Privacy Policy
What we collect, why, and your rights.
Last updated: 19 June 2026. This policy explains how AssetFrame collects and uses your personal data, and your rights under the UK GDPR and the Data Protection Act 2018.
Who we are (controller)
AssetFrame is the data controller for personal data processed through this site. For any privacy question, or to exercise your rights, contact us at contact@assetframe.co.uk. Where we act as controller, the providers listed in the sub-processors table below act as our processors (or, for card payments, as an independent controller in their own right).
What we collect
We keep what we need to run the service, and no more:
- Account data — your email address, name (if provided), and authentication details, handled by our identity provider, Clerk.
- Billing data — whether you have an active AssetFrame Pro subscription and the related billing identifiers we receive from our billing provider, Clerk. Card payments are processed by Stripe; neither Clerk nor Stripe passes us your full card details — we never see or store card numbers.
- Usage & analytics data — privacy-friendly, aggregated analytics about how the site is used and performs, and (only with your consent) Google Analytics measurement.
- Web-push subscription data — if you enable browser notifications, the push subscription endpoint and keys your browser generates, so we can send you alerts. We do not receive your identity from this beyond what you have already given us.
- Newsletter email — if you subscribe, your email address, captured with double opt-in (we send a confirmation link and only add you once you confirm), plus your subscription status and unsubscribe events.
- Feedback & support correspondence — messages, ratings, and feedback you send us.
- Watchlists & follows — the instruments or reports you choose to save or follow, so we can tailor what we show and notify you about.
- IP address & logs — standard server/CDN log data (such as IP address, device/browser type, timestamps, and request details) used to deliver, secure, and debug the service.
How we use it, and our lawful bases
We process your data for the purposes below, and we rely on the lawful basis shown for each under UK GDPR:
- Create and secure your account; deliver the reports you are entitled to; process subscriptions and payments — performance of a contract with you (and legal obligation for tax/invoicing records).
- Provide support and respond to your feedback — performance of a contract and our legitimate interests in helping users and improving the service.
- Operate watchlists and follows, and send related product/web-push notifications — performance of a contract (delivering features you ask for), with web-push enabled only on your consent via your browser.
- Send the newsletter — your consent (double opt-in), which you can withdraw at any time by unsubscribing.
- Secure the service, prevent fraud and abuse, debug, and keep logs — our legitimate interests in running a safe, reliable service.
- Optional analytics cookies (Google Analytics) — your consent, given through the cookie banner.
- Privacy-friendly, cookieless measurement — our legitimate interests in understanding aggregate traffic and performance without identifying you.
- Meet legal and regulatory obligations — legal obligation.
Where we rely on legitimate interests, we have balanced those interests against your rights and consider the processing proportionate. You can object to legitimate-interests processing at any time (see “Your rights”).
Who we share it with (sub-processors)
We share data only with the providers that run AssetFrame, each under their own data-protection terms and only as needed for the purposes above. We do not sell your personal data and we do not share it for third-party advertising. Some of these providers process data outside the UK; where they do, the transfer is protected by an appropriate safeguard (see “International transfers”).
| Provider | Purpose | Location |
|---|---|---|
| Clerk | Authentication, account management & subscription billing | USA |
| Stripe | Payment processing (card payments for Pro subscriptions) | USA / global |
| Neon | Database — accounts, subscription status, watchlists, follows, report catalogue & track record | EU (London region) |
| Cloudflare | Private Pro-file storage (R2) & content delivery | Global edge |
| Vercel | Website hosting & privacy-friendly product analytics | USA / global edge |
| Google Analytics | Optional usage analytics — only with your consent | USA |
| Google (Places) | Displaying business reviews & ratings | USA |
| Resend | Transactional & newsletter email delivery | USA |
We may also disclose data where required by law, to enforce our terms, or to protect our rights, users, or the public.
Cookies & consent
Strictly necessary cookies — authentication and session cookies set by Clerk when you sign in. These are essential to log you in and need no consent.
Cookieless measurement — our default traffic and performance measurement (Vercel Web Analytics and Speed Insights) does not use cookies and does not identify you.
Analytics cookies (Google Analytics) — these are consent-gated and load only after you accept the cookie banner. If you choose Reject, no Google Analytics cookies are set. We store your banner choice in your browser's local storage so we don't ask again; you can change your mind by clearing that choice or adjusting your browser settings.
Web-push notifications
If you opt in, your browser creates a push subscription (an endpoint plus encryption keys) which we store so we can send you alerts about reports, watchlists, or follows. We use this only to deliver notifications you have asked for.
You can revoke push notifications at any time — either in your browser's site-notification settings, or from your account. Revoking stops further notifications and invalidates the stored subscription.
How long we keep it
We keep account, watchlist, and follow data while your account is active and for a reasonable period afterwards, then delete or anonymise it. Subscription and billing/tax records are retained by us and our billing and payment providers for as long as the law requires. Newsletter data is kept until you unsubscribe (plus a short suppression record so we don't re-add you). Web-push subscriptions are kept until you revoke them or they expire. Server and analytics logs are kept only for a short period for security and operational purposes.
Your rights
Under UK GDPR you have the right to: access your data; rectify inaccurate data; erase your data (“right to be forgotten”); request portability of data you gave us; restrict processing; object to processing based on legitimate interests; and withdraw consent at any time (for example, by unsubscribing from the newsletter or disabling web-push), without affecting processing carried out before withdrawal.
Email contact@assetframe.co.uk to exercise any of these and we will respond within the statutory time limit (normally one month). You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk if you are unhappy with how we handle your data — though we'd appreciate the chance to put things right first.
Security
Access to your account and to paid content is protected by authentication and short-lived, signed download links. Data is encrypted in transit, access is restricted, and we apply reasonable technical and organisational measures appropriate to the risk. No system is perfectly secure, but we work to protect your data and to notify you and the ICO of any breach where the law requires.
International transfers
Some of our providers process data outside the UK (for example, in the United States). Where they do, the transfer is protected by an appropriate safeguard recognised under UK law — such as an adequacy decision, the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses with the UK Addendum, or the UK extension to the EU–US Data Privacy Framework — together with any additional measures required to protect your data.
Children
AssetFrame is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the “last updated” date above; significant changes affecting your rights will be brought to your attention.
Contact
For any privacy question, or to exercise your rights, contact contact@assetframe.co.uk.