Legal

Privacy Notice

This notice explains what personal data StackTake collects, why, who it is shared with, and the rights you have. Last updated August 11, 2026.

Who we are and our role

StackTake (“StackTake”, “we”, “us”) operates the StackTake product workspace and is the data controller for the personal data described in this notice — meaning we decide what data is collected and why. Our payment reseller, Paddle.com, acts as an independent controller for the purchase data it processes as Merchant of Record. Privacy questions can be submitted through the Support page.

Data we collect and why

  • Account data — email address, login credentials managed by our authentication provider, and account settings. Used to create and secure your account and give you access.
  • Workspace content — product names, brands, photos, arrival and due dates, notes, stack organization, and filming or posting activity you record. Used to provide the Shelf, Stacks, Today's Stack, and Daily Check-In features.
  • Onboarding answers — the workflow questions you answer at signup. Used to tailor the workspace to how you work.
  • Subscription data — plan, status, and renewal dates received from Paddle. Used to grant and manage paid access. We never receive or store your full card details.
  • Support messages — what you send us when asking for help or sharing feedback. Used to respond and improve the service.
  • Device, usage and diagnostic data — browser and device information, IP address, pages viewed, actions taken, and error reports. Used to keep the service secure, detect abuse, and troubleshoot.
  • Product analytics — we use PostHog to understand marketing page visits, which sections people view, which calls to action they select, and whether account setup completes. For signed-in accounts these events may be linked to an internal user ID. We do not send passwords or workspace content to analytics, and session recording is disabled.

Legal bases for processing

  • Performance of a contract — creating your account, storing your workspace content, providing subscription features, and giving support.
  • Legitimate interests — keeping the service secure, preventing fraud and abuse, diagnosing errors, and understanding aggregate product usage to improve StackTake.
  • Consent — non-essential analytics or marketing cookies and any marketing emails, where consent is required. You may withdraw consent at any time.
  • Legal obligation — meeting accounting, tax, and lawful-request requirements.

Who we share data with

  • Paddle.com, our Merchant of Record — Paddle receives your name, email, billing and location data, and purchase details in order to sell the subscription, take payment, manage renewals and cancellations, calculate and remit tax, issue invoices, and handle refunds and billing support. Paddle processes this data as its own controller under its privacy notice, and returns subscription status data to us.
  • Service providers (processors) — hosting, database and image storage, authentication, error monitoring, product analytics (PostHog), and support tooling. They process data only on our instructions.
  • Professional advisers — legal and accounting advisers where necessary.
  • Authorities — where required by law or necessary to protect users, the public, or the service.

We do not sell personal data and do not share it for cross-context behavioural advertising.

International transfers

Our providers may process data outside your country, including in the United States. Where data leaves the UK or EEA, transfers rely on appropriate safeguards such as adequacy decisions or Standard Contractual Clauses.

How long we keep data

  • Account and workspace data: for as long as your account is active.
  • After you delete your account or ask us to close it: deleted within 30 days, except where longer retention is legally required.
  • Support messages: up to 24 months after the conversation ends.
  • Security, access and diagnostic logs: up to 12 months.
  • Analytics events: up to 24 months, then deleted or aggregated.
  • Billing and tax records held by us or Paddle: up to 7 years, as required by accounting and tax law.

When data is no longer needed, it is deleted or irreversibly anonymised.

Your rights

Subject to the law that applies to you, you can:

  • access a copy of the personal data we hold about you;
  • correct inaccurate or incomplete data;
  • request deletion of your account and data;
  • export your workspace content in a portable format;
  • ask us to restrict or object to certain processing, including analytics;
  • withdraw consent where processing is based on consent;
  • opt out of marketing emails at any time via the unsubscribe link;
  • complain to your local data protection authority — in the UK, the Information Commissioner's Office.

You can edit or remove most product information directly inside StackTake. For anything else, contact us through the Support page; we respond within one month.

Security

We use appropriate technical and organisational measures to protect personal data, including encryption in transit, encryption at rest with our infrastructure providers, row-level access controls so accounts can only reach their own data, private image storage, and limited administrative access. No online service can guarantee perfect security, so please use a strong, unique password.

Cookies and similar technologies

We use essential cookies and local storage to keep you signed in, remember in-progress onboarding answers, and secure the service. We also use analytics cookies via PostHog to measure page and feature usage. We do not use advertising cookies. You can clear or block cookies in your browser settings; blocking essential cookies will break sign-in.

Children

StackTake is not directed to children under 13 and we do not knowingly collect personal data from them. If you believe a child has created an account, contact us and we will remove it.

Changes and contact

We may update this notice as StackTake changes; the current version and effective date will always be on this page, and material changes will be communicated in-app or by email. Privacy questions, data requests, and account-deletion requests can be submitted through the Support page.