Contents
1. About This Policy
This Privacy Policy explains how Onlyintelligence Ltd, trading as StoreSpine ("we", "us", "our"), collects, uses, stores, shares, and protects your personal data when you use our AI-powered marketing automation SaaS platform ("the Service").
This policy applies to all users of our website at storespine.com and the StoreSpine platform, including free trial users, paying subscribers, and visitors to our marketing website.
We are committed to protecting your privacy and processing your personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR).
Please read this policy carefully. By using our Service, you acknowledge that you have read and understood this policy. If you do not agree with our practices, please do not use the Service.
2. Who We Are
Onlyintelligence Ltd is the data controller responsible for your personal data. We are a company registered in England and Wales, trading as StoreSpine.
Data Controller Details
| Legal Entity | Onlyintelligence Ltd |
| Trading As | StoreSpine |
| Registered Address | Office 13724, 182-184 High Street North, East Ham, London, E6 2JA, United Kingdom |
| Phone | 02381 222 319 |
| Data Protection Contact | privacy@storespine.com |
| ICO Registration | We are in the process of registering with the Information Commissioner's Office (ICO) as a data controller, as required under the Data Protection Act 2018. |
3. What Data We Collect
We collect and process the following categories of personal data:
| Category | Data Collected | Source |
|---|---|---|
| Account Information | Full name, email address, password (stored as a cryptographic hash — we never store your password in plain text), company name, job title | Provided by you at registration |
| Billing Information | Billing name, billing address, VAT number (if applicable). Payment card details are collected and processed exclusively by Stripe — card numbers, CVVs, and expiry dates never touch or are stored on our servers. | Provided by you; card details handled by Stripe |
| Social Media Data | OAuth access tokens and refresh tokens for social media accounts you connect (e.g. Facebook, Instagram, X/Twitter, LinkedIn), social media profile identifiers, and content you publish through our platform. | Provided via OAuth when you connect accounts |
| Usage Data | Pages visited within the platform, features used, timestamps of activity, IP addresses, browser type and version, operating system, device type, referring URLs, session duration. | Collected automatically |
| Communications | Support tickets and their contents, emails exchanged with our team, in-app feedback, marketing campaign content you create. | Provided by you |
| AI-Generated Content | Content and prompts you submit to our AI content generation features (powered by Anthropic's Claude). This data is sent to Anthropic for processing and is not retained by Anthropic after the request is completed, in accordance with Anthropic's commercial API data policy. | Provided by you when using AI features |
4. How We Use Your Data
We only process your personal data where we have a lawful basis to do so under UK GDPR Article 6. The table below sets out each purpose for which we process your data and the corresponding lawful basis.
| Purpose | Lawful Basis (UK GDPR Art. 6) | Data Used |
|---|---|---|
| Creating and managing your account | Contract (Art. 6(1)(b)) — necessary for the performance of our contract with you | Account information |
| Providing the marketing automation service | Contract (Art. 6(1)(b)) — necessary to deliver the service you have subscribed to | Account, social media, communications, AI content |
| Processing payments and billing | Contract (Art. 6(1)(b)) — necessary to process your subscription payments | Billing information (via Stripe) |
| AI-powered content generation | Contract (Art. 6(1)(b)) — a core feature of the service | Prompts and content submitted to AI features |
| Sending marketing emails and newsletters | Consent (Art. 6(1)(a)) — only with your explicit opt-in consent | Name, email address |
| Platform analytics and product improvement | Legitimate interests (Art. 6(1)(f)) — to understand how our platform is used and improve it | Usage data |
| Security monitoring and fraud prevention | Legitimate interests (Art. 6(1)(f)) — to protect our platform and users from threats | IP addresses, usage patterns, login attempts |
| Customer support | Contract (Art. 6(1)(b)) — necessary to provide support as part of the service | Account information, communications |
| Tax compliance and financial records | Legal obligation (Art. 6(1)(c)) — required by UK tax law (HMRC) | Billing information, invoices |
| Fraud prevention and legal compliance | Legal obligation (Art. 6(1)(c)) — required by applicable law and regulations | Account, billing, usage data |
Where we rely on legitimate interests, we have conducted a Legitimate Interests Assessment (LIA) to ensure our interests do not override your fundamental rights and freedoms. You may request a copy of our LIA by contacting us at privacy@storespine.com.
5. Marketing Communications
We will only send you marketing communications (such as newsletters, product updates, promotional offers, and educational content) where you have given us your explicit consent to do so, in compliance with the Privacy and Electronic Communications Regulations 2003 (PECR).
You can withdraw your consent to marketing communications at any time by:
- Clicking the "unsubscribe" link in any marketing email
- Updating your preferences in your account settings
- Contacting us at privacy@storespine.com
Withdrawing your consent to marketing will not affect the lawfulness of any processing carried out before withdrawal. Please note that even if you opt out of marketing communications, we may still send you essential service-related messages (such as security alerts, billing notifications, and changes to our terms), as these are necessary for the performance of our contract with you.
