OWN PAY LTD ("OWN PAY", "we") is a private limited company registered in England and Wales, with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. This Privacy Policy explains what personal data we collect, why, how long we keep it, who we share it with, and the rights available to you.
1. Who we are
Data controller: OWN PAY LTD. Registered office above. Contact for privacy matters: legal@ownpayltd.com. A formal Data Protection Officer has not been appointed; the legal address above acts as the privacy contact channel.
2. What data we collect
We collect only the personal data we need to operate the service.
Information you provide
- Contact form: name, email, company (optional), message.
- Account registration: name, email, password (stored as a hash, never in plaintext).
- Buy request: name, email, short description of your need, consent record.
Information collected automatically
- Server logs, including IP address and user agent, used for security and abuse prevention.
- Analytics events from Google Analytics 4 and Microsoft Clarity, only if you consent through the cookie banner.
Special category data
We do not collect special category data (health, biometric, religious belief, political opinion, sexual orientation, trade union membership, or similar). If a client submits such data in a message, we ask for it to be removed.
3. Why we collect it
- Contract: to deliver the consulting services you purchase and to administer the engagement.
- Legitimate interest: to operate the website securely, to prevent abuse of forms, and to improve the service.
- Consent: to load analytics and to send any optional updates you opt in to.
- Legal obligation: to keep records required under UK company and tax law.
4. How long we keep it
- Contact form submissions: 24 months.
- Buy request submissions: 24 months.
- Client engagement records: 6 years after the engagement ends.
- Server logs: 90 days.
- Analytics: 14 months (Google Analytics 4 default).
5. Who we share data with
We share personal data only with processors that are necessary to run the service.
- secserv.me: payment processing on hosted checkout pages.
- Resend, Inc.: transactional email delivery (contact replies, account emails, payment notifications).
- Cloudflare, Inc.: captcha verification (Turnstile) and incoming email routing.
- Google Ireland Limited: Google Analytics 4 (analytics consent required).
- Microsoft Ireland Operations Ltd: Microsoft Clarity (analytics consent required).
- Vercel Inc.: site hosting infrastructure.
6. International transfers
Some processors are based outside the United Kingdom and the European Economic Area, including the United States. Transfers rely on Standard Contractual Clauses and the UK International Data Transfer Addendum where applicable. A list of current processors and transfer mechanisms is available on request.
7. Your rights
Under UK GDPR and EU GDPR, you have the right to access, rectify, erase, restrict, port, or object to processing of your personal data, and to withdraw consent at any time without affecting the lawfulness of prior processing.
8. How to exercise your rights
Send a request to legal@ownpayltd.com. We respond within 30 days. We may ask for proof of identity where it is proportionate to the request.
9. Complaints
You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO), at ico.org.uk. EU residents may also lodge a complaint with their national supervisory authority.
10. Updates
We may update this Privacy Policy from time to time. Material changes are highlighted at the top of the page and the effective date is updated.
[LEGAL REVIEW REQUIRED BEFORE PUBLISHING]