Legal

Privacy policy

What we collect, why, how long we keep it, and your rights. Written in plain English because that is how we would want to read it.

Last updated 9 October 2026

Who we are

BePostcodes is run by Craig Simpson, a sole trader trading as BePostcodes.com, based in Moray, Scotland. For data protection law, Craig Simpson is the controller of the personal data described on this page, except where the section on lookups from customers' websites says otherwise.

You can reach us at [email protected] or through the contact page. A postal address is available on request.

If you have a BePostcodes account

When you subscribe we collect and hold:

  • Your name and email address, to create your account, send you your access details, and tell you about your subscription, such as when your lookups are running low or a payment fails.
  • Your password, stored only as a one-way hash. We cannot read it.
  • Billing details held by Stripe. Card numbers are entered on Stripe's own checkout page and never reach our servers. We store Stripe's reference for your customer record and subscription so we can show your plan and let you manage it.
  • Your API key, which identifies your sites when they make lookups.
  • Usage records. Each lookup is recorded against your account with the time, the postcode that was searched, and the software identifier (user agent) sent by your website. These records let us count lookups against your plan, show usage on your dashboard, and investigate problems. They are kept for 12 months and then deleted automatically.
  • Support messages you send from your dashboard or the contact page, with your name and email address, so we can reply.

We rely on our contract with you as the legal basis for all of this, and on our legitimate interest in running the service securely for the usage records and support history.

Lookups made from customers' websites

When someone fills in a form or checkout on a website that uses our plugins, that website sends us the postcode they typed so we can return the list of addresses at it. We do not receive their name, the rest of their address, their email address or their IP address. The website owner never sends us what the visitor finally chose or typed.

For those lookups the website owner is the controller and we act as their processor. The postcode is used only to return addresses and to record the lookup against the owner's account as described above. We do not build profiles from postcodes or use them for anything else.

If you have reached this page because a website you used shows "Find address" powered by BePostcodes, that website's own privacy policy covers what it does with your address.

If you visit this website

Our hosting provider keeps short-lived server logs, including IP addresses, for security and to keep the service running. We use them only to diagnose faults and abuse.

With your consent, we use Google Analytics to see which pages are read and roughly where visitors come from. Nothing is loaded and no analytics cookie is set until you choose Accept on the cookie notice. You can change your mind at any time from the Cookie settings link in the footer.

If you use the contact form we receive your name, email address and message so we can reply. The form is protected by Cloudflare Turnstile, which checks the request is not automated; Cloudflare's own privacy policy covers that check.

Cookies

CookiePurposeLasts
bepostcodescom_session, XSRF-TOKENEssential. Keeps you logged in and protects forms against forgery.Session, or two hours
remember_web_…Essential. Set only if you tick "Remember me" when logging in.Up to five years
cookie_consentEssential. Remembers whether you accepted or declined analytics, so we do not ask again.Six months
_ga, _ga_…Analytics, Google. Set only after you accept. Distinguishes visitors so page views are not double counted.Up to two years

Essential cookies do not need consent under UK law because the site cannot work without them. Declining analytics removes any analytics cookies already set.

Who we share data with

We use a small number of companies to run the service. Each only receives what it needs for its job:

  • Payments: Stripe, for subscriptions and top-ups. Stripe is based in the US and Ireland and transfers are covered by its standard contractual clauses and the UK addendum.
  • Email: Mailgun, which sends our account and notification emails.
  • Hosting: Laravel Cloud, with our servers and database in London, United Kingdom.
  • Analytics: Google, only if you accept analytics cookies. Google may process the data in the US under its standard contractual clauses.
  • Address data: UK address data providers, which receive only the postcode being searched in order to return the addresses at it.
  • Anti-spam: Cloudflare, for the Turnstile check on the contact form.

We do not sell personal data, and we do not share it with anyone else unless the law requires it.

How long we keep data

  • Account details: for as long as you have an account, then deleted when you delete your account from your profile page.
  • Lookup usage records: 12 months, then deleted automatically.
  • Billing records held by Stripe and our invoices: six years, as UK tax law requires.
  • Support and contact messages: up to two years, so we have the history if the same problem comes back.
  • Server logs: a few weeks.

Your rights

Under UK data protection law you can ask for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, object to our use of it, or ask us to restrict it. You can delete your own account at any time from your profile page, which removes your account details immediately.

To exercise any of these rights, email [email protected]. We will reply within a month. If you are unhappy with how we handle your data you can complain to the Information Commissioner's Office at ico.org.uk.

Security

Everything between your browser, your website and our servers travels over HTTPS. Passwords are hashed. API keys are only ever used server-side by the plugins, so visitors to your website never see them. Access to the production systems is limited to the developer who runs the service.

Changes to this policy

If we change how we use personal data we will update this page and change the date at the top. For anything significant we will also email subscribers.