Privacy Policy

Last updated: 21 March 2026

1. Who We Are

This Privacy Policy explains how slopless.co.uk (“we”, “us”, “our”) collects, uses, stores, and protects personal data when you use our platform.

We are the data controller for the purposes of UK data protection law (UK GDPR and the Data Protection Act 2018).

Platformslopless.co.uk
Contacthello@slopless.co.uk
Data controllerThe operator of slopless.co.uk

2. What Data We Collect

2.1 Account Information

When an account is created for you, we store:

2.2 Login History

Each time you log in, we record:

We retain the most recent 10 login entries per user. This information is used for security purposes (to detect unauthorised access) and is visible to platform administrators.

2.3 Bulk Referral Jobs

When you submit a Bulk Referral job, we store the following on our server:

Your original spreadsheet file is never uploaded to or stored on our server. Only the company names extracted from it are retained as part of the job record. Company names submitted via this tool are business data, not personal data, and are not subject to data subject rights under UK GDPR.

2.4 Referral Finder (Single-Company Tool)

Search queries submitted via the Referral Finder are routed through our server to the Companies House API (this is necessary for rate limiting and API key security). However, no search queries or results from this tool are stored on our server. All results are processed in your browser session only.

2.5 Referrals Watcher

When you use the Referrals Watcher tool, we store the following on our server in a per-user file:

This data persists for the duration of your account and is deleted when your account is removed. Your email address (if provided) is used solely to deliver Referrals Watcher alerts and is not used for any other purpose.

2.6 Live Stream

The Live Stream tool displays publicly available data sourced from the Companies House API. We do not store your SIC filter selections, keyword watches, or search activity from this tool beyond your current browser session. Presets and keyword sets you save are stored on the server and shared across your organisation.

2.7 Incorporation Digest

When you use the Incorporation Digest tool, we store the following on our server in a per-user file:

Matched company data is cleared after each weekly compilation. Compiled result files are automatically deleted after 30 days. Your email address (if provided) is used solely to notify you when your weekly digest is ready.

2.8 Website Watcher

When you use the Website Watcher tool, we store the following on our server in a per-user file:

Watched entries are automatically removed after 30 days. Discovered website results persist until you clear them manually. Your email address (if provided) is used solely to notify you when new websites are discovered and is not used for any other purpose.

2.9 Landing Page Analytics

When you visit the public landing page (slopless.co.uk), we record:

We retain the most recent 2,000 entries. Known bot and crawler traffic is excluded. This data is used for understanding how visitors find the site and is visible to platform administrators. Visits from logged-in users navigating within the platform are not recorded.

2.10 Technical Data

We may collect standard web server access logs (via nginx), which include IP addresses, request paths, and timestamps. These are used for security monitoring and service maintenance and are separate from the landing page analytics described above.

3. How We Use Your Data

We use the data we collect for the following purposes:

4. Legal Basis for Processing

We process your personal data under the following lawful bases:

5. Data Retention

Data Type Retention Period Notes
Account credentials & permissions Duration of account Deleted on account removal
Login history (IP, location) Last 10 entries per user Visible to administrators
Referrals Watcher entries & alert history Duration of account Deleted on account removal
Alert email address (if provided) Duration of account or until removed by user Used for alert delivery only
Incorporation Digest preferences & accumulated matches Duration of account; compiled results auto-deleted after 30 days Matches cleared weekly after compilation
Website Watcher entries & discovered websites Watched entries expire after 30 days; results persist until cleared by user Deleted on account removal
Bulk Referral job files (input, results, preview) 7 days from submission Auto-deleted by the system
Landing page visit data (IP, referrer, device) Last 2,000 entries Older entries overwritten
Web server access logs Up to 30 days Used for security monitoring

6. Who Can Access Your Data

6.1 Platform Administrators

The operators of slopless.co.uk have administrative access to the server and can view:

This access is used solely for platform operation, support, and security purposes.

6.2 Other Users

Other users of the platform cannot see your Bulk Referral jobs, your Referrals Watcher entries, your Incorporation Digest preferences, your Website Watcher entries, your uploaded company lists, your search activity, or any of your personal account data.

Users within the same organisation share presets and keyword sets. These contain SIC code selections and keyword lists only — no personal data.

6.3 Third Parties

We do not sell, rent, or share your personal data with third parties for marketing or commercial purposes.

We may share data with third parties only in the following limited circumstances:

6.4 Companies House API

All company data displayed on the platform is retrieved from the Companies House public API. We do not transmit your personal data to Companies House.

6.5 Email Delivery

If you enable email alerts in the Referrals Watcher, Incorporation Digest, or Website Watcher, notifications are sent via Resend (resend.com), a third-party transactional email service. Only your email address and the content of the notification are transmitted. Resend acts as a data processor under our instructions and does not use this data for its own purposes.

6.6 IP Geolocation

To determine approximate locations from IP addresses (for login history and landing page analytics), we query a third-party IP geolocation service. Only the IP address is transmitted for this lookup; no other personal data is shared.

7. Data Security

We take reasonable technical measures to protect your data, including:

We intend to implement additional measures including a dedicated non-root server user, UFW firewall configuration, and automated security updates. A full security hardening plan is in progress.

8. Your Rights

Under UK GDPR, you have the following rights regarding your personal data:

To exercise any of these rights, please contact us at hello@slopless.co.uk. We will respond within 30 days.

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk if you believe your data has been handled unlawfully.

9. Cookies and Local Storage

The platform uses:

We do not use advertising cookies, analytics cookies, or third-party tracking cookies. No cookie consent banner is required because the only cookies used are strictly necessary for authentication.

10. Children’s Privacy

This platform is intended for business use only and is not directed at individuals under the age of 18. We do not knowingly collect personal data from children.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this document. We encourage you to review this policy periodically.

Continued use of the platform after any changes constitutes acceptance of the updated policy.

12. Contact Us

If you have any questions about this Privacy Policy or how we handle your data, please contact us:

Emailhello@slopless.co.uk
Websiteslopless.co.uk

This document was prepared on 21 March 2026 and reflects the data handling practices of slopless.co.uk at that time.