Privacy Policy
Last updated: 19 July 2026
1. Who We Are
Shop Incognito Ltd (“we”, “us”, “our”) is the data controller for personal data processed through Incognito Fire & Security Professional (“the Service”).
Incognito Fire & Security is a trading name of Shop Incognito Ltd.
This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, how long we keep it, and your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Questions or concerns about your personal data: support@incognitofiresecurity.com
Incognito Fire & Security is a trading name of Shop Incognito Ltd.
2. What Personal Data We Collect
Account data
When you register, we collect your email address, name, and (optionally) your company name. This data is necessary to create and manage your account and to communicate with you about the Service.
Usage data
We collect data about how you use the Service, including the queries and searches you submit to the AI assistant, fault database searches, session data, and feature usage counts. Query content is processed by our AI provider (Anthropic) to generate responses. We maintain rolling usage counts to enforce fair-use limits. Certain high-risk query categories may be logged in summary form (category and a short excerpt only) for safety monitoring and quality assurance purposes.
Subscription and billing data
We collect and store subscription identifiers, plan type, and subscription status to manage your subscription and verify your access level. For website subscriptions this may include Stripe customer and subscription IDs. For iOS in-app subscriptions this may include Apple product and transaction identifiers. We do not store your card number, expiry date, or CVV.
Technical and device data
We automatically collect technical data including your IP address, browser type, device type, operating system, and access timestamps. This data is used for security monitoring, abuse prevention, and service reliability, and may appear in server access logs maintained by our hosting provider (Vercel).
Support and feedback data
If you contact us for support or submit feedback, we collect the content of your communications and your email address to respond to you and to improve the Service.
Onboarding preferences
During onboarding we may collect your preferred panel manufacturers and experience level. This data personalises your experience and is stored in your profile.
3. Legal Basis for Processing
| Processing activity | Lawful basis (UK GDPR Article 6) |
|---|---|
| Creating and managing your account | Performance of a contract (Art. 6(1)(b)) |
| Providing the AI assistant and fault database | Performance of a contract |
| Processing subscription payments via Stripe | Performance of a contract / Legal obligation (Art. 6(1)(c)) |
| Usage counts and fair-use enforcement | Performance of a contract / Legitimate interests (Art. 6(1)(f)) |
| High-risk query safety logging | Legitimate interests (safety and quality assurance) |
| Security monitoring and abuse prevention | Legitimate interests |
| Transactional and service emails | Performance of a contract / Legitimate interests |
| Marketing communications (if applicable) | Consent (Art. 6(1)(a)) — may be withdrawn at any time |
4. How We Use Your Data
We use your personal data to:
- provide, operate, and maintain the Service;
- create and manage your account and verify your subscription status;
- process payments and manage billing through Stripe;
- send transactional emails (account confirmation, password reset, billing receipts, service notices);
- enforce fair-use limits and service access controls;
- monitor for and prevent abuse, fraud, and security incidents;
- log high-risk queries in summary form for safety monitoring and quality assurance;
- respond to support requests and feedback; and
- improve and develop the Service (using aggregated, anonymised data where possible).
We do not sell your personal data to third parties. We do not use your data for advertising purposes. Incognito Fire & Security Professional is an ad-free product.
5. Who We Share Your Data With
We share your personal data only with the following third-party processors, under data processing agreements, and only to the extent necessary to provide the Service:
- Supabase Inc. — provides our database, authentication, and backend hosting. Your account data, profile data, usage counts, and subscription records are stored in Supabase. Supabase operates data centres in the EU and US.
- Stripe, Inc. — processes subscription payments and stores payment method details. We share your email address and subscription status with Stripe; we do not share card data (which Stripe collects directly from you). Stripe is certified PCI DSS Level 1.
- Apple Inc. — processes iOS in-app subscription purchases and provides purchase receipts and transaction identifiers used to verify app access.
- Anthropic, PBC — provides the large language model (AI) that powers our assistant. The text of queries you submit to the AI assistant is sent to Anthropic’s API for processing. Anthropic is based in the United States; see section 10 regarding international transfers.
- Vercel Inc. — hosts the web application. Vercel processes server access logs including IP addresses and request metadata. Vercel operates globally with infrastructure in the EU and US.
We may also disclose personal data if required to do so by law, court order, or by a regulatory or government authority, or where we believe disclosure is necessary to protect the rights, property, or safety of the Operator, our users, or others.
