Legal
Privacy Policy
What we collect, how it is used, retention periods and your data rights.
Draft pending legal review. This document has not yet been reviewed by a lawyer. Send questions to hello@steelcitysites.co.uk.
Last updated
This policy explains the data Ownerbar collects, how it is used and how to request access, correction or deletion.
Ownerbar is operated by a sole trader in the United Kingdom, acting as the data controller for account data and as a processor for the content you put into the service. Contact: hello@steelcitysites.co.uk.
Your data
- We do not sell or share your data with anyone for their own purposes. Not to advertisers, not to data brokers, not to "partners".
- We do not train shared AI models on your content. Your material builds your own voice model and runs the tools you enabled. Nothing crosses between workspaces.
- You can take everything and leave, whenever you want, including after you cancel.
What we collect
Account data
Your email address, name and avatar if you provide one, timezone, language and theme preference, and the identity provider you signed in with. Authentication, including password verification and optional two-factor authentication, is handled by Supabase. Passwords are not stored in the application database or included in application logs. Your onboarding answers, business type and priorities are stored in your workspace to personalize your starting tools.
Workspace and billing data
Workspace name, plan, members and their roles, invoices and subscription state. Card details go directly to Stripe and never touch our servers — we store a customer id and the last four digits Stripe gives us for display.
Connected account data
For each platform you connect: the access tokens (encrypted at rest), the account identifiers, and whatever the connected tools need — posts and their metrics, comments, community messages for channels you have enabled, subscriber lists, orders, transcripts, calendar availability. What is collected is determined by which tools you enable, and each connection screen states it before you authorise.
Content you create
Uploads, drafts, edits, published actions, media renders and transcripts.
Usage data
Load and navigation timings are reported to Ownerbar’s own performance endpoint with a metric name, value and broad page category. The payload does not include user IDs or message content. The app does not load PostHog. Server logs include request paths, status codes and timings and are kept for 30 days for debugging and abuse prevention.
What we do not collect
- Card numbers, CVCs, or bank details.
- Passwords.
- Direct messages or private channels you have not explicitly enabled.
- Your contacts, your browsing history outside our own site, or anything from device fingerprinting.
- Marketing cookies or cross-site trackers of any kind.
Why we process it, and on what basis
| What | Why | Legal basis |
|---|---|---|
| Account and workspace data | Run your account, authenticate you | Contract |
| Connected account data | Operate the tools you enabled | Contract |
| Content and drafts | Generate, store and publish your work | Contract |
| Billing data | Take payment, meet tax obligations | Contract, legal obligation |
| Product analytics | Understand which features work | Legitimate interests |
| Security logs | Prevent abuse and fraud | Legitimate interests |
| Product emails | Trial, billing and incident notices | Contract |
| Marketing emails | Tell you about new tools | Consent, opt in |
AI processing
Drafts are generated by third-party model providers. When a tool runs, the relevant content — a transcript, a comment, a post you wrote — is sent to the model provider to produce a draft.
- Providers are engaged under agreements that prohibit training on our data.
- Content is not retained by providers beyond the short abuse-monitoring window their terms require.
- Your voice model is scoped to your workspace and never applied to anyone else's.
- The current list of providers is on the subprocessors page, which we update before a new one starts processing.
Who we share data with
Only the subprocessors listed on the subprocessors page — hosting, storage, email delivery, payments, analytics, model providers — each under a data processing agreement, each only for the purpose stated there.
Plus the platforms you connect, when you publish to them. That is you posting to your own account, through us.
We will disclose data if legally compelled. Where we are allowed to tell you, we will.
International transfers
Data is hosted in the EU and, for some subprocessors, the United States. Transfers outside the UK and EEA rely on Standard Contractual Clauses or an adequacy decision, and each transfer is noted on the subprocessors page.
How long we keep things
| Data | Retention |
|---|---|
| Account and workspace | While the account exists |
| Content, drafts, media | While the account exists, then 90 days after cancellation |
| Connected account tokens | Until you disconnect, or 90 days after cancellation |
| Invoices | 7 years, because tax law requires it |
| Server logs | 30 days |
| Product analytics | 24 months |
| Deleted account data | Purged within 30 days of a deletion request |
Your rights
Wherever you live, you can:
- See it. Settings → Data exports the listed workspace records as JSON. Contact support for records or original files outside that export.
- Correct it. Edit anything in the app, or ask us.
- Delete it. Workspace owners can request workspace deletion in Settings → Workspace. Contact support for account deletion.
- Take it elsewhere. The export is machine-readable and yours.
- Object. Email us to object to processing or ask about performance measurements. The cookie notice only saves a dismissal preference.
- Complain. In the UK, to the Information Commissioner's Office. In the EU, to your local supervisory authority.
We answer requests within 30 days, usually within two business days.
Security
- All traffic over TLS. All data encrypted at rest.
- Connected account tokens encrypted with a separate key.
- Row-level isolation between workspaces, enforced in the database rather than only in application code.
- Access to production data is limited to what is needed to answer a support request or fix a fault, and it is logged.
- We will notify affected users and the relevant regulator within 72 hours of becoming aware of a personal data breach.
Children
Ownerbar is not for under-16s and we do not knowingly collect their data. If you believe a child has an account, email us and we will delete it.
Changes
Material changes are emailed to account owners at least 30 days before they take effect, and every version is dated at the top of this page.