Skip to content

Privacy Policy

1. What Data We Collect

  • Account information: name, email address, phone number (optional, for SMS notifications)
  • Business information: business name, sector, location, services offered, bio, profile photo, business logo
  • Content you create: posts, messages, opportunity listings, comments
  • Usage data: pages visited, features used, timestamps (collected automatically)
  • Payment information: processed securely by Stripe — we do not store card details

2. How We Use Your Data

  • Providing and improving the Colchester.Network service
  • Sending notifications (in-app, email, SMS, push — based on your preferences)
  • Processing payments and managing subscriptions
  • Moderating content and enforcing community guidelines
  • Generating anonymised usage analytics

3. Third-Party Processors

We use the following third-party services to operate Colchester.Network:

  • Supabase — database, authentication, and real-time features (EU-hosted)
  • Stripe — payment processing (PCI DSS compliant)
  • Twilio — SMS notifications
  • Resend — transactional email delivery
  • OneSignal — push notifications
  • Cloudflare — CDN, image storage (R2), and security, including Turnstile bot protection on our public forms
  • Vercel — website hosting

4. Cookies

We use a single essential cookie for authentication (Supabase session). This cookie is HttpOnly, Secure, and SameSite=Lax. We do not use tracking cookies, advertising cookies, or any third-party analytics cookies.

5. Account Deletion

You may delete your account at any time from Settings → Account. Deletion is permanent and takes effect immediately; it cannot be reversed. When you delete your account, we will:

  • Cancel any active subscription with Stripe and remove your customer record from Stripe.
  • Erase your profile, contact details, preferences, bookmarks, follows, notifications, and private message routing data from our database.
  • Reassign your public posts, articles, opportunities, jobs, and event listings to a “Former member” placeholder so the conversational record remains intact for the community.
  • Retain certain audit and legal records (moderation actions, reports) with your identifier removed — see the retention schedule below.

If you are the sole owner of any business profile or the host of any challenge, you must transfer or delete those before account deletion can complete. The deletion dialog will guide you through this.

6. Data Export (Article 20 portability)

You may download a copy of all data we hold about you at any time from Settings → Account. The export is a JSON file delivered immediately to your browser. It includes your profile, authored content, received messages, notifications, enquiries you have received from non-members, business memberships, billing history, and account preferences. Rate-limited to one export per day.

7. Retention Schedule

We retain different categories of data for different periods, based on the legal basis under which we process them:

CategoryRetentionLegal basis
Pseudonymised content (posts, messages, articles, opportunities, jobs, events with author reassigned to “Former member”)IndefiniteAuthor identifier severed; see “Former member” placeholder section below for what this means for the body of your content.
Moderation actions (with identifier removed)7 years from creationUK Limitation Act 1980 — defence against tort claims
Reports (with identifier removed)7 years from creationSame — defence against claims
Enquiries from non-members (name, email, phone, message)Until the member who received it deletes it, or their account is deletedLegitimate interest (Art. 6(1)(f)) — the member's own record of correspondence. No fixed expiry; deleted on request (see section 12)
SMS log + consent log (with identifier removed)12 monthsFraud-prevention legitimate interest (Art. 6(1)(f))
Stripe invoices6 yearsUK tax law (HMRC record-keeping)
Authentication / session logs90 daysSecurity
Server access logs (Vercel)30 daysSecurity; provider default
Account-deletion audit recordIndefiniteAccountability (Art. 5(2))

8. “Former member” placeholder and content responsibility

After account deletion, content you posted in public spaces (discussions, articles, opportunities, job listings, events) and private messages you sent remain visible attributed to Former member. This protects the conversation history of other community members who participated in your threads.

Important: this attribution change does not edit the body of your posts or messages. If your content contains identifying information about you (your name, contact details, or opinions identifiable by writing style), that text remains as you wrote it. You should review and delete or edit individual posts and messages via the in-app delete/edit action before deleting your account.

If you discover identifying content remains after deletion, contact privacy@colchester.network and we will assist with case-by-case erasure.

9. Your Rights (GDPR)

Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, you have the following rights:

  • Right of access — request a copy of your personal data
  • Right to rectification — correct inaccurate data
  • Right to erasure — request deletion of your data
  • Right to data portability — receive your data in a portable format
  • Right to withdraw consent — especially for SMS and push notifications
  • Right to lodge a complaint— with the Information Commissioner's Office (ICO). Make a complaint at ico.org.uk/make-a-complaint.

