Privacy Policy

Last updated: 13 April 2026

1st Unicorn Distribution LTD ("UnicornDS", "we", "us", "our") operates the UnicornDS Chrome extension and website at unicornds.io. We are the data controller for your personal data. This policy explains how we collect, use, store, and protect your information in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Data Controller

1st Unicorn Distribution LTD
Manchester, United Kingdom
Email: hello@unicornds.io
Company Number: [Your Companies House Number]

1. Information We Collect

Account Information: When you create an account, we collect your email address and display name. If you sign in with Google, we receive your name and email from Google — we do not receive your Google password.

Usage Data: We record listing counts, search counts, and feature usage to enforce plan limits and improve our service. We do not track your browsing history.

Device Information: We collect a device fingerprint (screen resolution, timezone, language, platform) solely to prevent trial abuse. This does not identify you personally.

Payment Information: Payments are processed by Revolut Pay. We never see, store, or have access to your credit/debit card numbers, CVV, or bank details. Revolut handles all payment data under their own PCI DSS-compliant security standards.

Communication Data: If you contact us via email or our support chat, we retain those communications to resolve your enquiry.

Cookies: We use essential cookies for authentication (Firebase session) and analytics (Google Analytics). We do not use advertising or tracking cookies. See Section 9 for details.

2. Legal Basis for Processing (GDPR Article 6)

We process your personal data under the following legal bases:

  • Contract: Processing your account data and usage is necessary to provide the UnicornDS service you signed up for (Article 6(1)(b)).
  • Legitimate Interest: We use device fingerprinting and analytics to prevent fraud, improve our product, and protect our business (Article 6(1)(f)).
  • Consent: We send you service-related emails (trial reminders, account updates). You can opt out at any time (Article 6(1)(a)).
  • Legal Obligation: We may process data to comply with applicable laws or regulations (Article 6(1)(c)).

3. What We Do NOT Collect

  • Your browsing history outside of eBay, Amazon, and AliExpress product pages.
  • Your eBay account credentials, eBay API tokens, or eBay sales data.
  • Credit card numbers, CVV codes, or bank account details (Revolut handles this).
  • Your location, contacts, camera, or microphone.

We do not sell, rent, or share your personal data with advertisers or data brokers. Never have, never will.

4. How We Use Your Data

  • Provide, maintain, and improve the UnicornDS service.
  • Enforce plan limits (listings, searches, scans per your subscription).
  • Process payments through Revolut.
  • Send transactional emails (welcome, trial reminders, account updates).
  • Prevent fraud and abuse (disposable email blocking, device fingerprinting).
  • Respond to your support requests.
  • Generate anonymised analytics to improve our product.

5. Data Storage & Security

Your data is stored in Google Firebase (Firestore database and Authentication), hosted on Google Cloud Platform infrastructure. Security measures include:

  • Encryption at rest and in transit (TLS 1.3).
  • Firestore security rules that block unauthorised access.
  • Firebase Authentication with secure token-based sessions.
  • Server-side validation of all tier limits and permissions.
  • No plain-text storage of passwords (handled by Firebase Auth).

While no system is 100% secure, we implement industry-standard security practices to protect your data.

6. Payment Security

Your card details are safe

We use Revolut Pay for payment processing. Revolut is authorised by the Financial Conduct Authority (FCA) and is PCI DSS Level 1 compliant — the highest level of payment security certification. Your card details are entered directly on Revolut's secure payment page. UnicornDS never sees, processes, or stores your card number, expiry date, or CVV.

7. Third-Party Processors

We use the following third-party services to operate UnicornDS. Each has their own privacy policy:

8. International Data Transfers

Some of our processors (Firebase, OpenAI, Vercel) are based in the United States. These transfers are protected by Standard Contractual Clauses (SCCs) as approved by the UK Information Commissioner's Office (ICO). Your data is treated with the same level of protection regardless of where it is processed.

9. Cookies

We use minimal cookies:

  • Firebase Authentication (essential) — Keeps you logged in. Cannot be disabled without breaking the service.
  • Google Analytics (analytics) — Anonymised page views and usage patterns. You can opt out using browser extensions or cookie settings.

We do not use advertising cookies, social media tracking pixels, or retargeting cookies.

10. Data Retention

  • Active accounts: Data retained while your account is active.
  • Cancelled accounts: Data deleted within 90 days of account deletion request.
  • Trial accounts (expired): Data retained for 12 months, then automatically deleted.
  • Payment records: Retained for 7 years as required by UK tax law (HMRC).
  • Support communications: Retained for 2 years.

11. Your Rights Under GDPR

Under UK GDPR, you have the following rights:

  • Right of Access — Request a copy of all personal data we hold about you.
  • Right to Rectification — Request correction of inaccurate data.
  • Right to Erasure — Request deletion of your data ("right to be forgotten").
  • Right to Data Portability — Receive your data in a machine-readable format.
  • Right to Object — Object to processing based on legitimate interests.
  • Right to Restrict Processing — Request we limit how we use your data.
  • Right to Withdraw Consent — Withdraw consent at any time for consent-based processing.

To exercise any of these rights, email hello@unicornds.io. We will respond within 30 days.

12. Children's Privacy

UnicornDS is not directed at children under 16. We do not knowingly collect personal data from anyone under 16 years of age. If you believe we have collected data from a child, please contact us immediately.

13. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of significant changes by email or by posting a notice on our website. Your continued use of UnicornDS after changes constitutes acceptance of the updated policy.

14. Complaints

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):

ico.org.uk/make-a-complaint
Helpline: 0303 123 1113

15. Contact Us

For any questions about this privacy policy or your personal data:
Email: hello@unicornds.io
1st Unicorn Distribution LTD, Manchester, United Kingdom