Public Safety Intelligence Platform
Privacy notice · FOLO-UP Whistle
Listing intelligence with a narrow, disclosed purpose.
Effective date: 18 August 2026 · Notice version: 2026-08-18
Whistle processes recognised marketplace listing information only to show FOLO-UP signals, receive good-faith concerns, prevent duplicate or abusive reporting, and support human product-safety and intellectual-property review. It does not sell Whistle data, use it for personalised advertising or credit decisions, or monitor general browsing.
1. Controller and contact details
FOLO-UP Whistle is operated by Irelco Ltd, under the FOLO-UP brand. Irelco Ltd is the controller responsible for the personal information described in this notice and is registered in England and Wales, company number 15377065.
Data-protection and rights enquiries: contact@folo-up.co.uk.
Postal address: FOLO-UP / Irelco Ltd, Goldworks, Mill Lane, Ebbw Vale, NP23 6GR, United Kingdom.
2. Whistle’s single purpose
Whistle lets a person check whether FOLO-UP has a community signal or controlled review status for a recognised marketplace listing, and submit that listing as a possible unsafe-product or fake/copy concern. The processing below is limited to that purpose and the related security, audit and service-reliability work needed to provide it.
3. Information processed
Optional automatic listing-status check
Automatic checks are off until the user acknowledges the current in-extension disclosure and chooses to enable them. On a recognised Amazon, eBay, AliExpress, Temu, TikTok Shop or Cut Price Wholesaler product-listing pattern, Whistle purifies the listing URL locally and sends that purified URL to the FOLO-UP API. It receives aggregate total, fake/copy and unsafe counts and any controlled FOLO-UP review status. Viewing a page never creates a report.
Information sent after a report category is selected
- the current listing URL, purified again by the server, and page title;
- public product metadata made available by the listing page, when present: product title, image URL, displayed price and currency, public seller name/profile link, brand, SKU/GTIN/MPN, description and product type;
- the selected category—possible fake/copy product or possible unsafe product—and the good-faith attestation version;
- a random extension-installation identifier, a temporary browser-session identifier and the Whistle version;
- for Professional only, the access key transmitted for validation and the non-secret entitlement label returned by that validation;
- for Professional only, a private follow-up record linking that entitlement label to each purified listing reported with the key, including the reporter’s concern category, report dates and later public-safe review status.
The listing snapshot is read only after the user selects Fake/copy or Unsafe. Whistle does not read other tabs, passwords, cookies, form entries, payment details, private messages or personal communications, and it does not continuously capture page content.
Network and service-log information
The server necessarily receives the network address used to deliver a request. The intake service immediately converts it into a salted one-way rate-limit fingerprint. Standard reverse-proxy security logs can temporarily contain the network address, request time, browser user-agent and requested API URL. Those logs rotate daily with up to 14 rotations on the current service. They are used for security, fault investigation and service reliability—not advertising or profiling.
Information stored by Chrome
- Local, Public edition: a random installation ID and up to 250 report receipts. Each receipt can include product title, marketplace, purified listing URL, the category reported, first/latest submission times, aggregate report counts, the latest public review status requested by the user and the time it was refreshed.
- Local, Professional edition: the individual access key. Professional report follow-up is supplied from the authorised remote profile rather than the Public local receipt list.
- Session: a random ID that expires with the browser session.
- Chrome sync: the automatic-check preference, API endpoint, acknowledgement version and endpoint-migration marker. Chrome may synchronise these settings through the signed-in Chrome profile under Google’s own terms and privacy policy.
The Public receipt list is stored only in chrome.storage.local. It is not a FOLO-UP account, is not synchronised by Whistle, cannot appear automatically on another device and cannot be restored by Irelco Ltd after the extension is removed or its local data is cleared. The underlying submitted report and pseudonymous server fingerprints remain subject to the separate server retention described below.
4. How and why the information is used
5. Lawful bases
Irelco Ltd relies on its legitimate interests in operating a proportionate product-safety and intellectual-property intelligence service, identifying repeated concerns, preserving the integrity of counts, preventing abuse and establishing or defending legal claims. The data is minimised and pseudonymised where possible, and Whistle does not ask public reporters for a name or contact details. For Professional customers, processing necessary to provide and administer the Professional service may also be based on performance of a contract. Information may be processed to comply with a legal obligation where applicable.
The optional automatic-check control is a user choice and can be withdrawn in Settings at any time. Turning it off stops future automatic URL checks; it does not erase reports already submitted.
6. Fingerprints, counters and status logic
Raw installation IDs, session IDs and network addresses are not retained in the Whistle intake database. They are transformed with HMAC-SHA-256 and a server secret into pseudonymous fingerprints. Fingerprints are not proof that each installation is a distinct person.
