Privacy Policy
Last updated: 4 July 2025
Your privacy is important to us. This policy explains how we collect, use, and protect your personal data in compliance with UK GDPR and data protection laws.
1. Who We Are
Upsticks Directory is a UK property services directory operated by UPSTICKS DIRECTORY LTD. We are committed to protecting and respecting your privacy in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Data Controller: UPSTICKS DIRECTORY LTD
Contact: privacy@upsticksdirectory.co.uk
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, phone number when you register as a business
- Business Information: Company details, business descriptions, contact information, addresses
- Contact Forms: Messages sent through our contact forms or Group Contact feature
- Payment Information: Billing details for business subscriptions (processed securely by our payment provider)
2.2 Information We Collect Automatically
- Usage Data: Pages visited, search queries, time spent on site
- Device Information: IP address, browser type, device type, operating system
- Location Data: Approximate location based on IP address for search results
- Cookies and Tracking: See our detailed cookies section below
3. How We Use Your Information
3.1 For Customers
- Provide search functionality and display relevant property professionals
- Enable Group Contact feature to message multiple businesses
- Improve our service and user experience
- Respond to support requests
3.2 For Business Members
- Display your business listing in search results
- Process subscription payments
- Send customer enquiries and Group Contact messages
- Provide account management and support
- Send service updates and important notifications
4. Legal Basis for Processing
We process your personal data based on:
- Contract: To provide our directory service and fulfill business subscriptions
- Legitimate Interest: To improve our service, prevent fraud, and ensure security
- Consent: For non-essential cookies and marketing communications
- Legal Obligation: To comply with tax, accounting, and legal requirements
5. Cookies and Tracking Technologies
We use cookies and similar technologies to provide and improve our service. Here are the types of cookies we use:
5.1 Essential Cookies
These cookies are necessary for our website to function properly:
- Session Cookies (koa.sess): Maintain your session and login state
- CSRF Token: Protect against security threats
- Authentication Cookies: Keep you logged into your account
5.2 Analytics Cookies
We use Google Analytics to understand how our website is used:
- Google Analytics (_ga, _ga_*): Track website usage and performance
- Purpose: Understand user behavior, improve our service
- Retention: Up to 2 years
- Opt-out: Use our cookie preferences or Google's opt-out tool
5.3 Third-Party Service Cookies
Our service providers may set their own cookies:
- Cloudinary: Image hosting and optimization service
- Google Services: Maps, authentication, and other Google services
- Intercom: Customer support chat functionality
- Marketo: Marketing automation and tracking
5.4 Managing Cookies
You can control cookies through:
- Our cookie consent banner when you first visit
- Your browser settings (though this may affect website functionality)
- Third-party opt-out tools for analytics services
6. How We Share Your Information
We only share your information in these circumstances:
6.1 With Property Professionals
When you contact businesses through our platform, we share your contact details and message with the relevant property professionals.
6.2 With Service Providers
- Payment Processors: To handle business subscription payments
- Email Services: To send notifications and support communications
- Analytics Providers: Google Analytics for website performance
- Hosting Providers: To store and serve our website and data
6.3 Legal Requirements
We may disclose information when required by law or to protect our rights and safety.
7. Data Security
We implement appropriate security measures including:
- SSL encryption for data transmission
- Secure hosting with regular security updates
- Access controls and authentication
- Regular security monitoring and testing
- Staff training on data protection
8. Data Retention
- Customer Data: Contact form submissions retained for 2 years
- Business Data: Retained while subscription is active plus 7 years for tax purposes
- Analytics Data: Anonymized data retained for up to 2 years
- Support Communications: Retained for 3 years
9. Your Privacy Rights
Under UK GDPR, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate personal data
- Erasure: Request deletion of your personal data
- Portability: Receive your data in a portable format
- Restriction: Limit how we process your data
- Objection: Object to processing based on legitimate interests
- Withdraw Consent: For processing based on consent
To exercise these rights, contact us at privacy@upsticksdirectory.co.uk
10. International Data Transfers
Some of our service providers (like Google Analytics) may transfer data outside the UK. We ensure appropriate safeguards are in place, including adequacy decisions and standard contractual clauses.
11. Children's Privacy
Our service is not intended for children under 16. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information, please contact us.
12. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of significant changes by email (for business members) and by posting a notice on our website.
Contact Us
If you have questions about this privacy policy or our data practices, please contact us:
Privacy Officer: privacy@upsticksdirectory.co.uk
General Support: support@upsticksdirectory.co.uk
Data Protection Queries: upsticksdirectory.co.uk/contact-us
Complaints: You can also contact the Information Commissioner's Office (ICO)