Privacy Policy
Last updated: 24 February 2026
1. Introduction
AI Exiter (company number 16932866), trading as AI Exiter, is the data controller responsible for your personal data.
This Privacy Policy explains how we collect, use, store, and share your personal information when you use the AI Exiter platform at aiexiter.com.
We process personal data in accordance with the UK Data Protection Act 2018 and the UK General Data Protection Regulation (UK GDPR). We are registered with the Information Commissioner's Office (ICO:00012757628).
2. Information We Collect
2.1 Account Information
When you create an account, we collect your name and email address. You may sign up using a magic link (email-based authentication) or via an OAuth provider (Google, Apple, GitHub, or Microsoft), in which case we receive basic profile information from that provider.
2.2 Listing Information
If you create a listing, we collect the details you provide including product descriptions, financial metrics, pricing, and contact information.
2.3 Automatically Collected Information
When you use the Platform, we automatically collect certain technical data including your IP address, browser type and version, pages visited, and the date and time of your visit.
We use essential cookies for authentication and session management. We do not use tracking or advertising cookies.
3. How We Use Your Information
We use your personal information to:
- Operate and maintain the marketplace
- Process, review, and display listings
- Authenticate your identity and manage your account
- Send transactional emails (account verification, listing status updates, password resets)
- Respond to your support enquiries
- Detect and prevent fraud and abuse
- Improve the Platform and develop new features
4. Legal Basis for Processing
We process your personal data on the following legal bases:
- Contract: Processing necessary to perform our contract with you (providing the Platform and its features as described in our Terms of Service).
- Legitimate interests: Processing necessary for our legitimate interests, including improving the Platform, ensuring security, and preventing fraud, where those interests are not overridden by your rights.
- Consent: Where we introduce marketing communications in the future, we will obtain your consent before sending them. You will be able to withdraw consent at any time.
- Legal obligation: Processing necessary to comply with our legal obligations under applicable law.
5. Sharing Your Information
5.1 Other Users
Listing information you submit is publicly visible on the Platform. Seller contact details are visible to registered users who view your listing.
5.2 Service Providers
We share data with the following third-party service providers who process data on our behalf:
- Supabase — database hosting and authentication
- Resend — transactional email delivery
- Vercel — website hosting and infrastructure
5.3 Legal Requirements
We may disclose your information where required by law, regulation, court order, or governmental request.
5.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you of any such change.
We do not sell your personal data to any third party.
6. Data Retention
- Active accounts: Your personal data is retained for as long as your account remains active.
- Account deletion: If you request account closure, your personal data will be deleted within 30 days, except where we are required by law to retain it.
- Listing data: Listing data is archived for 90 days after a listing is removed or marked as sold, then deleted.
7. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Encryption of data in transit using TLS
- Secure database hosting through Supabase infrastructure
- Access controls and authentication requirements for all systems
No method of electronic transmission or storage is completely secure. While we take reasonable steps to protect your data, we cannot guarantee absolute security.
8. International Transfers
Your personal data may be processed outside the United Kingdom by our service providers. Supabase and Vercel operate infrastructure in the United States and European Union.
Where data is transferred outside the UK, we ensure appropriate safeguards are in place, including standard contractual clauses approved by the Information Commissioner's Office.
9. Your Rights
Under the UK GDPR, you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — request correction of inaccurate or incomplete data
- Erasure — request deletion of your personal data
- Restriction — request that we restrict processing of your data
- Portability — request your data in a structured, machine-readable format
- Object — object to processing based on legitimate interests
To exercise any of these rights, contact us at info@aiexiter.com. We will respond within one month of receiving your request.
If you are not satisfied with how we handle your request, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
10. Contact and Changes
We may update this Privacy Policy from time to time. Material changes will be communicated via email or Platform notification. The “Last updated” date at the top of this page indicates when the policy was last revised.
If you have questions about this Privacy Policy or our data practices, please contact us:
- General enquiries: info@aiexiter.com
- Data protection: info@aiexiter.com
AI Exiter
Company number: 16932866
71-75 Shelton Street, Covent Garden, London WC2H 9JQ
ICO registration: ICO:00012757628