Privacy Notice · updated 17 September 2026
How we use personal information.
This notice explains how personal information is used to operate Aparine, provide subscriptions and build business-prospect intelligence from lawful public sources.
1. Controller and contact
The controller is Not yet configured, a sole trader trading as Bridgnorth IT and operating Aparine, at Not yet configured. Privacy enquiries: Not yet configured.
2. Information about account holders and customers
We process work email address, company or organisation name, account identifiers, authentication status, subscription and billing identifiers, supplier preferences, saved prospects, notes and follow-up activity. We also record product-usage events such as pages or features used, prospect-review actions and prospect-quality feedback, together with timestamps. Supabase authentication records may include last sign-in and security or audit events.
We process this information to create and secure accounts, provide the Free Preview and paid Service, personalise prospect ranking, administer billing and team access, support customers, prevent misuse, understand whether the Service is useful, validate prospect quality and improve matching and scoring.
3. Payment information
Payments and billing self-service are handled by Stripe. We store Stripe customer and subscription identifiers and status so the Service can decide whether an organisation has access. We do not receive or store full payment-card numbers.
4. Public prospect information
The Service processes business-related information from public sources, primarily UK Intellectual Property Office trade mark records and Companies House. This can include applicant names, company names and numbers, registered-office area, filing dates, company status and other public company-filing information. A trade mark applicant can sometimes be an identifiable individual.
For Companies House enrichment, the current Service is designed around organisation-level information and does not intentionally build profiles from named directors, people with significant control or personal contact details. Where an individual applicant appears in a public trade mark record, that record is treated cautiously and cannot become a top company prospect merely because no company match exists.
We use public information to identify and contextualise potential business prospects for beauty-sector suppliers. The source of prospect information is shown or linked where practicable so customers can verify it. Derived categories, scores, suggested needs and timing indicators are automated research interpretations and may be wrong.
5. Our lawful bases
We rely on contract where processing is necessary to create and operate a customer account or subscription. We rely on legitimate interests for proportionate B2B prospect intelligence, service security, fraud or misuse prevention, product administration and improvement, where those interests are not overridden by individual rights. Where the law requires consent, including optional analytics or advertising storage or access, we ask for it first. We may also process information where necessary to comply with legal obligations.
6. Scoring and automated interpretation
Aparine uses rules and automated processing to prioritise business research signals and personalise matches. Signal Scores and other derived indicators are not credit scores, risk scores or predictions that a person will buy. They do not make decisions that have legal or similarly significant effects on the people whose public-source information may appear in the Service. Customers are told to review the evidence and make their own commercial judgement.
7. Marketing and service communications
We may send essential account, security, preview, billing and service messages because they are needed to operate the Service. Promotional communications are sent only where lawful; you can opt out of marketing at any time without affecting necessary service messages.
8. Cookies, analytics and advertising measurement
Essential storage is used to keep the application secure and remember necessary settings. Google Analytics and Google Ads measurement are optional and are not loaded by us unless you give the relevant consent. You can change your choice at any time using Cookie settings. See the Cookie Policy.
We also keep limited server-side campaign and page-view counts so we can tell whether Aparine outreach is working. These records may include the campaign/source label supplied in an Aparine short link, the destination page, the referring website domain and a timestamp. This Aparine measurement does not set an analytics cookie or store a visitor identifier, IP address or browser user-agent in the product database.
9. Who receives information
We use service providers to operate the product, including Supabase for authentication and database services, Netlify for hosting and functions, GitHub for software and data-processing workflows, Stripe for billing, and, where configured and permitted, Google for analytics or advertising measurement and an email-delivery provider for operational notifications. Providers process information under their own contractual and security arrangements.
10. International processing
Some service providers may process information outside the United Kingdom. Where UK data-protection law requires safeguards for an international transfer, we rely on an applicable adequacy mechanism or contractual or other approved safeguards provided by the relevant processor.
11. Retention
We keep personal information only for as long as it is reasonably needed for the purpose collected, including providing the account, maintaining security and audit history, resolving disputes and meeting legal, tax and accounting requirements. Account and product-usage information is reviewed after an account closes rather than kept indefinitely.
Public prospect records can remain in retained historical intelligence while they continue to support the Service, its research purpose and the applicable lawful basis. We periodically review relevance, suppress or correct records where appropriate, and consider valid objection or erasure requests in light of the source, purpose and legal requirements.
12. Security
We use authenticated access, row-level database controls, server-side administrative functions, environment separation and third-party payment processing to reduce exposure of sensitive information. No online service can guarantee absolute security, so customers must also protect their login credentials.
13. Your rights
Depending on the circumstances, UK data-protection law may give you rights to access, correct or erase personal information, restrict or object to processing, and receive certain information in a portable form. Where processing relies on consent, you can withdraw it without affecting earlier lawful processing.
If your name appears in public-source prospect intelligence and you believe information is wrong or should not be processed, contact us with enough detail to identify the record. We will assess the request against the source, purpose, legitimate interests and applicable law and will correct, suppress or remove information where required or appropriate.
14. Complaints
Please contact us first so we can investigate. You also have the right to complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk.
15. Contact us
Email Not yet configured, or use this form. Do not include sensitive personal information unless necessary.