Madewithinter
  • Home
  • Product
  • Pricing
  • Blog
  • About
  • Contact
← Back to Home

Privacy Policy

Last updated: March 1, 2025

1. Introduction

Welcome to Madewithinter. We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how Madewithinter ("we", "us", or "our") collects, uses, discloses, and safeguards your information when you visit our website at madewithinter.com, use our AI-powered e-commerce personalization platform, or engage with any of our related services (collectively, the "Services").

Please read this policy carefully. If you disagree with any terms in this Privacy Policy, please discontinue use of our Services. This policy applies to all information collected through our Services and any related communications, including sales, marketing, and events.

By accessing or using our Services, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy.

2. Data Controller Identity

The data controller responsible for your personal data is:

Madewithinter Ltd
32 Threadneedle Street, Floor 4
London, EC2R 8AY
United Kingdom
Email: legal@madewithinter.com

Our Chief Executive Officer is David Mannheim. For questions relating to data protection, please contact us at the address above or via email.

Where we act as a data processor on behalf of our business customers (merchants and e-commerce operators), those customers are the data controllers for the personal data of their end-users. In such cases, our processing activities are governed by a Data Processing Agreement ("DPA") entered into between us and our customers.

3. Information We Collect

We collect several types of information in connection with the Services we provide. The categories of data we collect include:

3.1 Personal Identification Data

When you register for an account, request a demo, subscribe to a plan, or otherwise interact with us, we may collect:

  • Full name and job title
  • Email address and telephone number
  • Company name, size, and industry
  • Billing address and payment information (processed via our secure payment processor)
  • Login credentials (username and hashed password)
  • Profile settings and preferences

3.2 Behavioral Data

Our platform is specifically designed to collect, analyse, and act upon shopper behavioral data on behalf of our merchant customers. This data includes:

  • Pages viewed, products browsed, and categories explored on merchant storefronts
  • Click streams, hover events, and scroll depth patterns
  • Add-to-cart events, wishlist interactions, and purchase history
  • Search queries and filter selections
  • Session duration, visit frequency, and engagement patterns
  • Abandoned cart and checkout events
  • Cross-device behavioral signals where linked by an authenticated session

3.3 Device and Technical Data

When you or end-users interact with our platform, we automatically collect technical information, including:

  • IP address (which may be used to derive approximate geolocation)
  • Browser type, version, and language settings
  • Operating system and device type (desktop, tablet, mobile)
  • Screen resolution and viewport dimensions
  • Referring URL and exit URL
  • Device identifiers and advertising IDs (where permitted)
  • Time zone and locale settings

3.4 Usage and Platform Data

For customers using our dashboard and APIs, we collect:

  • Feature usage and configuration settings within the platform
  • API call logs, request timestamps, and response codes
  • Error logs and performance diagnostics
  • Integration settings and connected third-party service details
  • Support tickets, chat logs, and correspondence history

3.5 Communications Data

If you contact us by email, phone, or through forms on our website, we may retain a record of that correspondence, including your contact details and the content of your message.

4. How We Collect Your Information

4.1 SDK and JavaScript Tag

Our primary data collection mechanism for behavioral analytics is a lightweight JavaScript SDK ("inter.js") that merchant customers embed on their e-commerce storefronts. This SDK observes shopper interactions in real time and transmits event data to our processing infrastructure. Data is transmitted over encrypted HTTPS connections.

4.2 Cookies and Tracking Technologies

We and our partners use cookies, pixel tags, web beacons, and similar technologies to collect information about your browsing activity. Please see our Cookie Policy for detailed information about the specific cookies we use, their purposes, and how to manage your preferences.

4.3 Account Registration and Forms

We collect information when you complete registration forms, subscription sign-ups, contact forms, demo request forms, and similar web forms on our site.

4.4 Integrations and Third-Party Sources

When customers connect our platform to third-party services (such as Shopify, Magento, WooCommerce, or Google Analytics), we may receive data from those platforms pursuant to the relevant integration permissions. We may also receive business contact data from third-party lead generation services and publicly available sources.

4.5 Automated Technologies

Our servers automatically record log data when you use our Services. This server-side logging occurs as a standard part of delivering the Service and cannot be disabled without affecting functionality.

