Privacy Policy
This policy explains what personal information allpaintcolours.co.uk collects, why, how it’s used, and the rights you have over it. There are two halves: the website, which needs no account and collects very little, and accounts, which you create only if you want to use All Paint Colours inside an AI tool (the MCP connector) or through the API. We aim to be specific rather than generic — if anything is unclear, email [email protected].
Who we are
allpaintcolours.co.uk is operated by Sulis Minerva LLP (“we”, “us”), a limited liability partnership registered in England & Wales, VAT number 471 5544 84. We are the data controller for the personal information described here.
For privacy questions or requests about your data, contact [email protected].
Using the website without an account
Information you actively give us
- Photo uploads to the colour-match tool. When you upload a photograph to the match tool, the image is sent to our server, processed to extract a small palette of dominant colours, and discarded immediately afterwards. We do not retain the image.
- “What’s on your walls” submissions. If you submit a colour-on-the-wall record on a colour page, we store the brand, colour name, and room you provided. We don’t link this to any personal identifier.
- “Email me this link”. If you ask us to email you a link to your palette or planner project, your address is used once to send that email and is not stored by us afterwards (our email provider keeps delivery records for a short period — see Who we share it with).
Information collected automatically
- Server access logs. Like virtually every web server, ours records the URL you requested, the time, the page that referred you, your browser’s user-agent string, and your IP address. Logs are rotated and discarded after roughly 30 days.
- PostHog product analytics. We use PostHog (EU instance) to understand how the site is used: which pages get viewed, which paint colours get clicked, whether features like the planner or palette are working as intended. PostHog assigns each browser an anonymous identifier stored in a cookie/localStorage so that repeat visits aren’t double-counted. For visitors without an account we never associate this identifier with a name or email.
- Pinterest Tag. We embed a small script provided by Pinterest that lets us measure which Pinterest pins drive traffic to the site and (potentially in future) run retargeted Pinterest advertising. The Pinterest Tag sets cookies on your browser. Pinterest’s own privacy policy describes what they do with the data they receive.
- Cloudflare. Our site is served via Cloudflare’s content delivery network, which inspects incoming requests for security/performance reasons. Cloudflare’s handling of this data is described in their privacy policy.
Information stored only on your device
Two features keep state in your browser’s localStorage and never send it to us unless you have an account and choose to save it:
- Your palette (colours you’ve saved with the “+” button), and
- Your paint planner project (rooms, dimensions, colour assignments, materials list).
Clearing your browser data wipes these. Sharing a planner project via the “Share” button puts the project state into the shared URL itself; we don’t see or store it.
If you create an account
An account is needed to use All Paint Colours inside an AI tool (Claude, ChatGPT, Cursor and other MCP clients) or through the REST API, and to subscribe to a paid plan. Everything in this section applies only to account holders.
What we store
- Sign-in details. Your email address; a hashed password if you set one; the public part of any passkey you register (the private key never leaves your device); and, if you sign in with a provider such as Google, the identifier that provider gives us. These are held by our authentication provider, Supabase, in the EU (Frankfurt).
- Things you save. Palettes and planner projects you save through the connector, the API or the account page.
- API keys. Stored as a one-way hash; we can’t read a key back, only recognise it.
- Subscription. Your plan (Free, Home or Pro), its status and renewal date, and the identifiers Stripe assigns to you as a customer and to your subscription. We never see or store card details — payment happens on Stripe’s pages.
- Usage. A daily count of the tools and endpoints you called, so we can enforce the monthly allowance for your plan, plus a count of calls that asked for something above your plan. We store the counts, not the content of your requests.
- Consents. Which AI tools you have authorised to act as you. Each gets a token that works only with All Paint Colours; you can revoke it from within the tool.
What passes through, and isn’t kept
- Your requests. When your AI tool asks us something on your behalf — a colour name, a hex value from a screenshot, room dimensions — we process it to answer and keep it only if you save the result as a palette or project. Note that the AI tool itself (and the company behind it) sees your whole conversation; their privacy policy governs that, not ours.
- Emails we send you. Sign-in links, password resets, security notices (for example, that your password was changed) and links you ask us to email. These are transactional; we don’t send marketing email.
Analytics for account holders
Each call through the connector or API records an event in PostHog — the tool used, your plan, and whether the call was allowed — keyed by your account identifier, not your email. On the account page we mark your browser’s PostHog identifier with the same account identifier so we can see which features people actually use. This is pseudonymous data that we could link to you through our own database; we use it in aggregate to improve the product and never to profile you individually.
