Privacy Notice
Last updated: 5 August 2026
This notice explains how My Pocket Marketer Ltd collects and uses personal data through the My Pocket Marketer website and application (the Service), including the free marketing snapshot and the paid marketing plan.
1. Who we are
My Pocket Marketer Ltd is the controller of the personal data described in this notice. It is registered in England and Wales under company number 17312916, with its registered office at 2 Claridge Court, Lower Kings Road, Berkhamsted, England, HP4 2AF (we, us or our).
For privacy questions or to exercise your rights, contact emily@mypocketmarketer.com.
2. Who the Service is for
The Service is for adults acting for business purposes, including property professionals. It is not intended for children or for personal or household use. We do not knowingly collect personal data from anyone under 18.
3. Personal data we collect
| Category | Examples | How we obtain it |
|---|---|---|
| Identity and contact data | Name, business email address and display name | From you when you request a snapshot, create an account or contact us |
| Business profile data | Business name, business type and optional website or social-media URLs | From you |
| Report-selection data | The geographic area you select and your report preferences | From you |
| Account and security data | Email address, password hash, authentication data and account status | From you and generated by the Service. Your password is hashed before storage and is not stored in readable form |
| Subscription and transaction data | Stripe customer, subscription and price reference IDs, plan, payment status and transaction records | From you and Stripe. We do not receive or store your full card number |
| Report data | Free snapshots, paid reports, source references, scores, recommendations and previous report versions | Generated by the Service from your choices and licensed or aggregate data |
| Technical and usage data | IP address, request time, browser/device information, security signals and error logs | Automatically from your device and from hosting/security providers. IP addresses are not intended to be stored in our application database but may be held temporarily in provider or security logs |
| Communications data | Support, cancellation, privacy and other messages, plus our responses | From you and generated by us |
| Marketing preference data | Consent, opt-out and suppression records | From you when you choose to receive marketing, and generated by us when we record or update your preference |
| Publication contact data | A contact email address and phone number that you ask us to print in the marketing we write for you | From you, and only if you choose to give them. Both are optional |
We do not intentionally collect special-category data, criminal-offence data or personal data about the customers of your business. Please do not include such data in form fields or messages unless it is necessary and you have agreed this with us first.
If you give us personal data about another person, you must have authority to do so and give them this notice where appropriate.
4. Required and optional information
We need your name, email, business name, business type and selected geography to provide a free snapshot. If you do not provide these, we cannot provide that service. We need account and billing information to provide a paid subscription.
Your website address and social-media presence are optional. The website may be given when you request a snapshot; since 13 September 2026 both are asked for together on the Business Context form after you subscribe, where you can confirm, change or remove anything you gave earlier. We use them so that the strategy we build can tell the difference between channels you already use and ones you would be starting from scratch, and so that marketing we write for you can carry your real website address and social-media handles. This means the address and any handle you give are sent to our AI provider. We do not send the content of those pages, and we do not visit, measure or assess your website or social-media accounts.
The contact email address and phone number on the Business Context form are optional, and they are the only optional answers on it. We use them for one purpose: printing them in the marketing we write for you, such as a press release or an advert. If you leave them blank, that marketing simply asks readers to get in touch with your business without saying how, and nothing else about the service changes. Give us only details you are content to see published — if you trade as an individual, a personal mobile number printed in a local newspaper is public for good. You can change or remove them at any time by contacting us, though we cannot recall marketing you have already sent out.
