Legal
Privacy Policy
Last updated 2 October 2026
This policy explains what personal data Findlane collects, why, how long we keep it, and your rights. Findlane is a hosted product search service for online stores, operated by Mucho ehf. in Iceland ("Findlane", "we", "us").
Who is responsible
- For accounts and this website, we are the controller: the data of people who create an account, use the dashboard, or visit findlane.dev.
- For our customers' content and their shoppers' searches, the customer (the store) is the controller, and we process that data on the store's behalf, as its processor, under our Terms of Use. If you searched a store that uses Findlane, contact the store about that data.
You can reach us about privacy at privacy@findlane.dev.
What we collect
When you create an account and use the dashboard
- Your name, email address, and password. We store only a secure hash of the password.
- Workspace information: workspace names, members and their roles, invitations you send (including the invitee's email address), and API keys, which we store only as hashes.
- Sign-in sessions: the IP address and browser (user agent) each session signed in from, to keep your account secure.
- Email we send you: confirming your address, resetting your password, invitations, and notices about your workspaces. We don't send marketing email.
When you buy a plan
- Our reseller Polar sells paid plans, as the merchant of record. It collects your payment details, billing name and address, and any tax ID under its own privacy policy. We receive your plan, its billing period and status, and the name and email address you bought with. We never see full card numbers. To bill overage, we send Polar the number of extra searches and records a workspace used.
When a store installs Findlane for Shopify
- From Shopify, about the store: its name, its myshopify.com address and main domain, its currency, whether it's a development store, and its email address. The email becomes the Findlane account that owns the store's workspace, or the workspace is added to an existing account with that email.
- A token to read the store's products, which we store encrypted. The app can only read products: it has no access to the store's customers or orders.
- The store's active products: title, handle, description (up to 1,000 characters), vendor, product type, tags, prices, whether they're in stock, and the address of the main image. They become the store's index, which is customer content as described below.
- Stores that buy a plan in the app pay Shopify, under Shopify's own terms and privacy policy. We receive the subscription's plan, status, and renewal date, and send Shopify the overage charges.
- When a store uninstalls the app, search stops on its storefront at once. Shopify asks us to delete the store's data 48 hours later, and we then delete its workspace, index, and records. The Findlane account stays until you ask us to delete it.
When customers use the service
- The content customers upload to their indexes, such as product catalogs. We process it only to provide the service to them.
When shoppers search a store that uses Findlane
- The search request: the query, filters, sort, and page, along with the network information every website receives, including the IP address.
- For the search analytics a store sees in its dashboard, we keep: the query's words (lowercased, up to eight), the names of filtered and faceted fields but not their values, the sort, the number of results, the response time, and the country and network location that answered the request.
- For searches made from a shopper's browser, we also keep the approximate location our hosting provider derives from the IP address (region and city, with coordinates rounded to about 10 km), the device type (mobile, tablet, or desktop), the browser's preferred language, and the address of the site the search came from. Search analytics don't include IP addresses or user agents.
- The store's dashboard lists its latest searches with the time rounded to the minute. It names a town only after at least 100 searches in 30 days came from it, and shows the region otherwise.
- IP addresses are used briefly to limit how many searches one visitor can make, and are discarded within minutes.
When you visit findlane.dev
- The website sets no cookies and uses no analytics or advertising trackers. As with any website, our hosting provider processes your IP address to deliver pages and protect the service.
Cookies and local storage
- The dashboard at app.findlane.dev uses cookies only to keep you signed in. They're essential to the service, so we don't ask for consent to them.
- The dashboard remembers which workspace you last opened in your browser's local storage.
- findlane.dev, the docs, and the playground set no cookies.
Why we use it
- To provide the service you signed up for (performance of a contract): accounts, workspaces, indexes, the API, and email about your account.
- To keep the service secure and working (our legitimate interest in running a safe, reliable service): session IP addresses, rate limits, abuse prevention, technical logs, and uptime checks.
- To show stores their search analytics and improve the service (legitimate interest, and on the store's behalf for shoppers' searches).
- To comply with the law (legal obligation).
We don't sell personal data, and we don't use it for advertising.
Who we share it with
We use service providers to host and run Findlane on our behalf, under contracts that require them to protect the data and use it only for us:
- cloud hosting, networking, and security, including the network that serves our website and API around the world;
- database hosting;
- email delivery;
- payments and invoices, by our reseller Polar;
- Shopify, for stores that use our Shopify app: the store's plan and overage charges, when it pays through Shopify.
Members of a workspace can see its members, invitations, indexes, and analytics. We disclose data to authorities only when the law requires it.
International transfers
Some of our providers are based in the United States or operate worldwide. When personal data is processed outside the European Economic Area, we rely on the EU–US Data Privacy Framework for certified providers, or on the European Commission's Standard Contractual Clauses.
How long we keep it
- Account and workspace data: while your account exists, and deleted within 30 days after you ask us to delete your account.
- Sign-in sessions: they expire after 7 days without use.
- Rate-limit records: minutes.
- Search analytics: three months.
- Technical logs: up to 7 days.
- Customer content: until the customer deletes it or its account, and then within 30 days.
- A Shopify store's workspace and products: until Shopify asks us to delete them, 48 hours after the app is uninstalled.
Deleted data can remain in backups for a limited time before the backups are replaced.
Your rights
You can ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how we use it, or give it to you in a portable format. Email privacy@findlane.dev, and we'll answer within a month. There's no charge.
If you think we've handled your data wrongly, you can complain to the Icelandic Data Protection Authority (Persónuvernd) or to the data protection authority where you live or work.
Security
We protect data with encryption in transit (HTTPS), encryption at rest by our providers, hashed passwords and API keys, and access limited to the people who run the service. To report a security issue, email privacy@findlane.dev.
Children
Findlane is a service for businesses: you must be at least 18 to create an account, and we don't knowingly collect personal data from children. Searches made on a store that uses Findlane are the store's responsibility, as described above.
Changes
We'll post changes to this policy on this page and update the date at the top. For significant changes, we'll also email account holders before they apply.
Contact
Mucho ehf. (kennitala 460722-0550), Hábæ 2, 851 Hella, Iceland: privacy@findlane.dev