← Back to Home

Privacy Policy

Last updated: 7 April 2026

Contents

1. About This Policy

This Privacy Policy explains how Onlyintelligence Ltd, trading as StoreSpine ("we", "us", "our"), collects, uses, stores, shares, and protects your personal data when you use our AI-powered marketing automation SaaS platform ("the Service").

This policy applies to all users of our website at storespine.com and the StoreSpine platform, including free trial users, paying subscribers, and visitors to our marketing website.

We are committed to protecting your privacy and processing your personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR).

Please read this policy carefully. By using our Service, you acknowledge that you have read and understood this policy. If you do not agree with our practices, please do not use the Service.

2. Who We Are

Onlyintelligence Ltd is the data controller responsible for your personal data. We are a company registered in England and Wales, trading as StoreSpine.

Data Controller Details

Legal EntityOnlyintelligence Ltd
Trading AsStoreSpine
Registered AddressOffice 13724, 182-184 High Street North, East Ham, London, E6 2JA, United Kingdom
Phone02381 222 319
Data Protection Contactprivacy@storespine.com
ICO RegistrationWe are in the process of registering with the Information Commissioner's Office (ICO) as a data controller, as required under the Data Protection Act 2018.

3. What Data We Collect

We collect and process the following categories of personal data:

CategoryData CollectedSource
Account InformationFull name, email address, password (stored as a cryptographic hash — we never store your password in plain text), company name, job titleProvided by you at registration
Billing InformationBilling name, billing address, VAT number (if applicable). Payment card details are collected and processed exclusively by Stripe — card numbers, CVVs, and expiry dates never touch or are stored on our servers.Provided by you; card details handled by Stripe
Social Media DataOAuth access tokens and refresh tokens for social media accounts you connect (e.g. Facebook, Instagram, X/Twitter, LinkedIn), social media profile identifiers, and content you publish through our platform.Provided via OAuth when you connect accounts
Usage DataPages visited within the platform, features used, timestamps of activity, IP addresses, browser type and version, operating system, device type, referring URLs, session duration.Collected automatically
CommunicationsSupport tickets and their contents, emails exchanged with our team, in-app feedback, marketing campaign content you create.Provided by you
AI-Generated ContentContent and prompts you submit to our AI content generation features (powered by Anthropic's Claude). This data is sent to Anthropic for processing and is not retained by Anthropic after the request is completed, in accordance with Anthropic's commercial API data policy.Provided by you when using AI features

4. How We Use Your Data

We only process your personal data where we have a lawful basis to do so under UK GDPR Article 6. The table below sets out each purpose for which we process your data and the corresponding lawful basis.

PurposeLawful Basis (UK GDPR Art. 6)Data Used
Creating and managing your accountContract (Art. 6(1)(b)) — necessary for the performance of our contract with youAccount information
Providing the marketing automation serviceContract (Art. 6(1)(b)) — necessary to deliver the service you have subscribed toAccount, social media, communications, AI content
Processing payments and billingContract (Art. 6(1)(b)) — necessary to process your subscription paymentsBilling information (via Stripe)
AI-powered content generationContract (Art. 6(1)(b)) — a core feature of the servicePrompts and content submitted to AI features
Sending marketing emails and newslettersConsent (Art. 6(1)(a)) — only with your explicit opt-in consentName, email address
Platform analytics and product improvementLegitimate interests (Art. 6(1)(f)) — to understand how our platform is used and improve itUsage data
Security monitoring and fraud preventionLegitimate interests (Art. 6(1)(f)) — to protect our platform and users from threatsIP addresses, usage patterns, login attempts
Customer supportContract (Art. 6(1)(b)) — necessary to provide support as part of the serviceAccount information, communications
Tax compliance and financial recordsLegal obligation (Art. 6(1)(c)) — required by UK tax law (HMRC)Billing information, invoices
Fraud prevention and legal complianceLegal obligation (Art. 6(1)(c)) — required by applicable law and regulationsAccount, billing, usage data

Where we rely on legitimate interests, we have conducted a Legitimate Interests Assessment (LIA) to ensure our interests do not override your fundamental rights and freedoms. You may request a copy of our LIA by contacting us at privacy@storespine.com.

