Privacy Policy
What Starboard collects from agencies, from visitors to this site, and from customers leaving reviews on an agency's page, and what happens to it.
Effective 14 September 2026. Operated by TODO: legal entity name.
- 1. Who this policy covers
- 2. What we collect from agency users
- 3. What we collect on this website
- 4. What is collected on review pages
- 5. How we use it
- 6. Who can see it
- 7. Cookies
- 8. How long we keep it
- 9. Your rights
- 10. Security and transfers
- 11. Children, changes and contact
1. Who this policy covers
Three groups of people use Starboard: agencies with an account, visitors to this website, and customers leaving reviews on an agency-run page. This policy covers all three.
TODO: legal entity name (“we”) operates the Starboard service. This policy explains what personal data we hold, why, and what you can do about it. It applies to:
- Agency users who create and use a workspace. We are the controller of your account data.
- Website visitors to our marketing site and live demo. We are the controller of that data.
- Reviewers who open a review page run by an agency for one of its clients. The agency is the controller of your data and we process it on the agency’s behalf. The privacy notice linked from the review page names that agency and tells you how to contact it.
2. What we collect from agency users
Your name, email, a hashed password, your agency’s branding and settings, and a Stripe customer reference. Cards never touch our servers.
When you create a workspace we store your name, email address, agency name and a one-way hash of your password. We never store the password itself. If you arrived through an advertising link we also store the campaign parameters from that link so we know which channel brought you.
As you use the service we store what you add: your logo, colours and credit line; each client’s name, review links and optional contact email; each technician’s first name; and a log of significant actions taken in the workspace, with the time and the user who took them.
When you subscribe, Stripe collects your payment details directly. We receive and store only a customer reference, a subscription reference and the subscription’s status and renewal date.
We keep a record of every email the service sends you, including password reset links and feedback alerts, so support can see what was sent.
3. What we collect on this website
Two small first-party cookies so the live demo works and so we can tell which ad you clicked. No analytics scripts, no advertising pixels.
Our marketing site and live demo set at most two cookies, both created by us and readable by no one else. Neither is used for advertising or shared with third parties.
| Cookie | Purpose | Lifetime |
|---|---|---|
sb_demo_visitor | A random identifier so the demo review page and the demo dashboard show the same sample data to the same visitor. | 30 days |
sb_src | The campaign parameters, landing page and referring site from your first visit, set only when you arrive via a tagged link. | 90 days |
We do not run third-party analytics, session recording or advertising pixels on this site. Our server logs record the IP address and browser of each request for a short period for security and rate limiting.
4. What is collected on review pages
A star rating, whatever you choose to type, and a scrambled version of your IP address that we cannot turn back into the address. Review pages set no cookies at all.
Review pages, testimonial walls and widgets set no cookies. When you open one we record that the page was viewed, and when you tap a star we record the rating. Both are tied to a keyed hash of your IP address and browser, which we use to count visitors and to stop abuse. The key is a server secret, the hash cannot be reversed without it, and we never store the raw IP address.
If you leave a testimonial we store the rating, the name you enter if any, your words, and the time you ticked the box allowing the business to publish it. If you send private feedback we store the rating, your message and the phone number or email you leave if you would like a call back. Private feedback is never published; it is emailed to the business and shown in the agency’s dashboard and client report.
Testimonials appear on the business’s public wall and website widget only after you have given permission and the agency or business has approved them. Every wall and widget carries a notice with an email address for removal requests.
5. How we use it
To run the service, send the emails you expect, keep out bots, and see whether our advertising works. Nothing else.
We use personal data to provide and improve the service; to send transactional email such as password resets, feedback alerts and account notices; to bill subscriptions; to detect and limit abuse; and to measure which marketing channels bring agencies to us. We do not sell personal data, use it to build advertising profiles, or send marketing email without consent.
Our legal bases, where the law requires one, are performance of the contract with the agency, our legitimate interests in running a secure and viable service, consent for publishing testimonials, and compliance with legal obligations.
8. How long we keep it
While the workspace is open, plus 30 days after you ask us to close it. Deleting a client deletes everything collected for that client straight away.
We keep account and workspace data while the workspace is active or read-only. When an agency deletes a client, every rating, review, feedback message and technician record for that client is deleted immediately. When an agency asks us to close its workspace we delete all of its data within 30 days, keeping only billing records the law requires us to hold.
Dashboard sessions expire after 30 days or when you log out. Server logs are kept for a short period for security. Backups roll over on a fixed schedule, so deleted data can persist in a backup for a limited time before it is overwritten.
9. Your rights
You can ask what we hold, have it corrected or deleted, or object to how we use it. Reviewers should ask the business first; if that fails, ask us.
Depending on where you live, including under the GDPR, the UK GDPR, and state privacy laws such as the CCPA, you may have the right to access the personal data we hold about you, to have it corrected or deleted, to receive a copy in a portable form, to object to or restrict certain processing, and to withdraw consent you have given. You also have the right to complain to your data protection authority.
Agency users can update most details in the dashboard and can email TODO: legal contact email for anything else. Reviewers should first contact the business or agency named in the notice on the review page or the removal email under a testimonial, because they control that data. If you cannot reach them or are not satisfied, email us and we will pass on the request and help resolve it.
We do not discriminate against anyone for exercising these rights, and we will respond within the time the applicable law allows, normally within 30 days.
10. Security and transfers
Passwords are hashed, sessions are hashed, IP addresses are scrambled with a secret key, and every connection is encrypted. Data may be stored outside your country.
Passwords are hashed with scrypt. Session, invite and reset tokens are stored only as hashes. IP addresses are stored only as keyed hashes. Every workspace’s data is isolated by workspace identifier at the database layer. All traffic is encrypted in transit.
Our servers and providers may be located outside the country where you live. Where the law requires safeguards for international transfers, we rely on standard contractual clauses or an equivalent mechanism with each provider.
No system is perfectly secure. If we become aware of a breach affecting your data we will notify the affected agency without undue delay and, where required, you and the relevant authority.
11. Children, changes and contact
The service is for businesses, not children. We will tell agencies by email if this policy changes in a way that matters. Our contact details are below.
The service is offered to businesses and is not directed at children. We do not knowingly collect data from anyone under 16; if you believe we have, email us and we will delete it.
We may update this policy. Material changes will be emailed to agency support addresses before they take effect, and the effective date at the top of this page will change.
Questions and requests about privacy go to TODO: legal contact email, or by post to TODO: legal entity name, TODO: postal address.
The plain-words notes explain each section and are not part of the agreement. Where they and the full text differ, the full text applies.