5. Legal Basis for Processing

We process personal data only where we have a valid legal basis to do so under applicable data protection law, including the UK GDPR and EU GDPR. The legal bases we rely upon include:

5.1 Contract Performance

Processing is necessary to perform our contract with you, including to operate your account, deliver the Services you have subscribed to, process payments, and provide customer support.

5.2 Legitimate Interests

We process certain data based on our legitimate interests or those of third parties, provided those interests are not overridden by your data protection rights. Our legitimate interests include:

  • Improving and developing our platform, algorithms, and AI personalization models
  • Preventing fraud, abuse, and security threats
  • Marketing our services to existing customers and qualified prospects
  • Conducting analytics to understand how our Services are used
  • Maintaining the security and integrity of our infrastructure

5.3 Consent

Where required by law, we obtain your explicit consent before processing your data for specific purposes, such as placing non-essential cookies, sending marketing emails to new contacts, or processing sensitive personal data. You may withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

5.4 Legal Obligation

We may process personal data where necessary to comply with a legal obligation, such as tax recordkeeping requirements, responding to lawful requests from public authorities, or complying with applicable financial regulations.

5.5 Vital Interests

In rare circumstances, we may process data to protect the vital interests of you or another person, such as in emergency safety situations.

6. How We Use Your Information

6.1 Service Delivery

We use your information to provide, operate, and maintain the Madewithinter platform, including account management, subscription billing, API access, and technical support.

6.2 Personalization Engine

Behavioral and technical data collected through our SDK is used to power real-time product recommendations, dynamic content rendering, and predictive merchandising on merchant storefronts. Our AI models process this data to identify patterns, preferences, and intent signals at the individual and cohort level.

6.3 Analytics and Reporting

We use aggregated and anonymized data to generate performance dashboards, conversion reports, and A/B testing results for our merchant customers. We also conduct internal analytics to measure platform performance and identify areas for improvement.

6.4 Platform Improvement and AI Training

We may use de-identified behavioral data to train, validate, and improve our machine learning models. Where such training uses data derived from merchant customers' end-users, we do so only in accordance with our DPA and applicable data protection obligations.

6.5 Communications and Marketing

We use your contact information to send transactional communications (account confirmations, invoices, password resets), product updates, security notices, and, where you have opted in or where we have a legitimate interest, marketing communications about our Services.

6.6 Security and Fraud Prevention

We monitor usage of our platform to detect, prevent, and respond to fraudulent activity, abuse of our terms, security vulnerabilities, and other threats to the integrity of our Services.

6.7 Legal Compliance

We use your data to comply with applicable laws, regulations, and legal processes, including responding to court orders, regulatory inquiries, and law enforcement requests.

7. Data Sharing and Disclosure

7.1 Service Providers and Sub-Processors

We share data with carefully selected third-party service providers who assist us in operating our business and delivering our Services. These include cloud infrastructure providers, payment processors, customer relationship management platforms, email delivery services, and analytics tools. All sub-processors are bound by contractual data protection obligations and are permitted to use your data only to the extent necessary to perform services on our behalf.

7.2 Business Customers

When we act as a data processor for merchant customers, we share processed analytics, recommendation outputs, and event data with those customers through our platform dashboard and API. Such sharing is governed by the DPA and the merchant's own privacy policy with respect to their end-users.

7.3 Business Transfers

In the event of a merger, acquisition, reorganisation, sale of assets, or similar corporate transaction, personal data held by us may be transferred as part of that transaction. We will notify affected individuals in advance of any such transfer and ensure that the acquiring entity is bound by appropriate data protection obligations.

7.4 Legal Requirements and Safety

We may disclose your information if required to do so by law or in the good-faith belief that such action is necessary to: (a) comply with a legal obligation or judicial process; (b) protect and defend the rights or property of Madewithinter; (c) prevent or investigate possible wrongdoing in connection with the Service; or (d) protect the personal safety of users of the Service or the public.

7.5 Aggregated and Anonymised Data

We may share aggregated, anonymised, or de-identified data with third parties for industry research, benchmarking, and business development purposes. Such data cannot reasonably be used to identify any individual.

