This policy explains how Clearpath Labs Ltd ("we", "us") - trading as SnapAddress - collects, processes, and protects personal data when you use the SnapAddress API, dashboard, or WooCommerce plugin (the "Service"). We are the data controller for the information described here.
Who we are
Clearpath Labs Ltd (company no. 17145150) is registered in England and Wales at 35 Floyer Close, Richmond, England, TW10 6HS. We act as the data controller for the account and usage data described here. You remain responsible, as controller, for any personal data you or your end users submit to your own application. Where we process lookup queries on your behalf, we act as your processor under our Data Processing Agreement. For privacy queries, contact snapaddress@clearpathlabs.co.uk.
What we collect
- Account data - your email address and authentication identifiers, held by Supabase on our behalf.
- Billing data - Stripe customer and payment identifiers. Payment card details are handled by Stripe and never touch our servers.
- API credentials - we store hashes of your API keys, never the raw keys after issuance.
- Usage events - timestamps, request metadata, and the postcode queried. Postcodes on their own are not personal data under UK GDPR, but in combination with other identifiers (e.g. your account) may be treated as personal data and are handled accordingly.
- Operational logs - standard server logs (including IP address) retained briefly for abuse prevention and debugging.
We do not store the addresses returned to end users of your application. Lookups are served from our own licensed copy of the Royal Mail PAF data; we do not send your queries to Royal Mail.
Why we process it
- Contract - to provide the Service you signed up for: issuing API keys, authenticating requests, metering usage, billing.
- Legitimate interest - to prevent abuse, protect the Service, and improve reliability.
- Legal obligation - to retain records required for tax and accounting.
Sub-processors
We rely on the following sub-processors to run the Service:
- Supabase - authentication and database hosting (EU region).
- Stripe - payment processing (US).
- Vercel - website and API hosting (UK/London function region).
- AWS (Amazon Web Services) - address-lookup API infrastructure (UK/London region, eu-west-2).
- Resend - delivery of transactional and lifecycle emails, such as sign-up, purchase confirmation and credit-expiry reminders (US).
- Sentry - error monitoring and diagnostics (EU region).
Royal Mail is the licensor and source of the PAF (Postcode Address File) data, not a sub-processor: we query our own licensed copy of PAF and do not send your lookup queries to Royal Mail.
How long we keep it
- Usage events - 13 months, to cover the billing dispute window.
- Account and billing records - for the life of your account, plus the period required by UK tax law after deletion.
- Server logs - up to 30 days.
Your rights under UK GDPR
You can request:
- Access to the personal data we hold about you
- Correction of inaccurate data
- Erasure of your account and associated data - you can delete your account any time from the billing page
- Restriction of our processing of your data in certain circumstances
- A portable copy of your data
- To object to processing based on legitimate interest
When you delete your account we anonymise your personal data, but we retain a non-identifying record of credit transactions and usage events where required for tax, accounting, and Royal Mail PAF licence audit obligations.
To exercise any of these rights, email snapaddress@clearpathlabs.co.uk. You can also complain to the UK Information Commissioner's Office at ico.org.uk.
International transfers
Most processing takes place in the UK or the EEA: Vercel function execution and the AWS address-lookup infrastructure run in the UK (London) region, and Supabase and Sentry operate in the EU (EEA). Some sub-processors process personal data outside the UK/EEA - currently Stripe and Resend, both in the US. For each such transfer we rely on the UK Extension to the EU-US Data Privacy Framework (the UK-US Data Bridge) where the sub-processor is certified under it, and otherwise on the UK International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses) in that sub-processor's data processing agreement.
Cookies
We use a small number of first-party cookies strictly necessary to keep you logged in and to remember your preferences. We do not use advertising or tracking cookies.
Changes to this policy
If we make material changes we will update the "last updated" date above and, where appropriate, notify you by email.