Privacy Policy
Exactly what SellRadar collects, why we are allowed to use it, who processes it on our behalf, how long we keep it, and the rights you can exercise.
Contents
1. Who we are and what this policy covers
SellRadar ("SellRadar", "we", "us", "our") operates the keyword and product-opportunity analysis service at sellradar.ai. You submit a keyword and a marketplace, we analyse the live listings ranking for it, and we return a verdict, a set of scores, a competitor breakdown, and a written recommendation.
This policy explains how we handle personal data — any information that identifies you or can be linked to you. It applies to the SellRadar website, the signed-in application, our marketing emails, and our support channels. It does not apply to Amazon, Google, or any other site we link to or analyse.
For the purposes of the EU and UK General Data Protection Regulation ("GDPR"), SellRadar is the data controllerfor the personal data described here. Our team is established in Estonia, so our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon). Under the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA"), we act as a business.
Privacy contact: support@sellradar.ai. We answer privacy questions from this address and no other.
This policy forms part of our Terms of Service.
2. Information we collect
We collect three kinds of information: what you give us, what our systems record while you use the service, and what our sign-in and payment partners send back to us.
(a) Information you provide
| Category | Specific fields | When we get it |
|---|---|---|
| Account identity | Email address, display name, profile picture URL, and the provider account identifier (your Google subject ID, or Apple subject ID if you use Sign in with Apple). | When you first sign in. Passed to us by Google or Apple — see (c). |
| Scan input | The keyword text you type, the marketplace and country you select, and — for bulk runs — every keyword in the batch. | Each time you run a scan or a batch. |
| Scan annotations | Free-text tags you attach to a saved analysis, and the analyses you add to your watchlist. | When you tag a result or add it to your watchlist. |
| Business profile | Your selling model (private label, wholesale, arbitrage, dropship, handmade, bundle, used books, or other) and the product category you pick during onboarding. | During onboarding, and whenever you change it in settings. |
| Communication preferences | Your per-category email toggles (onboarding, product alerts, re-engagement, watchlist alerts) and an unsubscribe token tied to your account. | Set on sign-up, changed in settings or via an unsubscribe link. |
| Feedback | A reason code, an optional free-text comment of up to 2,000 characters, and where in the product you submitted it. | When you send feedback or tell us why you cancelled. |
| Marketing sign-ups | Your email address and which page or prompt captured it, if you give us your email without creating an account. | When you submit an email capture form. |
| Support correspondence | Whatever you write to us, including your email address and any details you choose to include. | When you email support. |
(b) Information collected automatically
| Category | Specific fields | Where it lives |
|---|---|---|
| Usage and quota records | Analyses used against your monthly limit, your plan limit and quota reset date, grace-scan counters, an event log of scans you run (event type, keyword, timestamp), and last-active and last-seen timestamps. | Our application database. |
| Scan output linked to you | The verdict, opportunity / competition-weakness / viability scores, data-confidence rating, the AI-written explanation and recommendation, the competitor listing table, and score snapshots taken over time for watchlisted keywords. | Our application database, linked to your user ID. |
| Notifications | Watchlist alerts generated for you — alert type, title, body text (which contains your keyword), created time, and whether you have read it. | Our application database. |
| IP address | Your public IP address is used in the moment to enforce rate limits, to verify the anti-bot challenge, and to guess which marketplace to preselect. Rate-limit counters keyed to your IP live in memory for 60 seconds to 2 minutes. Geo lookups are cached against your IP for 24 hours. | In-memory cache only. We do not write your IP into your account record. |
| Approximate location | A two-letter country code derived from your IP, or from your browser's Accept-Language header if the IP lookup fails. Country only — never a city, address, or GPS coordinate. | Held in the in-memory cache described above; used to preselect a marketplace. |
| Server logs | Request paths, status codes, timing, and error traces produced by our application servers, forwarded to our hosting provider's log service. | Hosting provider log storage, retained 30 days. |
| Device storage | Cookies and browser storage keys listed in section 4. | Your browser. |
One exception on IP addresses: if someone attempts to sign in to our internal admin console, the IP address and the email address used are written to a security audit log. That log covers our own staff and anyone probing the admin login. It does not record ordinary customer activity.
