Privacy notice
Last updated 9 September 2026
This notice explains what personal data we hold, why we hold it and what you can do about it. The controller is the company set out on the legal information page, and it applies the UK GDPR and the Data Protection Act 2018, the EU GDPR where it applies to you, and the California Consumer Privacy Act where it applies to you.
Two things worth saying at the top. This service accepts no image uploads of any kind — there is no upload channel to build one on. And the dimensions and route descriptions you enter are not used to train any model, ours or anybody else’s.
What we collect and why
- Your email address and password
- To create your account and let you sign back in. Lawful basis: performance of our contract with you. Passwords are stored only as a salted hash and cannot be read back.
- The routes and measurements you enter
- The item description, the numbers you measured and the unit you typed them in, so a reading can be produced and, on the Movein plan, so a route can be reused. Lawful basis: performance of our contract with you. These are not personal data in themselves, but they are held against your account, so they are treated as if they were.
- Billing records
- Which plan you are on, when it renews, and the receipts we are required to keep. Lawful basis: legal obligation, and performance of our contract. We never receive or store your card number: it is entered on our payment provider’s own secure hosted page.
- Support correspondence
- To answer you and to keep a record of what was agreed. Lawful basis: legitimate interests.
- Analytics, only if you say yes
- Counts of page visits, with no attempt to identify you. Lawful basis: your consent, which you can withdraw at any time from the cookies page. Saying no changes nothing about how the site works.
We do not buy personal data, and we do not sell or share it for advertising.
How long we keep it
- Account data: while the account is open, and for 30 days after it is closed.
- Routes and measurements: while the account is open. You can delete any of them yourself at any time.
- Billing records: six years, because tax law requires it.
- Support correspondence: two years.
- Analytics: 14 months, and only if you consented.
Who else sees it
Only the processors we need to run the service: a hosting provider, a database and authentication provider, an email provider, and a payment provider. Each is bound by a written contract that permits them to act only on our instructions.
We disclose personal data to anyone else only where the law requires it, and we tell you when we can lawfully do so.
Transfers out of the United Kingdom
Some of our processors operate outside the UK. Where personal data is transferred, we rely on UK adequacy regulations where they cover the destination, and otherwise on the UK International Data Transfer Agreement, or on the EU Standard Contractual Clauses together with the UK Addendum, in each case with a transfer risk assessment on file.
You can ask us for a copy of the safeguards that apply to a particular transfer.
Your rights
- Ask for a copy of the personal data we hold about you.
- Have inaccurate data corrected.
- Have data deleted, where we have no overriding reason to keep it.
- Ask us to restrict how we use it while a question about it is resolved.
- Receive the data you gave us in a portable form.
- Object to processing we carry out on the basis of legitimate interests.
- Withdraw consent to analytics at any time, with no effect on anything else.
Email support@sparklingen.shop. We answer within one month and there is no charge. We will never make you justify a request.
If you are in California, you also have the right to know what is collected, to have it deleted, to correct it, and not to be treated differently for exercising those rights. We do not sell or share personal information as those terms are defined there.
Complaining to a regulator
If you think we have handled your personal data wrongly, you have the right to complain to the Information Commissioner’s Office, the United Kingdom’s data protection regulator, at ico.org.uk, by telephone on 0303 123 1113, or by post to Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
You can complain to the ICO without contacting us first, though we would rather have the chance to put it right.
Security
Everything is served over HTTPS. Passwords are hashed. Access to production data is limited to the people who need it and is logged. If a breach occurs that is likely to result in a risk to your rights, we tell the ICO within 72 hours and tell you without undue delay where the risk is high.
Automated decisions
Nothing here makes an automated decision that produces a legal effect for you. A reading is a calculation you asked for, and the numbers it works from are the ones you entered.