Privacy Policy

What we hold on you,
and why.

Exactly what information Feed API collects, why we need it, who we share it with, and what rights you have over it.

VERSION 1.0/Last updated 28 AUGUST 2026
Contents

What this covers

Feed API is an online wholesale marketplace connecting suppliers and resellers. This policy applies to all three groups of platform users: suppliers, resellers, and website visitors before registration.

It does not cover a reseller's end customers. Feed API does not interact with end consumers directly. Each reseller is responsible for their own customers' privacy on their own sales channel.

Who's responsible for this data

Registered company name

Cognivise Limited

Companies House number

16461721

Country of incorporation

England and Wales

Registered office

Flat 65 Sherborne Court, 180-186 Cromwell Road, London SW5 0ST

Cognivise Limited is the Data Controller for information collected through Feed API, under UK GDPR and the Data Protection Act 2018.

How we respond to requests

We respond to privacy requests within the statutory 30-day limit under UK GDPR. If a complex request needs more time, we will tell you within that period.

What we collect, and why

CATEGORY

EXAMPLES

WHY WE NEED IT

Identity & contact

Full name, email, phone number

Account login, order and account notifications

Business identity

Company name, trading name, address, registration number, VAT number, business type

Verifying and approving accounts, tax obligations

Listing content

Product descriptions, images, category, pricing

Displaying the product catalogue

Transaction history

Orders, amounts, payment status, returns

Fulfilling the agreement between both parties

Support

Ticket message text, file attachments

Responding to your support requests

Technical integration

API key (hashed), webhook URL, last-used IP

Letting resellers integrate with their own systems

Technical logs

IP address, login timestamps, system errors

Security and troubleshooting

Payments

All payment processing and money movement is handled by Stripe, a PCI-DSS certified processor. We never receive or store raw card details, meaning the full card number or CVV, on our own servers.

What we do store is limited to identifiers and statuses: a Stripe Connect account ID for suppliers, a Stripe customer ID and default payment method for resellers, and the status of each transaction. succeeded, failed, or refunded.

Who we share information with

We do not sell your data. We share it only with the processors below, each essential to running the platform:

SERVICE

ROLE

Stripe

Payment processing, KYC verification, fund transfers

Supabase

Database hosting and account authentication

Cloudflare R2

File storage for product images and support attachments

Resend

Transactional email for verification codes and order notices

We may also disclose information where legally required, such as under a court order.

How long we keep data

These figures come from the automated cleanup rules actually running in our system, not estimates:

  • Active account data: for as long as your account is open.
  • Financial and order records: minimum 6 years, as UK tax law requires.
  • Successful webhook delivery logs: 30 days.
  • Failed webhook delivery logs: 90 days, kept longer for troubleshooting.
  • Unused registration verification codes: deleted automatically once expired.
  • Bulk import files: 7 days after processing completes.

Security

  • All data is encrypted in transit over HTTPS and TLS.
  • Database access is scoped to each user's own identity using Row Level Security, so suppliers and resellers can only reach data tied to their own account.
  • Sensitive financial operations, such as refunds and payment status changes, sit behind additional controls a regular user account cannot reach.

If something goes wrong

No system is completely secure. If a security incident affecting your personal data occurs, we will notify you and, where required, the ICO, as the law requires.

Your rights

  • Access: request a copy of the information we hold about you.
  • Correction: ask us to fix inaccurate information.
  • Erasure: request deletion, subject to the legal retention requirements in section 07.
  • Portability: receive your data in a machine-readable format.
  • Objection: object to processing based on legitimate interest.

Contact us via section 14 to exercise any of these.

International data transfers

Some of our processors, including Stripe, Supabase and Cloudflare, may process data on servers outside the UK. Where that happens we rely on valid legal transfer mechanisms, such as Standard Contractual Clauses.

Cookies

Three cookies, and this is all of them. None of them profile you, follow you between sites, or feed an advertising network.

COOKIE

WHAT IT DOES

HOW LONG IT LASTS

sb-… (authentication)

Keeps you signed in as you move between pages. Set when you log in, cleared when you sign out.

Your session

panel-sidebar-collapsed

Remembers whether you collapsed the sidebar in your dashboard. Only ever set because you used that control.

1 year

We do not use analytics, advertising, heat-mapping or any other third-party tracking cookies, and there are no third-party cookies on the site at all.

That is also why you have not been shown a cookie banner. Consent is required for cookies that are not necessary for a service you asked for — tracking and advertising cookies above all — and we do not set any. If we ever add one, we will ask you before it is set rather than after, and this section will be updated to match.

Children's privacy

Feed API is a B2B platform built for businesses, not individuals under 18. We do not knowingly collect information from children.

Changes to this policy

This is version 1.0, and it will evolve as the platform grows. We will notify you of material changes by email or in-app notice. The “last updated” date at the top of this page always reflects the current version.

Contact and complaints

If you have questions about how we use your information, or want to exercise any right from section 09, please reach out:

Email

[PRIVACY_EMAIL]

Postal address

Flat 65 Sherborne Court, 180-186 Cromwell Road, London SW5 0ST

If you believe your concern has not been addressed properly, you can complain directly to the UK's data protection regulator:

Authority

Information Commissioner's Office

Website

ico.org.uk

Phone

0303 123 1113