Bitroad · Legal

Privacy Policy

How Bitroad collects, uses, shares, and protects personal data, and the rights you have over yours.

Last updated 28 July 2026

Bitroad is a trading name of Bitroad Limited, a company registered in England and Wales under company number 17310887. Contact us at [email protected], about privacy at [email protected], or to complain at [email protected].

In plain English

Bitroad Limited is the data controller. We collect what we need to run the marketplace, take payments, deliver orders, and keep the platform safe — and no more.

  • We use a small set of trusted providers (Stripe for payments, Cloudflare for delivery, Postmark for email, Anthropic for internal AI assistance) and host the app on infrastructure we control.
  • We use AI to help explain flagged activity and summarise disputes internally. It never makes a significant decision about you on its own — a human reviews contested and high-value cases.
  • We run no advertising, analytics, or third-party tracking.
  • When you buy, the seller sees the name, email, and delivery address needed to fulfil your order. Your agent's interface only sees an order reference.
  • You can access, correct, export, or delete your data. Erasure and a machine-readable data export are built into your account.

This summary is for convenience; the full policy below governs.

1. Who we are (controller)

Bitroad Limited is the "controller" of the personal data described in this policy. Our company and contact details appear at the top of this page; for privacy matters, contact [email protected].

We are registered with the UK Information Commissioner's Office (ICO) under registration number ZC208039. We are not required to appoint a statutory Data Protection Officer; responsibility for privacy sits with a named internal privacy lead, reachable at the address above.

Age. Bitroad is intended for use by individuals aged 18 and over. We do not knowingly collect personal data from children under 13, and if we become aware that we have done so, we will delete it. If you believe a child has provided us with personal data, contact [email protected].

2. What we collect

We collect:

  • Account data — name, email, password (hashed), and, for sellers, trading identity and geographic trading address.
  • Order and transaction data — items, prices, delivery address, order status, refunds, and returns.
  • Payment data — handled by Stripe; we store limited details such as card brand, last four digits, and expiry, not full card numbers.
  • Agent and delegation data — the agent instances you connect, the spending limits you set, and the attribution record linking each order to the principal, agent, and delegation (see section 6).
  • Support and dispute data — messages, evidence, and correspondence.
  • Technical and security data — limited logs needed to operate the service securely (for example request and anomaly logs).

3. How and why we use your data (lawful bases)

We rely on the following lawful bases under UK GDPR:

PurposeLawful basis
Creating your account, taking orders, processing payments and refunds, enabling deliveryPerformance of a contract
Keeping the platform secure, detecting anomalies and fraud, running our AI assistance, improving the serviceLegitimate interests (with a balancing assessment)
Keeping tax, accounting, and dispute records; responding to lawful requestsLegal obligation

Where we rely on legitimate interests, we have weighed our interests against your rights and use the data in the least intrusive way that meets the purpose.

4. AI processing

We use Anthropic's Claude models, on our own internal API key, to help explain anomaly-flagged activity and to summarise disputes for our internal review. Our lawful basis is legitimate interests, supported by a balancing assessment. This processing is carried out under Anthropic's terms on a no-training basis — your data is not used to train their models.

AI is never the sole basis of a decision that produces legal or similarly significant effects for you. In line with Article 22 UK GDPR, a human reviews contested outcomes and high-value cases before any such decision is made.

5. What sellers see when you buy

To fulfil your order, the seller needs to know who is buying and where to send it. In the seller's web console, the seller sees your name, email, and full delivery address for that order. This disclosure is grounded in the performance of your contract of sale with the seller, and sellers are bound to use it only to fulfil and support the order — not for unrelated marketing.

The machine (agent) interface is more limited: it exposes only an order identifier, not your contact details. This asymmetry is deliberate.

6. The order-attribution log and erasure

For every order we keep an "attribution log" that links the order to the principal, the agent instance, and the delegation under which it was placed. This record is essential for accountability, dispute defence, fraud prevention, and demonstrating that agent purchases were properly authorised.

We retain the attribution log even after an account is otherwise erased, relying on the Article 17(3) exceptions to the right to erasure (establishment, exercise, or defence of legal claims, and compliance with legal obligations). We keep it for 6 years from the order — a defined, justified period rather than "forever" — and we minimise and, where practical, pseudonymise it after erasure.

7. Who we share data with

We host the application on infrastructure we control (our own Ubuntu/Docker server running the app and its Postgres database, physically located in the United Kingdom); that server is Bitroad itself, not a third-party processor. No international transfer arises from our own infrastructure.

