1. Who we are
Surfacly ("we", "us") is an AI-commerce visibility platform operated from Bangladesh. This policy explains what data we collect, why, and your choices. It covers merchants who use Surfacly and the store data they connect.
Last updated July 2, 2026.
Surfacly ("we", "us") is an AI-commerce visibility platform operated from Bangladesh. This policy explains what data we collect, why, and your choices. It covers merchants who use Surfacly and the store data they connect.
Account details you provide at sign-up: name, email, workspace name, and the store domain you connect (e.g. your WooCommerce / WordPress site).
Catalog data synced from your store via the API key you generate: product titles, descriptions, schema, images, and variants. We do not pull your shoppers' personal information or order contents for catalog auditing.
AI-attributed order metadata your plugin may send us: a hashed customer email (SHA-256), order total, currency, and the AI source name. We never store the raw email.
Usage data: which dashboard pages you visit, which fixes you generate, and aggregate timing/error data used to keep the product fast and reliable.
To operate the service: run audits, generate AI fixes, score products, track AI-channel citations, and render reports inside your workspace.
To improve the product using anonymised, aggregate statistics. We do not use your catalog to train external AI models.
To send essential emails: account verification, billing notices, optional weekly digests (you can opt out in settings), and service or security announcements.
Audits and fix drafts are produced by large language models accessed through OpenRouter, our AI gateway. Relevant catalog content is sent to the model to generate output and is transmitted securely.
Providers accessed via OpenRouter operate under data-processing terms that prohibit training their models on data passed through the API. Nothing is auto-published to your store — you review every AI suggestion first.
We store data in a managed PostgreSQL database with encrypted backups, and use a short-lived cache (rate limiting and de-duplicating AI responses) with a retention of roughly 7 days or less.
We rely on a small set of sub-processors, each under their own privacy terms and data-processing agreements: Dodo Payments (subscription billing / merchant of record), OpenRouter (AI gateway), Resend (transactional email), plus our hosting, database, and cache providers.
We do not sell your data, and we don't share it for advertising.
Some sub-processors operate outside your country, so your data may be processed internationally. Where required, transfers rely on appropriate safeguards such as standard contractual clauses or equivalent protections.
We keep your data while your account is active. After you delete your account we retain data for up to 60 days to allow restoration, then permanently delete it — unless we're legally required to keep certain records longer.
You can access, export, correct, or delete your data at any time — use the Danger Zone in workspace settings, or email privacy@surfacly.top for assisted requests.
If you're in the EU / UK, GDPR rights apply (access, rectification, erasure, restriction, portability, objection). We respond to verified requests within 30 days.
We use first-party cookies strictly for authentication and remembering your theme preference. If analytics are enabled, they're used only in aggregate. We don't set advertising or cross-site tracking cookies.
Surfacly is a business tool not intended for anyone under 18. We don't knowingly collect data from children.
We'll announce material changes to this policy by email at least 14 days before they take effect.
Privacy questions or requests: privacy@surfacly.top.