10. Requests on Behalf of Someone Else

For data subject requests on behalf of another person — for example a legal representative, executor of an estate, or next-of-kin — contact privacy@colchester.network. We respond within 30 days, in line with Article 12(3) of the UK GDPR.

11. SMS Communications

If you opt in to SMS notifications, you will receive a maximum of 4 messages per week. You can opt out at any time by replying STOP, updating your notification preferences in account settings, or contacting us directly.

12. Enquiries from people who are not members

Some public directory pages carry an enquiry form. This section is about you if you used one — you do not need an account with us, and most of this policy is written for members, so the specifics are set out here.

  • What we collect:the name, email address and (if the page asks for it) phone number you type in, your message, your answers to that member's own questions, and your browser's user-agent string. We do not store your IP address with the enquiry.
  • What we do with it: we pass it to the one person you addressed it to, and we email you a confirmation. We do not add you to any mailing list, we do not use it for marketing, and we do not share it with anyone else — including other members of the same business.
  • Who can see it: the person you wrote to. Not their colleagues, and not the owner of the business page you used, even though they set the form up. Our staff can access it only through database administration tools, which we use for support and abuse investigations.
  • How long we keep it: until the member you wrote to deletes it, or until their account is deleted. There is no fixed expiry — the message is their record of correspondence with you, and they decide when it has served its purpose.
  • Lawful basis: legitimate interest (Article 6(1)(f)) — you asked us to pass a message to a member, and they have an interest in keeping their own correspondence.

To have your enquiry deleted, email privacy@colchester.network and tell us roughly when you sent it and to whom. We will delete it and confirm. You do not have to give a reason.

Enquiry forms are protected by Cloudflare Turnstile — see “Third-Party Processors” above — and are rate-limited to prevent them being used to send unwanted mail to anyone.

12a. The free visibility check

Anyone can run a free check at /check-your-visibility to see where their business appears on Google Maps. This section is about you if you used it without having an account with us.

  • What we collect: the business you picked from the Google results, the search phrase you typed, and a one-way scrambled version of your IP address. If you choose to give us an email address after seeing your result, we keep that too. Giving an address is optional and you get the full result either way.
  • What we do with it: we run the check and show you the result. If you left an email address, Marc may write to you personally about it. Nothing is ever sent to that address automatically. You are not added to any mailing list.
  • The scrambled IP: we use it only to spot somebody running the check hundreds of times. It cannot be turned back into your IP address and we never display it.
  • How long we keep it: twelve months, then it is deleted automatically along with the check itself. You have no account to delete it from, so the deletion is on a timer rather than on request.
  • Lawful basis: legitimate interest (Article 6(1)(f)) — you asked us to run a check and show you the result.

To have it deleted sooner, email privacy@colchester.network and tell us the business name you checked. We will delete it and confirm.

The check is protected by Cloudflare Turnstile and is rate-limited. It queries the Google Places API — see “Third-Party Processors” above — with the business and phrase you chose. We do not send Google anything about you.

13. Data Security

All data is encrypted in transit (TLS) and at rest (Supabase encryption). Access to personal data is restricted through row-level security policies. Only authorised personnel can access system administration tools.

14. Joining: Applications and Invitations

Membership is invitation-only. There are two routes in, and both involve us holding some information about you before you have an account.

If you apply to join at /apply, we store the name, email address, business name, website, sector and description you give us, together with how you heard about us. We use it for one purpose: deciding whether to offer you a place. We do not create an account, take payment details or add you to any mailing list at this stage. If we accept you, we email you an invitation code. If we decline, we keep the record so we can recognise a repeat application, and we delete it after 12 months.

If a member recommends you, they give us your name and email address so we can send you an invitation code. They are responsible for having a reasonable basis to pass those details on. The code is tied to your email address and expires after 30 days. If you never use it, the record is deleted after 12 months.

When an invitation is used, we keep a record linking the new member to whoever invited them. Both people can see that link in their own data export, and we use it to understand how the community grows and to follow up if an account causes problems.

To have an application or an unused invitation erased before those periods elapse, email privacy@colchester.network. Because you have no account at that point, we handle these requests by hand rather than through the self-service export and deletion tools described above.

15. Contact

For data protection queries, contact us at privacy@colchester.network.

Last updated: July 2026