(c) Information we receive from third parties
| Source | What they send us |
|---|---|
| Google Sign-In | Your email address, whether that address is verified, your name, your profile picture URL, and a stable Google account identifier. We request only the openid, email, and profile scopes. We have no access to Gmail, Drive, Contacts, Calendar, or any other Google service. |
| Sign in with Apple (where enabled) | Your Apple account identifier, your email address (or Apple's private relay address if you chose to hide it), and your name — which Apple sends only on your first sign-in. |
| Stripe | Your Stripe customer ID and subscription ID, the plan and billing interval you chose, subscription status, and any scheduled cancellation date. Stripe also sends us the raw event payloads behind those updates, which can include the billing name, billing address, card brand, and last four digits Stripe holds on file. We never receive or store your full card number, expiry date, or security code. |
| Our email provider | Bounce and complaint notifications, which we use to stop sending to an address that is failing or that reported us as spam. |
What we never collect
- Passwords. Sign-in is handled entirely by Google or Apple; we never see or store a password.
- Card numbers, expiry dates, or CVC codes. Those go directly to Stripe and never touch our servers.
- Precise or GPS location. Country-level only.
- Browser user-agent strings. We do not persist them.
- Special category data — health, biometrics, race, religion, political opinions, sexual orientation, or trade union membership. Please do not put any of it in a keyword, tag, or feedback comment.
- Government identifiers such as passport, national insurance, or social security numbers.
3. How we use your information, and our legal basis
Under the GDPR we must have a lawful basis for every use of your personal data. The table below pairs each purpose with the basis we rely on. "Contract" means Article 6(1)(b) — processing necessary to deliver the service you signed up for. "Legitimate interests" means Article 6(1)(f), where we have balanced our interest against your rights and recorded the outcome. "Consent" means Article 6(1)(a), which you can withdraw at any time. "Legal obligation" means Article 6(1)(c).
| What we do | Data used | Legal basis |
|---|---|---|
| Create your account, sign you in, and keep your session alive | Email, name, provider account ID, session tokens | Contract |
| Run scans, generate verdicts and recommendations, and show your history | Keyword, marketplace, selling model, scan results | Contract |
| Maintain your watchlist, re-scan saved keywords, and raise alerts when a verdict or score moves | Watchlist entries, score snapshots, alert records | Contract |
| Meter and enforce your monthly quota and plan limits | Usage counters, plan, quota reset date | Contract |
| Take payment, manage your subscription, and handle upgrades, downgrades, and cancellations | Email, Stripe customer and subscription IDs, plan, billing events | Contract |
| Send service emails you cannot opt out of: billing confirmations, payment failures, quota warnings and resets, and security notices | Email, name, plan and quota figures | Contract |
| Send lifecycle and marketing email: onboarding sequences, product announcements, weekly digests, watchlist digests, and re-engagement nudges | Email, name, keywords and verdicts referenced in the digest | Consent where required by local law; otherwise legitimate interests in marketing our own service to existing customers. Every category has its own opt-out toggle and every message carries an unsubscribe link. |
| Email people who gave us their address without opening an account | Email, capture source | Consent |
| Prevent abuse: rate limiting, bot challenges, quota-evasion checks, and suspending accounts that break our terms | IP address, user ID, request counts, anti-bot token | Legitimate interests in keeping the service available and affordable for everyone |
| Preselect the right marketplace for you | Country derived from IP or browser language | Legitimate interests in a usable default; you can change the marketplace at any time |
| Improve scoring accuracy and product design using aggregate patterns across scans | Aggregated and de-identified scan and usage data | Legitimate interests in improving a service you pay for |
| Measure how the site is used with Google Analytics and Google Tag Manager | Pages viewed, referrer, coarse device and browser data, a pseudonymous analytics identifier | Consent — analytics storage stays off until you accept the cookie banner |
| Keep security audit records of administrative access to production systems | Administrator email, action taken, target record, IP address | Legitimate interests in securing the service, and legal obligation to protect personal data under GDPR Article 32 |
| Keep financial and tax records | Billing events, invoices, subscription history | Legal obligation |
| Answer support requests and handle privacy rights requests | Email, account record, whatever you send us | Contract, and legal obligation for rights requests |
| Establish, exercise, or defend legal claims, and respond to lawful requests from authorities | Whatever is strictly relevant | Legitimate interests, and legal obligation where a valid order applies |
If you want more detail on any legitimate-interests assessment above, email support@sellradar.ai and we will summarise it for you. You can object to processing based on legitimate interests — see section 10.
