Who we are
Feedara is run by BitValue Ltd (company number 17504924). The full registered details are in the legal notice.
For the personal data described here, we are the controller: we decide why and how it is used, and we are responsible for it under UK data protection law (the UK GDPR and the Data Protection Act 2018). We are registered with the Information Commissioner’s Office under number to confirm: ICO registration number.
We are a small company and are not required to appoint a data protection officer. Every question about your data goes to hello@feedara.ai, and a person reads it.
Visiting the site and running an audit
You do not need an account to run an audit, and running one tells us nothing about you. What we store is the store address you typed and the report about that store. The report is kept at an unlisted address that search engines are told not to index, and it is not linked to you unless you are signed in. If you do not save it to a store in an account, it is deleted a year after it was run.
Beyond that, a visit involves three things:
- Server logs. Our hosting provider records each request, including your IP address, your browser type and the page asked for. We use these only to keep the site secure and to fix faults. Our lawful basis is our legitimate interest in running a site that works and is not abused.
- Your country, for prices. We show prices in euros, pounds or dollars, chosen from the country your connection comes from. That lookup happens as the page loads and is not stored. If you later subscribe, we note only whether the currency was chosen this way or picked by you. If you do pick one yourself on the Billing page, your choice is kept in a cookie so prices stay in it (see the cookie policy).
- Your light or dark preference, kept in your own browser. It never reaches us.
We do not use analytics cookies, advertising cookies, tracking pixels or any third-party script that follows you around the web. The cookie policy lists everything the site keeps in your browser, and it is a short list.
Having an account
You sign in with a link we email you, with Google, or with a password if you choose to set one. A password is kept by our sign-in provider only in a scrambled form that cannot be turned back into it; we never see it.
The sign-in page and the contact form also run a quick check from Cloudflare that a request comes from a person and not a script, which keeps the sign-in emails from being used up by bots and the contact form from being filled with spam. Cloudflare receives your IP address and some details of your browser to do that, and sets no cookies. Our lawful basis is our legitimate interest in keeping sign-in and our inbox working and secure.
If you choose Continue with Google, Google tells our sign-in provider your name, your email address and your profile picture, and the provider stores them with your account. We use your email address to find or create your account and nothing else from what Google sends. We ask Google for nothing beyond that: no access to your mail, contacts, calendar or files. What Google itself records about the sign-in is covered by Google’s privacy policy. To run your account we keep:
- your email address;
- records of when you signed in, including the IP address used, which our sign-in provider keeps to protect accounts from misuse;
- if you turn on two-step sign-in, the secret your authenticator app shares with our sign-in provider, so it can check your codes;
- which days you used the signed-in app (a date, nothing about what you did), so we can count how many people use Feedara each week and month;
- which kinds of email you have chosen to receive;
- if you joined through a friend’s link, or invite a friend yourself: your referral code, which account invited which, and whether the friend has paid, so the discount reaches both of you. You see only totals, never who the friends are, and a friend is told nothing about you;
- your workspace’s name, which starts as your email address until you change it;
- what you put into Feedara: the stores you track, the questions you set for them, their monthly readings, and your brand settings (a name, a colour and a logo, if you upload one).
We use this to provide the service you signed up for, which is our lawful basis: it is necessary for our contract with you. That includes the monthly check-up email, which every account holder receives and which you can turn off from a link in any of them, or in Settings. Counting the days people use the app is our legitimate interest in knowing whether the service is used, and it is only ever read as totals. The referral records are part of our contract with you: they are what lets us give you the discount the programme promises. A friend’s link carries its code in the web address, not in your browser.
We may also email you service updates (changes to Feedara) and notifications about your own stores. Both are on when you create an account, as the sign-in page says, and each can be turned off at any time in Settings. We send news and tips only if you turn them on there, which is your consent, and you can withdraw it in the same place. Messages about your account itself (sign-in links, security, billing and changes to these terms) always go, because the service cannot run without them.
Only Feedara’s founder can see account details, and only to run the service, answer your questions and prevent misuse.
Paying for a plan
Payments are handled by Stripe. Your card details go straight to Stripe and never reach us. Your billing name, address and any tax number you add are kept by Stripe for your invoices.
From Stripe we keep:
- a reference to your Stripe customer record, your plan, and whether it is active;
- the currency you pay in;
- the country that issued your card, compared with the country we guessed from your connection, so we can tell whether we are showing people the right currency. It is never used to decide anything about you.
Our lawful bases are our contract with you, and our legal obligation to keep accounting records, which UK tax law requires for six years.
Writing to us
If you email us, or use the form on a report to ask for a correction or removal, we keep your email address, your message and which report it is about. If you use the contact form, we keep your name, your email address, what the message is about, the store you name (if you do), your message and our replies to it. If you use the “Need more? Get in touch” form, we also keep what it asks: your name, company and website, the kind of business you run, roughly how many stores you manage, what you need and when you want to start. We use them to answer you and to act on what you asked, which is in our legitimate interest and yours. We delete these messages after two years.
Reports used to offer to email you when monthly monitoring opened. If you asked for that, we send you that one email and then delete your address. Your lawful basis here is your consent, and you can withdraw it at any time by writing to us.
If your store is audited
Anyone can audit any online store, because an audit reads only what the store publishes to every visitor. Our crawler, FeedaraBot, identifies itself, obeys the store’s robots.txt and reads no private pages.