5. Marketing Communications

We will only send you marketing communications (such as newsletters, product updates, promotional offers, and educational content) where you have given us your explicit consent to do so, in compliance with the Privacy and Electronic Communications Regulations 2003 (PECR).

You can withdraw your consent to marketing communications at any time by:

  • Clicking the "unsubscribe" link in any marketing email
  • Updating your preferences in your account settings
  • Contacting us at privacy@storespine.com

Withdrawing your consent to marketing will not affect the lawfulness of any processing carried out before withdrawal. Please note that even if you opt out of marketing communications, we may still send you essential service-related messages (such as security alerts, billing notifications, and changes to our terms), as these are necessary for the performance of our contract with you.

6. Cookies and Tracking

Our website and platform use cookies and similar tracking technologies. In accordance with PECR and UK GDPR, we request your consent before placing any non-essential cookies on your device.

Types of Cookies We Use

TypePurposeDurationConsent Required
Strictly NecessaryAuthentication, session management, security (CSRF protection). These are essential for the platform to function.Session / up to 30 daysNo (exempt under PECR)
FunctionalRemembering your preferences, language settings, and UI customisations.Up to 1 yearYes
AnalyticsUnderstanding how users interact with the platform to improve our service. We use self-hosted analytics.Up to 1 yearYes

You can manage your cookie preferences at any time through the cookie banner displayed on our website, or by adjusting your browser settings. Please note that disabling strictly necessary cookies may prevent you from using core features of the platform.

Cloudflare, which provides our CDN and security services, may also set cookies for bot detection and security purposes. These are classified as strictly necessary cookies. For more information, see Cloudflare's Privacy Policy.

7. Data Sharing and Sub-Processors

We do not sell your personal data to third parties. We share your data only with the third-party sub-processors listed below, solely for the purposes described. Each sub-processor is bound by a Data Processing Agreement (DPA) that ensures compliance with UK GDPR.

Sub-ProcessorPurposeData SharedLocation
StripePayment processingBilling name, address, payment card detailsUS / EU
Amazon Web Services (AWS)Cloud infrastructure and storageAll platform data (encrypted at rest)EU-West (Ireland)
ResendTransactional email deliveryEmail address, name, email contentUS
CloudflareCDN, DDoS protection, securityIP addresses, request metadataGlobal
Anthropic (Claude AI)AI-powered content generationContent prompts and inputs submitted to AI featuresUS
HetznerServer hostingAll platform data (encrypted at rest)Germany
PostgreSQL (self-hosted)Primary databaseAll account and platform dataGermany (Hetzner)
Redis (self-hosted)Session caching, rate limitingSession tokens, temporary dataGermany (Hetzner)

We may also share your data with law enforcement or regulatory authorities if we are required to do so by law, or if we believe in good faith that disclosure is necessary to comply with legal obligations, protect our rights, or prevent harm.

8. International Data Transfers

Your personal data is primarily stored and processed within the European Economic Area (EEA) on our servers hosted by Hetzner in Germany and AWS in Ireland. However, some of our sub-processors are based in the United States, which means your data may be transferred outside the UK.

Where data is transferred internationally, we ensure that appropriate safeguards are in place as required by UK GDPR Article 46:

  • EU/EEA transfers: The UK recognises the EEA as providing adequate data protection under UK adequacy regulations. Transfers to Germany (Hetzner) and Ireland (AWS) are therefore permitted without additional safeguards.
  • US transfers (Stripe, Resend, Anthropic, Cloudflare): These transfers are protected by the UK International Data Transfer Agreement (IDTA) and/or UK Addendum to the EU Standard Contractual Clauses (SCCs), which are approved by the ICO. We have executed appropriate agreements with each US-based sub-processor.

