1. Who we are
GapScope UK, United Kingdom. Data-protection contact: privacy@gapscope.uk. We are registered (or will register before commercial launch) with the Information Commissioner's Office (ICO) as required by the Data Protection (Charges and Information) Regulations 2018.
Part A — Account holders (our customers)
2. Data we collect
- Account data: name, e-mail, company, password hash (or Google account identifier if you sign in with Google), plan and billing status.
- Billing data: handled by Stripe. We store only Stripe's customer and subscription IDs and the renewal date — never card numbers.
- Usage data: campaigns you configure, leads and social profiles retrieved for you, notes, outreach log (channel, recipient, timestamp, message body), exports.
- Technical data: IP address, browser, timestamps and error logs needed to run and secure the service.
3. Why and on what lawful basis
- Providing the service you signed up for — contract.
- Billing, tax records, fraud prevention — legal obligation and legitimate interests.
- Security, abuse prevention, service improvement — legitimate interests.
- Service e-mails (verification, password reset, billing, policy changes) — contract. We do not send marketing newsletters.
4. Retention
- Account and usage data: for the life of the account and 30 days after closure.
- Billing records: 6 years after the tax year (HMRC requirement).
- Security logs: up to 12 months.
Part B — Businesses that appear in results
5. What we collect about you and where from
If you run a business in the UK, our customers may discover information that you have published yourself on your own website or a public business profile (Instagram, Facebook, TikTok, LinkedIn business/creator pages). We access these pages through Exa's search and content API in the same way a person using a search engine would. The information can include:
- Business name, trading address, town and postcode;
- Business telephone, mobile or WhatsApp number and business e-mail only where displayed publicly;
- Website URL, social-media links, published follower counts, opening hours and services;
- Technical characteristics of the website (HTTPS, mobile-friendliness, presence of a contact form) and our derived scores.
We never access private profiles, log-in walls, private messages or data behind a paywall. We do not purchase data lists. We do not guess or generate contact details: every value is stored together with the exact source URL and sentence it came from.
6. Lawful basis
Our lawful basis, and that of our customers, is legitimate interests (Article 6(1)(f) UK GDPR): enabling businesses to identify and contact other businesses about relevant services, using contact channels those businesses have chosen to publish for business enquiries. We have carried out a legitimate-interests assessment, taking into account that the data is business-related, already public, low-sensitivity, and that individuals can object at any time.
7. Your rights
- Object / opt out: e-mail privacy@gapscope.uk with your business name and the number or e-mail concerned. We add it to a suppression list within 5 working days so that it is removed from all customer accounts and excluded from future results.
- Access, rectification, erasure, restriction: available on request; we verify identity first.
- Complain: to the ICO at ico.org.uk or 0303 123 1113.
8. Retention
Records in a customer's account are re-verified when a campaign is re-run and are deleted with the customer's account. Suppression-list entries are kept indefinitely so that your opt-out keeps working.
9. Processors and international transfers
- Lovable Cloud — hosting, database, authentication and transactional e-mail (infrastructure in the EU/UK and USA).
- Exa — web search and page content retrieval (USA).
- Stripe — payments (USA/Ireland).
- Google — optional sign-in.
Transfers outside the UK rely on the UK International Data Transfer Addendum / adequacy regulations and each provider's standard contractual clauses.
10. Security
- All traffic is encrypted (TLS). Passwords are hashed by our authentication provider; we never see them.
- Every customer's data is isolated by database row-level security so that no other customer can read it.
- Search and payment API keys live only in server-side secrets, never in the browser.
- Crawling is restricted to public HTTP(S) URLs with protection against internal-network access.
11. Data-processing terms for customers (Article 28)
For personal data inside your campaigns you are the controller and we are your processor. We: process only on your documented instructions (the configuration of the Service); apply the security measures above; use the sub-processors listed in section 9 and notify you of changes; assist with data-subject requests; delete or return data on termination; and make information available to demonstrate compliance. You warrant that you have a lawful basis for the campaigns you run and will comply with PECR when contacting leads, as set out in the Terms.
12. Cookies
We use only strictly necessary cookies / local storage for sign-in. Details in the Cookie Policy.
13. Children
The Service is for businesses and is not directed at anyone under 18.
14. Changes
We will post changes here and, for material changes, e-mail account holders at least 14 days in advance.