Privacy Policy

Last updated: 10 August 2026

This policy explains what EMData (“the Service”) does with personal data. The controller is [legal entity name], [registered address], reachable at [contact email].

What we hold

Your account. Your name, email address, a hash of your password (or none at all, if you only ever sign in through a provider), your chosen language, when you registered and when you last signed in.

Company accounts. If you register as a company: the company name, its country, and its VAT and registration numbers where you give them.

Teams. Who belongs to which team and in what role, and the email addresses of people invited but not yet joined.

Security. If you turn on two-factor authentication, its secret and your recovery codes, both encrypted. API tokens are stored hashed, not in a form we can read back. Your active sessions, with the IP address and browser they were started from, so you can review and end them.

Messages you send us. If you use the contact form we keep what you wrote — your name, your email address, the subject and the message — together with our reply, so the conversation stays readable. Alongside it we record how the message reached us: the IP address the request came from, the browser's user-agent string, the page you sent it from, the language your browser asked for, and any forwarding headers the request carried. We keep that to tell one sender from another, to recognise repeat abuse, and to spot messages sent by scripts rather than by people. It is visible only to our administrators.

Files uploaded by administrators. Our administrators can upload a logo for each retailer we track. Those images are stored on our own servers and served publicly to anyone using the Service — they are pictures of shop brands, not of people, and nothing you upload about yourself is stored anywhere: the Service has no profile picture upload, and the picture shown beside your name comes from Gravatar (see below).

We do not ask for payment details, and we do not profile you or make automated decisions about you.

Why we hold it

  • To provide the Service and the account you asked for — performing our contract with you.
  • To keep accounts secure: signing in, verifying your address, two-factor authentication, and the sign-in and session records above — our legitimate interest in protecting the Service and your account.
  • To answer messages you send us, and to keep the contact form usable: the technical details recorded with a message are our legitimate interest in telling senders apart and in refusing automated abuse.
  • To meet legal obligations, such as retaining company and VAT details where accounting rules require it.

Cookies and browser storage

We use no advertising or analytics cookies, and there is no third-party script anywhere in the Service.

What we cannot do without. These are set whatever you choose, because without them the Service does not work or does not do what you just asked it to.

  • Session cookie — keeps you signed in. Essential; the Service cannot work without it.
  • Security token — a cookie that protects forms you submit from being sent by another site on your behalf.
  • Language cookie — set only when you pick a language, so the first page of your next visit is already in it. Encrypted, httpOnly, and kept for a year.

What we ask about. The first time you arrive we ask whether we may remember your preferences on this device: the theme you chose (emdata.theme), whether the menu is a narrow rail (emdata.sidebar), and which menu groups you left open (emdata.nav). They are kept in your browser's local storage, belong to the device rather than the account, and are never sent to us.

If you decline, we stop writing them and delete any we already had, and the Service simply forgets those choices between visits. Your answer itself is kept in the same storage (emdata.consent) — it is the only way to honour it, and to stop asking you every time.

Others who receive data

Gravatar. Wherever the Service shows a profile picture, your browser asks gravatar.com for one using a SHA-256 hash of your email address. Automattic, who run Gravatar, therefore receive that hash and your IP address. We send no name and no plain address, and no image is requested if you never load a page that shows one.

Sign-in providers. If you choose to sign in with a provider such as Google, we receive your name, email address and whether the provider has verified it. We do not receive your password, and we ask for nothing else.

Email delivery. Messages such as address verification, password resets and team invitations are sent through [email provider], who processes the recipient address and the message.

Hosting. The Service and its database run on infrastructure provided by [hosting provider] in [region].

We do not sell personal data.

How long we keep it

Account data is kept while the account exists.

Deleting your account hides it and the teams it owns; both can be restored for [retention period] on request, after which they are removed permanently. Two consequences are deliberate: API tokens are revoked immediately and permanently, and your email address stays reserved so that a new account cannot be attached to the old one's history. Reserving the address means we keep it after deletion — that is the trade-off, and if you would rather it were erased entirely, write to us.

Messages sent through the contact form, and the technical details recorded with them, are kept for [message retention period] after the conversation is closed, and then deleted.

Sessions expire on their own, and you can end them yourself from your profile page.

Your rights

You can ask us to give you a copy of your data, correct it, delete it, or export it, and you can object to processing we base on legitimate interests. Most of it you can do yourself: your profile page lets you change your name and address, change your password, review sessions and delete your account.

Write to [contact email] and we will respond within [response period]. If you are not satisfied you may complain to [supervisory authority].

Security

Passwords are hashed, never stored in a readable form, and checked against known breached-password lists when set. API tokens are stored hashed. Two-factor secrets and recovery codes are encrypted. Traffic is served over HTTPS.

No service can promise perfect security, but if a breach affects your data we will tell you and the relevant authority as the law requires.

Children

The Service is not intended for anyone under 16, and we do not knowingly collect their data.

Changes

We may update this policy. If a change materially affects you we will tell you by email, or in the Service, before it takes effect.

Contact

[legal entity name] [registered address] [contact email]