You may request a copy of the relevant transfer safeguards by contacting us at privacy@storespine.com.

9. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. The specific retention periods for each category of data are:

Data TypeRetention PeriodReason
Account informationDuration of account + 30 days after deletion requestService provision and grace period for recovery
Billing and invoices7 years after the transactionUK tax law (HMRC requirement)
Social media OAuth tokensUntil you disconnect the account or delete your accountService provision
Campaign contentDuration of account + 30 daysService provision
Usage and analytics data24 months from collectionProduct improvement and analytics
Server logs (IP addresses)90 daysSecurity monitoring and incident investigation
Support tickets3 years from resolutionCustomer support quality and dispute resolution
AI content promptsNot retained after processingSent to Anthropic for real-time generation only
Marketing consent recordsDuration of consent + 3 years after withdrawalEvidence of consent (regulatory compliance)

When data reaches the end of its retention period, it is securely deleted or anonymised so that it can no longer be associated with you.

10. Your Rights Under UK GDPR

Under the UK GDPR and the Data Protection Act 2018, you have the following rights in relation to your personal data. These rights are not absolute and may be subject to exemptions under applicable law.

Right of Access (Article 15)

You have the right to request a copy of the personal data we hold about you, along with information about how we process it. This is commonly known as a "Subject Access Request" (SAR). We will respond within one month of receiving your request.

Right to Rectification (Article 16)

You have the right to request that we correct any inaccurate personal data we hold about you, or complete any incomplete data. You can also update most of your information directly through your account settings.

Right to Erasure (Article 17)

You have the right to request that we delete your personal data in certain circumstances, including where it is no longer necessary for the purpose it was collected, where you withdraw consent, or where you object to processing and there are no overriding legitimate grounds. Please note that we may need to retain certain data to comply with legal obligations (e.g. tax records).

Right to Restrict Processing (Article 18)

You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of your data, when processing is unlawful but you do not want erasure, or when you have objected to processing pending verification of our legitimate grounds.

Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format (such as JSON or CSV), and to transmit that data to another controller. This right applies to data you have provided to us where processing is based on consent or contract and carried out by automated means.

Right to Object (Article 21)

You have the right to object to processing of your personal data where we rely on legitimate interests as our lawful basis. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is necessary for legal claims. You also have an absolute right to object to direct marketing at any time.

Rights Related to Automated Decision-Making (Article 22)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. See Section 12 below for details on our use of automated decision-making.

11. How to Exercise Your Rights

To exercise any of the rights described above, please contact us using one of the following methods:

  • Email: privacy@storespine.com
  • Post: Data Protection, Onlyintelligence Ltd, Office 13724, 182-184 High Street North, East Ham, London, E6 2JA, United Kingdom
  • Phone: 02381 222 319

When submitting a request, please provide enough information for us to verify your identity (such as your full name and the email address associated with your account). We may request additional information to confirm your identity before processing your request.

We will respond to your request within one calendar month of receiving it. In complex cases or where we receive a high volume of requests, we may extend this period by up to two additional months, but we will inform you of any extension within the initial one-month period, along with the reasons for the delay.

There is no fee for exercising your rights in most circumstances. However, we may charge a reasonable fee if your request is manifestly unfounded or excessive, or if you request additional copies of your data under a Subject Access Request.

12. Automated Decision-Making

Our platform uses AI and machine learning to provide features such as content generation, campaign optimisation, and audience targeting suggestions. These features are designed to assist and augment your marketing activities, not to make decisions that produce legal or similarly significant effects on you.

Specifically:

  • AI content generation: Claude AI generates suggested content based on your prompts. You always have the final decision on whether to use, edit, or discard any AI-generated content.
  • Campaign analytics: We provide automated insights and recommendations about your campaign performance. These are advisory only and do not automatically take action on your behalf.
  • Fraud detection: We use automated systems to detect potential fraudulent activity on accounts. If an account is flagged, a human member of our team reviews the case before any action is taken.

