Privacy Notice
Last updated: 6 June 2026
1. Who we are
Hartstone Holdings ("we", "us") provides the Hartstone Holdings property investment tools. For data we process about you in connection with the Service, we act as the data controller.
2. Personal data we collect
- Account data — email address, password hash, profile.
- Usage data — pages visited, features used, calculations saved, search queries.
- Device & technical data — IP address, browser type, device identifiers, cookies.
- Support communications — emails and messages you send us.
- Payment data — handled directly by Paddle; we receive only subscription status and the last four digits / brand of your card from Paddle for billing display purposes.
3. Why we use it
- Creating and operating your account (contract performance).
- Providing and improving the Service (legitimate interests).
- Security, fraud prevention and abuse detection (legitimate interests).
- Responding to support requests (contract performance / legitimate interests).
- Sending operational emails (legitimate interests) and marketing where you have consented (consent).
- Meeting legal obligations.
4. Who we share data with
- Hosting & infrastructure — cloud providers we use to run the Service.
- Merchant of Record — Paddle.com Market Limited, for sale of subscriptions, subscription management, payments, tax compliance and invoicing.
- Analytics & support tooling — providers that help us understand and improve usage.
- Professional advisers — legal and accounting, where required.
- Authorities — where required by law.
5. International transfers
Some recipients may be based outside the UK / EEA. Where this happens, we rely on appropriate safeguards such as Standard Contractual Clauses or UK/EU adequacy decisions.
6. Retention
We keep account data while your account is active and for a reasonable period afterwards to comply with legal obligations and resolve disputes. We delete or anonymise data when it is no longer needed.
7. Your rights
Under UK / EU GDPR you have the right to access, rectify, erase, restrict or object to processing of your personal data, the right to data portability, the right to withdraw consent at any time, and the right to lodge a complaint with a supervisory authority (e.g. the UK ICO). We will respond to requests within one month.
8. Security
We use appropriate technical and organisational measures including encryption in transit, access controls, and least-privilege roles for our staff.
9. Cookies
We use essential cookies to keep you signed in and analytics cookies to understand how the Service is used. You can manage cookies in your browser settings.
10. Contact
For any privacy question or to exercise your rights, email privacy@hartstoneholdings.com.