DataSpice
What DataSpice collects, and what it never stores
What this service collects, why, how long it is kept, and how to have it removed. It covers two different groups of people, and the difference matters: the customers who sign in here, and the visitors to the websites those customers measure.
Last updated 11 August 2026
Who is responsible
TOORX LTD, doing business as DataSpice, operates dataspice.net from its registered office at 71-75 Shelton Street, London, WC2H 9JQ, United Kingdom. Questions about this policy, and any request described below, go to [email protected].
For the account data of customers who sign in, we are the controller. For the website measurements a customer collects through our tracker, the customer is the controller and we are their processor: they decide what is measured and why, and we act on their instructions.
What we hold about customers
An account exists to let someone sign in and be billed. It holds:
- The email address used to sign in, and a display name if one is provided.
- A profile picture, only if one is uploaded.
- Sign-in records: the time, the provider used, and the network address the request came from. These exist so an account owner and we can both see unfamiliar access.
- Subscription state held by our payment provider, and the plan chosen. Card details are entered on the provider’s own pages and never reach our servers.
What the tracker collects, and what it deliberately does not
The script a customer installs on their site reports a page view and a small set of facts about it. It is built so that the things most analytics tools collect, and that make them a privacy problem, are not collected here at all.
- The page address is reduced to its origin and path before it is sent. Query strings and fragments, which routinely carry names, tokens and search terms, are dropped in the browser and never transmitted.
- The referring address is reduced to its origin, so which page someone came from is known only as far as the site.
- The visitor’s time zone, as reported by their operating system.
- Browser, operating system and device type, derived from the request.
- Country, established from the connection by our server. No location is read from the device, and no permission is requested.
- Custom properties a customer chooses to send, filtered against a sensitive-value screen before they leave the page.
No cookies, and no cross-site identity
The tracker does not need a cookie banner because it does not set the kind of identifier a banner exists to disclose. Repeat visits are recognised with a value kept in the browser’s own storage for the one site being measured, or, when a customer configures it, with no stored value at all. Nothing is shared between sites, no profile follows anyone across the web, and no data is sold, rented, or passed to an advertising network.
Traffic that no person produced, such as automated browsers, crawlers and requests from development machines, is identified and either excluded or reported separately, so it is not counted as a visitor.
One exception on this site, stated rather than buried: the support chat widget sets its own storage in your browser so a conversation survives a page change. It is the chat provider’s, it is used for nothing else, and it is not part of what the tracker measures. Customers’ sites do not carry it.
Why we are allowed to hold it
Account and billing data is processed to perform the contract a customer enters when they open an account. Sign-in and audit records are processed on our legitimate interest in keeping accounts secure and in being able to investigate access to them. Website measurements are processed on our customer’s instructions under their own lawful basis; where their local law requires consent for what they collect, obtaining it is theirs to do, and the tracker supports being held until consent is given.
How long it is kept
Measurements are kept for the window the customer’s plan states and are then removed by an automatic sweep. The plan’s window is the promise and the rule, and they are the same number: what the pricing page states is what the system enforces.
Account data is kept while the account exists. Deleting a project deletes the measurements under it. Closing an account removes the account and its measurements; records we are required to retain for tax and accounting are kept for the period the law of England and Wales requires and for no longer.
Who else processes it
We use a small number of providers, each for one purpose, and none of them receives data for their own use:
- A payment provider, for subscriptions and invoices. Card details are handled entirely by them.
- An email provider, to deliver sign-in links and service notices.
- An identity provider, when a customer chooses to sign in with an external account. It verifies the sign-in once; the session afterwards is ours.
- Apple, when a customer connects App Store Connect, and their payment provider, when they connect revenue data. In both cases it is to read the customer’s own figures at their instruction.
- Google, when a customer connects Google Search Console. We read the search performance figures for the customer’s own verified property — the queries, pages, clicks, impressions and positions Google already reports to them — using read-only access they grant and can withdraw at any time from their Google account. We do not read anything else in their Google account, and we never write to it. The authorisation is held encrypted on our servers and is never sent to a browser.
- A live-chat provider, Tawk.to, for support conversations on this site. It receives what you type into the chat, the page you opened it from, and your network address. It loads only on this site and never on a customer’s.
Your rights
You may ask for a copy of what we hold about you, ask for it to be corrected, ask for it to be deleted, ask us to restrict or stop a particular use, and object to processing we base on legitimate interest. Write to [email protected] and we will answer within one month.
If you are a visitor to a site measured with our tracker rather than a customer of ours, the operator of that site decides what is collected and is the right party to ask first. Tell us and we will identify them to you and act on their instruction.
If you believe we have handled your data wrongly you may complain to the Information Commissioner's Office (ICO), the data protection regulator for the United Kingdom, at ico.org.uk. We would rather you told us first.
Security
Every customer record is scoped to the workspace that owns it and access is checked on every request. Credentials for connected services are encrypted before storage with keys held separately from the data. Session tokens are stored only as hashes, so a copy of the database cannot be replayed as a sign-in. Traffic is served over HTTPS only.
No system is beyond compromise. If a breach affects you, we will tell you and the relevant authority within the time the law requires, and we will tell you what we know rather than waiting until we know everything.
Changes
When this policy changes materially we will say so on this page and, for changes that affect customers, by email before they take effect. The date at the top is the date of the current text.
Contact
- Company
- TOORX LTD, trading as DataSpice
- Registered office
- 71-75 Shelton Street, London, WC2H 9JQ, United Kingdom
- [email protected]