Privacy Policy
Last updated: [TODO: date]
Who we are
This website is operated by [TODO: Company Name Ltd], a company registered in England and Wales (company number [TODO]), registered office at [TODO: address]. We are registered with the Information Commissioner's Office as a data controller under registration number [TODO].
For any privacy-related question or to exercise your rights below, contact us at [TODO: email].
What we collect
When you use this service we collect:
- The photo you upload of your driveway. It is sent to Google's Gemini service to generate the after-mockup, and is shared with the tradesperson if you submit a quote request.
- The AI-generated after-image we produce from your photo.
- If you submit the quote form: your name, UK mobile number, postcode, and the timestamp of submission.
- Technical data: your browser's user-agent string, IP address (held briefly in server logs), and basic analytics events (page views) through Vercel Analytics.
Why we collect it and on what legal basis
Under the UK GDPR we rely on the following lawful bases:
- Consent (Art. 6(1)(a)) for sharing your name, phone, postcode and photos with a local surface-cleaning professional who will contact you about a quote. You provide this consent by ticking the box on the quote form.
- Legitimate interests (Art. 6(1)(f)) for the technical data we hold (logs, analytics) to operate the website securely.
You can withdraw consent at any time by emailing us — see Your rights below.
Who we share it with
- The local tradesperson we match you with (the person who pays for your lead). They receive your name, phone number, postcode and before/after photos. They are an independent business and process your data as a separate controller. [TODO: confirm with solicitor that joint-controller vs controller-to-controller language is correct here.]
- Service providers acting on our behalf (data processors): Vercel (hosting), Resend (email delivery), Google (AI image processing). Each is bound by industry-standard data processing terms.
- We do not sell your data, share it with advertising networks, or use it for any purpose beyond what you consented to.
How long we keep it
[TODO: confirm retention period with solicitor.] Suggested defaults:
- Photos and AI-generated images: deleted from our systems within [TODO: 30 days] of submission. Once shared with the tradesperson, retention by them is governed by their own policy.
- Lead details (name, phone, postcode): kept for [TODO: 12 months] in case of follow-up, then deleted.
- Server logs and analytics: 30 days.
Your rights
Under UK GDPR you have the right to:
- Ask for a copy of the data we hold about you (subject access)
- Ask us to correct inaccurate data
- Ask us to delete your data
- Ask us to restrict or stop certain uses of your data
- Withdraw consent for the data sharing at any time
- Complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint
To exercise any of these rights, email [TODO: email]. We aim to respond within one calendar month.
Cookies
We use a small number of strictly-necessary cookies and Vercel Analytics' first-party page-view tracker. We do not use advertising cookies, retargeting pixels, or third-party trackers. [TODO: if you later add Facebook Pixel for ads, this section must be updated and a cookie banner added.]
Changes to this policy
If we make material changes we will update the "last updated" date at the top. Continued use of the service after changes constitutes acceptance.
[TODO] with text reviewed by a qualified UK solicitor before launch.