8. International Data Transfers

Madewithinter is headquartered in the United Kingdom. However, some of our service providers and sub-processors are located in countries outside the UK and European Economic Area ("EEA"), including the United States. Where we transfer personal data to countries that have not been found to provide an adequate level of data protection, we implement appropriate safeguards, including:

  • Standard Contractual Clauses (SCCs): We rely on the International Data Transfer Agreements (IDTAs) approved by the UK Information Commissioner's Office, and/or the Standard Contractual Clauses approved by the European Commission, as applicable.
  • Supplementary Measures: Where required by our transfer impact assessments, we implement additional technical and organisational safeguards, such as encryption at rest and in transit and data minimisation.
  • Adequacy Decisions: Where a transfer is to a country covered by an adequacy decision (such as the UK-US Data Bridge for qualifying US organisations), we may rely on that decision.

You may request a copy of the transfer mechanisms we have in place by contacting us at legal@madewithinter.com.

9. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. Our retention periods by data category are as follows:

Data Category Retention Period Basis
Account and registration data Duration of contract + 3 years Contract performance, legal obligation
Billing and financial records 7 years from transaction date Legal obligation (UK tax law)
Behavioral event data (end-user) 24 months from collection (default) Legitimate interest; configurable per merchant DPA
Marketing preferences and consent records Until withdrawal of consent + 1 year Consent; legal obligation
Support and correspondence records 3 years from last interaction Legitimate interest
Security and access logs 12 months Legitimate interest
Anonymised/aggregated analytics Indefinite (no personal data) No personal data; not subject to GDPR

When data is no longer required, we securely delete or anonymise it in accordance with our data disposal procedures.

10. Your Rights Under Data Protection Law

Depending on your location and applicable law, you may have the following rights with respect to your personal data:

10.1 Right of Access (Article 15 UK/EU GDPR)

You have the right to request a copy of the personal data we hold about you, along with information about how it is processed. We will respond to access requests within one calendar month of receipt.

10.2 Right to Rectification (Article 16 UK/EU GDPR)

You have the right to request correction of any inaccurate or incomplete personal data we hold about you.

10.3 Right to Erasure (Article 17 UK/EU GDPR — "Right to be Forgotten")

You have the right to request deletion of your personal data where: it is no longer necessary for the purposes for which it was collected; you withdraw consent and there is no other legal basis; you object and there is no overriding legitimate interest; the data has been unlawfully processed; or deletion is required by law. This right is subject to certain exceptions, including where processing is necessary for legal claims or compliance.

10.4 Right to Data Portability (Article 20 UK/EU GDPR)

Where processing is based on consent or contract performance and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format, and to request that we transmit that data to another controller where technically feasible.

10.5 Right to Object (Article 21 UK/EU GDPR)

You have the right to object to processing of your personal data where we rely on legitimate interests as the legal basis. You also have an unconditional right to object to processing for direct marketing purposes.

10.6 Right to Restriction of Processing (Article 18 UK/EU GDPR)

You have the right to request that we restrict processing of your personal data in certain circumstances, such as while we verify the accuracy of disputed data or assess an objection you have raised.

10.7 Rights Related to Automated Decision-Making (Article 22 UK/EU GDPR)

You have the right not to be subject to decisions based solely on automated processing — including profiling — that produce legal or similarly significant effects. Where we engage in automated decision-making, you have the right to request human review, to express your point of view, and to contest the decision.

10.8 California Privacy Rights (CCPA/CPRA)

California residents have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including the right to know what personal information is collected, the right to delete personal information, the right to opt out of the sale or sharing of personal information, the right to correct inaccurate personal information, the right to limit use and disclosure of sensitive personal information, and the right to non-discrimination for exercising privacy rights. We do not sell personal information as defined under the CCPA. To exercise CCPA rights, please use the contact methods below.

11. How to Exercise Your Rights

To exercise any of the rights described above, please contact our data protection team using one of the following methods:

  • Email: legal@madewithinter.com
  • Post: Madewithinter Ltd, 32 Threadneedle Street, Floor 4, London, EC2R 8AY, United Kingdom

We will acknowledge your request within 5 business days and respond substantively within one calendar month. In complex cases or where we receive a high volume of requests, we may extend this period by a further two months, in which case we will notify you of the extension and the reasons for it.