A report is about a business, not a person. But a store run by a sole trader can carry its owner’s name, and a report quotes the store’s own product data word for word as evidence, which now and then includes a name, such as a reviewer’s. We hold that only as part of the evidence, on the basis of our legitimate interest in giving stores an accurate picture of how AI assistants see them.
If a report about your store is wrong, or you would rather it did not exist, tell us at hello@feedara.ai or with the form at the foot of the report. We correct or remove it quickly and without argument.
If we write to you about your store
We sometimes email people who run online stores to share their store’s audit. If we have written to you, this is what we hold and why.
- What: your business email address, the page of your website we found it on, the store it relates to, and its audit. For UK stores we also note the company registration line your site prints, because that is how we know it is a limited company.
- Where from: your store’s own website or a public business listing. We write only to addresses a business publishes for contact, and we never buy lists.
- Why: to tell a business about specific, free findings on its own store. Our lawful basis is our legitimate interest in doing that, which we have weighed against your interests: the email is about your business, it is useful whether or not you ever buy anything, and stopping it takes one reply.
- Stopping it: every email says how, with a link that needs no account. If you opt out, we delete everything else we hold about you and keep only your address on a do-not-contact list, which is the only way to make sure we never write again.
- How often: at most twice. If you have not replied after about a month, we may send one short follow-up, after checking your store again. Never more than that.
- How long: if you do not reply, we delete your details within twelve months.
Services that handle data for us
These companies process personal data on our behalf, under contracts that allow them to use it only to provide their service to us. Each link goes to their own privacy policy.
Vercel
United States
Runs the website and its servers.
Every request to the site passes through it, including your IP address and browser type.
Supabase
Ireland
Our database, sign-in system and file storage.
Your email address, sign-in records, your account's stores and settings, and any logo you upload.
Stripe
United States and Ireland
Takes payments and manages subscriptions.
Your billing name, email, address, tax number and card. Card details go to Stripe directly and never reach us.
Resend
United States
Delivers our emails: sign-in links and monthly check-ups.
Your email address and the content of the email.
Cloudflare
United States
Checks, on the sign-in page and the contact form only, that a request comes from a person and not a script.
Your IP address, browser details and a few technical signals from your browser, when you open the sign-in page or the contact form. Cloudflare says it uses them only to detect and block bots.
Namecheap
United States
Holds our domain and forwards mail sent to our address.
Your email address and your message, when you write to us.
Proton
Switzerland
Hosts the inbox your messages arrive in.
Your email address and your message, when you write to us.
What the AI assistants receive
The visibility tracker asks five AI assistants (ChatGPT, Gemini, Claude, Perplexity, Meta AI) the questions a shopper might ask about your store’s products, once a month.
What they receive: your store’s name and web address, its product categories, and those questions. What they never receive: your name, your email address, or anything about your account.
We reach each of them through their paid developer services, not their consumer apps, and each provider’s own developer documentation says it does not train its models on what we send. How we use AI explains the rest.
Data outside the UK
Our database is in Ireland. Our servers, Stripe, Resend, Cloudflare and Namecheap process data in the United States, and the inbox that receives your emails is in Switzerland.
UK law treats the EU and Switzerland as protecting personal data adequately. For the United States we rely on the UK Extension to the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on the UK’s International Data Transfer Addendum in that provider’s data processing terms. Either way, your data carries the same protection it would have here.
How long we keep it
- Your account: for as long as it is open. When you ask us to close it, we delete it within 30 days, and it leaves our providers’ backups as those expire.
- Billing records: six years, as UK tax law requires.
- Messages and correction requests: two years.
- “Tell me when monitoring opens”: until we have sent that one email.
- Outreach details: twelve months if you do not reply; an opted-out address for as long as we write to anyone.
- Server logs: no more than 30 days, by our hosting provider.
- Audit reports: a report saved to a store in an account stays for as long as that account keeps the store. Any other report, including one run without an account and one left behind when an account or store is deleted, is deleted one year after it was run. Anyone can ask us to remove a report sooner.
Your rights
Under UK data protection law you can ask us to:
- show you the personal data we hold about you, and give you a copy;
- correct it if it is wrong;
- delete it;
- stop or limit using it, including where we rely on our legitimate interests;
- give it to you, or to another company, in a format a computer can read. You can download everything we hold for your account yourself, any time, with “Download my data” in Settings.
Write to hello@feedara.ai. It is free, and we answer within one month. We may ask you to confirm the request comes from the address it concerns, so that nobody can obtain someone else’s data by asking for it.
We make no decisions about people by automated means. The score Feedara calculates is about a store’s published data, not about you.
Cookies, children and changes
Cookies. We use only what is needed to keep you signed in and to remember your choices (your theme, and your currency if you pick one). The cookie policy has the details.
Children. Feedara is a service for businesses and is not meant for anyone under 18. We do not knowingly collect children’s data.
Changes. When this policy changes, the date at the top changes too. If a change affects how we use data we already hold, we email account holders before it takes effect.
Questions and complaints
Write to hello@feedara.ai first. We would rather hear about a problem from you than have it go unanswered.
You can complain about how we handle your data in any way that reaches us, such as an email or the form on a report. We acknowledge a complaint within 30 days, look into it properly, keep you informed, and tell you what we found without undue delay.
You also have the right to complain to the Information Commissioner’s Office, the UK regulator for data protection, at ico.org.uk/make-a-complaint or on 0303 123 1113.