Privacy policy
Last updated: 2 September 2026
This policy describes our data practices in plain language. It is not legal advice. Depending on where you live, you may have specific rights; have qualified counsel review this text for your jurisdiction and product roadmap. Related: cookies, affiliate disclosure, contact.
1) Who we are
WEM ("we", "us") operates the wem3.ai website and related services. The data controller for personal data described here is the entity operating the service; for questions, use the contact details on our contact page. For privacy-specific requests, email the same channel and include "Privacy request" in the subject.
2) Data we may collect
Depending on which features you use, we may process:
- Account and profile: identifiers and settings you provide (e.g. email, display name) when you sign in or use support.
- Product and shopping activity: searches, product views, cart and wishlist data stored in your browser, clicks on outbound retailer links, and technical metadata needed to attribute affiliate or native rewards where programs exist.
- Referral and campaign data: creator codes, UTM parameters, and cookies or local storage we use to remember attribution you requested (e.g. from a shared link).
- Support and communications: content you send to us (including contact forms and email) and related metadata.
- Security and device data: IP address, user agent, approximate region (derived), timestamps, and diagnostic data for fraud prevention, security, and service reliability.
- Payment data: when you use card or other payment methods, our payment providers process card and transaction data under their own terms; we do not store full card numbers on our servers.
3) How we use data (purposes)
We use personal data to:
- Provide, maintain, and improve the site and features you request.
- Authenticate sessions, protect accounts, and prevent abuse and fraud.
- Operate reward, referral, and creator programs where applicable, including accounting and disputes.
- Measure product usage in aggregate, fix bugs, and develop new functionality.
- Comply with law, respond to lawful requests, and enforce our terms.
- Communicate with you about the service, security, and (where allowed) product updates.
Where required by law (for example in the EEA, UK, or Switzerland), we rely on appropriate legal bases such as performance of a contract, legitimate interests that are not overridden by your rights, compliance with legal obligations, or consent for optional activities (e.g. certain non-essential cookies or marketing where you have opted in).
4) Affiliate link partners (Skimlinks, Sovrn)
We participate in affiliate link-partner programs to monetize eligible outbound product links. When you opt in through our cookie banner (or the controls on our cookie notice), one or more of the following partners' scripts may run on this site:
- Skimlinks (Skimbit Ltd., a UK company). Their script rewrites eligible outbound retailer links so commissions on qualifying purchases can be attributed back to us. Skimlinks may set or read cookies and similar identifiers on domains such as skimresources.com. See Skimlinks' privacy policy.
- Sovrn Commerce (VigLink) — listed for completeness. Sovrn is not currently active on this site; if and when it is enabled in the future, their script may set or read cookies on vglnk / viglink patterns, and would only load after you opt in via the cookie banner.
Categories of data shared with these partners can include: a unique tracking identifier, IP address, user-agent, the URL of the retailer link you clicked, and basic engagement metadata. See our affiliate disclosure for what this means commercially. You can withdraw consent at any time on the cookie notice page.
Independent of the on-page scripts, retailers and affiliate networks you interact with may process data on their own sites when you leave WEM; we do not control their privacy practices.
5) Browser Extension
We offer a free browser extension for Chrome, Microsoft Edge and Firefox that compares prices across retailers. This section describes what the extension collects and how we handle that data.
- Product information from the page you are viewing: on supported retailer product pages (Amazon, eBay and 40 other major retailers; the 44 domains are listed in full on the extension page), the extension reads the product's title, listed price and — where the retailer publishes one in the page's own structured data — its barcode (GTIN/EAN/UPC), so it can compare it against other retailers. The product title and barcode are sent to our comparison service (wem3.ai/api/extension) to find matching listings, and the title, price, barcode and retailer are recorded as an anonymous product-view event. For products in WEM's tracked catalog, the page's product identifier (such as an Amazon ASIN or eBay item number) is also sent to fetch that product's price history (since 25 Aug 2026, up to 90 days).
- "Compare this page's product" on any other shop: when you click that button in the extension popup, the extension reads product details the current page already publishes (schema.org product data, OpenGraph/product meta tags, the page title, displayed price and any published barcode) and sends the product title, price, barcode and the shop's domain — the domain only, never the full web address — to our comparison service to look for a better price. This happens only on that click — never automatically. Outside the supported retailers above, the extension runs nothing on a page unless you ask it to, and it never reads other tabs or your browsing history.
