DRAFT — must be reviewed by counsel before going live. This is a templated starting point, not legal advice.
UCP Audit

Privacy Policy

Last updated: 2026-06-04 · Effective: 2026-06-04

This Privacy Policy explains how UCP Audit (“we”, “us”, “our”) collects, uses, and protects information when you use our website at ucp-audit.example.com and the related Shopify app. By using the service you agree to the practices described below.

1. What we collect

We run a tight ship. The information we collect is limited to what is needed to provide the audit tool and, optionally, notify you when the full product launches.

Information you give us

Information collected automatically

We do not collect: full product data, customer data, order data, payment information, device fingerprints, advertising identifiers, or any data outside the above list.

2. Why we collect it

Legal bases under the GDPR: consent (waitlist email) and legitimate interest (rate-limiting to keep the service available).

3. Shopify’s role

Shopify is the platform on which our app runs. We do not store, log, or back up the product data we transform on behalf of merchants. The flow is:

  1. An AI agent (or a merchant auditing their own store) calls our Worker.
  2. The Worker fetches the merchant’s product data from Shopify’s public APIs in real time.
  3. The Worker rewrites the data into the UCP-compliant feed format.
  4. The rewritten feed is returned to the caller. The Worker discards the in-memory representation immediately after the response is sent.

We do not write product data to durable storage, do not replicate it to a database, and do not train models on it.

4. Data retention

5. Your GDPR rights

If you are in the EEA, the UK, or Switzerland, you have the right to:

To exercise any of these rights, email privacy@ucp-feed.example.com. We respond within 30 days.

6. Sub-processors

We use one sub-processor: Cloudflare, Inc.

Cloudflare’s data-processing addendum and standard contractual clauses apply. No other third parties receive your data.

7. Cookies & tracking

The website sets no cookies. We do not use Google Analytics, Meta Pixel, or any third-party tracking script. The audit runs entirely in your browser; the only network calls leaving your device are (a) your browser fetching the merchant’s public /products.json, and (b) your browser submitting the waitlist form (if you choose to).

8. International transfers

Our infrastructure is operated by Cloudflare, which stores data in the regions you select at sign-up. Waitlist email is stored in the EU (Cloudflare’s Frankfurt region). We rely on Cloudflare’s SCCs for any cross-border transfer.

9. Changes to this policy

If we make material changes, we will update the “Last updated” date at the top of this page and, where appropriate, notify active waitlist subscribers by email. The previous version will be archived and available on request.

10. Contact

Email: privacy@ucp-feed.example.com

Postal address: To be supplied before going live — counsel to confirm registered address.