Privacy Policy
Last updated 12 July 2026
Who's responsible for what
For your account details (your name, email, billing), Opsentio Ltd is the data controller.
For the business data you put into the app — your staff, customers, suppliers, stock, sales — you are the controller and we are your processor. We only handle it to provide the service, and only on your instructions.
What we collect
To run your account
- Your name, email address and company name
- Your subdomain and plan
- Billing details — card numbers are handled by Stripe and never touch our servers
- Basic logs: when you signed in, from roughly where, and errors the app hit
Whatever you put in the app
That's up to you. Typically staff records, customers, suppliers, stock, purchases, sales. We don't look at it except when you ask us to help with a problem, or where we have to for security or the law.
What we don't do
- We don't sell your data. Not to anyone, ever.
- We don't show you adverts.
- We don't use your business data to train AI models.
- We don't track you across other websites.
Cookies
We use a session cookie so you stay signed in. That's it — no advertising or tracking cookies, which is why you don't get a cookie banner.
Who else touches your data
Only the suppliers we need to run the service:
- DigitalOcean — hosting. Your data is stored in the UK/EU.
- Stripe — payments. They handle your card; we never see it.
- Resend — sending email (password resets, notifications).
- SumUp — only if you turn on card payments, and only what's needed to take one.
- Xero — only if you connect it, and only what you choose to send.
Each is bound to protect your data and to use it only to provide their service to us.
How long we keep it
Your data stays while your account is open. If you cancel, you can export it for 30 days, after which we delete it. Backups roll off within 90 days. We keep billing records for six years because tax law requires it.
Keeping it safe
- Encrypted in transit (HTTPS everywhere)
- Each customer's data is stored separately, not mixed into one shared database
- Passwords are hashed, never stored as text
- Payment keys are held server-side and never sent to the browser
- Backed up nightly, and the backups are verified
If there's ever a breach affecting your data, we'll tell you and the ICO within 72 hours as the law requires.
Your rights
Under UK GDPR you can ask us to show you what we hold, correct it, delete it, or give it to you in a portable format. The app already lets you export everything yourself, any time. Anything else, email us and we'll respond within 30 days.
If you're not happy with how we've handled it, you can complain to the Information Commissioner's Office: ico.org.uk