Privacy Policy

Last Updated: October 2025

1. Introduction

Cranford Tech Limited (trading as DocuPotion), company number 15069364, with registered office at 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE ("we", "us", "our") is committed to protecting your privacy and personal data.

This Privacy Policy explains how we collect, use, store, and protect your personal information when you use DocuPotion, our software-as-a-service platform for creating and generating PDF documents.

We are the data controller for the purposes of UK data protection law, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Information We Collect

2.1 Information You Provide to Us

Free Trial Users: When you sign up for a free trial, we collect:

  • Your name
  • Your email address

Paid Plan Users: When you upgrade to a paid plan, we additionally collect:

  • Your billing address
  • Your payment method details (processed securely by Stripe - see section 5.3)
  • Your IP address

Account and Service Usage: When you use DocuPotion, we may also collect:

  • Information about your templates, designs, and documents
  • Images you upload to use in your templates
  • Data you provide via our API to populate templates
  • Communications you send to us (support requests, feedback, etc.)
  • Information about your API usage and service interaction

2.2 Information We Collect Automatically

When you access our service, we automatically collect:

  • Technical information about your device and browser
  • Usage data and analytics (via Plausible.io)
  • Log data (IP address, access times, pages viewed)
  • API usage statistics

2.3 Information From Third Parties

We may receive information about you from third-party services you use to sign up or log in to DocuPotion (if applicable).

3. How We Use Your Information

We use your personal data for the following purposes:

3.1 To Provide Our Service

  • Set up and administer your account
  • Provide technical and customer support
  • Verify your identity
  • Process your API requests and generate PDFs
  • Store your templates, images, and generated documents

Legal Basis: Performance of a contract with you

3.2 To Communicate With You

  • Send you important account and service information
  • Respond to your queries, refund requests, or complaints
  • Send you service updates and notifications

Legal Basis: Performance of a contract with you, and our legitimate business interests in maintaining customer relationships

3.3 To Process Payments

  • Process payments for your subscription
  • Prevent fraudulent transactions
  • Handle billing and invoicing

Legal Basis: Performance of a contract with you, and our legitimate business interests in preventing fraud

3.4 To Improve Our Service

  • Analyze how users interact with DocuPotion
  • Identify and fix technical issues
  • Develop new features and improvements

Legal Basis: Our legitimate business interests in improving our service

3.5 To Comply With Legal Obligations

  • Comply with applicable laws and regulations
  • Respond to legal requests and prevent harm

Legal Basis: Legal obligation and our legitimate interests in protecting our rights

4. How We Store and Protect Your Information

4.1 Data Storage Locations

Your data is stored using the following services:

AWS (Amazon Web Services):

  • Region: us-east-1 (US East, N. Virginia)
  • Used for: Generating PDFs, storing reusable templates, storing images used in templates, and storing generated PDFs when you choose 'url' output from our API
  • Important: All generated PDFs are automatically deleted after 7 days

Supabase:

  • Used for: Storing user account data, authentication information, and application data

Bubble:

  • Used for: Storing user account data, authentication information, and application data

4.2 Data Retention

  • Generated PDFs: Automatically deleted after 7 days
  • Templates and Images: Retained for as long as you maintain your account, plus 30 days after account closure
  • Account Information: Retained for as long as you maintain your account, plus a reasonable period after closure for legal and accounting purposes
  • Communications: Retained for as long as necessary to provide support and for our legitimate business interests
  • Data added to Bubble.io plugin actions: Retained for 48 hours before being automatically deleted. This is used to help troubleshoot customer support queries.

4.3 Data Security

We implement appropriate technical and organizational security measures to protect your personal data, including:

  • Encryption of data in transit and at rest
  • Access controls and authentication
  • Regular security assessments
  • Secure data centers with physical security measures

However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your personal data, we cannot guarantee absolute security.

