Privacy Policy — castleX designer
CASTLE X LTD (company no. 17205101, registered in England and Wales) is the data controller for personal data processed through castleX designer. This policy explains what we collect, why, and your rights under UK GDPR and the Data Protection Act 2018.
What we collect
- Account data — your e-mail address, the name you give, your company (if provided) and the date you accepted the Terms.
- Sign-in and security data — the time of each sign-in attempt, the IP address and browser / device type it came from, and whether it succeeded. Sign-in codes are stored only as one-way hashes and expire within minutes.
- Billing data — subscription status, plan and renewal dates, and the identifiers Stripe gives us. Card details are entered on Stripe's pages and never reach our servers.
- Your projects — layouts, quotes, surveys and files you save or upload, so that the Service can show them back to you.
- Technical data — server logs needed to run and protect the Service, and the performance report the app sends about the device it runs on (graphics card, timings — no content).
- Usage events — which steps of the Service were reached (for example: landing page viewed, trial started, first design saved, quote made). Each event carries a random visitor id and, for signed-in accounts, a keyed hash of the account — not your e-mail, IP address or browser details, and never the contents of your projects, prices or files.
- Free audit requests — the name, business, work e-mail, store type, approximate area and notes you type into the "free store layout audit" form on our site, with your consent to be contacted about it.
Why we use it (lawful basis)
- To provide the Service and your account — performance of a contract.
- To send sign-in codes, receipts and service notices — performance of a contract.
- To protect the Service against unauthorised use and copying, including alerting our administrators to sign-ins and refused attempts, and marking each copy of the Service with the account that opened it — legitimate interests (security and protection of our intellectual property).
- To keep accounting records — legal obligation.
- To understand how our own site and Service are used, in aggregate, and improve them — legitimate interests, using the minimal usage events described above.
- To reply to a free audit request and discuss it with you — your consent, given on the form; withdraw it at any time by e-mailing info@castlex.uk.
We do not sell personal data and we do not use it for advertising.
Who we share it with
- Stripe Payments (payments and invoices) — see stripe.com/privacy.
- Our hosting provider (Render) and our e-mail provider, which process data on our instructions to run the Service and deliver e-mail.
- Authorities, where the law requires it.
Some providers process data outside the UK; where they do, transfers rely on the UK International Data Transfer Agreement or an adequacy decision.
How long we keep it
Account data and projects: for as long as the account exists and up to 12 months after it closes. Sign-in and security logs: 12 months. Usage events: 12 months. Free audit requests: until the enquiry is closed and at most 24 months, unless you become a customer. Billing records: 6 years, as required by UK tax law. Uploaded survey files: as shown in the Service (currently 30 days unless saved to a project).
Your rights
You can ask for a copy of your data, have it corrected or deleted, restrict or object to its processing, and receive it in a portable form, by e-mailing info@castlex.uk. We answer within one month. You may also complain to the Information Commissioner's Office (ico.org.uk).
Cookies
The Service uses one strictly necessary cookie that keeps you signed in, one first-party cookie on our website that holds a random visitor id so we can count visitors and see which steps of our own site and app are used (it identifies a browser, not a person, is never shared and is not used for advertising), and the browser's local storage to remember your own settings on your device. No third-party advertising or analytics cookies are set.
Security
All traffic is encrypted (HTTPS). Sign-in is by one-time e-mail code; only one session per account is active at a time. Access to the Service and to administration pages is logged.
Changes
We will post any changes here and, where they matter, tell you by e-mail.