6. Data Retention
- Account data (email, name, profile): retained while your account is active and for 90 days after account deletion to allow reactivation and resolve post-deletion disputes.
- Subscription and billing records: retained for the duration of your subscription plus 7 years to meet statutory accounting and tax obligations.
- Usage counts: retained on a rolling basis for the duration of your subscription.
- High-risk query logs: retained for up to 24 months from the date of logging, then permanently deleted.
- Server access logs: retained for a short period (typically 30–90 days) for security purposes.
- Support communications: retained for up to 2 years after the last communication.
When data is no longer required, it is securely deleted or anonymised.
7. Your Rights Under UK GDPR
You have the following rights in relation to your personal data:
- Access: request a copy of the personal data we hold about you.
- Rectification: ask us to correct inaccurate or incomplete data.
- Erasure (“right to be forgotten”): ask us to delete your personal data, subject to legal retention requirements (see section 8).
- Data portability: request your data in a structured, machine-readable format.
- Restriction of processing: ask us to restrict how we use your data in certain circumstances.
- Object: object to processing based on legitimate interests.
- Automated decision-making: we do not make solely automated decisions that produce legal or similarly significant effects about you.
To exercise any of these rights, email support@incognitofiresecurity.com with the subject line “Data Rights Request”. We will respond within one calendar month. We may need to verify your identity before processing your request.
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.
8. Data Deletion Requests
You can delete your account and request erasure of your personal data in one of two ways:
- Via your account dashboard: go to Account settings and select “Delete Account”. You will be asked to type DELETE to confirm. This permanently deletes your account, profile, and associated data.
- By email: send a request to support@incognitofiresecurity.com with the subject line “Data Deletion Request” and include the email address associated with your account. We will process your request within 30 days and confirm by email.
Following deletion, we will retain only the data we are legally required to keep (principally billing records for accounting purposes) and a minimal deletion audit record. All other personal data will be permanently deleted.
If you have an active paid subscription, please cancel it before requesting account deletion to avoid continued billing.
9. Cookies
We use cookies and local storage entries necessary to operate the Service, plus Google Analytics on public website pages to understand aggregate traffic and improve the product. We do not use advertising cookies or sell personal data.
- Authentication cookies (Supabase): session tokens that keep you signed in. These are strictly necessary and cannot be disabled while using the Service. They expire when you sign out or after a period of inactivity.
- Theme preference: a local storage entry recording your light/dark mode preference. Stored locally on your device only; not transmitted to our servers.
- Google Analytics: public page-view and event measurement used to understand which pages are being visited and where the website needs improvement.
We do not use Meta Pixel or advertising trackers.
10. International Data Transfers
Some of our third-party processors are based outside the UK. Your data may be transferred to and processed in the United States and other countries:
- Anthropic (US): query data sent to the AI assistant is processed in the United States. Transfers are safeguarded by the UK International Data Transfer Agreement (IDTA) or Standard Contractual Clauses (SCCs) as appropriate.
- Stripe (US): payment processing involves limited personal data transfer to the US. Stripe maintains SCCs and is certified under applicable international transfer frameworks.
- Supabase and Vercel: may use infrastructure in both the EU and US; transfers are conducted under appropriate safeguards.
We take steps to ensure that international transfers are made under appropriate safeguards that provide protection equivalent to UK GDPR requirements.
11. Security
We take reasonable technical and organisational measures to protect your personal data, including:
- database row-level security enforced at the Supabase layer;
- server-side storage of all API secrets and credentials;
- HTTPS encryption for all data in transit; and
- authentication required to access all personal data.
No system is perfectly secure. If you believe your account has been compromised, please contact us immediately at support@incognitofiresecurity.com.
12. Children
The Service is intended for professional use by adults (18+) in the fire and security industry. We do not knowingly collect personal data from persons under 18. If you believe a minor has registered, please contact us and we will delete their account promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email and/or a prominent notice within the Service at least 14 days before the changes take effect. Your continued use of the Service after that date constitutes acceptance of the revised policy.
14. Contact and Complaints
For questions, concerns, or data rights requests:
Email: support@incognitofiresecurity.com
Incognito Fire & Security is a trading name of Shop Incognito Ltd.
You also have the right to complain to the ICO: ico.org.uk/make-a-complaint | Tel: 0303 123 1113