- What we collect: anonymous usage data only — product categories, titles and barcodes viewed, price ranges browsed, which retailers you compare, and the domain of a shop you ran a one-click compare on. A barcode identifies a product, not a person. We do not collect names, email addresses, the full web address of any page, or any other personal information through the extension. Nor do we build a picture of your general browsing: we see a page only where a comparison actually runs — its domain, the product on it and the time — never the pages in between, and never a page where the extension found no product.
- Approximate country and browser: when the extension contacts our servers, we derive your approximate country (country-level only — never your city or precise location) and your browser and operating-system type, to understand where and how the extension is used. We read this from your connection at the moment of the request; we do not store your IP address or full browser details, and these coarse values cannot identify you individually.
- Anonymous identifier: a random identifier is generated when you install the extension. It is used solely to distinguish one install from another in aggregate analytics and cannot be linked to your identity.
- How we use it: to understand shopping trends, to improve our price comparison service, and to check the prices we hold against what retailers are actually charging — a price we show that a real page disagrees with is a price we need to correct. Data is sent to our servers in batches and stored securely.
- Opting out: you can turn off price comparisons with the "Enable on shopping sites" toggle in the extension popup, or disable the extension entirely in your browser's extension settings. No data is collected while either is off.
- No selling or sharing: we do not sell or share extension data with third parties.
5a) AI assistants (ChatGPT, Claude and other MCP clients)
WEM publishes a connector at wem3.ai/api/mcp that lets an AI assistant — ChatGPT, Claude, or any other client speaking the Model Context Protocol — search products, compare offers and check a price against our catalogue on your behalf. This section describes that channel. It applies when you add the connector to your assistant; the assistant itself is run by its own provider under its own privacy policy, which governs your conversation.
- No account, and nothing to sign in to: the connector is open and unauthenticated. We do not ask for, and cannot receive, your name, email or assistant account. Each request is answered on its own — we hold no session and build no profile of you across requests.
- What your assistant sends us: the tool it wants to run and the shopping details it needs to run it — typically a product description, barcode, price and retailer name. We use those to answer the request. We do not receive your conversation, and your assistant should not send us anything beyond what the tool asks for.
- What we keep: for each tool call we store which tool ran, which assistant called it, a coarse HTTP-library family (for example python or curl — never the raw User-Agent string), whether it succeeded and how long it took — not the search terms. The single exception is when you ask us to check a product we do not hold: we then record the barcode, catalogue reference or product name asked about, so we know what to add to the catalogue. That record carries no price, no caller and nothing that identifies you, and the same product asked about twice updates one row rather than creating two.
- Approximate country and connection data: as with any request to our servers, we read your approximate country, and use the connecting IP address transiently for rate limiting and abuse prevention. We do not store the IP address against your tool calls.
- Product images: where an assistant renders a WEM result card, the product photo is served through our own image proxy on wem3.ai. The retailer that hosts the photo is therefore not contacted from inside your chat window and cannot use it to observe you there.
- Links your assistant shows you: retailer links in a WEM answer are affiliate-tracked and pass through wem3.ai/api/go, exactly like links on the site. Following one records the outbound click described in section 2, tagged with the assistant it came from so we can tell this channel apart from the website. Reading an answer records nothing — only a click does. See our affiliate disclosure for what that means commercially.
- Stopping it: remove the connector in your assistant's settings. There is nothing on our side to disable, because there is no account holding it.
6) Sharing and sub-processors
We may share data with:
- Infrastructure and hosting (e.g. cloud providers, CDNs) that store or process data on our instructions.
- Authentication providers (e.g. when you use third-party sign-in).
- Payment processors for card and alternative payment methods.
- Affiliate networks and retailers to attribute qualifying clicks or orders under program rules.
- Analytics and product tooling (only where enabled for your account or environment).
- Advisors, auditors, and authorities when required for compliance or legal process.
We use contractual and technical measures we reasonably can to require service providers to protect data.
7) International transfers
We may process data in the United States and other countries. Where the law requires safeguards for transfers out of your country, we use appropriate mechanisms (e.g. standard contractual clauses) where applicable.