7. Data Sharing and Sub-Processors
We do not sell your personal data to third parties. We share your data only with the third-party sub-processors listed below, solely for the purposes described. Each sub-processor is bound by a Data Processing Agreement (DPA) that ensures compliance with UK GDPR.
| Sub-Processor | Purpose | Data Shared | Location |
|---|---|---|---|
| Stripe | Payment processing | Billing name, address, payment card details | US / EU |
| Amazon Web Services (AWS) | Cloud infrastructure and storage | All platform data (encrypted at rest) | EU-West (Ireland) |
| Resend | Transactional email delivery | Email address, name, email content | US |
| Cloudflare | CDN, DDoS protection, security | IP addresses, request metadata | Global |
| Anthropic (Claude AI) | AI-powered content generation | Content prompts and inputs submitted to AI features | US |
| Hetzner | Server hosting | All platform data (encrypted at rest) | Germany |
| PostgreSQL (self-hosted) | Primary database | All account and platform data | Germany (Hetzner) |
| Redis (self-hosted) | Session caching, rate limiting | Session tokens, temporary data | Germany (Hetzner) |
We may also share your data with law enforcement or regulatory authorities if we are required to do so by law, or if we believe in good faith that disclosure is necessary to comply with legal obligations, protect our rights, or prevent harm.
8. International Data Transfers
Your personal data is primarily stored and processed within the European Economic Area (EEA) on our servers hosted by Hetzner in Germany and AWS in Ireland. However, some of our sub-processors are based in the United States, which means your data may be transferred outside the UK.
Where data is transferred internationally, we ensure that appropriate safeguards are in place as required by UK GDPR Article 46:
- EU/EEA transfers: The UK recognises the EEA as providing adequate data protection under UK adequacy regulations. Transfers to Germany (Hetzner) and Ireland (AWS) are therefore permitted without additional safeguards.
- US transfers (Stripe, Resend, Anthropic, Cloudflare): These transfers are protected by the UK International Data Transfer Agreement (IDTA) and/or UK Addendum to the EU Standard Contractual Clauses (SCCs), which are approved by the ICO. We have executed appropriate agreements with each US-based sub-processor.
You may request a copy of the relevant transfer safeguards by contacting us at privacy@storespine.com.
9. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. The specific retention periods for each category of data are:
| Data Type | Retention Period | Reason |
|---|---|---|
| Account information | Duration of account + 30 days after deletion request | Service provision and grace period for recovery |
| Billing and invoices | 7 years after the transaction | UK tax law (HMRC requirement) |
| Social media OAuth tokens | Until you disconnect the account or delete your account | Service provision |
| Campaign content | Duration of account + 30 days | Service provision |
| Usage and analytics data | 24 months from collection | Product improvement and analytics |
| Server logs (IP addresses) | 90 days | Security monitoring and incident investigation |
| Support tickets | 3 years from resolution | Customer support quality and dispute resolution |
| AI content prompts | Not retained after processing | Sent to Anthropic for real-time generation only |
| Marketing consent records | Duration of consent + 3 years after withdrawal | Evidence of consent (regulatory compliance) |
When data reaches the end of its retention period, it is securely deleted or anonymised so that it can no longer be associated with you.
10. Your Rights Under UK GDPR
Under the UK GDPR and the Data Protection Act 2018, you have the following rights in relation to your personal data. These rights are not absolute and may be subject to exemptions under applicable law.
Right of Access (Article 15)
You have the right to request a copy of the personal data we hold about you, along with information about how we process it. This is commonly known as a "Subject Access Request" (SAR). We will respond within one month of receiving your request.
Right to Rectification (Article 16)
You have the right to request that we correct any inaccurate personal data we hold about you, or complete any incomplete data. You can also update most of your information directly through your account settings.
Right to Erasure (Article 17)
You have the right to request that we delete your personal data in certain circumstances, including where it is no longer necessary for the purpose it was collected, where you withdraw consent, or where you object to processing and there are no overriding legitimate grounds. Please note that we may need to retain certain data to comply with legal obligations (e.g. tax records).
Right to Restrict Processing (Article 18)
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of your data, when processing is unlawful but you do not want erasure, or when you have objected to processing pending verification of our legitimate grounds.
Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, and machine-readable format (such as JSON or CSV), and to transmit that data to another controller. This right applies to data you have provided to us where processing is based on consent or contract and carried out by automated means.
Right to Object (Article 21)
You have the right to object to processing of your personal data where we rely on legitimate interests as our lawful basis. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is necessary for legal claims. You also have an absolute right to object to direct marketing at any time.
Rights Related to Automated Decision-Making (Article 22)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. See Section 12 below for details on our use of automated decision-making.
11. How to Exercise Your Rights
To exercise any of the rights described above, please contact us using one of the following methods:
- Email: privacy@storespine.com
- Post: Data Protection, Onlyintelligence Ltd, Office 13724, 182-184 High Street North, East Ham, London, E6 2JA, United Kingdom
- Phone: 02381 222 319
When submitting a request, please provide enough information for us to verify your identity (such as your full name and the email address associated with your account). We may request additional information to confirm your identity before processing your request.
