Privacy Policy
What CompeteIQ collects, why we collect it, who we share it with, and the rights you have over it.
Roles
Who decides, who processes
Controller. CompeteIQ (the entity that operates the service — placeholder details to be finalized with counsel before publication of the final version) is the data controller for the personal data described in this policy.
Processors. We use a small set of sub-processors to operate the service:
- Stripe — payment processing and subscription billing.
- Amazon SP-API and eBay — data sources; we read competitor pricing and your own catalog data through their authorized APIs under your OAuth grant.
- Hosting provider — application and database hosting (e.g. a Vercel-shaped managed platform). Tokens are encrypted at rest in our database; the host does not have plaintext access to token material.
Data we collect
Categories of personal data
- Account. Name and email address at sign-up. The password you set is hashed by better-auth — we do not store plaintext passwords.
- Billing. Stripe handles the payment instrument; we receive a customer identifier, plan tier, and subscription status. We never see full card numbers.
- Marketplace OAuth tokens. Tokens granted by Amazon SP-API and eBay when you connect an account. Encrypted at rest with AES-256-GCM; decrypted only to make authorized API calls on your behalf.
- Pricing data. Pricing snapshots, reprice-run history, and the rules you define.
- Server logs. Standard request logs (timestamp, route, status, anonymized IP) used for security and abuse investigation.
Lawful basis
Why we are allowed to use it
- Contract. Operating the repricing service you signed up for.
- Legitimate interests. Keeping the service secure, preventing fraud, and understanding aggregate product usage to improve it.
- Consent. Where required — for example, marketing email — we ask before we send it, and you can withdraw at any time.
How we use data
What we do with it
We use the data above to operate the service: read competitor prices, propose and write your prices under your rules, surface alerts when something changes, bill you, support your account, and send service notices. We do not sell personal data.
Marketing analytics on the landing and signup pages may use a generic Meta Pixel tag for conversion attribution — the signup form fires a Lead event exactly once per sign-up. No third-party advertising tracker is enabled beyond what the marketing team has explicitly opted into.
Retention
How long we keep it
- Account data. While the account is active, plus a 30-day grace period after closure for recovery; then deleted.
- Marketplace OAuth tokens. While the connection is active, plus a 30-day reconnection grace after disconnection; discarded immediately on Disconnect.
- Pricing snapshots and reprice runs. Account lifetime, plus 12 months after closure for audit; then deleted.
- Billing records.Retained per the longer of Stripe's retention and the statutory minimums in the jurisdictions where we operate.
You can export your data from the dashboard at any time while the account is active.
Sharing
Who else sees it
We share data only with the sub-processors listed above, on a need-to-know basis, to operate the service. We do not sell personal data. We do not share data with third-party advertising networks beyond what we have explicitly opted into for marketing measurement.
International transfers
Where the data lives and how it moves
Our application infrastructure and database may be hosted in multiple regions. When personal data is transferred across borders — for example, from the EEA to a processor in the United States — we rely on the European Commission's Standard Contractual Clauses (or an equivalent adequacy mechanism) and require the recipient to apply an equivalent level of protection.
To request our latest Data Processing Agreement, email competeiq-1783908657300-b7sv@polsia.app.
Your rights
Access, erasure, and the rest
You have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your account and associated data, subject to the retention windows above.
- Restrict or object to specific processing.
- Port your data in a machine-readable format (export from the dashboard).
- Withdraw consent where processing is based on consent — for example, unsubscribe from marketing email at any time.
- Complain to a supervisory authority in your jurisdiction.
To exercise any of these rights, email competeiq-1783908657300-b7sv@polsia.app. We respond within the statutory window (typically 30 days; longer with notice where the request is complex).
Security
How we protect it
Marketplace OAuth tokens are encrypted at rest with AES-256-GCM. All data is transmitted over TLS. Every authenticated /api route is scoped to the signed-in user — the request handler reads requireAuth() and every database query includes where: { userId: user.id }, so one account cannot read another account's data.
Changes
How we tell you about updates
We notify active customers by email at least 14 days before any material change to this policy takes effect, with a summary of the change and the right to cancel or delete your account before the effective date. Non-material changes (typographic fixes, clarifications that do not change what we do) are posted directly.
Contact
How to reach us
For any question, complaint, or data-rights request related to this policy, email us at competeiq-1783908657300-b7sv@polsia.app.
This policy is a draft pending final counsel review. Material updates will be posted to this page with a new "Last updated" date, and active customers will receive an email notice at least 14 days in advance.