Skip to content
Get early access

AtomSearch

Privacy & data

Last updated 31 August 2026

Search is built on data, so we would rather be specific about which data, why we hold it, and what we refuse to touch. This notice covers the AtomSearch website, apps, and API.

The short version

We hold your product catalogue and the queries your shoppers type. We do not want your customer records, your order history, or anything to do with payments — none of it improves retrieval, and all of it would increase the damage if we got security wrong. We do not sell data. We do not use one merchant’s catalogue to give a competitor better results.

What we collect

From merchants using the service

Catalogue data. Products, variants, descriptions, attributes, categories, pricing, and stock levels. This is what the engine indexes. It is business data, not personal data.

Search queries. The text shoppers type into your search, plus which results were shown and which were clicked. This is what surfaces the queries that returned nothing, and the vocabulary your shoppers use that your catalogue does not.

Account data. The name, work email, and store URL of the people who administer your account, so we can operate it and talk to you.

Operational logs. API request metadata — timestamps, endpoints, response times, error codes — used for reliability, debugging, and abuse prevention.

From shoppers on your storefront

A pseudonymous session identifier so that a sequence of searches within one visit can be understood as a sequence rather than as unrelated queries. We do not receive names, email addresses, payment details, or account identifiers from your storefront, and we do not build cross-site profiles of individual shoppers.

Search queries are free text, so a shopper can always type something personal into a search box. We treat query text as potentially personal for that reason, and it is covered by the retention and access rules below.

From visitors to this website

Standard web server logs, and anything you volunteer by emailing us. Fonts are served from our own servers rather than a third party, so visiting this site does not send your IP address to a font provider.

What we will not collect

Customer names and contact details. Order and transaction history. Payment card data. Anything in a special category under data protection law — health, biometrics, political or religious views. If our integration ever appears to be receiving any of this, that is a bug; tell us and we will fix it and purge it.

Why we hold it, and on what basis

To deliver the service you have asked for — performance of a contract. To keep it secure, reliable, and free of abuse — our legitimate interests. To improve retrieval quality using aggregate, de-identified patterns — our legitimate interests, balanced against the fact that no individual is identifiable in that aggregate. To meet legal and accounting obligations where they apply.

Where we act on your catalogue and your shoppers’ queries, we are a processor and you are the controller. For our own account and website data, we are the controller.

How long we keep it

Catalogue data: for as long as your account is active, then deleted within 30 days of termination. Query logs with session identifiers: 13 months, after which they are aggregated and the identifiers discarded. Operational logs: 90 days. Account and billing records: as long as required for legal and accounting purposes.

These periods are a commitment, not an aspiration. If you need shorter retention for your own compliance reasons, ask — it is usually possible.

Subprocessors

We use third parties to run the service — cloud infrastructure and hosting, error monitoring, and email delivery. Each is bound by a data processing agreement and may only act on our instructions.

The current list, with each provider’s role and the region their processing takes place in, is available on request and will be published here. We will give notice before adding a subprocessor that processes merchant data, so you have the chance to object.

Where data is processed

Primarily in the EU and the UK. Where data is transferred outside the UK or EEA, we rely on adequacy decisions or standard contractual clauses with appropriate safeguards. Tell us if you need your data pinned to a specific region and we will confirm what is possible.

Security

Encryption in transit and at rest. Access to production data restricted to the engineers who need it, logged, and reviewed. Credentials rotated on a schedule and immediately on any suspicion of exposure. Least-privilege access to your platform — we request read access to catalogue data and nothing more.

If we suffer a breach affecting your data, we will tell you without undue delay, with what we know and what we are doing about it — including while the picture is still incomplete.

Your rights

Under UK and EU data protection law you can ask for access to your personal data, correction of it, deletion of it, restriction of processing, portability, and you can object to processing based on legitimate interests. Email privacy@atomsearch.io and we will respond within one month.

If a shopper on your storefront exercises a right with you and it touches query data we hold, contact us and we will help you fulfil it. You can also complain to the Information Commissioner’s Office in the UK, or your local supervisory authority in the EU.

Cookies

This website uses only what it needs to function. We do not run advertising or cross-site tracking cookies here. The search integration on your storefront uses a session identifier as described above; where consent is required for that in your jurisdiction, obtaining it is your responsibility as the controller, and we will give you whatever technical detail you need to do it properly.

Changes

We will update this notice as the service changes, and the date at the top will always reflect the current version. If a change materially affects how we handle merchant or shopper data, we will tell you rather than quietly editing the page.

Questions, or anything here that does not match what you have observed: privacy@atomsearch.io.