Privacy Policy

This policy explains what personal data FlashAlert collects, why we collect it, how we use it, and what rights you have over it. It applies to everyone who visits flashalert.co.uk, creates a retailer account, or subscribes to alerts from a retailer who uses our service.

BusinessFlashAlert, a trading name of Naxtech.com
Owner / DPONaxtech
Address1 Burcombe Way, Reading, RG4 8RX
Last updatedJune 2025

1. Who we are

FlashAlert is a trading name of Naxtech, registered at 1 Burcombe Way, Reading, RG4 8RX, England.

For the purposes of UK data protection law, Naxtech is the data controller and data protection officer for FlashAlert. You can contact us at any time at contact@flashalert.co.uk.

2. Data we collect and why

2.1 Retailer accounts

When a retailer creates a FlashAlert account we collect:

We do not collect payment card details directly. Payment is handled entirely by Stripe (see Section 5). We receive a transaction reference and your email address from Stripe to record that a credit purchase was made.

2.2 Subscriber data (end customers)

When a member of the public scans a retailer's QR code and subscribes to their alerts, we collect:

We do not collect names, phone numbers, postal addresses, or any other personal data from subscribers. We do not profile subscribers or use their email address for any purpose other than delivering the alerts they signed up for.

2.3 Website visitors

When you visit flashalert.co.uk we collect standard technical data through Microsoft Clarity, including anonymised information about how you interact with the page (mouse movements, scroll depth, clicks). This data is aggregated and does not identify you personally. See Section 9 for more on cookies and analytics.

Under the UK GDPR, we rely on the following legal bases:

4. How we use your data

Retailer data

Subscriber data

We never use subscriber email addresses for marketing, profiling, or any purpose other than delivering the alerts they specifically signed up for. We never sell, rent, or share subscriber lists with any third party, including other retailers using our platform.

5. Third parties and data processors

We use the following third-party processors who may handle personal data on our behalf. All are bound by data processing agreements and applicable law.

SendGrid (Twilio)

We use SendGrid to deliver all outbound emails — both retailer account emails and subscriber flash alerts. SendGrid processes email addresses and email content on our behalf. SendGrid is certified under the UK–US Data Bridge framework. For more information, see Twilio's privacy policy.

Stripe

We use Stripe to process credit purchases. When you make a payment, your card details are entered directly into Stripe's secure environment — we never see, store, or process your card number, expiry date, or CVV. Stripe is PCI DSS Level 1 certified. For more information, see Stripe's privacy policy.

Microsoft Clarity

We use Microsoft Clarity for website analytics. Clarity collects anonymised behavioural data (scroll depth, click maps, session recordings) to help us understand how visitors use our website. Clarity does not collect personally identifiable information in a form we can access. For more information, see Microsoft's privacy statement.

6. Where data is stored

All FlashAlert account data and subscriber data is stored on servers located in the United Kingdom. We do not transfer personal data outside the UK except where a third-party processor (such as SendGrid or Stripe) operates internationally under appropriate safeguards, including the UK–US Data Bridge or standard contractual clauses.

7. How long we keep data

Retailer accounts

Retailer account data (shop name, town, email address) is retained for as long as the account is active. If you close your account or request deletion, we will delete your account data within 30 days, except where we are required to retain records for legal or accounting purposes (for example, records of financial transactions, which we retain for 6 years under HMRC requirements).

Subscriber data

A subscriber's email address is retained for as long as they remain subscribed to a retailer's alerts. When a subscriber clicks the unsubscribe link, their email address is immediately suppressed — meaning it is added to a do-not-contact list and no further alerts are sent. We retain suppressed addresses on our suppression list to prevent accidental re-addition, but they are not used for any other purpose.

If a retailer account is closed, all associated subscriber data is deleted within 30 days.

Website analytics

Anonymised analytics data collected by Microsoft Clarity is retained in accordance with Microsoft's standard data retention periods.

8. Your rights

Under UK GDPR you have the following rights in relation to your personal data:

To exercise any of these rights, email us at contact@flashalert.co.uk. We will respond within one calendar month.

9. Cookies and analytics

We use only the following cookies and tracking technologies on flashalert.co.uk:

We do not use advertising cookies, tracking pixels, or any third-party marketing cookies. We do not use Google Analytics or any Google tracking product.

10. Children

FlashAlert is a business-to-business service. We do not knowingly collect personal data from anyone under the age of 18. If you believe a child has provided us with personal data, please contact us at contact@flashalert.co.uk and we will delete it promptly.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify active account holders by email. Continued use of the service after any update constitutes acceptance of the revised policy.

12. Contact and complaints

For any questions about this policy or to exercise your rights, contact:

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection: