Privacy Policy
Last updated: 3 June 2026
This policy explains what personal data Kept collects, why, and what your rights are under UK GDPR and the Data Protection Act 2018.
1. Who is the data controller?
The data controller is the individual operating Kept (a sole-trader beta in Middlesbrough, UK). Contact: hi@send.kept-tees.uk.
2. What we collect
- Email address β to sign you in (passwordless magic link).
- Optional profile info you choose to provide (display name, bank details for payouts).
- Listings you create: photos, descriptions, prices, category.
- Orders, carts, pickup tokens while buying.
- Technical data: IP address, browser/OS, request timestamps, error traces (held briefly for security and debugging).
- Cookies: see our Cookie Policy.
3. Why we use it (lawful basis)
- Performance of contract: running your account, listings, orders, pickups.
- Legitimate interests: preventing fraud and abuse, keeping the service secure, basic analytics on usage.
- Legal obligation: keeping records where the law requires (e.g. tax-relevant transaction logs).
- Consent: for marketing emails (we currently send none β if we ever do, you'll be asked first).
4. Who we share it with (processors)
We use the following service providers. Each receives only the data necessary for its function:
- Vercel (US/EU) β application hosting
- Neon (EU-West-2, London) β database
- Cloudflare R2 (EU) β image storage
- Cloudflare (global) β DNS and edge security
- Resend (EU) β sign-in and transactional emails
- OpenRouter (US) β AI to draft listing descriptions from your photos (photos and generated text only; no email)
- Stripe (UK/EU) β payment processing (once enabled)
We do not sell your data. We do not pass it to advertisers or data brokers.
5. How long we keep it
- Account data: while your account is active, plus up to 12 months after closure for fraud prevention.
- Listings and orders: typically up to 6 years for tax / dispute purposes (UK statutory periods).
- Email magic-link tokens: 24 hours.
- Server logs: rolling 30 days.
6. Your rights
Under UK GDPR you have the right to:
- Access the data we hold about you
- Correct inaccurate data
- Request deletion (subject to legal retention)
- Restrict or object to certain processing
- Receive your data in a portable format
- Withdraw consent at any time (for processing based on consent)
Email hi@send.kept-tees.ukto exercise any of these rights. You can also complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
7. Security
We encrypt data in transit (HTTPS everywhere). Passwords are not stored (we use magic-link sign-in). We follow least-privilege for admin access and apply security updates promptly. No system is 100% secure, but we'll notify you within 72 hours of becoming aware of a personal data breach that materially affects you, as UK GDPR requires.
8. International transfers
Some processors (e.g. Vercel, OpenRouter) may process data outside the UK. We rely on UK/EU adequacy decisions or Standard Contractual Clauses for these transfers.
9. Children
Kept is not intended for users under 16. If you believe a child has used Kept, email us and we'll delete the account.
10. Changes
We'll update the βLast updatedβ date when we change this policy. Material changes will be notified by email or in-app.