Skip to content
NiftySeeker

Privacy Policy

Last updated 28 July 2026

This policy is a draft pending legal review. It describes accurately what the software does with data. Items marked [to be completed] require a decision from the operator and review by a qualified adviser before this is relied upon.

Who we are

NiftySeeker is operated by [to be completed: registered legal entity and address], the data controller for the personal data described here. You can reach us at privacy@niftyseeker.com.

What we collect

  • Account details — your name, email address, and a hash of your password. We never store your password itself.
  • Workspace content — the products, retailers, offers, watchlists, alert rules, and purchase records you create.
  • Activity records — an append-only audit log of significant actions, including who did them and when. This is a security feature and cannot be edited or deleted from within the application.
  • Technical data — your IP address and browser user agent, in server logs, for security and diagnostics.
  • Analytics — only if you accept analytics cookies. See our cookie policy.

What we do not collect

We do not collect payment card details, we do not buy personal data from third parties, and we do not use your workspace content to train machine-learning models.

Why we process it, and on what basis

  • To provide the service — performance of our contract with you.
  • To keep accounts secure and investigate misuse — our legitimate interests, and in the case of the audit log, our legal obligations.
  • To send price alerts and digests you configured — performance of our contract; you can change or stop these at any time in your notification settings.
  • Analytics — your consent, which you may withdraw at any time.

Who else sees it

  • Other members of your workspace, according to the permissions its administrators grant.
  • Our hosting provider, which stores the data on our behalf: [to be completed: hosting provider and region].
  • Your chosen AI vendor, but only if a workspace administrator connects one, and only product names, brands, model numbers, and listing titles. Members, purchases, and credentials are never sent. This is off by default.
  • Endpoints you configure — if you register a webhook or issue an API token, data goes where you have directed it.
  • Analytics — Google, if you accept analytics cookies.

We do not sell personal data.

How long we keep it

  • Account and workspace data — while your account is open, and [to be completed: retention period] after you close it.
  • Audit records[to be completed: retention period]. These are append-only by design and are retained for security and accountability.
  • Server logs[to be completed: retention period].
  • Database backups — fourteen days, after which they are automatically deleted.

Your rights

Under UK GDPR you have the right to:

  • ask for a copy of your personal data;
  • ask us to correct data that is wrong;
  • ask us to delete your data, where we have no overriding obligation to keep it;
  • object to, or ask us to restrict, some processing;
  • withdraw consent to analytics at any time;
  • complain to the Information Commissioner's Office at ico.org.uk.

You can do the first and the third yourself, without asking us, from Settings → Your data inside the application. For anything else, email privacy@niftyseeker.com and we will respond within one month.

What closing your account actually does

Being precise about this matters more than sounding reassuring.

  • Removed: your account, your membership of every workspace, your roles, your notification settings and notifications, and any API tokens you issued.
  • Kept, but disconnected from you: the append-only audit log. Those entries lose their link to your account, so what remains records that something happened and when — not who did it. They hold no workspace content and are kept for security and accountability.
  • Kept: workspace content. A workspace's products, retailers, and prices are not personal data and do not belong to whichever member leaves. A workspace left with nobody in it is suspended; removing it entirely is a separate request to us.

If you are the only person in a workspace who can manage members, and other people are still in it, we will ask you to give someone else that permission first. Otherwise closing your account would leave your colleagues inside a workspace nobody can administer.

Security

  • All traffic is encrypted in transit over HTTPS.
  • Passwords are hashed; API tokens are stored only as hashes and are unrecoverable.
  • Webhook signing secrets and AI vendor keys are encrypted at rest.
  • Every workspace's data is isolated from every other's, enforced on every query.

To report a vulnerability, email security@niftyseeker.com.

Changes

If we change this policy materially we will say so here and update the date at the top. Continuing to use NiftySeeker after a change means you accept the updated policy.