matchitfy
Log in

Legal

Privacy policy

This document is available in English only. A translated version would have to be reviewed by a lawyer in each jurisdiction before it could be relied on, and an unreviewed translation of a contract is worse than none. The English text governs.

Effective 9 August 2026. Two parts. Part A is what happens today, on a website for a product that does not exist yet, and it is short because almost nothing happens. Part B is what the product will process once it launches, written now so it can be read before anyone connects anything.

Part A — the website, today

What we collect

An email address, if you type one into a form. That is the only personal information this website asks for, and the only one it keeps.

Our server also writes ordinary web logs: the requesting IP address, the page requested, the time, the referring page and the browser's user agent string. These are used to keep the site running and to notice abuse. They are deleted after 30 days.

What we do not do

  • No advertising or analytics trackers. There is no Google Analytics, no pixel, no tag manager and no third-party script of any kind on this site.
  • No cookies. The site sets none. Your theme and language choices are stored in your own browser's local storage, never sent to us, and readable only by this site.
  • No selling or sharing. We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are used in California law.
  • No profiling and no automated decisions. Nothing here scores you or decides anything about you.

Why we are allowed to hold your email

Because you gave it to us for a stated purpose: to be written to once, when the product opens. Under GDPR that is consent, and you can withdraw it at any moment. Under the CCPA it is a direct collection for a disclosed business purpose.

How long we keep it

Until the product opens and we write to you, or until you ask us to remove it, whichever comes first. If the product is abandoned, the list is deleted and we will tell you before deleting it.

Getting it removed

Write to privacy@matchitfy.com from the address you signed up with, and we will delete it and confirm. No form, no account, no reason required. If you cannot write from that address, tell us the address and we will verify another way.

Part B — the product, when it launches

This part describes planned processing. It is published now so it can be read early, and it will be reissued as an operative policy, with a data processing agreement, before the first store is connected.

What the product will process

To reconcile an ecommerce store against an accounting system, the product needs commercial records, not personal ones:

  • Orders and their money: totals, taxes, discounts, refunds, currency, and the date.
  • Payouts and their components: gateway fees, chargebacks, adjustments and the resulting deposit.
  • Products, variants and inventory, including bundle components and their costs.
  • Accounting records that these are matched against: chart of accounts, journal entries, invoices.
  • Bank transactions, only where a merchant chooses to connect an account, and only to confirm a deposit arrived.

What the product deliberately will not store

An order identifier is what links a payout line to a customer. We store it hashed, not in the clear. That means a Matchitfy database, on its own, cannot be used to look up who bought what.

  • No customer names, email addresses, phone numbers or shipping addresses.
  • No card numbers, and no part of one. Payment instruments are never seen by us.
  • No bank credentials. Bank access, where a merchant enables it, is delegated to a regulated provider that holds the credential; we receive read access to transactions and nothing else.

These are design constraints on the schema, not policy promises made about a system that could do otherwise.

The merchant is the controller

For the commercial records above, the merchant decides why and how they are processed, and we process them on the merchant's instruction. In GDPR terms the merchant is the controller and we are the processor. For the website and the early access list, in Part A, we are the controller.

Who else will see it

Only the providers required to run the service, each for a stated purpose, listed by name on the subprocessors page. That page is the authoritative list and it changes before the change takes effect, not after.

Where it will be held

On servers in the United States. If we later serve the European Union or the United Kingdom, transfers will rest on Standard Contractual Clauses and the applicable UK addendum, and this page will say so before it happens rather than afterwards.

Your rights

Wherever you are, you can ask us what we hold about you, ask for a copy, ask us to correct it, and ask us to delete it. Under GDPR you may also object to processing, ask for it to be restricted, and complain to your supervisory authority. Under the CCPA you may ask what was collected and why, ask for deletion, and ask us to correct it; there is nothing to opt out of selling because we do not sell.

We answer within 30 days. We will never charge you for exercising a right and we will never make the service worse because you did.

Children

This is a tool for businesses. It is not directed at children, and we do not knowingly collect information from anyone under 16. If you believe we have, write to privacy@matchitfy.com and we will delete it.

If something goes wrong

If personal data is exposed, we will notify affected merchants without undue delay and in any case within 72 hours of becoming aware, together with what we know, what we do not yet know, and what we are doing about it. A notification that waits until the picture is complete is a notification that arrives too late to be useful.

Changes

The effective date at the top changes whenever this page does. For material changes affecting people on the early access list, we will write to them — which is, so far, the only thing we have ever promised to email anyone about.

Contact

Privacy: privacy@matchitfy.com
Security: security@matchitfy.com
General: hello@matchitfy.com

See also the terms of service, the security page and the list of subprocessors.