5. Sharing Your Information

5.1 Third-Party Service Providers

We share your information with trusted third-party service providers who help us operate our service:

Stripe:

  • Purpose: Payment processing
  • Data Shared: Billing information, payment method details
  • Important: We do not store payment information or credit card details on our systems. Your credit card details are securely processed by Stripe. You can read Stripe's Privacy Policy for more information.

AWS (Amazon Web Services):

  • Purpose: Cloud infrastructure, PDF generation, data storage
  • Data Shared: Templates, images, generated PDFs, and related data
  • Location: us-east-1 region

Supabase:

  • Purpose: User data storage and authentication
  • Data Shared: Account information and user data

Bubble:

  • Purpose: Application platform and data storage
  • Data Shared: User data and application data

Loops.so:

  • Purpose: Email services
  • Data Shared: Name, email address, and communication preferences

Plausible.io:

  • Purpose: Privacy-friendly website analytics
  • Data Shared: Anonymized usage data (Plausible does not use cookies or track personal data)

5.2 Legal Requirements

We may disclose your personal data if required to do so by law or in response to valid requests by public authorities (e.g., court orders, government agencies).

5.3 Business Transfers

If we are involved in a merger, acquisition, or sale of assets, your personal data may be transferred. We will provide notice before your data is transferred and becomes subject to a different privacy policy.

5.4 With Your Consent

We may share your information with third parties when we have your explicit consent to do so.

6. Your Rights

Under UK data protection law, you have the following rights:

  • Right of Access: You can request a copy of the personal data we hold about you.
  • Right to Rectification: You can ask us to correct inaccurate or incomplete personal data.
  • Right to Erasure: You can request that we delete your personal data in certain circumstances.
  • Right to Restrict Processing: You can ask us to limit how we use your personal data in certain circumstances.
  • Right to Data Portability: You can request a copy of your personal data in a machine-readable format.
  • Right to Object: You can object to our processing of your personal data based on legitimate interests.
  • Right to Withdraw Consent: Where we rely on consent, you can withdraw it at any time.
  • Right to Lodge a Complaint: You can complain to the Information Commissioner's Office (ICO), the UK's data protection supervisory authority, at www.ico.org.uk or by calling 0303 123 1113.

To exercise any of these rights, please contact us using the details in section 10.

7. Cookies and Tracking Technologies

We use minimal tracking technologies to ensure our service functions properly. Specifically:

  • Plausible.io Analytics: We use Plausible for privacy-friendly analytics. Plausible does not use cookies, does not collect personal data, and is fully compliant with GDPR, CCPA, and PECR. All data is anonymized.
  • Essential Cookies: We may use strictly necessary cookies to maintain your session and ensure the service functions correctly.

We do not use advertising cookies or third-party tracking cookies.

8. Children's Privacy

DocuPotion is not intended for use by children under the age of 18. We do not knowingly collect personal data from children. If you believe we have collected information from a child, please contact us immediately, and we will delete such information.

9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, regulatory, or operational reasons. We will notify you of any material changes by:

  • Posting the updated policy on our website
  • Sending you an email notification (for significant changes)
  • Displaying a notice when you log in to your account

The "Last Updated" date at the top of this policy indicates when it was last revised. Your continued use of DocuPotion after changes are posted constitutes your acceptance of the updated Privacy Policy.

10. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Data Protection Contact:

Cranford Tech Limited (trading as DocuPotion)

Email: support@docupotion.com

Address: 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE

Company Number: 15069364

We will respond to your inquiry within 30 days.

11. Your Responsibilities

When using DocuPotion, you are responsible for:

  • Ensuring you have the legal right to process any personal data you upload to our service
  • Complying with applicable data protection laws in relation to data you process using our service
  • Implementing appropriate security measures for data you collect and process
  • Providing necessary privacy notices to your end users if you process their data using our service

If you process personal data of others using DocuPotion, you act as a data controller for that data, and we act as a data processor providing the service to you.

By using DocuPotion, you acknowledge that you have read and understood this Privacy Policy.