Privacy

What we hold, and why.

This notice covers this website, the free audit, the emails we send to Shopify brands, and the Stillsold app.

Last updated 26 September 2026

The short version

  • This website sets no cookies and runs no analytics.
  • The free audit uses your store’s address and your email to run and send the audit, answer you, and stop abuse.
  • If we emailed you, we used your work details from public sources. Reply “stop” and we won’t email again.
  • We never sell personal data.

Who we are

Stillsold is a trading name of Catchlead Ltd, registered in England and Wales, company no. 17079928. Registered office: 124 City Road, London EC1V 2NX.

For the website, the audit and our emails, we decide how your data is used: we are the controller. Questions or requests: privacy@stillsold.io.

This website

  • No cookies, no analytics, no ad or tracking pixels.
  • Our host, Cloudflare, processes your IP address and browser details to deliver the site and protect it from attacks.
  • The site’s fonts load from Google Fonts, so your browser sends your IP address to Google when it fetches them.

Our lawful basis is legitimate interests: showing you the site and keeping it secure.

The free audit

When you ask for an audit we collect:

  • your store’s web address and your email address;
  • a scrambled (salted hash) version of your IP address, to limit how often the audit can be run. We never store the address itself;
  • the audit result: the public pages we checked and the dead ends we found.

We use them to run the audit, email it to you, reply if you write back, and stop abuse. We don’t add you to a newsletter. Our lawful basis is legitimate interests: providing the audit you asked for and keeping the service safe.

If we emailed you

We look at the public ads of Shopify brands in Meta’s Ad Library and at their public product pages. When a live ad sends shoppers to a page that can’t sell, we contact the person whose job covers it, show them the evidence and offer our service.

What we hold

Your name, job title and employer, your work email and public LinkedIn profile address, our messages to each other and notes from any call. No personal emails, home addresses, phone numbers or anything sensitive.

Where we got it

Public, professional sources: your employer’s website, your public LinkedIn profile, press releases and company filings, or, for your work email, your company’s usual email format. Ask and we’ll tell you which one.

Lawful basis

Legitimate interests (UK GDPR Article 6(1)(f)): telling a business about a problem on its own store and offering a way to fix it. We have weighed this against your interests; ask and we’ll send you a summary.

In the UK we email only limited companies, PLCs and LLPs without consent, as PECR allows, and never sole traders or partnerships. Our emails don’t track opens or clicks.

To stop: reply “stop”, or write to privacy@stillsold.io. We’ll then keep only your name, email and the date on a do-not-contact list, so we can respect your request.

Stores using Stillsold

When a store installs the Stillsold app, the store is the controller of its shoppers’ data and we process it on the store’s behalf. What the app collects, where it lives and how it’s protected is on the security page. We sign a data processing agreement with every store before install.

For the people we deal with at a customer (contact names, work emails, billing details), we are the controller and use them to run the service and invoice it. Our lawful basis is legitimate interests (running the contract with your company) and, for invoices, our legal obligation to keep tax records.

Who else sees it

Only the services that run our business, under contracts that protect your data. We don’t sell or share your details for anyone else’s marketing.

Cloudflare

Hosts this website.

Google

Our email (Google Workspace) and this site’s fonts.

HubSpot

Our contact list, and the do-not-contact list.

Fly.io and Neon

Will run the audit and the Stillsold app, in London.

Resend

Will send audit and app emails.

Sentry

Error reports from the app, if we switch them on. EU region, no request data.

Stripe

Pilot invoices and payments (billing contacts only).

LinkedIn

When we message you there.

Some of these providers are in the US. Where your data leaves the UK, it is protected by the UK–US data bridge (for certified companies) or the ICO’s standard contract clauses (the IDTA or the UK Addendum).

How long we keep it

Audit requests
30 days, then deleted automatically.
Prospecting records
12 months after our last contact, unless you become a customer.
Do-not-contact list
For as long as we need to respect your request.
Customer records
For the contract, then as long as UK tax law requires (usually 6 years for invoices).
Other messages to us
2 years. We use them to reply and keep a record (legitimate interests).

Your rights

  • Object at any time to direct marketing. This right is absolute: reply “stop” and we stop.
  • Ask for a copy of your data, or ask us to correct or delete it, or to limit how we use it.
  • Object to any use based on legitimate interests.
  • Complain to the Information Commissioner’s Office: ico.org.uk/make-a-complaint, 0303 123 1113.

Write to privacy@stillsold.io. We answer within one month.

US recipients: we follow the CAN-SPAM Act. Every email shows our postal address (124 City Road, London EC1V 2NX, United Kingdom) and a working opt-out, and we act on opt-outs within 2 business days.

We make no decisions about you by automated means alone.

If we change this notice, we’ll update the date at the top.