest in being paid |
| Keeping accounting records and meeting tax obligations | Legal obligation |
| Operational email: a failed collection, a low balance, a payment, an expiring card, a report you asked for | Contract |
| Keeping the service working, secure and free of abuse, investigating incidents, enforcing our terms | Legitimate interest in protecting the service |
| Improving the service, measuring which features are used, in aggregate | Legitimate interest in developing our product |
| Occasional email suggesting you finish setting up or top up your account | Legitimate interest in customer retention, with an opt out in every message |
| Marketing email to people who are not customers, and advertising tags if they are ever added | Consent, which you can withdraw |
| Answering a legal request, defending a claim | Legal obligation, or legitimate interest in defending ourselves |
Where we rely on a legitimate interest, we have weighed it against your interests, and you can object at any time under section 13.
6. Data about people other than you
The service reports on companies, not on individuals. But some of what a shop, a public register or a review site publishes has a person's name in it, and we would rather set that out than pretend otherwise. Three things:
- Company officers. Where a public company register publishes who represents the operator of a shop, we store those names, the role and body they hold, and a year of birth used only to tell two people of the same name apart. The year of birth is never displayed. Nothing here is bought from a data broker or scraped from a private source; it is what the register itself publishes.
- Review authors. Where a shop or a review platform publishes reviews, the name printed under a review, as the publisher printed it, is stored with the rating and the text.
- Public social media profiles and posts of the shops themselves, and public business contact details a shop publishes on its own website.
What we do not do with it: we do not enrich it, cross-reference it against other sources to build a profile of a person, sell it, use it to advertise to anyone, or send anybody a message because of it. It exists so a customer can see who runs a competitor and what its buyers say, which is why it is there in the first place.
Our basis is our legitimate interest, and our customers', in commercial research using information those sources have already made public, weighed against the limited effect on the person named. If you are named in something we hold and you want it removed, write to [email protected] and we will remove it unless we have a compelling reason not to, and tell you either way.
Separately, our own addresses are used to subscribe to shops' marketing newsletters, so that customers can see what a competitor sends. We never use a customer's address for that, and we never subscribe anybody else.
7. If you sign in with Facebook
Signing in with Facebook is optional; Google sign-in and email are alternatives. When you choose it, we ask Meta for two permissions and no others: public_profile and email. What we receive back is your name, your email address and your Facebook user identifier, passed to us through Firebase Authentication.
We never post anything on your behalf, we do not read your posts, your friends or your pages, and we do not use Facebook data for advertising. The identifier is used for one thing only: recognising you as the same person the next time you sign in. You can remove that connection at any time; see how to delete your data.
8. Cookies, analytics and advertising tags
Inside the panel we set a session cookie that keeps you signed in, and a cookie that remembers your language. Those two are necessary for the service to work and they are the only cookies the panel sets. Our delivery provider may also set a cookie that distinguishes automated traffic from a real browser, for security.
As of today there is no analytics or advertising tag anywhere on this site. No Google Analytics, no Meta (Facebook) Pixel, no TikTok pixel, no LinkedIn Insight Tag, and no profile of your browsing built by us or by anyone else.
We intend to add measurement and advertising tags to the public marketing pages. When we do, three things will be true of them, and this paragraph is the commitment:
- They will run on the public marketing pages only, and never inside the panel. What you look at about your competitors is not sent to an advertising network.
- They will not load until you have agreed to them, and you will be able to decline and to change your mind later. Declining leaves the service fully usable.
- They will receive ordinary web-visit data, such as pages viewed, approximate location from your IP address, device and browser, and never your shop list, your readings or the contents of your account.
Until that consent mechanism exists, no such tag is present. If you are reading this and you can see one, it is a mistake and we want to hear about it.
9. Who else processes it
We do not sell personal data and we do not share it for anyone else's marketing. It is handled on our behalf by the following, each under a contract limiting them to what we ask:
| Who | For what | What they receive |
|---|---|---|
| Google (Firebase Authentication) | Sign-in | Your email address, name and identifier |
| Stripe | Payments and card storage | Your name, email, billing details and card, which we never see |
| Cloudflare | Traffic delivery, security, inbound mail routing | Your IP address and request metadata |
| SendGrid (Twilio) | The email we send you | Your address and the message itself |
| OpenAI | Only if you ask us to suggest competitors | The shop address you typed, and nothing about your account |
| DataForSEO, Apollo, BuiltWith, Brandfetch, Context.dev, Apify | Research about a shop you asked us to look at | The shop's address. They are not told who asked |
| BrightData, ProxyMarket | Carrying our requests to the shops you monitor | The request to the shop. Your identity is not part of it |
| Our hosting provider | The servers the service runs on | Everything the service stores, at rest |
We also disclose data where a law, a regulator or a court requires it, where we must to establish or defend a legal claim, and to our professional advisers under a duty of confidence. If the business is ever sold or merged, account data passes to the buyer under this policy.