We do not currently make any solely automated decisions that produce legal effects or similarly significantly affect you, as defined under UK GDPR Article 22. If this changes in the future, we will update this policy and, where required, obtain your explicit consent.

13. Children's Privacy

StoreSpine is a business-to-business marketing platform and is not intended for use by individuals under the age of 16. In accordance with the UK GDPR and the Age Appropriate Design Code (Children's Code), we do not knowingly collect or process personal data from children under 16 years of age.

If we become aware that we have inadvertently collected personal data from a child under 16, we will take immediate steps to delete that data from our systems. If you believe we may have collected data from a child under 16, please contact us immediately at privacy@storespine.com.

14. Data Security Measures

We take the security of your personal data seriously and implement appropriate technical and organisational measures in accordance with UK GDPR Article 32 to protect your data against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher (HTTPS).
  • Encryption at rest: Databases and backups are encrypted at rest using AES-256.
  • Password security: User passwords are hashed using industry-standard algorithms (bcrypt) and are never stored in plain text.
  • Access controls: Strict role-based access controls limit employee access to personal data to only those who need it to perform their duties.
  • Infrastructure security: Our servers are hosted in SOC 2 and ISO 27001 certified data centres (Hetzner, Germany). Cloudflare provides DDoS protection and a Web Application Firewall.
  • Regular backups: Automated daily backups with encrypted off-site storage.
  • Monitoring: Continuous security monitoring and logging of access to personal data.
  • Payment security: Payment card details are handled exclusively by Stripe, a PCI DSS Level 1 certified payment processor. Card data never touches our servers.

While we implement strong security measures, no method of transmission over the internet or method of electronic storage is 100% secure. We cannot guarantee absolute security, but we commit to promptly addressing any security incidents in accordance with our data breach procedures.

15. Data Breach Procedures

In the event of a personal data breach, we will follow the procedures required by UK GDPR Articles 33 and 34:

  • Notification to the ICO: Where a breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach.
  • Notification to affected individuals: Where a breach is likely to result in a high risk to the rights and freedoms of individuals, we will notify the affected individuals without undue delay, providing clear information about the nature of the breach, the likely consequences, and the measures we are taking to address it.
  • Internal documentation: All breaches, regardless of severity, are documented in our internal breach register, including the facts, effects, and remedial actions taken.
  • Remediation: We will take immediate steps to contain and investigate the breach, mitigate its effects, and prevent future occurrences.

16. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the services we offer, legal requirements, or other factors. When we make changes:

  • We will update the "Last updated" date at the top of this policy.
  • For material changes that significantly affect how we process your data, we will notify you by email or through a prominent notice on our platform at least 30 days before the changes take effect.
  • Where changes require your consent under UK GDPR, we will seek your consent before implementing those changes.

We encourage you to review this policy periodically to stay informed about how we protect your data. Your continued use of the Service after changes take effect constitutes your acknowledgement of the updated policy.

17. How to Complain

If you are unhappy with how we have handled your personal data, we would like the opportunity to resolve your concerns. Please contact our data protection team first at privacy@storespine.com and we will do our best to address your concerns.

However, you also have the right to lodge a complaint with the supervisory authority. In the UK, this is the Information Commissioner's Office (ICO):

Information Commissioner's Office

AddressWycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline0303 123 1113
Websiteico.org.uk

You can raise a concern or make a complaint with the ICO at any time. However, we appreciate the chance to address your concerns before you approach the ICO, so please contact us in the first instance.

18. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please do not hesitate to contact us:

CompanyOnlyintelligence Ltd (trading as StoreSpine)
AddressOffice 13724, 182-184 High Street North, East Ham, London, E6 2JA, United Kingdom
Emailprivacy@storespine.com
Phone02381 222 319
Websitestorespine.com

© 2026 Onlyintelligence Ltd, trading as StoreSpine. All rights reserved.