Polyntor

Privacy Policy

Last updated September 5, 2026

This page says what information the service keeps about you and your stores, what it is used for, who else touches it, and how you get it out or delete it.

Polyntor”, “we” and “us” mean the service at app.polyntor.com. “You” means the person or business with an account.

What we collect

Your account. Your email address and, if you set one, a password — stored as a hash, never as the password itself. A name, company and role if you enter them, and a timezone if you choose one.

Google sign-in. If you continue with Google, Google gives us your Google account id, your email address, whether Google has confirmed it, and your name. We keep the id to recognise you next time and the email and name for the account. We do not receive your Google password and cannot see anything else in your Google account.

Your stores. The store addresses you add, the pages the scanner fetches from them, screenshots of those pages, and the findings, scores and action plans the scan produces.

Your product feeds. Feed files you upload, or the address of a feed you connect and the copy we fetch from it before each scan — product titles, prices, links, images and the other fields in it — and the issues found in them.

Usage and billing. Your plan, when it renews, how many scans you have used and bought, and a record of each scan and its charge.

Security. The IP address, the country derived from it and the browser identifier of each sign-in, sign-up and password change, kept as a log you and we can read if something looks wrong.

Settings. Which alert emails you want, and which is the last thing you did on a page (a chosen tab, a theme) — the last of these stays in your browser only.

What it is used for

  • Running the service: scanning your stores and feeds, showing you the results, sending the alerts you turned on, and keeping your session signed in.
  • Keeping accounts safe: limiting sign-in attempts, spotting a sign-in from somewhere new, and letting you sign every device out.
  • Billing: counting scans against your plan and the packs you bought.
  • Support: answering you when you write to us.

We do not sell your information, use it for advertising, or build profiles of you for anyone else. We do not read your store pages or feeds for any purpose other than the scan you asked for.

Legal bases

Where a law asks us to name one: we process your account, your stores and your feeds because that is the contract you entered by creating an account and asking for scans. We keep the sign-in log and rate limits out of a legitimate interest in keeping accounts safe. Alert emails are sent because you turned them on, and you can turn them off in Settings at any time. We do not process anything that needs your consent beyond that, and we do not make automated decisions with legal effect on you.

AI analysis

Part of each scan sends text from your store pages — and, on some plans, a sample of product images from your feed — to Anthropic's Claude API, which reads it against Google's merchant policies and returns an assessment. This happens under Anthropic's commercial API terms, which do not use the content to train their models. Nothing about you as a person is sent: no email, no name, no account id.

Who else handles it

These companies process data on our behalf, only as far as running the service needs:

  • Neon — the database, hosted in the EU (Frankfurt).
  • DigitalOcean — the servers that run scans, in the EU (Frankfurt).
  • Vercel — serves the web app.
  • Cloudflare — DNS and the proxy in front of the servers.
  • Google — sign-in with Google, when you use it.
  • Anthropic — the AI analysis described above.
  • Resend — delivers the emails we send you.

The scanner also visits your store the way a browser would, so your store's own hosting sees requests from our servers.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Where it is stored and moved

The database and the scanning servers are in the European Union. Some of the companies above operate from the United States or route traffic through it — Vercel, Cloudflare, Google and Anthropic — so pieces of your data cross borders when the service is used. Each of them is bound by a data processing agreement and, for transfers out of the EU and UK, by the standard contractual clauses those regions require.

If something goes wrong

If we learn that your data was accessed by someone who should not have had it, we will tell you by email without undue delay, say what was involved, and say what we did about it — and notify the authorities where the law requires it.

Cookies

One cookie keeps you signed in. A second, short-lived one exists only during a Google sign-in, to make sure the answer that comes back from Google is for the request that went out. Your theme choice is kept in the browser's local storage. There are no advertising or analytics cookies.

How long we keep it

As long as your account exists. Scan results and feed copies stay so you can compare runs over time. When you delete your account, everything it owns — stores, scans, screenshots, feeds, the sign-in log — is deleted in the same step, and it is not recoverable. Backups of the database are rotated out on the hosting provider's schedule.

Your choices

  • See and change your profile, timezone and alert emails in Settings.
  • Export everything the account holds as one JSON file, from Settings → Data & account.
  • Delete the account from the same place. It asks for your password, or for a fresh Google sign-in if the account has none.
  • Sign out everywhere from Settings → Password & 2FA if a device is lost.

If you are in a place with a data protection law — the EU, the UK, Ukraine, California and others — the rights it gives you (access, correction, deletion, portability, objection) are met by the controls above, and anything they do not cover you can ask for by email.

Children

The service is for businesses and is not directed at anyone under 16. We do not knowingly keep an account for a child.

Changes

When this page changes, the date at the top changes with it. A change that affects what we collect or who handles it is announced in the app before it takes effect.

Contact

Questions about this document go to support@polyntor.com.