How we use this information
- Provide the website, the connector and the API, and the things you save
- Sign you in and keep your account secure, including notifying you of security-relevant changes
- Take payment for paid plans, apply the right plan to your account, and enforce its monthly allowance
- Send the transactional emails described above
- Understand which features are used and fix what isn’t working, in aggregate
- Measure how visitors find the site (search engines, AI assistants, Pinterest, direct)
- Protect the service from automated abuse
- Keep the records tax law requires of a VAT-registered business
We do not sell personal information, do not run third-party advertising on the site, and do not send marketing emails.
Legal basis (UK GDPR)
- Performance of a contract — everything needed to run your account and any paid plan: sign-in, saved work, billing, usage allowances, transactional email.
- Legitimate interests — analytics, security logging and abuse prevention for a small service, assessed against your interests and kept pseudonymous wherever we can.
- Legal obligation — retaining billing records for the period tax law requires.
- Consent — any retargeting cookies via the Pinterest Tag, where the law requires it. We will add a cookie consent mechanism if and when our use clearly requires one.
Who we share it with
These providers process personal data for us (or, where noted, as independent controllers). We don’t share personal information with anyone else for their own purposes.
- Supabase (EU, Frankfurt) — authentication and the database holding your account, saved work, keys, subscription status and usage counts.
- Stripe — payments and invoices. Stripe is an independent controller for the payment data you give it on its pages; see Stripe’s privacy policy.
- Postmark (ActiveCampaign, United States) — delivers our transactional email and keeps delivery records, including message content, for up to 45 days.
- PostHog (EU) — product analytics, as described above.
- Cloudflare — content delivery and security for the website.
- Pinterest — the Pinterest Tag, as described above.
- The AI tool you connect (Anthropic, OpenAI, Cursor or another) — not our processor: you chose it, it sends us your requests, and its own policy applies to your conversations.
International transfers
Supabase and PostHog hold data in the EU. Postmark, Pinterest and parts of Cloudflare and Stripe involve transfers outside the UK and EEA. Where this happens we rely on the UK International Data Transfer Agreement or Addendum, or the provider’s equivalent Standard Contractual Clauses, together with each provider’s technical safeguards.
How long we keep it
- Account data (sign-in details, saved work, keys, usage counts): until you delete your account. You can do that yourself at any time from the account page; it removes everything listed above and cancels any subscription immediately.
- Billing records: Stripe keeps invoice records for the period UK tax law requires (six years) even after you delete your account; we keep no copy beyond that link.
- Server access logs: ~30 days
- PostHog event data: 12 months by default; we may keep anonymous aggregated metrics longer
- Postmark delivery records: up to 45 days
- User submissions (“what’s on your walls”): retained indefinitely as part of the public site dataset, but they contain no personal identifiers
- Photo uploads: discarded immediately after palette extraction
Your rights
Under UK GDPR you have the right to:
- Ask what personal information we hold about you (subject access request)
- Ask us to correct or delete it — account holders can delete everything themselves from the account page
- Object to processing based on legitimate interests
- Restrict our processing of it
- Receive a portable copy — your palettes and projects are also available to you through the API at any time
- Withdraw consent (where consent was the basis)
To exercise any of these, email [email protected]. If you don’t have an account we may need additional information to identify which records (if any) relate to you — typically the rough date and IP address of your visit.
You also have the right to complain to the Information Commissioner’s Office (ICO) if you believe we’ve handled your information improperly. We’d genuinely prefer you contact us first so we can fix it.
Cookies and local storage
The site sets cookies via PostHog and Pinterest as described above. If you sign in, your session is kept in your browser’s localStorage (not a cookie) so you stay signed in on that device; Stripe sets its own cookies on its checkout and billing pages. You can block or delete cookies in your browser settings; the planner and palette use localStorage, which is a separate mechanism, and will keep working. If your browser sends a Global Privacy Control or Do-Not-Track signal we will respect it where it applies.
Children
The site is not directed at children under 13, and you must be 18 or over to buy a plan. We don’t knowingly collect personal information from anyone under 13. If you believe a child has provided us with information, please contact us and we’ll delete it.
Changes to this policy
We may update this policy as the service evolves or as the law changes. The “Last updated” date at the top reflects when changes took effect. We will email account holders about material changes and flag them on the homepage for at least 14 days.
Contact
Sulis Minerva LLP
[email protected]