Privacy Policy
Last updated 11 September 2026. Version 2026-09-11.
1. Who is responsible for your data
Klipx Limited is the controller of personal data processed through Commodity.codes. We are registered in England and Wales under company number 17221685, with our registered office at 66 Paul Street, London EC2A 4NA, United Kingdom. For anything to do with your data, email help@commodity.codes.
This policy is written to meet the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR). Where it refers to the EU GDPR, that is because visitors from the European Economic Area have equivalent rights.
2. What we collect
- Account details: your name, email address and a one-way hash of your password (we never store the password itself). If you sign in with Google, we receive your name, email address and Google account identifier from Google. If you enable two-factor authentication, we store the secret needed to verify your codes and hashed backup codes.
- Searches: the product descriptions you type, the answers you give to clarifying questions, the candidate codes shown and the code you were given, with dates and times.
- Feedback: anything you tell us when you rate a search, including the code you think it should have been.
- Purchases: which credit pack you bought, when, the amount and Stripe’s reference for the payment. Card details go directly to Stripe; we never see or store them.
- Technical data: your IP address, browser type and the pages you request. IP addresses are used for security and rate limiting and, for visitors who are not signed in, are stored only as a salted hash so the address itself cannot be recovered.
- Correspondence: emails you send us, and our replies.
Please do not include other people’s personal data in a product description. The Service only needs to know about the goods.
3. Why we use it, and our lawful basis
- To run your account and answer your searches — creating and securing your account, sending verification and password emails, running searches, keeping your history. Basis: performance of our contract with you.
- To generate questions and codes — the description you type and your answers are sent to a third-party AI model provider together with the tariff entries being considered. Your name, email and account details are not sent. Basis: performance of our contract with you.
- To take payment and keep accounts — processing purchases through Stripe and keeping the records the law requires. Basis: performance of our contract; legal obligation for tax and accounting records.
- To keep the Service secure and fair — detecting abuse, limiting request rates, preventing fraud, keeping audit logs of security-relevant actions. Basis: our legitimate interest in running a secure service, which we have balanced against your interests.
- To improve the Service — reviewing feedback and failed searches to find and fix mistakes in how codes are suggested. Basis: our legitimate interest in providing an accurate service. We do not use your data to train AI models, and our providers are contractually prevented from doing so with the data we send.
- To understand how the site is used — Google Analytics, only if you accept optional cookies. Basis: your consent, which you can withdraw at any time.
- To measure our advertising — Google Ads conversion tracking, only if you accept optional cookies. It tells us whether a visitor who arrived from one of our Google adverts went on to run a search or buy credits. Basis: your consent, which you can withdraw at any time.
- To respond to you and to meet legal duties — replying to your emails, handling rights requests, complying with law and lawful requests from authorities. Basis: legitimate interests and legal obligation.
We do not sell personal data, and we do not use it for advertising or profiling.
4. Who we share it with
- Hosting and database: Google Cloud (Firebase App Hosting and Cloud SQL), in the Netherlands (EU region europe-west4).
- AI model providers: the provider whose model generates the clarifying questions and code suggestions receives product descriptions, answers and tariff entries, but not your identity. These providers are currently based in the United States.
- Payments: Stripe, which processes your card and holds the payment record. Stripe’s own privacy notice applies to the data it collects from you at checkout.
- Email delivery: the email service we use to send verification, password and security messages receives your email address and the message content.
- Analytics: Google (Google Analytics 4, via Firebase), only with your consent, receives pseudonymous usage data as described under Cookies below.
- Advertising measurement: Google (Google Ads), only with your consent, receives the page paths you visit and a pseudonymous identifier for your browser so it can match a visit to an advert click.
- Authorities and advisers: where the law requires it, to enforce our terms, or to protect rights, property or safety.
Each provider acts under a written contract that restricts what it may do with the data. We never share your search history with other users.
5. International transfers
Your data is stored in the European Economic Area, which the UK recognises as providing adequate protection. Where a provider processes data in the United States (AI model providers, Stripe and Google may do so), the transfer is protected by the UK Extension to the EU–US Data Privacy Framework where the provider is certified, or otherwise by the UK International Data Transfer Agreement or the Addendum to the EU Standard Contractual Clauses. You can ask us for details of the safeguards that apply.