7a) Creators, brands and marketplace vendors
Most of this policy is about shoppers. This section is about people on the other side of the platform — creators who earn commission or take campaign bookings, brands that book campaigns, and businesses that sell through the WEM marketplace.
Creators. We hold the account details you give us (name, email, creator code, the platforms and audience figures you choose to list), your payout details, and the record of what you earned and when we paid it. If you opt into the public creator directory or a public storefront, the profile fields you fill in are shown publicly — that is the point of them, and you can opt out again.
Brands. When a brand books a campaign we hold the contact and company details on the brief, the brief itself, the terms accepted (with the version, timestamp and IP address, so the acceptance is attributable), payment references, and the record of the campaign through to settlement or refund.
Vendors. Business and listing details, order records, and payout records.
Campaign messages and disputes. Where a dispute is raised we hold what each side said about it and what we decided, because that record is what makes the decision reviewable.
7b) Tax information we are required to collect
UK law requires digital platforms to collect, verify and report information about people who earn money through them. The rules are in the Platform Operators (Due Diligence and Reporting Requirements) Regulations 2023, which implement the international standard often called DAC7. If you are paid through WEM, they apply to you.
What we collect: your legal name, date of birth, address, and tax identification number (in the UK, your National Insurance number or UTR). If you have no tax identification number we collect your place of birth instead, which is the alternative the rules allow. If you are registered as a business we collect the business name and registration number, and your VAT number where you have one. We also ask you to certify your tax residency on a W-9 or W-8BEN form, which is standard practice for platforms that pay people internationally.
Why, and on what legal basis: we process this under Article 6(1)(c) of the UK GDPR — compliance with a legal obligation. This matters for two reasons. It is not based on your consent, so we cannot simply stop processing it on request while the obligation runs. And we cannot pay you without it: there is no minimum threshold for services, so a creator paid any amount at all is reportable, and paying someone we cannot report on would put us in breach. If your record is incomplete your balance stays with us and rolls over until you complete it — it is not lost.
Who sees it: HM Revenue & Customs, in the annual report due each 31 January. Internally it is restricted to the systems that build that report — it is not visible on your public profile, is not used for marketing, and is not shared with brands, vendors or other creators.
How long we keep it: for the period the reporting rules require records to be retained, and no longer. Because the basis is a legal obligation, a request to erase it will not be honoured while that period is running — we will tell you when it expires. Your other rights, including access and correction, are unaffected, and correcting a wrong tax number is something we want you to do.
8) Retention
We keep personal data only as long as needed for the purposes above, including legal, tax, and accounting obligations, fraud prevention, and dispute resolution. Retention periods vary by data type: for example, raw server logs may be kept for a shorter rolling window, while order or reward records may be kept longer where required. When we no longer need data, we delete or anonymize it where feasible.
Specific periods for marketplace participants: financial and transaction records (campaigns, orders, earnings, payouts, invoices) are kept for six years after the end of the relevant financial year, which is the ordinary UK accounting and tax retention period. Contact and profile details for an account that goes inactive are kept for two years and then removed. Tax information collected under section 7b is kept for the period the platform-reporting rules require.
Erasure requests are honoured against contact and profile data. They do not remove the financial record of a transaction that actually happened — we are required to keep that, and a marketplace that could delete its own payment history on request would be no use to anyone audited later. Where we erase, the financial record is retained in a reduced form that no longer identifies you beyond what the law requires.
9) Your rights and choices
Depending on your location, you may have rights to access, correct, delete, or port your personal data, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. California residents may have additional rights under the CCPA/CPRA (e.g. to know categories of data collected, to delete, and to opt out of "sale" or "sharing" of personal information as those terms are defined in California law). We do not "sell" personal information in the conventional sense; some cookie-based or affiliate technology may be treated as a "share" under U.S. state law — use browser controls and our cookie options where provided.
To exercise rights, contact us via the contact page. We may need to verify your request. You may also lodge a complaint with your local data protection authority.
10) Children
The service is not directed at children under 16 (or the age required in your region). We do not knowingly collect personal data from children. If you believe we have, contact us and we will take appropriate steps.
11) Security
We use administrative, technical, and organizational measures designed to protect data. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
12) Changes to this policy
We may update this page from time to time. The "Last updated" date at the top will change when we make material edits. Continued use of the service after changes means you acknowledge the updated policy where the law allows.