The short version
- This website sets no cookies and runs no analytics.
- The free audit uses your store’s address and your email to run and send the audit, answer you, and stop abuse.
- If we emailed you, we used your work details from public sources. Reply “stop” and we won’t email again.
- We never sell personal data.
Who we are
Stillsold is a trading name of Catchlead Ltd, registered in England and Wales, company no. 17079928. Registered office: 124 City Road, London EC1V 2NX.
For the website, the audit and our emails, we decide how your data is used: we are the controller. Questions or requests: privacy@stillsold.io.
This website
- No cookies, no analytics, no ad or tracking pixels.
- Our host, Cloudflare, processes your IP address and browser details to deliver the site and protect it from attacks.
- The site’s fonts load from Google Fonts, so your browser sends your IP address to Google when it fetches them.
Our lawful basis is legitimate interests: showing you the site and keeping it secure.
The free audit
When you ask for an audit we collect:
- your store’s web address and your email address;
- a scrambled (salted hash) version of your IP address, to limit how often the audit can be run. We never store the address itself;
- the audit result: the public pages we checked and the dead ends we found.
We use them to run the audit, email it to you, reply if you write back, and stop abuse. We don’t add you to a newsletter. Our lawful basis is legitimate interests: providing the audit you asked for and keeping the service safe.
If we emailed you
We look at the public ads of Shopify brands in Meta’s Ad Library and at their public product pages. When a live ad sends shoppers to a page that can’t sell, we contact the person whose job covers it, show them the evidence and offer our service.
What we hold
Your name, job title and employer, your work email and public LinkedIn profile address, our messages to each other and notes from any call. No personal emails, home addresses, phone numbers or anything sensitive.
Where we got it
Public, professional sources: your employer’s website, your public LinkedIn profile, press releases and company filings, or, for your work email, your company’s usual email format. Ask and we’ll tell you which one.
Lawful basis
Legitimate interests (UK GDPR Article 6(1)(f)): telling a business about a problem on its own store and offering a way to fix it. We have weighed this against your interests; ask and we’ll send you a summary.
In the UK we email only limited companies, PLCs and LLPs without consent, as PECR allows, and never sole traders or partnerships. Our emails don’t track opens or clicks.
To stop: reply “stop”, or write to privacy@stillsold.io. We’ll then keep only your name, email and the date on a do-not-contact list, so we can respect your request.
Stores using Stillsold
When a store installs the Stillsold app, the store is the controller of its shoppers’ data and we process it on the store’s behalf. What the app collects, where it lives and how it’s protected is on the security page. We sign a data processing agreement with every store before install.
For the people we deal with at a customer (contact names, work emails, billing details), we are the controller and use them to run the service and invoice it. Our lawful basis is legitimate interests (running the contract with your company) and, for invoices, our legal obligation to keep tax records.
Who else sees it
Only the services that run our business, under contracts that protect your data. We don’t sell or share your details for anyone else’s marketing.
Cloudflare
Hosts this website.
Our email (Google Workspace) and this site’s fonts.
HubSpot
Our contact list, and the do-not-contact list.
Fly.io and Neon
Will run the audit and the Stillsold app, in London.
Resend
Will send audit and app emails.
Sentry
Error reports from the app, if we switch them on. EU region, no request data.
Stripe
Pilot invoices and payments (billing contacts only).
When we message you there.
Some of these providers are in the US. Where your data leaves the UK, it is protected by the UK–US data bridge (for certified companies) or the ICO’s standard contract clauses (the IDTA or the UK Addendum).
How long we keep it
- Audit requests
- 30 days, then deleted automatically.
- Prospecting records
- 12 months after our last contact, unless you become a customer.
- Do-not-contact list
- For as long as we need to respect your request.
- Customer records
- For the contract, then as long as UK tax law requires (usually 6 years for invoices).
- Other messages to us
- 2 years. We use them to reply and keep a record (legitimate interests).
Your rights
- Object at any time to direct marketing. This right is absolute: reply “stop” and we stop.
- Ask for a copy of your data, or ask us to correct or delete it, or to limit how we use it.
- Object to any use based on legitimate interests.
- Complain to the Information Commissioner’s Office: ico.org.uk/make-a-complaint, 0303 123 1113.
Write to privacy@stillsold.io. We answer within one month.
US recipients: we follow the CAN-SPAM Act. Every email shows our postal address (124 City Road, London EC1V 2NX, United Kingdom) and a working opt-out, and we act on opt-outs within 2 business days.
We make no decisions about you by automated means alone.
If we change this notice, we’ll update the date at the top.