Privacy Policy
Last updated 15 Jan 2026
Template only
This is placeholder text so the route renders. Replace it with a policy written or reviewed by someone qualified before you take real customers.
What we collect
Account data. Your name, email address and password hash, so you can sign in. If you use Google sign-in we receive your name, email and profile image.
Organisation data. Whatever you and your team put into the product, plus membership records showing who belongs to which organisation.
Usage data. Request logs, error reports and aggregate feature usage. We use these to keep the service running and to work out what to fix.
Payment data. Handled by Stripe. We store a customer identifier and subscription status; we never see or store card numbers.
Why we can use it
We process account and organisation data to perform our contract with you, usage data under legitimate interest in operating a reliable service, and marketing communications only with your consent.
How long we keep it
Account data lasts as long as your account, then 30 days. Logs are kept for 90 days. Invoices are retained for six years because tax law requires it.
Your rights
You can request access, correction, export or deletion of your data, and you can object to processing. Write to us and we will respond within one month.