Privacy Policy
Last updated: 10 June 2026
1. Who is responsible for your data
The data controller is Distressed Sites Ltd, company number 17266301, registered in England and Wales, ICO registration number ZC241153. Contact for anything in this policy: use the contact page.
2. What we collect
- Account details: name, email address, company name, phone number, and what best describes you (for example investor or land agent).
- Your password, stored only as a salted hash. We cannot read it.
- Preferences: the regions and property types you choose for alerts, and your alert settings.
- Payment metadata: your plan, subscription tier, subscription status and billing dates.
- Site interaction data: which sites you view, unlock or save, and (for records created before 5 October 2026) any interest you registered in a site under the earlier introduction service.
- Technical data needed to run the service securely, such as IP addresses used for rate limiting.
We do not collect or store your card details. Payments go directly to Stripe, our payment processor, and your card number never touches our servers.
3. Why we are allowed to use it
UK GDPR requires a lawful basis for each use. Ours are:
- Contract: providing the service you signed up for, including your account, subscription and alerts.
- Legitimate interests: keeping the platform secure, preventing fraud and abuse, and improving the product.
- Consent: marketing emails. These are opt-in only, and you can withdraw consent at any time.
5. Who processes data for us
We use a small number of service providers, each bound by a data processing agreement and operating GDPR-compliant programmes:
- Stripe: payment processing.
- Resend: transactional email, such as verification and alert emails.
- Vercel: application hosting.
- Supabase: database hosting.
- Upstash: rate limiting.
6. International transfers
Some of these providers, including Stripe and Vercel, process data in the United States and other countries outside the UK. Those transfers are safeguarded by UK-approved standard contractual clauses, including the UK International Data Transfer Addendum, and by each provider's own compliance programme.
7. How long we keep it
- Account data: kept while your account is active, then retained for up to 6 years after closure for accounting and dispute purposes, as required by HMRC rules, then deleted.
- Site interaction data: kept for product analytics for up to 24 months, then deleted or anonymised.
8. Your rights
Under UK GDPR you can ask us to:
- give you a copy of your personal data (access);
- correct inaccurate data (rectification);
- delete your data (erasure);
- hand your data over in a portable format (portability);
- limit what we do with it (restriction);
- stop certain processing (objection).
To exercise any of these, reach us through the contact page. We respond within one month.
How to delete your account or get a copy of your data: sign in and open Your data.
9. Children
The service is for property professionals and is not directed at anyone under 18. We do not knowingly process children's data.
10. Security
All traffic is encrypted in transit with TLS. Passwords are stored as salted hashes. Authentication routes are rate limited, access to production data is restricted, and we review our security measures regularly.
11. Changes to this policy
If we change this policy in a way that affects you, we will post the updated version here and update the date at the top. For significant changes we will tell you by email.
12. Complaints
If you are unhappy with how we handle your data, please contact us first and we will try to put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk.