Privacy Policy
Last updated: March 2026
1. Who We Are
StreetStrike ("we", "us", "our") is operated by STREETSTRIKE.IO LTD (Company No. 17110289), operating the streetstrike.io website and platform. We provide a postcard marketing service for UK tradespeople. This policy explains how we collect, use, and protect your personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. The data controller is STREETSTRIKE.IO LTD, contactable at support@streetstrike.io.
2. Data We Collect
We collect the following categories of personal data:
- Account information: Email address, business name, phone number, website URL
- Business details: Return address, logo, cover photos
- Payment information: Processed securely by Stripe. We do not store card details.
- Campaign data: Postcodes searched, addresses targeted, template selections
- QR scan data: IP address, user agent, and timestamp when a QR code on a postcard is scanned
- Usage data: Pages visited, features used, campaign performance metrics
3. Lawful Basis for Processing
We process your data under the following lawful bases:
- Contract: Account data, campaign data, and payment processing — necessary to deliver the service you signed up for
- Legitimate interest: Usage analytics, platform improvement, and fraud prevention
- Legal obligation: Payment records retained for UK tax requirements (6 years)
- Consent: Marketing emails (you can unsubscribe at any time)
4. How We Use Your Data
- To provide our postcard printing and delivery service
- To process payments via Stripe
- To look up postal addresses via Ideal Postcodes
- To track postcard QR code scans for your campaign analytics
- To send service-related communications
- To improve our platform and user experience
5. Third-Party Services
We share data with the following processors to deliver our service:
- Supabase: Database hosting and user authentication (EU-based)
- Stripe: Payment processing (PCI DSS compliant)
- Stannp: Postcard printing and Royal Mail delivery (UK-based)
- Ideal Postcodes: UK address lookup service
- Mapbox: Postcode geocoding for campaign maps
6. International Data Transfers
Some of our processors are based outside the UK. Stripe and Mapbox operate from the US under Standard Contractual Clauses (SCCs) approved by the UK ICO. Supabase hosts data in the EU. Stannp and Ideal Postcodes are UK-based. We ensure all international transfers have appropriate safeguards in place as required by UK GDPR.
7. Recipient Address Data
When you create a campaign, we look up residential addresses using Ideal Postcodes (a licensed Royal Mail PAF data provider). These addresses are used solely to print and deliver your postcards via Stannp. We cache address lookups to reduce API costs. We do not sell or share recipient address data with any other party.
8. Data Retention
- Account data is retained while your account is active
- Campaign data is retained for analytics and audit purposes
- Address cache expires after 180 days
- Payment records are retained as required by UK tax law (6 years)
- QR scan logs are retained for campaign analytics
9. Your Rights
Under UK GDPR, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Request deletion of your data
- Restrict or object to processing
- Data portability
To exercise any of these rights, contact us at support@streetstrike.io.
10. Cookies
We use essential cookies for authentication and session management. We do not use third-party tracking cookies. Stripe may set cookies as part of payment processing.
11. Security
We use industry-standard security measures including encrypted connections (HTTPS), row-level security on our database, and secure authentication via Supabase Auth. Payment data is handled entirely by Stripe and never touches our servers.
12. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will:
- Notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach
- Notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms
- Document all breaches, including the facts, effects, and remedial actions taken
13. Contact
For privacy inquiries, contact us at support@streetstrike.io.
Business Information
STREETSTRIKE.IO LTD (Company No. 17110289). For all enquiries, please contact support@streetstrike.io.
Registered address: 18a Lyndhurst Road, CH45 6XA, United Kingdom
ICO registration: C1894496