Privacy Policy
Last updated: 8 February 2026
1. Who We Are
PickedByAI is operated by Rob Hindhaugh, a sole trader based in the United Kingdom. For the purposes of data protection law, we are the data controller.
Contact: hello@pickedbyai.co.uk
2. Information We Collect
We collect information you provide directly to us:
- Business name, category, and location
- Email address
- Website URL
- Agency and contact details (if you register interest)
- Payment information (processed securely by Stripe — we never see or store your card details)
We automatically collect certain technical information when you use our service:
- IP address and device information
- Browser type and version
- Pages visited and time spent
- Referring website
3. Lawful Basis for Processing
We process your personal data on the following legal bases:
- Contract performance: To deliver the audit service you requested and manage your subscription
- Legitimate interests: To improve our service, prevent fraud, and send service-related communications
- Consent: For optional marketing emails (you can unsubscribe at any time)
4. How We Use Your Information
We use the information we collect to:
- Generate your AI visibility audit report
- Send you your audit results via email
- Process payments for paid services
- Improve our service and develop new features
- Send service-related communications (you can unsubscribe)
- Respond to your enquiries and provide support
5. Data Sharing and Third Parties
We share your information with the following third-party processors, solely to deliver our service:
- AI Service Providers: OpenAI, Anthropic, Perplexity, and Google — to generate audit insights. We send your business name, category, and location to these providers as part of query generation. We do not send your email address or personal details.
- Stripe: For secure payment processing
- Resend: For transactional emails
- Vercel: For website hosting
- Supabase: For secure data storage (hosted in the EU)
We do not sell your personal information to third parties.
6. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. All data is encrypted in transit using TLS and at rest in our database.
7. Data Retention
We retain your audit data for 12 months from the date of creation, or for the duration of your subscription plus 30 days, whichever is longer. After this period, data is deleted. You can request deletion of your data at any time by contacting us.
8. Your Rights (UK GDPR)
Under UK data protection law, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your data
- Restriction: Request limitation of processing
- Portability: Request transfer of your data in a machine-readable format
- Objection: Object to processing based on legitimate interests
To exercise any of these rights, email us at hello@pickedbyai.co.uk. We will respond within 30 days.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
9. Cookies
We use only essential cookies necessary for the website to function (such as authentication session cookies). We do not use advertising or tracking cookies. You can control cookies through your browser settings, though disabling essential cookies may prevent the service from working correctly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the updated policy on this page with a new "Last updated" date. Your continued use of the service after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have any questions about this Privacy Policy or how we handle your data, please contact us at:
Email: hello@pickedbyai.co.uk