We may need to verify your identity before processing your request. We will not charge a fee for reasonable requests, but reserve the right to charge an administrative fee for manifestly unfounded or excessive requests.

If you are not satisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority. In the United Kingdom, this is the Information Commissioner's Office (ICO), which can be reached at ico.org.uk. If you are in the EU, you may contact your local data protection authority.

12. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience on our platform and website. Cookies are small text files placed on your device that allow us to recognise your browser and capture certain information.

We use the following categories of cookies:

  • Strictly Necessary Cookies: Essential for the operation of our website and platform
  • Functional Cookies: Enable enhanced features and personalisation
  • Analytics Cookies: Help us understand how visitors use our Services
  • Marketing Cookies: Used to deliver relevant advertising

For full details of the cookies we use, including their names, purposes, durations, and instructions for managing your cookie preferences, please refer to our Cookie Policy.

13. Children's Privacy

Our Services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children under 16. If you are a parent or guardian and believe that your child has provided us with personal data without your consent, please contact us immediately at legal@madewithinter.com. Upon receiving such notification, we will take prompt steps to verify the information and, if confirmed, delete any such data from our records.

Our merchant customers are responsible for ensuring that their use of our platform complies with applicable laws regarding children's privacy, including COPPA (in the United States) and equivalent legislation in other jurisdictions. Where a merchant's storefront is directed to children, they must notify us and obtain appropriate consents before deploying our SDK.

14. Security Measures

We take the security of your personal data seriously and implement a range of technical and organisational measures designed to protect your information against unauthorised access, accidental loss, destruction, or disclosure. Our security measures include:

  • Encryption: All data in transit is protected using TLS 1.2 or higher encryption. All data at rest is encrypted using AES-256.
  • Access Controls: Access to personal data is restricted on a need-to-know basis. We enforce multi-factor authentication for all internal systems containing personal data.
  • Penetration Testing: We conduct regular penetration testing and vulnerability assessments of our infrastructure and applications.
  • Security Monitoring: Our systems are monitored continuously for suspicious activity, intrusion attempts, and anomalous behaviour.
  • Incident Response: We maintain a documented incident response plan. In the event of a personal data breach, we will notify the ICO within 72 hours where required, and notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
  • Data Minimisation: We collect only the data necessary for the stated purposes and avoid storing sensitive data in plain text.
  • Vendor Management: All sub-processors undergo security assessments before engagement and are contractually required to maintain appropriate security standards.
  • Employee Training: All employees with access to personal data receive regular data protection and security awareness training.

Notwithstanding these measures, no method of transmission over the internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security.

15. Third-Party Links

Our website and platform may contain links to third-party websites, integrations, or services that are not operated by us. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party sites or services. We encourage you to review the privacy policies of every site you visit. This Privacy Policy does not apply to any third-party website or service.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will update the "Last updated" date at the top of this page. For material changes, we will provide more prominent notice — such as an email notification to registered users or a banner on our website — at least 14 days before the change takes effect. We encourage you to review this policy periodically.

Your continued use of our Services after any changes to this Privacy Policy constitutes your acceptance of those changes, to the extent permitted by applicable law.

17. Contact Information

If you have questions, concerns, or complaints about this Privacy Policy or our data processing practices, please contact us:

Madewithinter Ltd — Data Protection Enquiries
32 Threadneedle Street, Floor 4
London, EC2R 8AY
United Kingdom
Email: legal@madewithinter.com

We aim to resolve all privacy-related queries promptly and fairly. If you remain dissatisfied after contacting us, you have the right to escalate your complaint to the Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint or by calling 0303 123 1113.

Madewithinter

AI-powered e-commerce personalization platform. Real-time behavioral data, predictive analytics, and dynamic recommendations.

Platform

  • Product
  • Pricing
  • About
  • Team
  • Blog
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy

© 2025 Madewithinter. All rights reserved.

We use cookies to improve your experience. Learn more