SurfaclySurfacly
LEGAL

Privacy Policy

Last updated July 2, 2026.

1. Who we are

Surfacly ("we", "us") is an AI-commerce visibility platform operated from Bangladesh. This policy explains what data we collect, why, and your choices. It covers merchants who use Surfacly and the store data they connect.

2. Information we collect

Account details you provide at sign-up: name, email, workspace name, and the store domain you connect (e.g. your WooCommerce / WordPress site).

Catalog data synced from your store via the API key you generate: product titles, descriptions, schema, images, and variants. We do not pull your shoppers' personal information or order contents for catalog auditing.

AI-attributed order metadata your plugin may send us: a hashed customer email (SHA-256), order total, currency, and the AI source name. We never store the raw email.

Usage data: which dashboard pages you visit, which fixes you generate, and aggregate timing/error data used to keep the product fast and reliable.

3. How we use your data

To operate the service: run audits, generate AI fixes, score products, track AI-channel citations, and render reports inside your workspace.

To improve the product using anonymised, aggregate statistics. We do not use your catalog to train external AI models.

To send essential emails: account verification, billing notices, optional weekly digests (you can opt out in settings), and service or security announcements.

4. AI processing

Audits and fix drafts are produced by large language models accessed through OpenRouter, our AI gateway. Relevant catalog content is sent to the model to generate output and is transmitted securely.

Providers accessed via OpenRouter operate under data-processing terms that prohibit training their models on data passed through the API. Nothing is auto-published to your store — you review every AI suggestion first.

5. Where your data lives and sub-processors

We store data in a managed PostgreSQL database with encrypted backups, and use a short-lived cache (rate limiting and de-duplicating AI responses) with a retention of roughly 7 days or less.

We rely on a small set of sub-processors, each under their own privacy terms and data-processing agreements: Dodo Payments (subscription billing / merchant of record), OpenRouter (AI gateway), Resend (transactional email), plus our hosting, database, and cache providers.

We do not sell your data, and we don't share it for advertising.

6. International transfers

Some sub-processors operate outside your country, so your data may be processed internationally. Where required, transfers rely on appropriate safeguards such as standard contractual clauses or equivalent protections.

7. Retention

We keep your data while your account is active. After you delete your account we retain data for up to 60 days to allow restoration, then permanently delete it — unless we're legally required to keep certain records longer.

8. Your rights

You can access, export, correct, or delete your data at any time — use the Danger Zone in workspace settings, or email privacy@surfacly.top for assisted requests.

If you're in the EU / UK, GDPR rights apply (access, rectification, erasure, restriction, portability, objection). We respond to verified requests within 30 days.

9. Cookies

We use first-party cookies strictly for authentication and remembering your theme preference. If analytics are enabled, they're used only in aggregate. We don't set advertising or cross-site tracking cookies.

10. Children

Surfacly is a business tool not intended for anyone under 18. We don't knowingly collect data from children.

11. Changes

We'll announce material changes to this policy by email at least 14 days before they take effect.

12. Contact

Privacy questions or requests: privacy@surfacly.top.