← Back to site

Legal

Privacy Policy

Last updated: August 6, 2026

Draft for review. This is a working template, not legal advice. Have it reviewed by a qualified lawyer before publishing, and fill every [HIGHLIGHTED] field. Requirements differ by jurisdiction — GDPR/UK GDPR if you handle EU or UK data, India's DPDP Act 2023 if you are established in India, CCPA/CPRA if you handle California residents' data.

1. Who we are

MatchLayer is operated by [REGISTERED ENTITY NAME], a company registered in [JURISDICTION] under company number [COMPANY NUMBER], with its registered office at [REGISTERED ADDRESS].

For anything relating to this policy or your personal data, contact us at hello@matchlayer.tech.

We have not appointed a Data Protection Officer or an EU/UK representative. Privacy questions should be sent to hello@matchlayer.tech. If applicable law requires a representative appointment in future, we will update this policy.

2. Scope

This policy covers personal data we handle in two distinct roles, which are worth separating because the obligations differ:

Sections 3 to 9 concern our controller role. Section 10 concerns our processor role.

3. What we collect

CategoryExamplesSource
Contact and enquiry dataWork email, store URL, store type, approximate SKU count, and any context you type into the sample request formYou, directly
Business relationship dataCorrespondence, meeting notes, contract and billing detailsYou, and our own records
Technical dataIP address, user agent, approximate country from CDN headers, timestamps, request path, form submission rate-limit data, and standard hosting/CDN logs. The site does not run analytics scripts, advertising pixels, or product-level shopper tracking.Automatically

We do not ask for, and ask that you do not send us, special category data (such as health or biometric data) through this site.

4. Why we use it, and our legal basis

PurposeLegal basis (GDPR/UK GDPR)
Preparing and sending your requested sampleSteps taken at your request prior to entering a contract
Replying to your enquiry and discussing our servicesLegitimate interests — responding to a business enquiry you initiated
Providing and administering our services to clientsPerformance of a contract
Keeping the site secure and preventing spam submissionsLegitimate interests — protecting our systems
Meeting legal, tax and accounting obligationsLegal obligation
Marketing newslettersNot currently sent from this site. If that changes, we will rely on consent or another lawful business-to-business marketing basis available in the relevant jurisdiction.

5. What we do not do

6. Who we share it with

We share personal data only with service providers who help us run the business, each under a written contract limiting them to our instructions:

The active sub-processors for this website are Hostinger for hosting/infrastructure and Google Workspace for email. If the Cloudflare Worker and Resend email handler are enabled, this list should be updated before launch to include Cloudflare and Resend.

7. International transfers

We operate from [COUNTRY] and use providers located in [COUNTRIES]. Where personal data moves out of the UK or EEA, we rely on [Standard Contractual Clauses / UK IDTA / adequacy decision — state which] and take reasonable steps to ensure it stays protected.

8. How long we keep it

DataRetention
Sample requests that do not become clients24 months from last contact, unless we need to keep a shorter or longer record for legal reasons
Client recordsDuration of the contract, plus 7 years for tax and accounting records
Correspondence24 months from last contact, unless it forms part of client records or legal records

9. Your rights

Depending on where you live, you may have the right to access your personal data, correct it, delete it, restrict or object to how we use it, receive it in a portable format, and withdraw consent where consent is the basis we rely on.

To exercise any of these, email hello@matchlayer.tech. We will respond within the period required by applicable law — one month under GDPR and UK GDPR. There is no charge unless a request is manifestly unfounded or excessive.

If you are unhappy with our response you can complain to your supervisory authority: the ICO in the UK, your national data protection authority in the EEA, or the Data Protection Board of India under the DPDP Act.

10. Client data — our role as processor

When we operate a client's product graph and recommendation module, we act on that client's documented instructions under a services agreement and data processing agreement. In that role:

If you are a shopper on a store that uses MatchLayer and have questions about your data, contact that store directly — they are the controller of that relationship.

11. Cookies

This site does not set analytics or advertising cookies. We do not use tracking pixels or behavioral advertising tags. The hosting/CDN layer may use strictly necessary technical controls to deliver, secure, cache, or troubleshoot the site. If analytics, advertising, or non-essential cookies are added, we will update this policy and add consent controls where required.

12. Security

We use appropriate technical and organisational measures to protect personal data, including HTTPS/TLS in transit, access-controlled hosting and email accounts, protected lead storage that is not web-readable, server-side validation, spam controls, rate limiting, and restricted access to administrative systems. No system is perfectly secure, but we take this seriously and will notify you and any relevant regulator of a qualifying breach within the timeframes the law requires.

13. Changes

If we change this policy we will update the date at the top. For significant changes affecting how we use your personal data, we will contact you directly where we hold your contact details.