Security
Security and data handling
Price Intelligence holds your product catalogue, the competitor prices we collect for you, and your account details. This page states what that data is, where it lives, who can reach it, and — just as importantly — which certifications we do not currently hold.
We would rather tell you exactly what we do and do not have than imply a compliance posture we have not earned. If a control below matters to your procurement process and we do not have it, ask us and we will give you a straight answer about timing.
What data we hold
| Category | Examples | Why we hold it |
|---|---|---|
| Catalogue data | SKU, title, your price, cost if you provide it, GTIN, MAP price | To match competitor listings and calculate margin and MAP position |
| Collected market data | Competitor prices, availability, seller identity, capture screenshots | The core of the service |
| Account data | Name, work email, company, hashed credentials, billing contact | Authentication, billing and support |
| Operational logs | Request logs, collection results, error traces | Diagnosing failures and detecting abuse |
We do not ask for, and have no use for, your customers' personal data. If you upload a catalogue file containing it by accident, tell us and we will delete it.
How it is protected
- In transit — TLS on every connection, to the application and to the API.
- At rest — encrypted storage for the database and for evidence captures.
- Evidence integrity — MAP evidence captures are written to write-once storage with a retention lock, so a capture cannot be altered after the fact. That property is the point of the evidence, so it is enforced by the storage layer rather than by policy.
- Access control — least-privilege access to production. Access to customer data is limited to what is needed to operate the service or to answer a support request you have raised.
- Secrets — held in the platform's managed secret storage, never in source control.
- Backups — automated, encrypted, with restores exercised rather than assumed.
Authentication and account safety
- Passwords are hashed with a modern, deliberately slow algorithm. We never store or display them.
- SAML single sign-on is available on the Scale and Enterprise plans.
- API keys are scoped and revocable, and are shown once at creation.
- Every plan supports unlimited users, so nobody has to share a login for cost reasons. Shared logins are the most common cause of an access problem we cannot help you investigate.
What we do not currently claim
We are happy to complete a security questionnaire, describe our architecture, and agree contractual security commitments including breach notification timelines. What we will not do is tick a box we cannot evidence.
How we collect data from third-party sites
Our crawler fetches publicly accessible pages only. It does not create accounts, log in, use your credentials, or attempt to bypass access controls. It identifies itself and rate limits per domain. The full description is on the methodology page.
Reporting a vulnerability
If you believe you have found a security issue, email hello@priceintelligence.io with the detail and, if you can, a reproduction. We will acknowledge within two business days. Please give us a reasonable window to fix an issue before disclosing it publicly, and please do not run automated scans against production or access data that is not yours.
Data ownership and exit
- Your catalogue data and the price history collected for you belong to you.
- CSV export and full API access are on every plan with no surcharge.
- After cancellation you keep export access for 30 days.
- On a deletion request we delete your account data and collected history, retaining only what we are legally required to keep for billing records.
Questions your security team needs answered?
Send them over. You will get a direct answer from someone who can change the product rather than a form response.
Frequently asked questions
Where is data hosted?
In managed cloud infrastructure in the United States, with encrypted storage and automated encrypted backups. If your organisation has a specific data-residency requirement, contact us before you start a trial so we can tell you honestly whether we can meet it.
Do you have SOC 2?
Not today. We would rather say so than imply otherwise. We will complete security questionnaires, describe our controls in detail and make contractual commitments including breach notification. If certification is a hard requirement for you, tell us and we will be straight about timing.
Can other customers see my data?
No. Catalogue data, cost data and collected price history are scoped to your account. Aggregate research we publish is derived and anonymised, and any page containing it says so explicitly.
Do you use my data to train models?
We do not train models on your catalogue, your costs or your pricing decisions. Match corrections you make improve matching for your own account. Where we use machine learning in extraction and matching, it operates on publicly collected page content, not on your private commercial data.
What happens if there is a breach?
We notify affected customers without undue delay, with what we know, what we do not yet know, and what we are doing about it. We will contract to a specific notification window if your agreement requires one.
Keep reading
Start monitoring in the next ten minutes
Connect your store, match your catalogue and get your first competitor comparison in the same session.
14 days, no credit card, cancel in one click.