Privacy Policy

Effective: 2026-06-20

Seekmodo (operated by Numinix) is a multi-tenant search and AI gateway for storefronts, content sites, knowledge bases, and communities. Each customer's data lives in an isolated tenant namespace (see §7 for the narrow exception where anonymous aggregates are shared between tenants for relevance model training). We collect only what we need to make search work and to bill you for it.

1. What we collect

  • Account data — email address, hashed password (bcrypt), optional TOTP secret, last-login timestamp. If you choose Sign in with Google, we receive your Google account email and profile identifier from Google.
  • Subscription data — your plan, billing status, PayPal subscription ID, and (if you opt in) a PayPal Card Fields vault token for card-on-file billing and prepaid-credit auto-recharge. We never see or store your card number; PayPal tokenises and stores it.
  • Storefront catalog data — the documents your connector pushes through POST /v1/index. We hold only what you send.
  • Search telemetry — query strings, click paths, and result IDs from POST /v1/events. We use this to rank your own results; we don't sell or share it.
  • Operational logs — IP, user-agent, latency, and response code per request, kept 30 days for abuse / debugging.
  • Support tickets — if you contact us via /support or email, we store the thread (name, email, message body) on our self-hosted helpdesk. AI triage may send ticket text to OpenAI to draft replies; see our DPA sub-processor list.

2. What we don't collect

  • We don't sell, rent, or share data with advertisers.
  • No card data ever touches Seekmodo. The 14-day free trial starts without a payment method. Subscriptions run through PayPal; card-on-file and auto-recharge use PayPal Card Fields — billing happens between you and PayPal, and we only see subscription state webhooks and vault token references, never the card number.

3. Where it lives

Application data is stored on Numinix-owned infrastructure in North American data centres. Search documents and telemetry live on managed databases we operate. Backups are encrypted at rest with AES-256.

4. Your rights

You can request export or deletion of your account data at any time by emailing [email protected], or by clicking Delete account in /billing (self-serve, two-step confirm). The self-serve path cancels any active PayPal subscription (no refunds), stops data ingest within 24 hours, and hard-purges all tenant data after a 30-day soft-delete window during which restore is possible by reply.

We action emailed requests within 30 days. If you're an EU resident, the GDPR controller is Numinix; our data-protection contact is the same address.

5. Cookies & analytics

  • Session cookie — strictly necessary next-auth.session-token for authentication.
  • Cloudflare Turnstile — may set a short-lived cookie when you complete a bot check on signup, contact, or support forms.
  • Google Analytics 4 — we load GA4 on seekmodo.com for product analytics. EU/EEA/UK/CH visitors see a cookie banner; analytics cookies are denied until you click Accept. Non-EU visitors receive analytics by default. You can also use "Necessary only" to stay on session + Turnstile cookies only.

A full sub-processor list (PayPal, Resend, Cloudflare, Google, OpenAI) is in our Data Processing Addendum.

6. Updates

We'll post material changes here and email account holders at least 14 days before they take effect.

7. Aggregate data & shared models

Seekmodo improves search quality across all tenants by training shared models — for example a per-vertical base learning-to-rank ranker, cross-tenant synonym candidates, zero-result rescue suggestions, and abuse-detection pattern libraries. The signals that feed these models are derived from tenant query / click traffic but are reduced to anonymous aggregates before they cross tenant boundaries:

  • What we aggregate: query strings, query-to-clicked-document pairs, click positions, dwell buckets, and zero-result query patterns — stripped of tenant identifier and any session/shopper PII before they enter the shared pipeline.
  • What never leaves your tenant boundary: your catalog documents, your specific shoppers' identities or IPs, your tenant-attributable analytics. We serve those back only to you, never to any model that ships to another tenant.
  • Opt-out: deleting your account stops contribution within 24 hours and removes your tenant's signal from any newly-trained shared model. A per-tenant "don't include my data in shared models" toggle is on our roadmap.

8. What your tenant's operator sees

Each Seekmodo tenant is owned by a merchant (the "operator") — typically the store you visited from. Operators sign in to an admin console that shows their own tenant's search activity for the purpose of tuning relevance, fixing zero-result queries, and detecting bot abuse. Specifically, the operator can see, for traffic on their own storefront:

  • Query strings — the search text shoppers entered, with timestamps.
  • Result IDs, click positions, and result-page dwell buckets — to identify under-performing queries.
  • Aggregate per-IP rate — for abuse triage, not individual targeting.

Operators cannot see the shopper's personal identity (we don't collect it), their full IP address (truncated in operator-visible logs), or queries from any other Seekmodo tenant. We surface this disclosure so merchants who deploy Seekmodo on their storefront can tell their own shoppers, and so visitors who recognise the Seekmodo search bar know the merchant has a view of what they typed there. If you don't want a merchant to be able to see what you searched for on their site, don't use their search bar.