4. Cookies and similar technologies
A cookie is a small file a site stores in your browser. We also use local storage and session storage, which work similarly but are never sent to our servers — they exist only to remember your preferences on your own device. We use no advertising cookies, no tracking pixels, and no cross-site or cross-context trackers.
Strictly necessary — always on
These make sign-in and security work. The service cannot function without them, so they do not require consent, and there is no way to switch them off while staying signed in.
| Name | What it does | Lifetime |
|---|---|---|
authjs.session-token | Holds your signed-in browser session. Issued as __Secure-authjs.session-token over HTTPS. | 30 days, rolling |
session-token | Authenticates your browser to the SellRadar API. HttpOnly, Secure, SameSite=Lax. | 7 days |
authjs.csrf-token | Blocks cross-site request forgery on sign-in. | Browser session |
authjs.callback-url | Remembers where to send you back to after sign-in. | Browser session |
authjs.pkce.code_verifier, authjs.state, authjs.nonce | One-time values that secure the OAuth handshake with Google or Apple. | Minutes — cleared once sign-in completes |
Functional — on your device only
These are browser storage keys, not cookies. They stay on your device, are never transmitted to us, and clearing your browser data removes them.
| Key | What it remembers |
|---|---|
cookie-consent | Whether you accepted or declined analytics. |
sr-theme | Your light or dark appearance choice. |
sr-sidebar-collapsed | Whether the app sidebar is collapsed. |
sr-marketplace | The marketplace you last scanned. |
sr-notifications-v1 | Which notifications you have already seen. |
sr-toast-pref-v1 | Your in-app notification style preference. |
sr-upgrade-banner-dismissed, sr-annual-upgrade-banner-dismissed | That you dismissed an upgrade banner, so we stop showing it. |
userId | Your account ID, so the app can restore state after a reload. |
sr-active-batch, sr:pending-keyword | A batch or keyword in progress, so a refresh does not lose your work. Cleared when you close the tab. |
Analytics and tag management
We use Google Tag Manager to load our measurement tags, and Google Analytics 4 — loaded through that container — to understand which pages people use and where they get stuck. We run both in Google Consent Mode v2 with ad_storage, ad_user_data, and ad_personalization permanently set to denied — so this data is never used for advertising, remarketing, or audience building, whatever you choose.
Consent works by region, as Google Consent Mode allows. If you are in the EEA, the UK, or Switzerland, no analytics cookie is written and no analytics identifier is stored until you accept — until then Google receives only a cookieless signal. Elsewhere, analytics storage starts on, in line with the opt-out model those jurisdictions apply. Declining switches it off immediately wherever you are, and we never enable advertising or personalisation storage for anyone.
| Name | What it does | Lifetime |
|---|---|---|
_ga, _ga_<id> | Distinguishes one visitor from another so we can count unique visits and sessions. Written once analytics storage is on for you — after you accept in the EEA, the UK and Switzerland; from the first page view elsewhere, unless you decline. | Up to 2 years |
How the banner actually behaves
On your first visit the cookie banner appears after a moment with two choices, Accept and Decline.
Accept turns on analytics storage. Google Analytics then sets the _ga cookies described above.
Decline leaves analytics storage off. In that state the Analytics script still loads and sends a cookieless page-view ping — it stores nothing on your device and cannot recognise you across visits, but Google does receive your IP address as it would for any request to their servers. If you would rather Google received nothing at all, block googletagmanager.comin your browser or install Google's Analytics opt-out browser add-on.
Changing your mind: click Cookies in the site footer. That clears your stored choice and brings the banner straight back, without a page reload and without losing your place on this page.
Fonts and the anti-bot challenge
Two other services load in your browser and therefore see your IP address and user agent: our typeface provider, which serves the fonts this site is set in, and Cloudflare Turnstile, the challenge that runs when you submit a scan. Turnstile is a strictly necessary security control. Neither is used for advertising or cross-site tracking. Both are listed in section 5.