6. How long we keep it
- Account details: until you ask us to delete your account, then removed within 30 days.
- Search history: until you delete it (you can delete individual searches or everything from your account’s history page) or until your account is deleted.
- Feedback: kept after a search or account is deleted, but with the link to you removed, so that we can keep learning from mistakes without being able to identify who reported them.
- Payment records: six years after the end of the financial year in which the payment was made, as UK tax law requires.
- Security and audit logs: deleted after 12 months.
- Anonymous visitor counters: the salted hashes used for the free search are deleted after 12 months.
- Analytics data: held by Google for up to 14 months from collection.
- Advertising measurement data: the Google Ads cookie expires after 90 days; Google keeps conversion reports under its own retention policy.
7. Your rights
Under the UK GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- correct data that is inaccurate or incomplete;
- erase your data where we no longer need it or you withdraw consent;
- restrict or object to processing based on our legitimate interests;
- receive the data you gave us in a portable, machine-readable form;
- withdraw consent at any time for processing based on it, such as analytics cookies; and
- complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We would be grateful for the chance to resolve your concern first.
To exercise any of these rights, email help@commodity.codes from the address on your account. We will respond within one month, and we may ask for information to confirm your identity.
8. Deleting your data
You can delete any search, or your whole search history, from the history page in your account. To delete your account itself, email help@commodity.codes; we will close it and remove your personal data within 30 days, keeping only what the law requires us to retain (see section 6).
9. Automated decisions
The code suggestions are produced by automated processing, including AI. They are suggestions for you to check, not decisions with legal effect: you decide what to declare, and the Service makes no decision about you as a person. Nothing in the Service profiles you or makes automated decisions that significantly affect you.
10. Cookies
We use two kinds of cookie: strictly necessary ones, and optional ones that are set only if you accept them.
Strictly necessary (no consent needed)
better-auth.session_tokenand related cookies — keep you signed in and protect against forged requests. Deleted when you sign out; otherwise expire after 7 days.cc_anon— lets a visitor who is not signed in run one free candidate search. Expires after 12 months.cc_consent— remembers your cookie choice. Expires after 12 months if you accepted, 6 months if you rejected.
Analytics (only with your consent)
_gaand_ga_*— Google Analytics 4, set through Firebase. They give your browser a random identifier so we can count visits and see which pages lead to a search. IP addresses are truncated by Google before storage. We do not send anything you type; only page paths, counts and sizes. Expire after 2 years.
Advertising measurement (only with your consent)
_gcl_auand, if you arrived from one of our adverts,_gcl_awand_gcl_gs— Google Ads. They record that your visit followed a Google advert so Google can tell us whether the advert led to a search or a purchase. Google may also set its own cookies on google.com and doubleclick.net for the same purpose. We do not use them to show you personalised adverts elsewhere. Expire after 90 days.
The Google tag itself loads on every page in Google’s “consent denied” mode. Until you accept, it sets no cookies and reads none; it sends Google only cookieless signals (the page path, a random number for that page load and your consent state) that Google uses for aggregate conversion modelling and cannot tie to you across visits.
None of the optional cookies are set until you press “Accept optional cookies” on the cookie bar. You can change your choice at any time using Cookie settings in the footer; rejecting stops collection and removes the analytics and advertising cookies from your browser. You can also block or delete cookies in your browser settings, though blocking the strictly necessary ones will stop you signing in.
11. Children
The Service is for people aged 18 and over. We do not knowingly collect data from anyone younger.
12. Security
Data is encrypted in transit and at rest. Passwords are hashed, API keys and other secrets are encrypted in the database, and access to production systems is limited to those who need it and protected by two-factor authentication. No system is perfectly secure; if we become aware of a breach affecting your data we will tell you and the ICO as the law requires.
13. Changes to this policy
We will post any changes here and update the date at the top. If a change materially affects how we use your data we will tell account holders by email or by a notice in the Service first.
See also our Terms and Conditions.