Compliance

How we collect data

We collect data from pages that are already public, the way a visitor's browser would see them. Here's what that means in practice.

Public data only

We collect information from pages anyone can visit without logging in, such as product listings, prices and public reviews. We don't access account areas, order history or anything behind a paywall. If a page requires credentials to view, it's out of scope for what we collect.

No login bypass

We never use stolen, shared or purchased credentials to get past a login wall. If data is only visible after signing in, we don't collect it, regardless of how the request is framed. This applies to every source we work with, not just the ones a client names.

No personal data beyond what the page shows

We collect product, price and review data, not customer accounts, order details or anyone's personal information. A public review may include a reviewer's display name exactly as the store itself shows it; we don't collect anything beyond what the page already displays to any visitor.

Access rules and rate limits

We check a site's published access rules before collecting from it and pace our requests to stay within reasonable limits, rather than maximizing request speed. This protects the site we're collecting from and reduces the chance of disrupting it for other visitors.

GDPR and CCPA

Our data collection is built around public product and pricing information, not personal data, which limits our exposure under GDPR and CCPA. Where a dataset incidentally includes a name a store already displays publicly, like a review byline, we handle it under the same access and retention rules as everything else we collect.

Data retention

Raw collected pages are kept for 30 days to support troubleshooting and are then deleted. Delivered datasets are retained according to what's agreed in your contract, since different clients need different retention periods for their own records.

Removal requests

If you're a store owner and want data about your site reviewed or removed, email support@jyaba.com with the URL or domain in question. We'll look into the request and respond directly.

Security basics

Data in transit is encrypted, and access to collected and delivered data is limited to the people who need it to do their job. We follow least-privilege access internally, rather than giving broad access by default.

Questions or removal requests: support@jyaba.com

Need a written data policy for procurement?

We answer security and compliance questionnaires as part of onboarding.