5. How we share your information
We share personal data only with the vendors listed below, who process it on our instructions and on our behalf under a written data processing agreement. This list is complete — no other company receives your personal data from us.
| Processor | Purpose | Data shared | Location and transfer mechanism |
|---|---|---|---|
| Google LLC (Google Sign-In) | Authenticating you | Your Google account identifier and the profile fields you authorise: email, name, picture | United States. EU-U.S. Data Privacy Framework, backed by Standard Contractual Clauses. |
| Google LLC (Google Analytics 4) | Measuring site usage | Pages viewed, referrer, coarse device and browser data, IP address, and a pseudonymous analytics ID once you accept | United States. EU-U.S. Data Privacy Framework, backed by Standard Contractual Clauses. |
| Google LLC (Google Tag Manager) | Loading and managing our measurement tags, including Google Analytics | IP address and browser user-agent | United States. EU-U.S. Data Privacy Framework, backed by Standard Contractual Clauses. |
| Apple Inc. (Sign in with Apple) | Authenticating you, where the option is enabled | Your Apple account identifier, email or relay address, and name on first sign-in | United States. Standard Contractual Clauses. |
| Stripe, Inc. | Payments, subscriptions, and the billing portal | Your email address, and the card and billing details you enter directly into Stripe's own checkout. We pass Stripe your account ID as metadata. | United States and Ireland. EU-U.S. Data Privacy Framework, backed by Standard Contractual Clauses. |
| Anthropic PBC (Claude API) | Writing the explanation and recommendation on a scan | Your keyword text, the marketplace country, your selling-model setting, and public listing data. No name, email, account ID, or IP address. See section 6. | United States. Standard Contractual Clauses. |
| DataForSEO LLC | Retrieving live marketplace listing, review, seller, and search-volume data | The keyword text or product identifier, plus a marketplace and language code. No user identifiers of any kind. | United States. Standard Contractual Clauses. |
| Cloudflare, Inc. (Turnstile) | Blocking bots and scripted abuse when you submit a scan | Your IP address and the challenge token from your browser | Global edge network. Standard Contractual Clauses. |
| Amazon Web Services, Inc. | Hosting: compute, database, cache, content delivery, and log storage | All service data, at rest and in transit | US East (Northern Virginia), United States. EU-U.S. Data Privacy Framework, backed by Standard Contractual Clauses. |
| Amazon Web Services (Simple Email Service) | Delivering our transactional and lifecycle email | Your email address, your name, and the content of the message — which can include a keyword, a verdict, or your quota figures | US East (Northern Virginia), United States. Same mechanism as above. |
| Indian Type Foundry (Fontshare) | Serving the typefaces this site is set in | Your IP address and user agent, as with any request for a file | Provider content delivery network. Standard Contractual Clauses. |
| ip-api.com | Working out your country to preselect a marketplace, only when our local lookup fails | Your IP address, and nothing else | European Union. No restricted transfer for EEA users. |
Country lookups happen on our own servers first
We license the MaxMind GeoLite2 country database and query a copy of it on our own infrastructure. That lookup sends nothing to MaxMind. Only when the local database has no answer do we fall back to ip-api.com, and only then does your IP address leave our systems for this purpose.
Other circumstances in which we may disclose data
- To professional advisers — lawyers, accountants, auditors — where they need it and are bound by confidentiality.
- To comply with a court order, subpoena, or other legally binding request. Where we are permitted to tell you, we will.
- To protect the rights, safety, or property of SellRadar, our users, or the public — for example when investigating fraud or a security incident.
- To a buyer or successor if SellRadar is acquired, merged, or reorganised. We will notify you before your data becomes subject to a different privacy policy, and this policy continues to apply until then.
What we do not do
- We do not sell your personal information, and we have not sold it in the preceding twelve months.
- We do not share your personal information for cross-context behavioural advertising, as CCPA/CPRA defines sharing.
- We do not use or disclose sensitive personal information for any purpose beyond what CPRA permits without an option to limit.
- We do not disclose your keywords, tags, or scan history to other users, or let anyone use them for their own purposes.
- We do not sell, rent, or trade your email address, and we do not run advertising on the platform.
