Privacy Policy
Last updated: August 5, 2026
The purpose of this privacy policy is to inform users of Competiflow about how Bright Apex, registered in the Netherlands with the Chamber of Commerce (KVK) under number 99295466 and VAT identification number NL005378623B25 ("Bright Apex", "we", "us", or "our"), operating as "Competiflow", processes personal data and your rights in this respect.
We are committed to protecting your personal information and your right to privacy. If you have any questions or concerns about our policy, or our practices with regards to your personal information, please contact us at hello@competiflow.com.
Competiflow collects personal data from its users. This policy covers the Competiflow website, API, and Chrome extension. Acceptance of this privacy policy occurs when you first use the service via competiflow.com (or any of its subdomains) or the Competiflow Chrome extension.
Competiflow is a competitor-monitoring service: you tell us which competitor pages to watch, and on your behalf we fetch those public pages on a schedule, capture snapshots, detect and interpret changes, and deliver you a digest. Our goal is to ensure that the privacy of your company is protected at the highest level when you use Competiflow.
Data collection
We collect the following data:
- Your email address, IP address, and browser information for authentication purposes.
- Your email and associated product usage data for product analytics and improving the service.
- The competitors and pages you configure us to monitor, and usage metrics (monitors configured, check runs performed, changes detected, and checks used against your plan).
- Your payment transactions summary (amount and payment method, not the credit card details).
- Your company or organization name if you provide it.
Storing your data
Competiflow stores the following data in our database:
- Monitoring Configuration: The competitors, pages, and monitors you set up, including their URLs, monitor type, check cadence, and workspace organization.
- Snapshots and Extracted Fields: When we fetch a competitor page you asked us to monitor, we store a snapshot of that public page's content and the structured fields we extract from it. Snapshots serve as baselines and as evidence for the changes we surface to you.
- Detected Changes: The changes we compute between snapshots, including a severity, before/after evidence, review status, and any SEO or AI-generated interpretation attached to them.
- Usage and Billing Data: We log check runs, deliveries, and check-ledger entries for rate limiting, billing, and debugging purposes. This includes timestamps and status codes.
- Account Data: Your account information, including email address, API keys (hashed), and subscription details, is stored securely in our database.
Important note: The pages we capture belong to the third-party competitors you choose to monitor, and we only fetch pages that are publicly accessible. We do not sign in to or access private, gated, or authenticated areas on your behalf. During processing, data may be temporarily stored to pass through internal system components (such as queues, message brokers, or temporary buffers).
Your monitoring data, snapshots, and detected changes are scoped to your account. One customer cannot access another customer's monitors, snapshots, or changes.
Chrome extension
The Competiflow Chrome extension shows your competitor changes in a side panel and lets you watch the page you are browsing. It handles data as follows:
- Active tab URL (local): The extension reads the URL of your active browser tab on your device to match known competitors and to decide whether Watch is available. It does not inject content scripts and does not read the HTML of the open tab.
- When a URL is sent: The active tab URL is sent to Competiflow only when you click Watch site or Watch page to create a competitor or monitor. Feed and triage requests send workspace, competitor, and monitor filters. They do not upload your continuous browsing history.
- API key: Your Competiflow API key is stored in
chrome.storage.localon your device. On our servers, API keys are stored hashed with your account data. - Network: The extension talks only to
https://api.competiflow.com/(plus Chrome extension APIs). Requests includeX-Competiflow-ClientandX-Competiflow-Client-Versionso we can tell extension traffic from other clients. - After Watch: Creating a competitor or monitor uses the same monitoring pipeline as the website. We fetch that public page on a schedule through the providers listed below. We do not sell browsing data.
Limited Use (Chrome Web Store)
For the Competiflow Chrome extension, we comply with the Chrome Web Store User Data Policy, including Limited Use:
- We use permissions and user data only to provide or improve the extension's single purpose: competitor monitoring while you browse (feed, triage, Watch, and badge).
- We transfer user data only when needed to operate that purpose (including the third-party providers listed below for monitoring and interpretation), to comply with law, for security investigations, or as part of a merger, acquisition, or sale of assets.
- We do not sell user data. We do not use it for personalized, retargeted, or interest-based advertising.
- We do not allow unrestricted human reading of user data. Access is limited to the exceptions in Chrome's Limited Use requirements (for example user consent for support, security, legal obligation, or aggregated internal operations).
Third-party providers
A list of third-party providers used by Competiflow, links to their privacy policies, and why and how they are integrated into the Competiflow service and used:
Browserbeam
Browserbeam is used to fetch the public competitor pages you configure us to monitor. It reads the page content that we then snapshot, diff, and interpret.
Browserbeam: Privacy Policy
OpenAI
OpenAI is used to interpret detected changes and synthesize the summaries and digests we show you. We send it the relevant competitor page content and change data required to produce these interpretations.
OpenAI: Privacy Policy
DataForSEO
DataForSEO is used to enrich detected changes with SEO data (such as keyword and search-related metrics) for the competitor pages you monitor.
DataForSEO: Privacy Policy
Paddle
Paddle is used for processing payments.
Your credit card information is not stored, nor logged on our servers. It is all processed by Paddle.
Paddle: Privacy Policy
Postmark
Postmark is used to deliver transactional and digest emails (such as change notifications and account emails) to your email address.
Postmark: Privacy Policy
PostgreSQL (Database Hosting)
We use PostgreSQL databases hosted on Hetzner for storing your account data, API keys, monitoring configuration, snapshots, detected changes, and usage records.
The servers are located within the European Union.
Hetzner: Privacy Policy
Redis
Redis is used for background job processing, scheduling checks, rate limiting, and caching. No persistent personal data is stored in Redis.
GDPR compliance
Under the General Data Protection Regulation (GDPR), you have certain rights with respect to your data, including the right to request access, rectification, erasure, restriction of processing, data portability, and the right to object to processing.
You may exercise these rights by contacting us using the contact information provided below.
Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
Data retention
We retain your personal data for as long as your account is active or as needed to provide you with the Service. If you delete your account, we will delete or anonymize your personal data within 60 days, except where we are required to retain it for legal or regulatory purposes.
Snapshots that serve as a monitor's baseline or as evidence for a detected change are retained while your account is active so that we can show you an accurate before/after history. Other intermediate snapshots are pruned automatically once they are no longer needed to detect further changes.
Updates to the policy
From time to time, the policy might be updated. The latest version is always at https://competiflow.com/pages/privacy/.
Contact
Contact us if you have any questions, issues, or specific requests at hello@competiflow.com.