Privacy Policy
Version 1.3 · Last updated 2 October 2026
This policy explains how Spire Trade Advisors Ltd (“we”) collects and uses personal data when you use companypolicies.ai. We are the controller of that data under the UK GDPR and the Data Protection Act 2018 and, where it applies, the EU GDPR.
1. Contact details
Spire Trade Advisors Ltd, company number 16562883, 9 Soapworks House, Carrack Mews, London, England, E16 2EN. Email: contact@spiretrade.co. ICO registration number: [ICO REGISTRATION NUMBER — PENDING].
EU representative (Article 27 EU GDPR): Not appointed.
2. What we collect
- Order and acceptance information: your email address, organisation name and registration number, country, selected Templates, the Terms version you accepted, your confirmations, and the date and time; plus technical data submitted with it (a truncated or hashed IP address and browser user-agent).
- Payment information: handled by Stripe. We receive payment status, amount, billing name/address, any VAT/tax ID you provide and the last four digits and brand of your card — not your full card number.
- Company details you type into the generator (for example addresses and the name of your responsible person) and your logo: these are processed in your browser to generate documents and saved in your browser’s local storage so you can return to them. They are not sent to our servers before you pay, except for the fields listed above.
- Tailoring answers you give after payment (for example staff numbers, sites, energy use, vehicles and waste arrangements): saved against your order so you can return to them and, if you bought updates, reuse them.
- When you pay: the company details you entered in the generator and your logo are saved against your order, so the link to your order (on the confirmation page and in your order confirmation email) reopens your documents on any device. If you buy the 12 months of updates add-on, we also use them to regenerate and email your updated policies.
- Free tailored Whistleblowing policy: if you create one we collect your name, company name and work email (required to receive the policy), your answers about your organisation (for example sector, headcount, nations, risk areas, reporting routes and timescales, training, the names and roles of your Whistleblowing Officer, any deputy or escalation contact, and the approving director), the page design version you saw, the date and time, and whether you ticked the optional marketing box (with the time and wording). We use this to generate and send your policy, to issue your personal discount code (created in our payment provider Stripe, which records the code and its expiry, not your answers), to understand how our service is used and, only if you opted in, to send tender tips and policy updates. The generated PDF and Word files are stored for 12 months so you can download them again. If you created our earlier free Modern Slavery policy (offered until 2 October 2026), we hold the equivalent details you gave us then on the same basis.
- “My policies” sign-in: if you sign in with your email we send a one-time 6-digit code (stored only as a keyed hash, valid for 10 minutes) and set a strictly necessary sign-in cookie for 7 days. We use your email to show the purchases and free samples linked to it.
- Earlier free sample and checker: if you requested our earlier free sample policy we collected your email address, company name, optional contact name, sector and (optionally) your logo, which we used to generate your documents. Those files are stored for 30 days so you can download them. If you run the free checker, we store your answers and any tender text you paste (not your identity) for up to 90 days so a paid report can be generated from them. Please don’t paste personal data into the checker.
- Email preferences: whether you ticked the box to receive marketing emails, when you did so, and any unsubscribe.
- Enquiries and partner applications you send through our forms (name, email, company or organisation, type of organisation, website and phone if given, a description of your clients, message). If we approve a partner, we also keep their partner code, status, commission records and the bank details they send us for payouts.
- Referral and partner records: the referral or partner code used on an order and the resulting reward or commission. For refer a friend: your personal referral link; the email address a referred friend gives us to claim their discount (used only to check they are a new customer and to issue their code); whether a referred order was placed; rewards issued; and the details and documents you send us to claim a tender check (emailed to our support mailbox and used only to carry out the check). We don’t tell referrers who their friends are.
- Correspondence if you contact us.
- Anonymous usage statistics from our own cookieless analytics: pages viewed, key actions, approximate country, device type and referring site or campaign, linked only to a one-way visitor code that changes every day (created from your IP address and browser user-agent with a daily random value; the raw IP address is not stored). Lawful basis: legitimate interests in understanding and improving the Service. Individual event records are deleted after 90 days; daily totals are kept for up to 25 months.
- Analytics and advertising cookie data — only if you accept optional cookies: through Google Analytics, Microsoft Clarity and Google Ads, the providers collect information such as the pages you visit, clicks and scrolling, the ad or campaign that brought you, device and browser details, approximate location, cookie identifiers and, on the order confirmation page, the order value and order reference (never your name, email or payment details). See our Cookie Policy for each tool and its cookies.
- Technical data held by our hosting provider in server logs (e.g. IP address, request time) for security.