Keywords you scan are also stored in a shared cache so that a keyword someone has recently analysed can be served without spending a fresh API call. That cache holds the keyword and the marketplace result only. It is never linked to your account, your email, or your identity, and no other user can see that you were the one who scanned it.
6. AI processing
The written explanation and recommendation on every scan are generated by Claude, a large language model operated by Anthropic PBC. We call Anthropic's API directly from our servers.
Exactly what we send
- The keyword text you typed, truncated to 200 characters and sanitised.
- The marketplace domain, country, and currency you selected.
- Your selling-model setting — for example private label or wholesale — so the recommendation matches how you actually sell.
- The scores our own algorithm computed: verdict, opportunity, competition weakness, viability, and data confidence.
- Public marketplace listing data for the top results: title, price, rating, review count, and badge flags.
- For review analysis, the text of public customer reviews on a product you asked us to look at.
What we never send
- Your name, email address, or profile picture.
- Your account ID or any other identifier that points back to you.
- Your IP address or location.
- Your billing details, plan, or payment history.
- Your scan history, tags, watchlist, or feedback.
Anthropic processes this data as our sub-processor to return a response, and does not use it to train its models. Their commercial terms prohibit training on API inputs and outputs. See Anthropic's privacy policy for how they handle API data on their side.
We also do not train any model of our own on your keywords, tags, or feedback. We use aggregate patterns across scans to calibrate our scoring algorithm, which is statistical work on de-identified data, not model training on your content.
Please do not paste this into a keyword, tag, or feedback box
Keyword and tag fields are sent to a third-party model and stored in your history, so treat them as you would any text you type into a shared tool. Do not include personal details about yourself or anyone else, customer lists, supplier contracts, credentials, API keys, unpublished confidential information, or anything you are under an obligation not to disclose. A keyword should describe a product, not a person.
7. International data transfers
SellRadar is hosted in Amazon Web Services' US East (Northern Virginia) region. If you use the service from the European Economic Area, the United Kingdom, or Switzerland, your personal data is transferred to and stored in the United States.
The United States has not received an adequacy decision covering transfers generally, so we rely on the safeguards below:
- The European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914) with each processor located outside the EEA.
- The UK International Data Transfer Addendum to those clauses for transfers out of the United Kingdom, and the Swiss addendum for transfers out of Switzerland.
- The EU-U.S. Data Privacy Framework and its UK Extension where a processor is certified under it — currently Google, Stripe, and Amazon Web Services. We check certification status before relying on it.
- Supplementary technical measures: TLS on every connection, encryption at rest, least-privilege access controls, and a policy of challenging any government access request we believe to be unlawful.
SellRadar itself is not certified under the Data Privacy Framework, and we make no claim to be. We rely on the Standard Contractual Clauses as our own transfer mechanism. You can ask us for a copy of the clauses we have in place, with commercial terms redacted, by emailing support@sellradar.ai.
8. How long we keep your data
We keep personal data only as long as we need it for the purpose we collected it for, or as long as the law requires. These are the periods we work to:
| Data | How long we keep it |
|---|---|
| Account record — email, name, picture, provider ID, plan, preferences | For as long as your account is open. Deleted within 30 days of a verified deletion request or of you closing your account. |
| Scans, verdicts, scores, competitor tables, AI explanations, tags | For as long as your account is open, so your history stays available. Deleted with your account. |
| Watchlist entries, score snapshots, and notification alerts | For as long as your account is open. Deleted with your account. |
| Usage events and quota counters | For as long as your account is open, then deleted with it. Aggregated, de-identified counts may be retained for product analytics. |
| Feedback you submit | 24 months from submission, then deleted or de-identified. |
| Email addresses captured without an account | Until you unsubscribe, or 24 months after your last interaction, whichever comes first. If you unsubscribe we keep a minimal suppression record so we do not email you again — ask us and we will erase that too. |
| Billing and subscription records, including Stripe event payloads | 7 years from the transaction, to meet tax and accounting obligations. Retained even if you delete your account. |
| Security audit records of administrative access | 24 months. These include administrator email addresses and IP addresses. |
| IP-based rate-limit counters | 60 seconds to 2 minutes, in memory. Never written to permanent storage. |
| Country lookup results keyed to an IP address | 24 hours for a successful lookup, 1 hour for a failed one. In memory only. |
| Session tokens | API session 7 days; browser session 30 days; single-use email sign-in links 7 days or until used, whichever is sooner. Revoked immediately when you sign out. |
| Cached third-party marketplace data | 24 hours to 30 days depending on the data type. Keyed by keyword or product, never by user. |
| Server logs | 30 days, then automatically deleted. |
| Encrypted database backups | Up to 7 days on a rolling window. Deleted records persist in a backup until it ages out, and are not restored into the live service. |
| Support correspondence | 24 months from the last message in the thread. |
9. Security
We take the measures below to protect personal data. They are technical and organisational measures within the meaning of GDPR Article 32.