5. How and why we use personal data
UK data-protection law requires us to have a lawful basis for each use.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Provide the free snapshot you request | Identity, contact, business profile, report-selection and report data | Performance of our contract with you; our legitimate interests in providing and protecting the Service |
| Create, authenticate and administer your account | Identity, contact, business profile, account and security data | Performance of our contract; our legitimate interests in account security |
| Provide and archive paid marketing intelligence | Business profile, report-selection, subscription and report data | Performance of our contract |
| Take payment and manage renewals or cancellation | Identity, contact, subscription and transaction data | Performance of our contract; compliance with accounting and tax obligations |
| Prevent fraud, bots and abuse; secure and troubleshoot the Service | Technical, usage, account, security and relevant error data | Our legitimate interests in running a secure and reliable service; compliance with applicable security obligations |
| Provide support and deal with privacy requests | Identity, contact, account and communications data | Performance of our contract; compliance with legal obligations; our legitimate interests in customer administration and legal claims |
| Send account, security, renewal and material-change notices | Identity, contact, account and subscription data | Performance of our contract; our legitimate interests; legal obligation where applicable |
| Send direct marketing | Identity, contact and marketing preference data | Your consent, given by ticking the optional marketing box. You may withdraw it at any time |
| Comply with law, obtain advice, manage disputes or support a corporate transaction | Data relevant to the issue | Legal obligation; our legitimate interests in protecting legal rights and administering our business |
Where we rely on legitimate interests, we consider the effect on the people concerned and do not use personal data where their interests or rights override ours.
6. AI-generated reports
We use Anthropic's commercial AI service to write parts of the narrative in a snapshot or report. The input-builder is designed to send only:
- a business-type category;
- the selected geography name or code; and
- aggregate geodemographic and media/channel statistics for that area.
It is not designed to send your name, email, login credentials, payment data or website/social-media URLs. We contract for commercial API use and do not authorise Anthropic to use our API inputs or outputs to train general models.
The underlying scores and rankings are calculated separately. The AI writes narrative around those results. The Service does not use AI to make a decision about an identifiable person that produces legal or similarly significant effects. AI-generated content can be incomplete or inaccurate, so it should be reviewed before being relied on.
7. Who receives personal data
We use service providers and may disclose data to other recipients where necessary.
| Recipient | What it does and receives |
|---|---|
| Neon | Hosts the production database, including account, business and report records |
| Vercel | Hosts and delivers the application and processes requests and time-limited application logs. Also provides aggregate, non-identifying visit analytics (Vercel Web Analytics) — see our Cookie and Similar Technologies Notice |
| Sentry | Records and helps us investigate application errors. Depending on the error, it may receive technical and usage information, request details, an account or user identifier and relevant error context |
| Stripe | Processes payments and subscriptions. Stripe acts on our instructions for some activities and as an independent controller for others, such as meeting its own legal and fraud-prevention obligations |
| Anthropic | Generates narrative from business type and aggregate area statistics. Direct personal identifiers are not intended to be sent |
| Google reCAPTCHA | Helps prevent bots, fraud and abuse and may process IP address, device/browser information, cookies and security signals under Google's terms |
| Microsoft 365 | Hosts privacy, support, cancellation and other business email |
| Mailchimp (Intuit) | Sends marketing email and manages the marketing list, where you have opted in. Receives your email address and contact name only |
| Resend | Sends the password-reset email when you ask to reset your password. Receives your email address and the reset link only |
| Professional advisers, insurers, courts, regulators and authorities | Receive relevant information where needed for advice, insurance, legal claims or compliance |
| A buyer, investor or successor | May receive appropriately protected and minimised information during a proposed or completed sale, investment or reorganisation |
Our providers may use their own subprocessors. We require processors to protect personal data and use it only for the contracted service.
We do not sell personal data or disclose it to another organisation for that organisation's own marketing.
8. International transfers
Some providers, support teams or subprocessors may access personal data outside the UK. Where UK transfer restrictions apply, we use an approved safeguard. Depending on the provider and destination, this may be:
- UK adequacy regulations, including a valid UK Extension to the EU-US Data Privacy Framework;
- the UK International Data Transfer Agreement; or
- the UK Addendum to the EU Standard Contractual Clauses,
together with a transfer-risk assessment and any additional protections needed. Contact us if you would like more information about the safeguard used for a particular provider.
