01Introduction
UCP Checker is a free tool for checking Universal Commerce Protocol (UCP) manifest status across merchant websites. We're committed to protecting your privacy and being transparent about our data practices.
This policy explains what information we collect, how we use it, and your rights regarding your data.
02Information We Collect
Account information
When you create an account via Google, GitHub, or magic link, we collect:
- Your name and email address (provided by your authentication provider or entered by you)
- Your authentication provider and provider account ID
We do not receive or store your passwords. Authentication is handled entirely by Google, GitHub, or one-time magic link emails.
Early-access requests
When you request an invite to the monitoring dashboard (or sign in before you've been invited), we store your name, email address, the domain you told us about, any note you added, and the request's status so we can review the waitlist and send your invite.
Workspace & monitoring data
If you use the dashboard at app.ucpchecker.com, we store:
- Your workspace name and the domains on your watchlist (including any staging endpoint, which is kept private and never shown on public surfaces)
- Domain-ownership verification tokens — random values you publish in a public DNS TXT record; they contain no personal data and we read them from public DNS
- Teammate invitations: the email address a workspace owner invites, plus the invite's status
Domain alerts
If you use our alerts feature, we store the domains you choose to track (up to 3 per account). We use your email address to send notifications when a tracked domain's UCP status changes.
Domain data
We collect publicly available technical information about business websites, including:
- UCP manifest contents (from
/.well-known/ucpendpoints) - Robots.txt policies and llms.txt files
- Sitemaps and page-level technical signals (e.g. Open Graph tags, structured data)
- HTTP response metadata (status codes, response times)
This is public technical data about businesses — we do not seek or use personal information in our checks.
Information appearing in crawled public files
The public technical files we collect are published by website operators for programmatic access. Occasionally, such a file incidentally contains limited personal data that the operator chose to publish — most commonly a business contact email address or a name in a contact field.
- What we do with it: nothing, by design. We do not use it as a product field, do not include it in customer deliverables, do not build profiles of individuals, and never sell it. It exists only inside our restricted archive as part of a faithful copy of the public file, kept so we can evidence what a public resource displayed at a given time (provenance and change history).
- Lawful basis: legitimate interests — maintaining an auditable record of public technical resources, verifying the integrity of our observations, and investigating anomalies or disputes. We have assessed and documented this balance.
- Recipients: none in the ordinary course — archives are access-restricted to authorised personnel. Limited disclosure may occur to professional advisers, service providers under contract, or regulators where required by law.
- Retention: archived source files are retained for provenance purposes under our retention schedule, with access restrictions and annual necessity review.
- Your rights: if information about you appears in a file we have archived, you can ask us to suppress it from any surface we operate and to restrict its processing — contact [email protected]. Where the source website still publishes the information, you may also wish to contact the site operator, since our archive reflects what their site publishes.
Email addresses
We collect email addresses when you create an account or subscribe to our weekly stats reports. We never purchase email lists or collect addresses through other means.
Analytics
We use Umami Analytics, a privacy-focused analytics platform that:
- Does not use cookies
- Does not collect personal data
- Does not track users across websites
- Is GDPR compliant by design
Contact form
When you contact us, we collect your name, email address, and message content to respond to your inquiry.
03How We Use Your Information
- Account data: To authenticate you, maintain your session, and associate your domain alerts and workspace with your account.
- Early-access requests: To manage the beta waitlist and email you when your invite is ready.
- Workspace data: To run your watchlist checks, verify domain ownership, and show your team the same monitoring.
- Email addresses: To send magic sign-in links, domain alert notifications, teammate invitations, and weekly stats reports (if subscribed).
- Domain data: To power the public directory, stats pages, status badges, and alert notifications.
- Analytics: To understand usage patterns and improve the service.
- Contact info: To respond to your inquiries.
We never sell your data or share it with advertisers.
04Data Retention
- Account data: Retained until you delete your account. You can delete your account at any time from your profile settings or by contacting us.
- Early-access requests: Retained while the beta waitlist operates; deleted on request.
- Workspace data: Watchlist entries, verification records, and invitations are retained until you remove them or delete your account.
- Domain alerts: Retained until you remove them or delete your account.
- Email subscriptions: Until you unsubscribe. After unsubscribing, your record is marked inactive and deleted after 90 days.
- Domain data: Retained long-term under our retention schedule — the longitudinal record of protocol adoption is the core of the service, and archived source files support provenance and change history. Subject to the suppression rights described above.
- Contact messages: Retained for 1 year, then deleted.
05Your Rights
You have the right to:
- Delete your account: You can delete your account and all associated data (alerts, profile) from your profile settings at any time.
- Manage alerts: Add or remove tracked domains from the alerts page at any time.
- Unsubscribe: Every email includes a one-click unsubscribe link — no login required.
- Access your data: Contact us to request a copy of any personal data we hold.
- Delete your data: Contact us if you need assistance with deletion beyond the self-service options above.
We respond to all data requests within 30 days.
06Third-Party Services
We use the following third-party services:
- Google OAuth: For account authentication. Google provides your name and email address. See Google's Privacy Policy.
- GitHub OAuth: For account authentication. GitHub provides your name and email address. See GitHub's Privacy Statement.
- Umami Analytics: Privacy-focused analytics (no personal data collected).
- Email delivery: We use standard email infrastructure to send alert notifications and subscription emails.
We do not sell or share your data with advertisers, data brokers, or any other third parties.
08Browser Extension
Our browser extension:
- Only accesses
/.well-known/ucppaths on websites you visit - Does not collect your browsing history
- Does not access your cookies or personal data
- Telemetry is opt-in and anonymous (only public manifest data)
The extension operates locally in your browser and only communicates with our servers if you explicitly enable telemetry.
09Updates to This Policy
We may update this privacy policy from time to time. When we make significant changes:
- We'll update the "Last updated" date at the top of this page.
- For material changes affecting email subscribers, we'll send a notification.
Continued use of UCP Checker after changes constitutes acceptance of the updated policy.
10Contact
For privacy-related questions or requests, please use our contact form.
Data controller: PactMode Ltd (trading as UCP Checker), England & Wales company no. 17295877, 2-5 Trade Tower, Coral Row, London SW11 3UF · privacy contact: [email protected].