In transit
All traffic between your browser and SellRadar runs over HTTPS with TLS, terminated at our content delivery edge. Connections between our application servers and our database and cache require TLS. Session cookies are marked HttpOnly, Secure, and SameSite=Lax.
At rest
Our production database and its backups use provider-managed storage encryption. Service credentials held in the database — payment provider keys, webhook signing secrets, AI and data provider credentials, and administrator two-factor seeds — are additionally encrypted at the column level with authenticated AES-256-GCM, so they are unreadable even to someone holding a database dump. Application secrets live in a managed parameter store, encrypted with provider-managed keys, and are never committed to source control.
Access control
The database and cache sit in a private network segment with no route from the public internet. Access to production is limited to the small number of people who need it. Our internal admin console requires a separate login with time-based two-factor authentication, is rate-limited per IP address, and writes an audit record for every administrative action and every failed login.
Account security
We hold no passwords. Sign-in is delegated to Google or Apple, so your account is protected by whatever two-factor method you have enabled there — which we recommend you turn on. Scan submissions are protected by a bot challenge and per-endpoint rate limits.
Breach response
If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and notify you without undue delay where the risk is high — as GDPR Articles 33 and 34 require.
No service can promise perfect security, and we will not pretend otherwise. We hold no security certification — we are not SOC 2 audited, not ISO 27001 certified, and not HIPAA compliant — and SellRadar is not built for protected health information, payment card data, or any other regulated category. If you believe you have found a vulnerability, please report it to support@sellradar.ai rather than disclosing it publicly, and we will work with you on it.
10. Your privacy rights
If you are in the EEA, the UK, or Switzerland
The GDPR and UK GDPR give you the following rights:
- Access. Get confirmation of whether we process your data, and a copy of it along with the details in this policy.
- Rectification. Have inaccurate data corrected and incomplete data completed. Your name and email come from Google or Apple, so correcting them there and signing in again updates them here.
- Erasure. Have your data deleted where we no longer need it, where you withdraw the consent it rested on, or where you successfully object. We may keep billing records where the law requires it.
- Restriction. Have us pause processing while a dispute about accuracy or our legitimate interests is resolved.
- Portability. Receive the data you gave us, and the scans you generated, in a structured, commonly used, machine-readable format, and have us send it to another controller where technically feasible.
- Objection. Object to processing based on legitimate interests, on grounds relating to your situation. You can object to direct marketing at any time, for any reason, and we will stop immediately.
- Withdraw consent. Withdraw consent at any time — decline analytics via the footer Cookies link, or switch off any email category in settings. Withdrawal does not affect processing already carried out.
- Complain. Lodge a complaint with a supervisory authority. Ours is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon). In the UK that is the Information Commissioner's Office. In the EEA you may also complain to the authority where you live, work, or where the issue arose. We would appreciate the chance to put things right first.
If you are in California
Under the CCPA as amended by the CPRA you have the right to:
- Know. Learn the categories and specific pieces of personal information we have collected, the sources, our purposes, and the categories of third parties we disclose it to. Sections 2, 3, and 5 set all of this out.
- Delete. Ask us to delete the personal information we collected from you, subject to the exceptions the statute allows — such as completing a transaction or complying with a legal obligation.
- Correct. Ask us to correct inaccurate personal information.
- Opt out of sale or sharing.We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. We do not need a "Do Not Sell or Share My Personal Information" link, and we honour Global Privacy Control signals as a matter of course.