We will respond to your request within one calendar month of receiving it. In complex cases or where we receive a high volume of requests, we may extend this period by up to two additional months, but we will inform you of any extension within the initial one-month period, along with the reasons for the delay.
There is no fee for exercising your rights in most circumstances. However, we may charge a reasonable fee if your request is manifestly unfounded or excessive, or if you request additional copies of your data under a Subject Access Request.
12. Automated Decision-Making
Our platform uses AI and machine learning to provide features such as content generation, campaign optimisation, and audience targeting suggestions. These features are designed to assist and augment your marketing activities, not to make decisions that produce legal or similarly significant effects on you.
Specifically:
- AI content generation: Claude AI generates suggested content based on your prompts. You always have the final decision on whether to use, edit, or discard any AI-generated content.
- Campaign analytics: We provide automated insights and recommendations about your campaign performance. These are advisory only and do not automatically take action on your behalf.
- Fraud detection: We use automated systems to detect potential fraudulent activity on accounts. If an account is flagged, a human member of our team reviews the case before any action is taken.
We do not currently make any solely automated decisions that produce legal effects or similarly significantly affect you, as defined under UK GDPR Article 22. If this changes in the future, we will update this policy and, where required, obtain your explicit consent.
13. Children's Privacy
StoreSpine is a business-to-business marketing platform and is not intended for use by individuals under the age of 16. In accordance with the UK GDPR and the Age Appropriate Design Code (Children's Code), we do not knowingly collect or process personal data from children under 16 years of age.
If we become aware that we have inadvertently collected personal data from a child under 16, we will take immediate steps to delete that data from our systems. If you believe we may have collected data from a child under 16, please contact us immediately at privacy@storespine.com.
14. Data Security Measures
We take the security of your personal data seriously and implement appropriate technical and organisational measures in accordance with UK GDPR Article 32 to protect your data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher (HTTPS).
- Encryption at rest: Databases and backups are encrypted at rest using AES-256.
- Password security: User passwords are hashed using industry-standard algorithms (bcrypt) and are never stored in plain text.
- Access controls: Strict role-based access controls limit employee access to personal data to only those who need it to perform their duties.
- Infrastructure security: Our servers are hosted in SOC 2 and ISO 27001 certified data centres (Hetzner, Germany). Cloudflare provides DDoS protection and a Web Application Firewall.
- Regular backups: Automated daily backups with encrypted off-site storage.
- Monitoring: Continuous security monitoring and logging of access to personal data.
- Payment security: Payment card details are handled exclusively by Stripe, a PCI DSS Level 1 certified payment processor. Card data never touches our servers.
While we implement strong security measures, no method of transmission over the internet or method of electronic storage is 100% secure. We cannot guarantee absolute security, but we commit to promptly addressing any security incidents in accordance with our data breach procedures.
15. Data Breach Procedures
In the event of a personal data breach, we will follow the procedures required by UK GDPR Articles 33 and 34:
- Notification to the ICO: Where a breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach.
- Notification to affected individuals: Where a breach is likely to result in a high risk to the rights and freedoms of individuals, we will notify the affected individuals without undue delay, providing clear information about the nature of the breach, the likely consequences, and the measures we are taking to address it.
- Internal documentation: All breaches, regardless of severity, are documented in our internal breach register, including the facts, effects, and remedial actions taken.
- Remediation: We will take immediate steps to contain and investigate the breach, mitigate its effects, and prevent future occurrences.
16. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the services we offer, legal requirements, or other factors. When we make changes:
- We will update the "Last updated" date at the top of this policy.
- For material changes that significantly affect how we process your data, we will notify you by email or through a prominent notice on our platform at least 30 days before the changes take effect.
- Where changes require your consent under UK GDPR, we will seek your consent before implementing those changes.
We encourage you to review this policy periodically to stay informed about how we protect your data. Your continued use of the Service after changes take effect constitutes your acknowledgement of the updated policy.
17. How to Complain
If you are unhappy with how we have handled your personal data, we would like the opportunity to resolve your concerns. Please contact our data protection team first at privacy@storespine.com and we will do our best to address your concerns.
However, you also have the right to lodge a complaint with the supervisory authority. In the UK, this is the Information Commissioner's Office (ICO):
Information Commissioner's Office
| Address | Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF |
| Helpline | 0303 123 1113 |
| Website | ico.org.uk |
You can raise a concern or make a complaint with the ICO at any time. However, we appreciate the chance to address your concerns before you approach the ICO, so please contact us in the first instance.
18. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please do not hesitate to contact us:
| Company | Onlyintelligence Ltd (trading as StoreSpine) |
| Address | Office 13724, 182-184 High Street North, East Ham, London, E6 2JA, United Kingdom |
| privacy@storespine.com | |
| Phone | 02381 222 319 |
| Website | storespine.com |
© 2026 Onlyintelligence Ltd, trading as StoreSpine. All rights reserved.