Privacy Rights Request
Ask for a copy of your data, a correction, a deletion, or an opt out, and appeal if we say no.
No account neededYou do not have to be a customer to use this. If we hold information about you, you can ask what it is, and we will not charge you for asking.
Section 1What you can ask for
Which rights you have depends on where you live, but we apply the strongest of them to everybody. Running two standards is a good way to get one of them wrong.
- Know and access
- What we hold about you, where we got it, why we have it and who we shared it with, plus a copy of the data itself.
- Portability
- That copy in a structured, commonly used, machine readable format that you can take somewhere else.
- Correct
- Fix anything inaccurate or incomplete.
- Delete
- Erase it. If you only want your account gone, the deletion page is the faster route.
- Opt out of sale, sharing and profiling
- We do not sell personal information, we do not share it for cross context advertising, and we do not profile you. There is nothing here for you to opt out of, but the right exists and we will record the request.
- Object or restrict
- Object to a use that runs on our legitimate interests, or ask us to pause a use while a dispute is sorted out.
- Withdraw consent
- Where a use runs on consent, take it back. It does not undo what was lawful beforehand.
We will never charge you more, give you a worse service, or refuse to serve you because you used one of these rights.
Section 2Make a request
Use this form rather than the general contact form. Requests that come through here are logged and tracked against the legal deadline, so yours cannot quietly sit in an inbox.
Tell us which right you are using, and send it from the email address you think we hold. If you are appealing a decision we already made, say so at the top of the message.
Section 3How we check it is you
Before we hand over or delete data we have to be reasonably sure the request came from the person it concerns. Handing your data to somebody pretending to be you would be its own privacy breach.
Usually the email address is enough. If the request covers sensitive information, or the address does not match anything we hold, we may ask you to confirm details we already have on file. We ask for the least that verification requires, we never ask for a photograph of an identity document, and anything you send us for verification is deleted once the request is closed.
Section 4How long we take
- We acknowledge your request within one business day.
- We complete it within 45 days.
- If it is genuinely complicated we may extend once, by the period the law allows, and we will tell you before the first deadline passes and explain why.
Section 5If we say no
We will tell you in writing which part of the request we refused and the specific reason. You can appeal, and several state privacy laws require us to offer that route.
To appeal, reply to our decision or send the form again with "appeal" at the top. A different person reviews it where that is possible for a company our size, and we respond within 45 days with a written explanation. If we refuse the appeal we will give you the contact details for your state attorney general or your data protection authority.
Section 6Making a request for somebody else
An authorised agent can submit a request for you. We will ask for proof that you gave them permission, and we may still confirm the request with you directly. A parent or guardian can make a request on behalf of a child.
Section 7If your data sits in a client of ours
If you used software we built or operate for another company, or bought from a store running one of our apps, that company decides what happens to your data and we only act on their instructions. Your rights run against them first.
Send the request to them. If you send it to us anyway, we will tell you who the controller is and pass your request straight to them rather than leaving you to chase it. That is explained in more detail in the two roles we play.
Section 8Complaining to a regulator
You can complain to a regulator at any time, and you do not have to come to us first, although we would rather have the chance to fix it.
- In the United States, your state attorney general.
- In California, the California Privacy Protection Agency.
- In the European Economic Area, your national data protection authority.
- In the United Kingdom, the Information Commissioner’s Office.