- Limit use of sensitive information. We do not collect sensitive personal information as CPRA defines it, and we use nothing for purposes that would trigger a right to limit.
- Non-discrimination. We will never deny you service, charge you a different price, or give you a lower quality of service because you exercised a privacy right. We run no financial incentive programmes.
An authorised agent may submit a request on your behalf with written permission that we can verify. Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and other US states with comprehensive privacy laws have equivalent rights, including — where the state provides it — a right to appeal a decision we make on your request.
How to exercise any of these rights
Email support@sellradar.ai with the subject line Data request, from the email address on your account, and tell us which right you want to exercise. Sending from your account address is normally all the verification we need; if we cannot match it, we may ask for one more piece of information, used only to verify you and then discarded.
Our response times
GDPR and UK GDPR: within one month of receiving your request. We can extend by two further months if the request is complex, and we will tell you within the first month if we do. There is no fee unless a request is manifestly unfounded or excessive.
CCPA/CPRA: we acknowledge within 10 business days and respond within 45 calendar days. We can extend by a further 45 days with notice to you.
What we can and cannot do yet
Access, export, correction, and deletion requests are handled by our team when you email us — self-service buttons for deletion and export are not yet in the product. This does not change your rights or our deadlines, and we are building those controls. In the meantime you can already change your email preferences, unsubscribe from any category, and change your cookie choice yourself, at any time.
11. Children's privacy
SellRadar is a business tool for people selling products online. It is not directed at children, and our Terms of Service require you to be at least 18 to hold an account.
We do not knowingly collect personal data from anyone under 16, and we do not knowingly collect personal information from children under 13 as the US Children's Online Privacy Protection Act defines them. We do not offer child-directed features and we do not build profiles of minors.
If you believe a child has given us personal data, email support@sellradar.ai and we will delete the account and its data promptly, without requiring a formal rights request.
12. Automated decision-making and profiling
SellRadar scores keywords automatically. A scan produces an opportunity score, a competition weakness score, a viability score, a data-confidence rating, and a verdict, all computed by our algorithm and then described in writing by Claude.
Those outputs are advisory market research about a keyword, not decisions about you. They do not produce legal effects concerning you and do not similarly significantly affect you, so they fall outside GDPR Article 22. They do not determine your price, your access to the service, your creditworthiness, or your eligibility for anything. You are free to disagree with a verdict and target the keyword anyway.
To be explicit about the other automated processes in the product: quota enforcement applies the numeric limit of the plan you chose and is a contractual term, not a profiling decision; rate limiting and bot challenges can temporarily slow or block a request on volume and challenge signals, and you can email us to have it reviewed; and account suspension is always a human decision made by a member of our team, never automatic. In every case you can contact support@sellradar.ai to ask for human review, express your point of view, and contest the outcome.
We do not profile you for advertising, we do not score you as an individual, and we do not build behavioural profiles for sale or disclosure.
13. Changes to this policy
We update this policy when the product changes, when we add or remove a processor, or when the law requires it. The "Last updated" date at the top of this page always shows when it last changed.
If a change is material — a new purpose for your data, a new category of data, a new sub-processor receiving personal data, a shorter retention period, or a change to your rights — we will email every account holder at least 14 days before it takes effect and describe what is changing and why. Where a change requires your consent, we will ask for it rather than assume it.
If you disagree with a change, you can close your account before the effective date. Continuing to use SellRadar after that date means the updated policy applies to you.
14. How to contact us
For anything in this policy — questions, rights requests, complaints, or a security report — email support@sellradar.ai. We read everything sent there.
Data protection officer
We are not required to appoint a data protection officer under GDPR Article 37: our core activities do not involve large-scale monitoring of individuals or large-scale processing of special category data. Privacy questions go to support@sellradar.ai and are handled by our team directly.
EU and UK representative
We have not appointed a representative under GDPR Article 27 or UK GDPR Article 27. If we become required to, we will name them in this section and email account holders before the change takes effect. Until then, EEA and UK users should contact us at support@sellradar.ai, and remain free to complain to their own supervisory authority as described in section 10.
If you email us about a privacy matter and do not hear back within five working days, send it again and mark it urgent — it means something went wrong on our side, not that we are ignoring you.