10. International transfers
We are established in the United States and our service runs on servers in Europe. Personal data therefore moves between the two, and some of the providers in section 9 process it in the United States or elsewhere.
Where data covered by the GDPR leaves the European Economic Area, it is transferred under the European Commission's Standard Contractual Clauses or another lawful mechanism published by the provider concerned, together with the technical measures in section 11. Ask us at [email protected] and we will tell you which applies to a particular provider.
11. Security
- Everything travels over HTTPS. Certificates are renewed automatically.
- We never hold your password or your card number.
- Access to the production database and servers is limited to the people who operate the service, over keys rather than passwords.
- The panel is separated from the public pages, and administrative screens are limited to named operator accounts.
- Backups are taken regularly and are held under the same protections as live data.
- No system is perfectly secure. If a breach affects your personal data and is likely to present a risk to you, we will tell you and the competent authority within the time the law allows.
12. How long we keep it
| What | How long |
|---|---|
| Your account, settings and subscriptions | Until you close the account, then removed as described on the deletion page |
| Your email address and sign-in identifier | Erased immediately on closure. The address is overwritten with a non-deliverable placeholder |
| Payment and usage records | Kept after closure, with no name attached, for as long as tax and accounting rules require us to be able to produce the invoices |
| Messages you sent us | While needed to answer you and to show what was agreed, then deleted |
| Technical logs | Rotated and discarded in the ordinary course; not kept indefinitely |
| Identification scan results | Cached per domain for up to 30 days |
| Data about the shops themselves | Kept. It describes public listings, it is not personal data about you, and other customers may be watching the same shops |
Closing your account is immediate and cannot be undone. Exactly what happens, and what survives it, is set out on the data deletion page.
13. Your rights
Wherever you are, you can ask us to give you a copy of your data, correct it, delete it, export it in a portable form, restrict what we do with it, or object to a use we base on a legitimate interest. You can also withdraw a consent you have given, which does not affect what was done before.
Write to [email protected] from the address your account is registered with. If you write from another address we will have to ask you something that proves the account is yours, because otherwise anybody could ask for anybody's data. We answer within 30 days, and tell you if a request is genuinely complicated and needs longer.
We do not charge for this, and asking costs you nothing else: we will not close your account or degrade your service because you exercised a right.
If you are in the European Economic Area or the United Kingdom, these rights are those in Articles 15 to 22 of the GDPR, and you may also complain to your national data protection authority. We would rather you told us first.
14. If you are in California or another US state
In the last twelve months we have collected the categories of personal information described in section 3: identifiers, commercial information about your transactions with us, and internet activity such as logs. They come from the sources in section 4 and are used for the purposes in section 5.
We have not sold personal information, and we have not shared it for cross-context behavioural advertising, in the last twelve months or ever. We do not use or disclose sensitive personal information for any purpose that would require an option to limit it.
Residents of California and of other US states with similar laws may request to know, to delete, to correct, and to opt out of any sale or sharing, and may not be discriminated against for doing so. Use the same address as in section 13. An authorised agent may act for you if they provide written proof.
15. Email you receive from us
- Service email tells you what is happening to your account: a collection that failed, a low or negative balance, a payment or a failed card, an expiring card, a report you asked for, the answer to a request. You can turn most of it off per shop in your settings.
- Email about payment, suspension and account security is sent regardless of those settings, because it is part of the service and not marketing.
- Occasional prompts, such as a reminder that you have not added a shop yet, or that your balance is running out, carry an unsubscribe link and stop as soon as you use it.
- We do not sell or rent your address, and we do not send you other companies' advertising.
16. Automated decisions
We do not make decisions about you by automated means that produce a legal effect or similarly significantly affect you. Automation in the service decides things about shops, not about people: which shop to read next, how to read it, what a stock movement means and what it costs. Pricing is calculated from the shop, not from you, and it is the same for every customer.
17. Children
SKUmio is a business tool, sold to businesses, and is not intended for anyone under 18. We do not knowingly collect data about children. If you believe a child has given us personal data, write to us and we will delete it.
18. Mobile apps
There is no SKUmio app yet. When one is published on the App Store or Google Play, this policy covers it too, and an app involves a few things a website does not:
- A device identifier and a push token, if you turn notifications on, so a message can reach the right device. You can turn them off in the operating system.
- Crash and performance reports from the platform, which tell us that something failed and on what device, not who you are.
- Purchase records held by Apple or Google, if you ever pay through a store rather than through Stripe. In that case the store, not us, holds your payment details.
The app will show the same data as the panel and will not collect anything about you that the panel does not.
19. Changes
If this policy changes materially we will say so in the service, or by email, before the change takes effect. The version and date at the top always show which text you are reading. Earlier versions are available on request.
20. Contact
Observa Systems, LLC
131 Continental Dr, Suite 305
Newark, DE 19713, New Castle County, Delaware, USA
[email protected]
The terms on which the service is provided are in the Terms of Service.