Legal
Privacy Policy
Last updated: August 6, 2026
Draft for review. This is a working template, not legal advice. Have it reviewed by a qualified lawyer before publishing, and fill every [HIGHLIGHTED] field. Requirements differ by jurisdiction — GDPR/UK GDPR if you handle EU or UK data, India's DPDP Act 2023 if you are established in India, CCPA/CPRA if you handle California residents' data.
1. Who we are
MatchLayer is operated by [REGISTERED ENTITY NAME], a company registered in [JURISDICTION] under company number [COMPANY NUMBER], with its registered office at [REGISTERED ADDRESS].
For anything relating to this policy or your personal data, contact us at hello@matchlayer.tech.
We have not appointed a Data Protection Officer or an EU/UK representative. Privacy questions should be sent to hello@matchlayer.tech. If applicable law requires a representative appointment in future, we will update this policy.
2. Scope
This policy covers personal data we handle in two distinct roles, which are worth separating because the obligations differ:
- As controller — data about you and your colleagues when you visit this site, request a sample, or work with us as a client contact.
- As processor — data we handle on behalf of a client under a services agreement, when operating their product graph and recommendation module.
Sections 3 to 9 concern our controller role. Section 10 concerns our processor role.
3. What we collect
| Category | Examples | Source |
|---|---|---|
| Contact and enquiry data | Work email, store URL, store type, approximate SKU count, and any context you type into the sample request form | You, directly |
| Business relationship data | Correspondence, meeting notes, contract and billing details | You, and our own records |
| Technical data | IP address, user agent, approximate country from CDN headers, timestamps, request path, form submission rate-limit data, and standard hosting/CDN logs. The site does not run analytics scripts, advertising pixels, or product-level shopper tracking. | Automatically |
We do not ask for, and ask that you do not send us, special category data (such as health or biometric data) through this site.
4. Why we use it, and our legal basis
| Purpose | Legal basis (GDPR/UK GDPR) |
|---|---|
| Preparing and sending your requested sample | Steps taken at your request prior to entering a contract |
| Replying to your enquiry and discussing our services | Legitimate interests — responding to a business enquiry you initiated |
| Providing and administering our services to clients | Performance of a contract |
| Keeping the site secure and preventing spam submissions | Legitimate interests — protecting our systems |
| Meeting legal, tax and accounting obligations | Legal obligation |
| Marketing newsletters | Not currently sent from this site. If that changes, we will rely on consent or another lawful business-to-business marketing basis available in the relevant jurisdiction. |
5. What we do not do
- We do not sell personal data.
- We do not share your data with other clients, and we do not use one client's catalog, attributes or store signals to improve another client's recommendations.
- We do not require shopper accounts, quizzes or individual customer profiles for the recommendation module to operate.
6. Who we share it with
We share personal data only with service providers who help us run the business, each under a written contract limiting them to our instructions:
- Hostinger — website hosting, CDN, server logs, and the current PHP form endpoint
- Google Workspace — domain email for matchlayer.tech
- No CRM provider is connected to this site at launch
- No analytics provider is connected to this site at launch
- Professional advisers, and authorities where we are legally required to disclose
The active sub-processors for this website are Hostinger for hosting/infrastructure and Google Workspace for email. If the Cloudflare Worker and Resend email handler are enabled, this list should be updated before launch to include Cloudflare and Resend.
7. International transfers
We operate from [COUNTRY] and use providers located in [COUNTRIES]. Where personal data moves out of the UK or EEA, we rely on [Standard Contractual Clauses / UK IDTA / adequacy decision — state which] and take reasonable steps to ensure it stays protected.
8. How long we keep it
| Data | Retention |
|---|---|
| Sample requests that do not become clients | 24 months from last contact, unless we need to keep a shorter or longer record for legal reasons |
| Client records | Duration of the contract, plus 7 years for tax and accounting records |
| Correspondence | 24 months from last contact, unless it forms part of client records or legal records |
9. Your rights
Depending on where you live, you may have the right to access your personal data, correct it, delete it, restrict or object to how we use it, receive it in a portable format, and withdraw consent where consent is the basis we rely on.
To exercise any of these, email hello@matchlayer.tech. We will respond within the period required by applicable law — one month under GDPR and UK GDPR. There is no charge unless a request is manifestly unfounded or excessive.
If you are unhappy with our response you can complain to your supervisory authority: the ICO in the UK, your national data protection authority in the EEA, or the Data Protection Board of India under the DPDP Act.
10. Client data — our role as processor
When we operate a client's product graph and recommendation module, we act on that client's documented instructions under a services agreement and data processing agreement. In that role:
- Each client's product graph is isolated. Catalog attributes, relationships and store signals are not shared between clients.
- The recommendation module operates on product-level and aggregated store-level patterns. It does not require individual shopper profiles.
- Attributes, relationships and shopper-facing reasoning are generated and stored ahead of time. No language model runs on the storefront page.
- Clients may request deletion or return of their data on termination, as set out in their agreement.
If you are a shopper on a store that uses MatchLayer and have questions about your data, contact that store directly — they are the controller of that relationship.
11. Cookies
This site does not set analytics or advertising cookies. We do not use tracking pixels or behavioral advertising tags. The hosting/CDN layer may use strictly necessary technical controls to deliver, secure, cache, or troubleshoot the site. If analytics, advertising, or non-essential cookies are added, we will update this policy and add consent controls where required.
12. Security
We use appropriate technical and organisational measures to protect personal data, including HTTPS/TLS in transit, access-controlled hosting and email accounts, protected lead storage that is not web-readable, server-side validation, spam controls, rate limiting, and restricted access to administrative systems. No system is perfectly secure, but we take this seriously and will notify you and any relevant regulator of a qualifying breach within the timeframes the law requires.
13. Changes
If we change this policy we will update the date at the top. For significant changes affecting how we use your personal data, we will contact you directly where we hold your contact details.