3. Why we use it and our lawful bases
- To provide the Service, take payment and deliver documents — performance of a contract.
- To keep evidence of your acceptance of our Terms and to defend legal claims — legitimate interests (establishing, exercising and defending legal claims).
- To meet accounting, tax and other legal obligations — legal obligation.
- To secure and improve the Service — legitimate interests.
- Optional analytics cookies (A/B testing, Google Analytics, Microsoft Clarity) and, separately, marketing cookies that measure our ads (Google Ads), only if you opt in — consent, which you can withdraw at any time (see our Cookie Policy).
- Service emails about your order or sample (delivery, receipt, updates you bought, and a policy review reminder about 11 months after purchase) — performance of a contract / legitimate interests.
- Marketing emails (for example tender tips and policy updates after a free sample) — only if you ticked the consent box, or, for existing customers, about our own similar products where you were given a simple way to opt out when you bought and in every message (the PECR “soft opt-in”). Every marketing email has a one-click unsubscribe.
- Checkout reminders: if you start a checkout and don’t finish it, we may send up to two reminder emails (about 1 hour and 24 hours later; the second may include a time-limited discount) — legitimate interests and the PECR “soft opt-in” for a sale in negotiation. You can opt out at checkout (“Don’t send me checkout reminders”) or with the unsubscribe link in every email.
- Enquiries and partner applications — to reply to you and, for partners, to assess the application, calculate commission and pay it (legitimate interests / steps before a contract / contract). When a customer uses a partner code, we tell that partner only what we need to calculate their commission (order date, amount and the customer’s email domain). Bid-writing enquiries are shared with the West Gate bid team, who deliver that service.
4. Who we share it with
- Stripe (payments) — Stripe acts as an independent controller for some processing; see Stripe’s privacy policy.
- Netlify, Inc. (website hosting, serverless functions and storage of acceptance and order records) — processor.
- Resend (Plus Five Five, Inc.; sending order confirmations, download links and other emails from its EU (Ireland) region) — processor.
- Google (Google Ireland Limited and Google LLC; Google Analytics and Google Ads conversion tracking) — only if you accept the relevant cookies. Google acts as our processor for Google Analytics and as an independent controller for some Google Ads processing; see Google’s privacy policy.
- Microsoft (Microsoft Corporation and Microsoft Ireland Operations Limited; Microsoft Clarity) — only if you accept the relevant cookies. Microsoft acts as an independent controller for this data; see the Microsoft Privacy Statement.
- Professional advisers, and authorities where required by law.
5. International transfers
Some providers (e.g. Netlify, Stripe and, if you accept their cookies, Google and Microsoft) may process data in the United States or elsewhere outside the UK/EEA. Where they do, we rely on an adequacy decision/UK data bridge where available or on appropriate safeguards such as the UK International Data Transfer Addendum or EU Standard Contractual Clauses. [TO CONFIRM per provider.]
6. How long we keep it
- Order and acceptance records: 6 years after the order (limitation period for contract claims), then deleted.
- Accounting records: as required by law (normally 6 years).
- Company details and logo saved against your order: deleted within 3 months after the 12-month period from purchase (or, with the updates add-on, the 12-month update period) ends (order and acceptance records are kept as above).
- Tailoring answers: kept with the order record; you can ask us to delete them at any time.
- Update download links: expire after 30 days.
- Free sample files: 30 days (tailored free policy files, Whistleblowing and earlier Modern Slavery: 12 months). Sign-in codes: 10 minutes; sign-in sessions: 7 days. Sample request (lead) records and email preferences: until you unsubscribe or 24 months after our last contact, whichever is sooner, but we keep a minimal suppression record so we don’t email you again.
- Enquiries: 24 months after the last contact.
- Queued emails: deleted once sent or cancelled. Records of sent emails: 12 months.
- Browser-stored generator data: on your device until you clear it.
- Analytics and advertising cookie data: cookies expire as listed in our Cookie Policy; Google Analytics event data is kept for 14 months; Microsoft Clarity keeps session replays for about 30 days and heatmap data for about 13 months; data held by the advertising providers is kept under their own retention policies.
7. Your rights
You have rights to access, rectify, erase, restrict and object to processing of your personal data and to data portability, and to withdraw consent at any time. Contact contact@spiretrade.co. You can complain to the UK Information Commissioner’s Office (ico.org.uk) or, if you are in the EEA, your local supervisory authority.
8. Security
We use HTTPS, limit access to personal data, and minimise what we collect — for example by generating documents on your device rather than our servers.
9. Changes
We will post any changes on this page with a new version number.