# Privacy policy

> What personal data MISSIN collects, why, where it is processed, who it is shared with, how long it is kept, and how to use your rights.

## 1. Who we are

MISSIN is provided by **MISSIN LIMITED** (**MISSIN**, **we**, **us**), a
company registered in Scotland, registered office **20 Arthur View Terrace, Danderhall, Dalkeith, EH22 1NT**. For
anything in this policy, email Sam@missin.co.uk.

## 2. Our two roles

- **Controller, for our own customers.** When you sign up for MISSIN, use the
  app or pay for a plan, we decide how your data is used. This policy covers
  that data.
- **Processor, for merchants.** When a merchant uses MISSIN to run forms,
  waitlists, discounts or attribution, we process their customers' data on the
  merchant's instructions, under our
  data processing agreement. The merchant is
  the controller, and its own privacy notice explains what it does. If you are
  one of a merchant's customers, contact the merchant first; we will help them
  answer.

## 3. What we collect about our customers

- **Account and sign-in.** Your name, email address and profile picture, and
  records of when you sign in. Our identity provider holds these; MISSIN keeps
  only your sign-in id, the workspaces you belong to and your role in each.
- **Workspace.** The workspace's name and settings, the people invited to it,
  and the API keys created in it. We store only a hash of each API key, never
  the key itself, and a daily count of the requests each key makes.
- **Billing.** Your plan, your usage and the billing contact. Card payments are
  taken by Stripe: MISSIN never sees or stores your card number.
- **Connected accounts.** When you connect a store or a tool, we keep the access
  credentials it gives us, encrypted, and the data MISSIN reads from it to do its
  job, such as the orders and discounts in a Shopify store.
- **Support.** What you send us when you email us.
- **Errors.** When the app hits an error, a report goes to our error
  monitoring. Names, contact details, addresses, IP addresses and free text are
  removed from it first.

## 4. What we process for merchants

On a merchant's behalf, as the data processing agreement describes:

- **Orders.** The order references, totals and customer id a merchant's store
  reports, and the customer's email address where it is needed to match an
  order. We do not read customers' names, addresses or phone numbers from
  Shopify.
- **Form answers.** What a customer answers on a merchant's form, including
  free text. To work out which touch-point earned an order, free-text answers
  are sent to an AI model provider after email addresses, links, phone numbers
  and long numbers are masked.
- **Waitlist sign-ups.** The email address, the page and campaign the sign-up
  came from, and proof of consent: the decision, when it was made, the wording
  shown, the browser's user agent and a keyed hash of the IP address. We never
  store the IP address itself.
- **Visits.** On a merchant's website, the MISSIN snippet records a visitor id,
  the pages visited, the referrer and campaign parameters. Advertising click ids
  are kept only when the website signals marketing consent.
- **Partners' public posts.** The public posts and handles of the people who
  post for a merchant, and of the accounts those posts tag or mention, so the
  merchant can see which posts earned orders. The merchant chooses whose posts
  are tracked and is responsible for the lawful basis, usually its legitimate
  interests; MISSIN collects them as its processor, under the data processing
  agreement. Details of accounts that are not a merchant's partners are deleted
  after 90 days without being seen again, and anyone can ask not to be collected.

## 5. Why we use our customers' data, and our lawful basis

| Purpose | Lawful basis |
|---|---|
| Creating your account, running your workspace and providing the service | Contract |
| Taking payment and keeping billing records | Contract, and our legal obligation to keep accounts |
| Keeping the service secure and preventing fraud and abuse | Legitimate interests |
| Fixing errors and improving the service | Legitimate interests |
| Answering your support requests | Contract, or legitimate interests if you are not yet a customer |
| Sending service emails: account, billing and alerts | Contract |
| Telling you about changes to the service or these documents | Contract |

We use each workspace's data only to provide the service to that workspace. We
do not use it to improve Mend for other workspaces, we never sell it, and we
never use it to train third-party AI models.

Today we send only service emails. If we start sending marketing emails, we
will send them to existing customers only, under the UK soft opt-in, with an
unsubscribe link in every one.

