Your data and Thynklike
Privacy Policy
Last updated: 29 July 2026
1. Who we are
This policy explains how Noviom Labs (“Noviom Labs”, “Thynklike”, “we”, “us” or “our”) handles personal data when you use thynklike.com, our SEO, competitor and website security audit tools, the Thynklike Commerce mobile application, our AI-assisted features, support services and related products (together, the “Services”).
Noviom Labs is the controller of personal data described in this policy. Privacy questions and rights requests can be sent to [email protected].
2. Information we process
Website audits
- URLs, domains and competitor URLs that you submit.
- Publicly accessible page content, metadata, links, headers, DNS information, TLS details, technology indicators, public contact signals and other evidence required to generate SEO, competitor or passive security reports.
- Audit reports, scores, recommendations, job status, access tokens and technical logs associated with a report.
Thynklike Commerce
- Store name, WordPress/WooCommerce URL and the WooCommerce or WordPress credentials that you enter. Store credentials are saved locally by the app on your device so that it can connect directly to your store. Use dedicated, revocable API keys and application passwords.
- Store information requested through the WooCommerce or WordPress APIs, which may include products, inventory, orders, customers, shipping, refunds, categories, tags, images and blog posts.
- When you use an AI feature, relevant store and product context may be sent to Thynklike, including store name and URL, product names, descriptions, prices, stock status, categories, tags, an existing blog post and the instruction you provide. WooCommerce consumer secrets and WordPress application passwords are not intentionally included in AI prompts sent to our Commerce API.
- Subscription product, purchase, restoration and entitlement information supplied through Apple. We do not receive your full payment-card details.
- Device and push-notification identifiers where notifications are enabled.
Technical and support information
- IP address, browser or device information, timestamps, session and security-cookie data, request logs, crash or diagnostic details and anti-abuse results.
- Your email address, telephone number and the content of messages when you contact support.
3. How and why we use information
We process information to provide and secure the Services, connect the Commerce app to the store you authorise, produce audit reports, create AI-assisted drafts, operate subscriptions, respond to support, diagnose faults, prevent misuse and comply with legal obligations.
Our UK GDPR lawful bases may include performing a contract with you, our legitimate interests in operating and improving a secure service, compliance with law, and consent where it is appropriate. You may withdraw consent at any time, although this does not affect earlier lawful processing.
4. AI-assisted processing
Some audit reports, product-listing suggestions and blog drafts use artificial intelligence. Information included in the relevant request is sent to an AI service provider to produce a response. AI output can be incomplete or inaccurate and must be reviewed before it is published or used to make business, legal, financial, security or SEO decisions.
Do not include confidential information, special-category data, payment-card data or unnecessary personal data in an AI prompt or product description.
5. Service providers and disclosures
We may use carefully selected providers for hosting, databases, job processing, email, security and bot protection, AI generation, push notifications, threat intelligence and App Store payments. These currently may include OpenAI, Cloudflare Turnstile, Google services such as Firebase or Safe Browsing, Apple, and our infrastructure providers. They process information under their own terms and privacy notices as applicable.
We may also disclose information where required by law, to protect users or the Services, in connection with a corporate transaction, or to a professional adviser under confidentiality obligations. We do not sell personal data or use Commerce store content for third-party advertising.
6. Cookies and local storage
Thynklike uses cookies or similar storage where necessary for sessions, request security, fraud prevention, preferences and reliable operation. The Commerce app uses on-device storage for connection settings and subscription state. You can clear app data by signing out or removing the app, although records held by Apple, your store, or our service providers are controlled separately.
7. Retention
We retain information only for as long as reasonably necessary for the purpose described, including providing report links, maintaining security logs, resolving disputes and meeting legal, tax or accounting duties. Retention periods vary by record and may be shortened where you make a valid deletion request. Data stored in your WooCommerce or WordPress installation remains subject to your own retention settings.
8. Security
We use administrative and technical safeguards intended to protect information, including HTTPS, access controls, rate limits, request validation and anti-abuse controls. No service can guarantee absolute security. You are responsible for securing your device, WordPress account and store, limiting API permissions, rotating credentials and revoking access that is no longer required.
9. International transfers
Some providers may process information outside the United Kingdom. Where required, we rely on recognised safeguards such as adequacy regulations or approved contractual protections.
10. Your rights
Depending on your location, you may have rights to access, correct, erase or restrict personal data, object to processing, receive portable data, withdraw consent and complain to a regulator. In the UK, you may complain to the Information Commissioner’s Office. We may need to verify your identity before completing a request.
To make a request, email [email protected]. If information belongs to a merchant using Thynklike Commerce, the merchant may be the controller and should normally be contacted first.
11. Children
The Services are business tools and are not directed to children. You must be old enough to enter a binding contract in your country to purchase a subscription or operate a connected store.
12. Changes and contact
We may update this policy as the Services or law change. The latest version will be published here with a revised date. Material changes may also be communicated through the Services.
Contact: [email protected].