Privacy Policy
How Served Online collects, uses and protects data, and the rights you have under UK GDPR. This service is provided to businesses.
Who is responsible
Served Online is a trading name of Neatly Done, operated by Chris Charters (sole trader), Milton Keynes, England. Chris Charters is the data controller.
- Privacy contact: hello@servedonline.co.uk
- Correspondence address: 79 Broughton Grounds Lane, Brooklands, Milton Keynes, Buckinghamshire, MK10 7FD
- ICO registration: C1961955
Who this policy applies to
We sell to businesses. "You" means the business and its connected individuals. When we host a customer site that collects visitor data (for example, contact forms), we act as that customer's data processor — that relationship is governed by the Data Processing Agreement, not this policy.
What data we collect and where it comes from
- Public sources. Business name, trading address and phone number via the Google Places API and Companies House.
- Information you give us. Name, email, phone, business details and any content you upload via your portal.
- Account and portal data. Preferences, content edits and activity within your portal.
- Payment data. Stripe handles card data. We receive billing name and payment confirmation only — no card details.
- Email delivery data. SendGrid processes outbound emails and logs delivery status, including opens and clicks on prospecting email.
- Domain registration data. Passed to Namecheap and the relevant domain registry on your behalf.
- Server and security logs. IP address, browser type and pages visited. Used for security and performance monitoring only.
Where we obtained data you didn't give us directly
Prospect data is sourced from publicly available information (Google Places API and Companies House). Our first contact with you also serves as the Article 14 notice required by UK GDPR. You have the right to object or request erasure at any time — email hello@servedonline.co.uk.
Lawful bases
- Prospect contact. Legitimate interests. You can object at any time and we will add you to our suppression list.
- Service delivery. Contract performance.
- Financial records. Legal obligation. Retained 7 years per HMRC requirements.
- Suppression lists. Legal obligation and legitimate interests.
- Security and service monitoring. Legitimate interests.
Who we share your data with
- Stripe. Payment processing. stripe.com/privacy
- SendGrid (Twilio). Email delivery. twilio.com/en-us/legal/privacy
- Supabase. Database, hosted in the EU (Frankfurt). supabase.com/privacy
- Cloudflare. Hosting and CDN. cloudflare.com/privacypolicy
- Namecheap. Domain registration on your behalf. namecheap.com/legal
- Anthropic. The on-site assistant is currently rule-based and sends no personal data. If AI assistance is enabled, no personal data is retained beyond the session. anthropic.com/legal/privacy
- Google. Places/Maps API to locate trade businesses. No personal customer data is passed to Google.
We do not sell your data or share it for third-party marketing.
International transfers
Some providers (Stripe, SendGrid/Twilio, Cloudflare, Anthropic) process data outside the UK. Transfers are protected by the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or equivalent safeguards. Supabase is hosted within the EU.
How long we keep your data
- Active prospects. Deleted after 6 months of no engagement.
- Customers. 7 years from the end of the relationship.
- Opted-out contacts. Held indefinitely as a suppression record only.
- Server logs. Retained only as long as operationally necessary.
Your rights (UK GDPR)
Email hello@servedonline.co.uk to exercise any right. We respond within one month.
Cookies
Essential cookies only. See the Cookie Policy for details.
Complaints
You can complain to the ICO at ico.org.uk or on 0303 123 1113.
Changes to this policy
We may update this policy from time to time. The date at the top of this page always shows when it was last revised.
Governing law
England and Wales. UK GDPR as retained in UK law.