Grey (0), Yellow (1–4), Orange (5–10) and Red (11+) are assigned deterministically from accepted report count. Automated duplicate and rate-limit rules may reject or avoid counting a submission, but they do not make a legal, safety or authenticity decision about a person or product and do not produce legal or similarly significant effects. Green OK and Black NO statuses require a named human reviewer, explanation and supporting source.
7. Status and no-report limitation
No report recorded means only that FOLO-UP has no report associated with the purified listing address. It is not evidence that a product is safe, unsafe, genuine, counterfeit, legitimate or infringing. Community reports are allegations, not proof. A controlled Green or Black status is limited to the evidence, scope and review date and is not a guarantee about every unit, seller, use or future condition.
8. Who may receive or read information
Submitted listing information may be read by authorised Irelco Ltd personnel and contractors who operate or review FOLO-UP. It may also be disclosed, where necessary and proportionate to the Whistle purpose or required by law, to:
- infrastructure, hosting, security and technical service providers acting under appropriate obligations;
- Trading Standards, product-safety or market-surveillance authorities, regulators, law enforcement or courts;
- the relevant marketplace, seller, manufacturer, responsible person or IP rights holder when needed to assess or act on a concern;
- professional advisers or insurers where necessary to establish, exercise or defend legal claims.
FOLO-UP does not publish the installation/session/network fingerprints, does not sell Whistle information and does not transfer it to advertising platforms, data brokers or credit providers.
9. International transfers
Some infrastructure or technical suppliers may process information outside the United Kingdom. Where UK personal information is transferred internationally, Irelco Ltd uses an applicable UK adequacy regulation or appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to approved standard contractual clauses. Contact us to request available information about the relevant safeguard.
10. Retention
- Hourly rate-limit buckets: entries older than 24 hourly windows are eligible for deletion; cleanup occurs automatically during later service requests.
- Reverse-proxy security logs: currently rotate daily with up to 14 rotations.
- Listings, reports, public snapshots and installation/session fingerprints: retained while needed to deduplicate reports, maintain the intelligence/audit record, investigate repeated concerns, support review/action, or establish or defend legal claims. The launch system has no automatic fixed deletion date. Retention is assessed during case review and when a valid rights request is received.
- Public local report history: kept only in that browser installation until Whistle is removed, its extension data is cleared, or older receipts exceed the 250-listing local limit. Removal or clearing permanently deletes the local history. Irelco Ltd has no Public profile backup from which to restore it.
- Professional access key: kept locally until the user removes it or uninstalls Whistle. The server validates its hash in memory and stores the non-secret entitlement label with a submitted report, not the raw key.
- Professional report profile: the entitlement label/listing association is retained with the underlying intelligence record so the authorised user can follow later status changes. Rotating a key under the same label preserves that history; revoking the key removes access but does not automatically erase evidence records.
11. Security
Production transmission uses HTTPS. FOLO-UP uses access controls, pseudonymous fingerprints, rate limits, duplicate constraints, request-size limits, audit fields and controlled reviewer access. No internet service can guarantee absolute security. Please report a suspected security problem through the support contact without including exploit details in a public review.
12. Your choices and rights
You can leave automatic checks disabled, turn them off in Settings, restrict Whistle’s site access in Chrome, clear a Professional key, clear extension data, or uninstall Whistle. Clearing extension data or uninstalling permanently removes the Public My Whistle Reports history from that browser but does not itself erase reports already received by the FOLO-UP server. Depending on the circumstances and lawful basis, UK data-protection rights can include access, rectification, erasure, restriction, objection and portability.
Public reporting is designed not to request a name or contact address. That protects privacy but can mean Irelco Ltd cannot reliably connect a person to a particular pseudonymous report. We may ask for the purified listing URL, approximate report date/time, category and other details to evaluate a rights request without exposing another reporter’s data.
You may complain to the UK Information Commissioner’s Office at ico.org.uk, by telephone on 0303 123 1113, or by post at Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. We would appreciate the opportunity to address the concern first.
13. Children
Whistle is not directed to children under 13. A child under 13 should not submit a report independently; a parent, guardian or responsible adult should review the information and submit any appropriate concern.
14. Chrome Web Store Limited Use
FOLO-UP Whistle’s use and transfer of information received through Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. User information is used only to provide or improve Whistle’s disclosed single purpose and related security and reliability functions.
15. Changes to this notice
Material changes will be published here with a new effective date. When a change affects in-extension collection or use, Whistle will require acknowledgement of the new disclosure version before automatic checks or reporting resume.
Questions, rights requests or complaints
Email contact@folo-up.co.uk or use the Whistle support page. Do not include passwords, payment data or unnecessary personal information.
Document owner: Irelco Ltd · Version 1.3 · Effective 18 August 2026