## 6. Where your data is processed

MISSIN's servers and database run in the EU, in Railway's europe-west4 region.
Some of our providers process data outside the UK and the EEA. Each such
transfer relies on the UK International Data Transfer Agreement or Addendum,
the EU Standard Contractual Clauses, or the UK Extension to the EU–US Data
Privacy Framework where the provider is certified. The mechanism for each
provider is available on request.

## 7. Who we share it with

We do not sell personal data. We share it only with:

- the providers that run parts of the service for us: hosting, sign-in, email
  sending, payments and usage billing, error monitoring, bot checks on forms,
  AI classification of form answers, and collecting public posts. They are
  listed, with their location, on the sub-processor list;
- the stores and tools you connect yourself, when you tell MISSIN to send data
  to them;
- the members of your own workspace;
- authorities, when the law requires it.

## 8. How long we keep it

- **Your account** is kept while you use MISSIN. A sign-in account that no
  longer belongs to any workspace is not deleted automatically; we delete it when
  you ask.
- **A deleted workspace** is kept so it can be restored. We delete it within 30
  days if you ask us in writing. This is done by hand today, not automatically.
- **Billing records** are kept for six years, as HMRC requires.
- **Website visits** are deleted after 13 months. Customer details captured
  with a form answer are removed after 13 months; the answer itself is kept as
  proof that a reward was earned.
- **Waitlist sign-ups** that are never confirmed are deleted 30 days after the
  last attempt. After a waitlist is released or archived, sign-ups without
  marketing consent are erased once the merchant's retention period has passed
  (180 days unless the merchant chose between 30 and 730). Sign-ups with
  marketing consent are kept until the person unsubscribes or asks to be erased.
- **Customer data request exports** are deleted after 30 days.
- **A Shopify store's data** is erased when Shopify tells us the store has
  uninstalled MISSIN.

## 9. Your rights

You can ask us to give you a copy of your data, correct it, delete it, limit
how we use it, or send it to you in a portable format. You can object to a use
based on our legitimate interests, and withdraw any consent you gave. To do any
of these, email Sam@missin.co.uk. We answer within one month.

If you are a merchant's customer, ask the merchant: it controls your data, and
we help it answer.

## 10. Cookies and browser storage

MISSIN does not use advertising or analytics cookies, and the MISSIN website,
docs and app do not run analytics trackers.

- **The MISSIN app** keeps your sign-in in memory and a cookie, `sidebar_state`,
  for seven days to remember whether the sidebar is open. It keeps preferences
  (theme, layout and unsaved drafts) in your browser's local storage. Our
  identity provider sets its own cookies on its sign-in page to keep you
  signed in.
- **The MISSIN website and docs** set no cookies. They keep only your theme
  choice and dismissed announcements, in local storage.
- **On merchants' websites**, which we serve as processor: the MISSIN snippet
  keeps a visitor id in local storage and in a first-party cookie, `missin_vid`,
  for up to 400 days; a MISSIN form sets `missin_rs` for 24 hours to keep one
  answer session; and the form's bot check is run by Cloudflare Turnstile. The
  merchant is responsible for asking its visitors' consent where that is needed.

## 11. Security

Data is encrypted in transit, the credentials for the tools you connect are
encrypted at rest, each workspace is kept apart from every other, and access is limited to the people who need it. More is on the
trust center's security page.

## 12. Children

MISSIN is a service for businesses and is not meant for children.

## 13. Changes to this policy

We will update this policy when what we do changes. The date at the top of this
page shows when it last changed, and we will email workspace owners about a
change that affects them.

## 14. Contact and complaints

Email Sam@missin.co.uk, or write to us at 20 Arthur View Terrace, Danderhall, Dalkeith, EH22 1NT.

If you are unhappy with how we handle your data, you can complain to the
Information Commissioner's Office, the UK data protection regulator, at
[ico.org.uk/make-a-complaint](https://ico.org.uk/make-a-complaint/) or on 0303 123 1113.
We would like the chance to put it right first.

Sam, on behalf of MISSIN

Source: https://docs.missin.co.uk/legal/privacy
