Spawncamp

Privacy policy

Last updated: 30 August 2026

This policy explains what personal information Spawncamp handles, where it comes from, and what you can do about it. We've tried to write it in plain English rather than legal boilerplate.

Who we are

Spawncamp is operated by Completa of Derby, United Kingdom [add your full postal address]. We are the data controller for the information described below.

We are registered with the Information Commissioner's Office under registration number [add once registered at ico.org.uk].

You can reach us at privacy@spawncamp.co.uk.

Two different groups of people

We handle information about two separate groups, and the rules differ for each. Please read the section that applies to you.

If you subscribe to Spawncamp

What we hold

We do not hold your card details. Payments are handled entirely by Stripe and we never see your card number.

Your saved searches, notes and contact stages are stored in your own browser, not on our servers. If you clear your browser data, they're gone and we cannot recover them.

Why we hold it

To provide the service you've paid for — that's performance of a contract. IP-based rate limiting is a legitimate interest in keeping the service secure and available.

How long

Your email address for as long as you subscribe, plus six years afterwards where we need it for tax records. Rate-limiting records for a few hours.

If you're a company director whose details appear in Spawncamp

Want to be removed? Email privacy@spawncamp.co.uk with your company name or number. We'll suppress it permanently, usually within a few days and always within one month. Suppression survives all future data updates, so you won't reappear.

What we show, and where it comes from

InformationSource
Company name, number, registration date, registered office address, trade codesCompanies House public register, used under the Open Government Licence v3.0
Business phone number and website, where one is listedOverture Maps open data, and Google Places

Most of this is company information rather than personal data. But we recognise that for a small company the registered office is often the director's home address, and the listed phone number is often a personal mobile. Where that's the case, it is personal data and we treat it as such.

Our lawful basis

We rely on legitimate interests — specifically, enabling businesses to make lawful business-to-business contact using information that is already published on a public register.

We have carried out and documented a legitimate interests assessment. In summary: the information is already public, it is used in a business context, we hold no special category data, we do not profile individuals or make automated decisions about them, and objecting is straightforward and permanent. We will share that assessment on request.

Why we haven't contacted you individually

Data protection law normally requires us to tell you when we obtain your information from somewhere other than you. Where information is drawn from a public register covering hundreds of thousands of companies, contacting each person individually would involve disproportionate effort. The law recognises this, and requires us instead to publish a clear public notice — which is this page.

Your rights

We respond within one month and there's no charge.

Who we share information with

We don't sell personal data. We use these providers, each under a data processing agreement:

ProviderWhat for
NetlifyWebsite hosting
SupabaseDatabase, hosted in the London (eu-west-2) region
StripePayments and subscription records
GoogleBusiness listing lookups

Subscribers can export search results, which means information may pass to them. They agree in our terms to handle it lawfully and to follow direct marketing rules.

Cookies and tracking

We use no advertising cookies, no analytics and no tracking pixels. Spawncamp stores a sign-in token and your own settings in your browser's local storage, which is strictly necessary for the service to function. That's why you won't see a cookie banner here.

Our pages load fonts from Google Fonts and an animation library from jsDelivr. Doing so reveals your IP address to those providers. If you'd rather avoid that, a content blocker will stop it and the site still works.

Security

All traffic is encrypted. API keys are held server-side and never reach your browser. Sign-in tokens are cryptographically signed and expire after twelve hours. Sign-in attempts are rate limited. No system is perfect, but if we ever suffer a breach affecting your rights we will tell the ICO within 72 hours and tell you without undue delay.

Changes

If we change this policy meaningfully we'll update the date at the top and, for subscribers, email you.