9. How long we keep personal data
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected. We consider the type of information, why we need it, legal and contractual requirements, security and dispute risks, and the retention settings of the systems we use.
| Information | How long we keep it |
|---|---|
| Free snapshot information where no account is created | Normally for up to 12 months after the last interaction |
| Account, business profile and report information | While the account remains registered with us and the information is needed to administer it or preserve report history. Cancelling a subscription does not delete the account. You may request deletion at any time |
| Support and routine correspondence | Normally for 24 months from the date the message is received. It may be kept longer where needed for an ongoing complaint, dispute, incident or legal claim |
| Technical, security and error information | For the shortest period reasonably needed to secure, operate and troubleshoot the Service. Routine records are normally kept for no more than 90 days. Records relating to an active incident, investigation or claim may be kept longer |
| Marketing information | Until you withdraw consent or object. We may retain a minimal suppression record for as long as needed to honour an opt-out |
| Financial, legal and compliance records | For the applicable statutory or legal-claims period. Accounting and transaction records are normally kept for six years after the end of the relevant financial year |
| Backups | Deleted information may remain in encrypted rolling backups for up to seven days, where it is put beyond ordinary use and is not restored to live use |
The detailed periods applied to individual systems and providers are recorded in our internal retention schedule and reviewed regularly.
10. Direct marketing
We send marketing email only to people who have asked to receive it. When you request a free snapshot you may tick a separate, optional box to opt in. It is never pre-ticked, and leaving it unticked has no effect on the report you receive or on any other part of the service.
Where you opt in, we record the date, the place you opted in and the exact wording you agreed to, so we can show what you were told. We pass your email address and contact name to Mailchimp, which sends the marketing email on our behalf, and we tag you as a website subscriber. We do not pass any other information to Mailchimp.
You can object to direct marketing or withdraw consent at any time by using the unsubscribe route in the message or contacting us. This will not stop service, payment, security or legal notices. Withdrawing consent does not affect processing that was lawful before withdrawal.
11. Cookies and similar technologies
We use authentication and security technologies, including Auth.js cookies and Google reCAPTCHA, and aggregate, non-identifying visit analytics (Vercel Web Analytics, which does not use cookies). We do not currently use advertising or individual-tracking analytics technologies. More detail is in our Cookie and Similar Technologies Notice.
12. Security
We use technical and organisational measures intended to protect personal data. These include password hashing, encrypted connections, provider encryption at rest, access controls, multi-factor authentication for administrative accounts, rate limiting, bot protection, environment separation, backups and time-limited logging.
No system is completely secure. You are responsible for choosing a strong, unique password and telling us promptly if you suspect unauthorised access.
13. Your rights
Depending on the circumstances, you may have the right to:
- obtain a copy of your personal data and information about its use;
- correct inaccurate or incomplete personal data;
- have personal data deleted;
- restrict how personal data is used;
- receive personal data you provided in a portable form;
- object to processing based on legitimate interests;
- object at any time to direct marketing; and
- withdraw consent at any time where processing relies on consent.
Some rights are conditional and exemptions may apply. For example, we may need to retain transaction records to comply with law. We will explain any decision not to comply fully.
Contact us to exercise a right. We may ask for proportionate information to confirm your identity. Requests are normally free of charge and we will respond without undue delay, normally within one month.
Account deletion is handled manually. Cancelling a subscription does not automatically delete an account, and deleting an account does not by itself cancel a Stripe subscription. Tell us clearly whether you want cancellation, account deletion or both.
14. Complaints
You have the right to complain to us if you believe we have not handled your personal data in accordance with data-protection law. Please send your complaint to emily@mypocketmarketer.com.
We will acknowledge a data-protection complaint within 30 days. We will investigate it appropriately, keep you informed where necessary and tell you the outcome without undue delay.
You may also complain to the Information Commissioner's Office, the UK data-protection regulator, through ico.org.uk/make-a-complaint. Your right to contact the ICO is not affected by complaining to us first.
15. Changes to this notice
We will update this notice when our use of personal data changes and will change the date at the top. We will give registered users direct advance notice of a material change where it is practical and appropriate.