The Nullware Standard0 trackers on this page
Where data goes · verified at every review

Nobody knows where their data ends up. Our members publish it.

Customer data now leaks less through ad pixels and more through the tools businesses use every day: AI assistants, plugins, integrations and “enrichment” services. The Standard covers all of them.

The customerYour shopPaymentsNewsletterCourierAd platformsData brokersRetargeting
01

How data goes missing

None of these feel like selling data. All of them can end the same way.

01
Pasted into AI tools
Customer lists, emails and support conversations get pasted into AI assistants to write replies, segment audiences or “analyse” behaviour. Some services keep what they’re given, or use it to improve their own products.
02
Synced to apps and plugins
A new plugin asks for access to your customer database, and gets all of it. The app may pool it with data from its other customers.
03
Enriched and resold
Data “enrichment” services match your customers against other sources and add what they know. Your list becomes part of their product.
04
Impossible to take back
Once data has been copied, sold on or used to train a system, it is very hard to know where it went, and harder still to get it removed.
The rule
Customer data only goes to services that work for the member, not for themselves.

That covers names, emails, phone numbers, customer IDs, order histories and support conversations. Every service that receives any of it must be bound by contract to use it only for the member’s purpose: no model training, no profiling, no resale, and deletion once it’s no longer needed. For AI services, the maximum retention period goes on the data map too.

Fineinside the line
AI services whose terms rule out training on your data, used through business accounts, with their retention period on your data map.
Using AI on anonymised or aggregate data, like sales trends or page performance.
Processors that work for you: payments, delivery, email, hosting, bound by contract to your purpose.
Customer-facing AI support, when the provider can’t reuse the conversations for itself. Fraud and security services, for fraud and security only.
Neveroutside it
Staff pasting customer data into personal AI accounts, or into any AI service that may train on it.
Plugins, apps and integrations whose terms let them reuse or pool your customers’ data.
Data enrichment, lookalike or “identity resolution” services.
Any tool that can use your customers’ data for its own purposes: training, profiling or resale.
02

The data map

Every member publishes one. It lists each service that touches customer data, what it gets and why. This is an example layout.

Service
Why it gets data
What it gets
Where
Can use it for itself?
Payment provider
Taking payments
Name, card token, billing address
Ireland
No
Delivery courier
Shipping orders
Name, address, phone
UK
No
Newsletter tool
Newsletter the customer asked for
Email address
EU
No
AI support assistant, kept 30 days
Answering support questions
Support messages
US
No
Website hosting
Running the website
Order records
UK
No
03

Five questions for any vendor

Members ask these before connecting anything to customer data. Anyone can.

01Do you train any models on our customers’ data?
02Do you share it with anyone, including your own partners?
03Where is it stored, and who can access it?
04How long do you keep it, and can we delete it on request?
05Is all of that written into our contract, not just your marketing page?
04

How we check

During review we read the member’s data map, check the terms of the riskiest services and ask for three contracts of our choosing. A director signs for the rest. We check that staff use business AI accounts under a written policy. At re-certification we check the map again, because new tools arrive all the time. The rules are clauses NFS-4 and NFS-6.

This page is general information, not legal advice.
Know where your customers’ data goes?

Prove it. Apply for membership and put your data map in public.

Apply to joinTake the self-check