Privacy policy
Last updated: 13 August 2026
Who we are
SKULayer is operated by SKULayer Ltd, a company registered in England and Wales (company number 17333273). You can reach us at hello@skulayer.com. This policy explains what personal data we collect, why, and the rights you have over it under the UK GDPR and the Data Protection Act 2018.
The two hats we wear
For your account, billing, and our website analytics, SKULayer Ltd is the data controller. For the product feed data you connect to the service, we act as a data processor: we process that data on your instructions, to run audits, transformations, and channel delivery on your behalf. If your feeds contain personal data, you are the controller of it.
What we collect and why
- Account data (name, email address, password stored as a salted hash): to create and secure your account and to send essential service email such as email verification and password resets. Lawful basis: performance of a contract.
- Billing data: payments are handled by Stripe. Card details are entered on Stripe's systems and never touch our servers; we store only the subscription state Stripe reports to us (plan, status, billing period). Lawful basis: performance of a contract.
- Feed data (the product data in feeds you connect): processed on your behalf to provide the service. We do not sell it and we do not use it to train AI models. Lawful basis: your instructions under our contract.
- Usage analytics: Google Analytics 4 and PostHog help us understand how the site and product are used. In the UK and EEA, analytics cookies are set only with your consent (see the cookie policy). Lawful basis: consent.
- Technical logs and error reports: kept to run, secure, and debug the service. Lawful basis: legitimate interests.
Who processes data for us
- Cloudflare: hosting, application database, and file storage. Our storage is provisioned in Cloudflare's Western Europe region; content is served from Cloudflare's global network.
- Stripe: payment processing and billing.
- Resend: transactional email (verification and password reset), sent from EU infrastructure (eu-west-1).
- PostHog: product analytics, hosted in the EU.
- Google: Google Analytics 4, consent-gated; and, if you connect Merchant Center, the Google Merchant API as described under Google user data below.
Where a provider processes data outside the UK or EEA, transfers rely on UK adequacy regulations or standard contractual clauses.
Google user data
If you connect a Google Merchant Center account, SKULayer requests
access to the Merchant Center scope
(https://www.googleapis.com/auth/content) through
Google's OAuth consent screen. With it we access two things: the
list of Merchant Center accounts you can manage, so you can pick the
one to connect, and the product statuses and diagnostics Google
reports for that account, so the product can show you what Google
sees, recommend fixes, and confirm when an issue has cleared.
We store the OAuth refresh token encrypted at rest (AES-256-GCM) in our Cloudflare-hosted database, alongside the account id you chose and the issue snapshots we read. We never see your Google password. Google user data is not sold, is not used for advertising, is not used to train AI models, and is never read for any purpose other than operating the features described above.
Disconnecting the account in SKULayer deletes the stored token. You can also revoke SKULayer's access at any time from your Google account's security settings, which invalidates the token on Google's side. Issue snapshots already stored are deleted with your account, per the retention section below.
Sharing, transfer, and disclosure of Google user data
We do not share, transfer, or disclose Google user data to any third party, with three narrow exceptions. First, our infrastructure provider, Cloudflare, Inc., hosts the systems the data lives in (our database and file storage) and processes it only as our processor, under our instructions, to provide that hosting. Second, we will disclose data where the law requires it, for example a valid court order. Third, if SKULayer Ltd is ever party to a merger or acquisition, data may transfer to the successor entity, which remains bound by this policy and by Google's Limited Use requirements. Nobody else: Google user data is never shared with advertisers, data brokers, analytics providers, other customers, or any other third party, and it is never transferred in exchange for payment. Diagnostic error reports sent to our error-monitoring provider may include the technical details of a failed Google API request, such as a status code and Google's error message, but never product data, account lists, or tokens.
How we protect Google user data
All Google user data is protected by specific technical mechanisms. In transit, every connection uses HTTPS (TLS 1.2 or higher), both between your browser and SKULayer and between SKULayer and Google's APIs. At rest, the OAuth refresh token is encrypted with AES-256-GCM before it is stored, and the encryption key is held as a platform secret separate from the database, so a copy of the database alone cannot decrypt it. Access tokens are short-lived and held only in memory. All stored data sits in single-tenant rows keyed to your workspace, and every query in the product is scoped to the requesting workspace, so one customer's Google user data is never readable by another. Access to production systems is restricted to authorized personnel, protected by multi-factor authentication, and not used for routine access to customer data. Disconnecting Merchant Center or deleting your account deletes the stored token and snapshots, as described above.
SKULayer's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How long we keep things
Account and subscription data are kept while your account is active. Compiled feed files are cleaned up automatically: we keep only the most recent versions per feed, and anything incomplete for no more than 14 days. If you delete your account, we delete your account data and stored feed data, keeping only what we must retain for legal or accounting reasons.
Your rights
You can ask for access to your personal data, correction, deletion, restriction, portability, or object to processing, and you can withdraw consent at any time where consent is the basis. Email hello@skulayer.com and we will respond within one month. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).
Changes
If this policy changes in a way that matters, we will say so plainly on this page and update the date at the top.