Skip to content

Legal

Privacy Policy

What we collect, how it is used, retention periods and your data rights.

Draft pending legal review. This document has not yet been reviewed by a lawyer. Send questions to hello@steelcitysites.co.uk.

Last updated

This policy explains the data Ownerbar collects, how it is used and how to request access, correction or deletion.

Ownerbar is operated by a sole trader in the United Kingdom, acting as the data controller for account data and as a processor for the content you put into the service. Contact: hello@steelcitysites.co.uk.

Your data

  1. We do not sell or share your data with anyone for their own purposes. Not to advertisers, not to data brokers, not to "partners".
  2. We do not train shared AI models on your content. Your material builds your own voice model and runs the tools you enabled. Nothing crosses between workspaces.
  3. You can take everything and leave, whenever you want, including after you cancel.

What we collect

Account data

Your email address, name and avatar if you provide one, timezone, language and theme preference, and the identity provider you signed in with. Authentication, including password verification and optional two-factor authentication, is handled by Supabase. Passwords are not stored in the application database or included in application logs. Your onboarding answers, business type and priorities are stored in your workspace to personalize your starting tools.

Workspace and billing data

Workspace name, plan, members and their roles, invoices and subscription state. Card details go directly to Stripe and never touch our servers — we store a customer id and the last four digits Stripe gives us for display.

Connected account data

For each platform you connect: the access tokens (encrypted at rest), the account identifiers, and whatever the connected tools need — posts and their metrics, comments, community messages for channels you have enabled, subscriber lists, orders, transcripts, calendar availability. What is collected is determined by which tools you enable, and each connection screen states it before you authorise.

Content you create

Uploads, drafts, edits, published actions, media renders and transcripts.

Usage data

Load and navigation timings are reported to Ownerbar’s own performance endpoint with a metric name, value and broad page category. The payload does not include user IDs or message content. The app does not load PostHog. Server logs include request paths, status codes and timings and are kept for 30 days for debugging and abuse prevention.

What we do not collect

  • Card numbers, CVCs, or bank details.
  • Passwords.
  • Direct messages or private channels you have not explicitly enabled.
  • Your contacts, your browsing history outside our own site, or anything from device fingerprinting.
  • Marketing cookies or cross-site trackers of any kind.

Why we process it, and on what basis

WhatWhyLegal basis
Account and workspace dataRun your account, authenticate youContract
Connected account dataOperate the tools you enabledContract
Content and draftsGenerate, store and publish your workContract
Billing dataTake payment, meet tax obligationsContract, legal obligation
Product analyticsUnderstand which features workLegitimate interests
Security logsPrevent abuse and fraudLegitimate interests
Product emailsTrial, billing and incident noticesContract
Marketing emailsTell you about new toolsConsent, opt in

AI processing

Drafts are generated by third-party model providers. When a tool runs, the relevant content — a transcript, a comment, a post you wrote — is sent to the model provider to produce a draft.

  • Providers are engaged under agreements that prohibit training on our data.
  • Content is not retained by providers beyond the short abuse-monitoring window their terms require.
  • Your voice model is scoped to your workspace and never applied to anyone else's.
  • The current list of providers is on the subprocessors page, which we update before a new one starts processing.

Who we share data with

Only the subprocessors listed on the subprocessors page — hosting, storage, email delivery, payments, analytics, model providers — each under a data processing agreement, each only for the purpose stated there.

Plus the platforms you connect, when you publish to them. That is you posting to your own account, through us.

We will disclose data if legally compelled. Where we are allowed to tell you, we will.

International transfers

Data is hosted in the EU and, for some subprocessors, the United States. Transfers outside the UK and EEA rely on Standard Contractual Clauses or an adequacy decision, and each transfer is noted on the subprocessors page.

How long we keep things

DataRetention
Account and workspaceWhile the account exists
Content, drafts, mediaWhile the account exists, then 90 days after cancellation
Connected account tokensUntil you disconnect, or 90 days after cancellation
Invoices7 years, because tax law requires it
Server logs30 days
Product analytics24 months
Deleted account dataPurged within 30 days of a deletion request

Your rights

Wherever you live, you can:

  • See it. Settings → Data exports the listed workspace records as JSON. Contact support for records or original files outside that export.
  • Correct it. Edit anything in the app, or ask us.
  • Delete it. Workspace owners can request workspace deletion in Settings → Workspace. Contact support for account deletion.
  • Take it elsewhere. The export is machine-readable and yours.
  • Object. Email us to object to processing or ask about performance measurements. The cookie notice only saves a dismissal preference.
  • Complain. In the UK, to the Information Commissioner's Office. In the EU, to your local supervisory authority.

We answer requests within 30 days, usually within two business days.

Security

  • All traffic over TLS. All data encrypted at rest.
  • Connected account tokens encrypted with a separate key.
  • Row-level isolation between workspaces, enforced in the database rather than only in application code.
  • Access to production data is limited to what is needed to answer a support request or fix a fault, and it is logged.
  • We will notify affected users and the relevant regulator within 72 hours of becoming aware of a personal data breach.

Children

Ownerbar is not for under-16s and we do not knowingly collect their data. If you believe a child has an account, email us and we will delete it.

Changes

Material changes are emailed to account owners at least 30 days before they take effect, and every version is dated at the top of this page.

Contact

hello@steelcitysites.co.uk.