Privacy Policy

Last updated: April 2026

This Privacy Policy explains how Unlocked Labs Limited (“fulfild.ai”, “we”, “us” or “our”) collects, uses, shares and protects personal data when you use fulfild.ai (the “Service”). We comply with the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.

1. Controller and contact

Data controller: Unlocked Labs Limited, registered in the Republic of Ireland, with its registered office in Cork, Ireland.

Privacy contact: privacy@fulfild.ai.

When our customers (tenants) process their own customers' personal data through the Service, the customer is the data controller and we act as the data processor under a Data Processing Agreement (DPA). We do not determine the purposes for which such end-customer data is processed.

2. Data we collect

Account data. Name, email address, company name, phone number, VAT number, company registration number, postal address, timezone, and authentication credentials.

Billing data. Billing address, invoice history, subscription plan, add-ons, last four digits and brand of payment card (stored by Stripe, not by us), and Stripe customer and subscription identifiers.

Operational data. Products, inventory, orders, shipments, returns, warehouses, audit log entries, client brand records, rate cards and invoices. This may include end-customer names, shipping and billing addresses, order line items and contact details submitted to you by your integrated stores or entered by you.

Usage and device data. IP address, user agent, approximate geolocation, pages viewed, actions taken, timestamps, error reports, and session duration. This is used to secure the Service, debug issues and improve the product.

AI assistant data. Messages you send to the in-product AI assistant and data from your tenant that the assistant retrieves to answer you.

3. How we use your data

  • To provide, maintain and improve the Service.
  • To authenticate you and secure your account.
  • To take payment for your subscription and issue VAT-compliant invoices.
  • To process the orders, labels, returns and invoices you generate with the Service, which requires passing relevant data to third-party services (carriers, stores, payment processor, email sender).
  • To send transactional emails (order notifications, billing receipts, security alerts). We do not send marketing email without separate consent.
  • To respond to support requests, legal requests, and to enforce our Terms of Service.
  • To detect and prevent fraud, abuse and breaches of applicable law.

4. Legal bases

We process account, billing and operational data to perform our contract with you (Article 6(1)(b) GDPR). We process usage data and send security alerts based on our legitimate interest in operating and securing the Service (Article 6(1)(f)). We process certain billing data to comply with legal obligations, including VAT and tax record-keeping (Article 6(1)(c)). Where we rely on consent (for example, optional analytics cookies), we ask for it separately and you can withdraw it at any time.

5. Retention

  • Account data: retained while your subscription is active. After termination, we retain it for 30 days to allow reactivation, then delete unless legal retention applies.
  • Billing and tax records: retained for 7 years to comply with Irish tax law.
  • Operational data: retained while your subscription is active. Exportable on request. Deleted within 30 days of subscription termination, subject to legal retention.
  • Audit logs: retained for 12 months for security and compliance; longer for events under investigation.
  • Backups: production backups are retained up to 7 days (extendable to 28 days on higher database tiers); offsite long-term backups are retained up to 12 months.

6. Third-party processors

We use the following sub-processors to operate the Service. Each is contractually bound to process personal data only on our instructions and to protect it consistently with GDPR.

  • Supabase (Supabase Inc.) - database, authentication, file storage. Data is hosted in the European Union (Ireland / eu-west-1).
  • Stripe (Stripe Payments Europe, Limited, Dublin, Ireland) - payment processing, subscription management, Stripe Connect payouts, Stripe Tax calculation.
  • Resend (Resend, Inc.) - transactional email delivery. We route via the EU region where available.
  • Sendcloud (Sendcloud B.V., Netherlands) - shipping aggregator for label generation, rate quotes, tracking events and returns.
  • Anthropic (Anthropic PBC, United States) - the AI model powering the in-product AI assistant. Data processed under Anthropic's enterprise terms with zero-retention commitments where available.
  • Vercel (Vercel Inc.) - hosting and edge delivery of the application.
  • Cloudflare (Cloudflare, Inc.) - DNS, TLS and DDoS protection for the fulfild.ai domain.

Some sub-processors (notably Anthropic, Vercel and Cloudflare) may transfer data outside the European Economic Area. Where this happens, transfers are protected by Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

7. Your rights under GDPR

You have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased (“right to be forgotten”) where legal retention does not require us to keep it;
  • restrict or object to processing in certain circumstances;
  • receive a copy of your data in a portable, machine-readable format (data portability);
  • withdraw consent where processing is based on consent; and
  • lodge a complaint with the Irish Data Protection Commission or your local EU supervisory authority.

To exercise any of these rights, contact privacy@fulfild.ai. We will respond within one month.

8. Security

We apply industry-standard controls including TLS in transit, encryption at rest, row-level tenant isolation on the database, role-based access control, audit logging, scoped API tokens and mandatory two-factor authentication on internal administrative accounts. Sensitive third-party credentials (such as shipping API keys) are encrypted with separate key material. No system is perfectly secure; in the event of a breach affecting your personal data we will notify you and the relevant supervisory authority within 72 hours where required.

9. Cookies

We use strictly-necessary cookies to keep you signed in and to protect against cross-site request forgery. We do not use advertising cookies. Any optional analytics or product-analytics cookies will be introduced under a consent banner before they activate.

10. Children

The Service is not intended for people under 16. We do not knowingly collect data from children. If you believe we have, please contact us and we will delete it.

11. Changes to this Policy

We may update this Privacy Policy from time to time. Material changes will be notified by email or in-app notice. The “Last updated” date at the top reflects the current version.

12. Contact

Privacy contact: privacy@fulfild.ai
Data controller: Unlocked Labs Limited, Cork, Ireland.