We share personal data with the following processors and providers, only as needed to run the service:

ProviderRolePurpose & location
CloudflareProcessorNetwork tunnel, DNS, CDN, WAF, and R2 object storage (e.g. uploaded images and return labels). R2 storage jurisdiction is set to EU/UK. Cloudflare is certified under the UK Extension to the EU-U.S. Data Privacy Framework, which we rely on as the transfer mechanism for any processing outside the UK.
StripeIndependent controller and processorPayments and payouts. Stripe determines its own compliance purposes (independent controller) and also processes on our behalf. Contracting entity: Stripe Payments UK Limited, an electronic money institution authorised by the FCA (firm reference 900461) — a UK-established entity, so no international transfer arises for this processing.
PostmarkProcessorTransactional email (order confirmations, account and notification emails). Contracting entity: AC PM LLC (an ActiveCampaign company), US-based. Certified under the UK Extension to the EU-U.S. Data Privacy Framework, which we rely on as the transfer mechanism.
AnthropicProcessorInternal AI assistance (section 4), no-training basis. US-based. Unlike Cloudflare and Postmark, Anthropic's transfer mechanism is not DPF-based: it relies on the EU Standard Contractual Clauses (Module 2/3) together with the UK Addendum (the ICO's International Data Transfer Addendum).
GoogleProcessorOptional "Sign in with Google" authentication only.
Royal Mail / DPDProcessor (planned)Carrier/tracking integrations — planned, not yet wired. This policy will be updated before they go live.

We do not use advertising networks, third-party analytics, or tracking technologies, and we do not sell personal data. We state this affirmatively: there are no analytics, error-tracking, or ad trackers on Bitroad. Our own infrastructure keeps core processing in the UK, on a server physically located in the United Kingdom.

8. International transfers

Some providers above are outside the UK. Where personal data is transferred internationally, we rely on an appropriate safeguard for each provider: Stripe is UK-established and involves no international transfer; Cloudflare and Postmark are certified under the UK Extension to the EU-U.S. Data Privacy Framework; and Anthropic's transfer relies on the EU Standard Contractual Clauses together with the UK Addendum.

9. How long we keep data

We keep personal data no longer than necessary:

DataRetention
Orders, invoices, and payment records6 years from the end of the financial year (tax/limitation)
Dispute files and evidence6 years from closure (defence of claims)
Order-attribution log6 years from the order, retained through erasure (Art 17(3))
Account data after closure90 days, then erased or anonymised (except the rows above)
Support correspondence2 years
Anomaly and security logs12–24 months
Founding 50 registerProgramme life plus 6 years

10. Your rights

Subject to the exceptions in this policy, you have the right to access, correct, erase, restrict, or object to our processing of your data, to data portability, and to withdraw consent where we rely on it. Two of these are built directly into your account:

  • Erasure — buyers can delete their account, and sellers can close their store, from within the app.
  • Data export — you can request a machine-readable export of your data (a subject access request) from within the app.

To exercise any right, contact [email protected]. You can also complain to the ICO (ico.org.uk), though we would like the chance to resolve your concern first.

11. Security

We take appropriate technical and organisational measures to protect personal data (Article 32 UK GDPR), including disk encryption, keeping the database off the public internet and reachable only over our tunnel, restricted and authenticated access, secrets management, and patching. The database is backed up nightly to encrypted, access-controlled off-site storage. We maintain a breach-response procedure and will notify the ICO within 72 hours of becoming aware of a reportable personal-data breach, and affected individuals where required.

12. Cookies and tracking

We use only the strictly necessary cookies needed to sign you in and keep your session and preferences working. We do not use analytics, advertising, or cross-site tracking cookies, so no cookie-consent banner is required.

13. US state privacy law

Bitroad is operated from the United Kingdom. In addition to the rights described elsewhere in this policy, if you are a resident of a US state with its own comprehensive privacy law, you have the right to know what personal data we hold about you, to correct or delete it, and to opt out of the sale or sharing of personal data. You can exercise these rights the same way UK/EU users do — by contacting [email protected] or using the in-app tools described above. We do not sell personal data, use it for targeted advertising, or use tracking cookies, so there is currently no sale or sharing for you to opt out of. For that reason, we do not yet operate a Global Privacy Control (GPC) or similar automated opt-out signal; if that changes, we will implement one and update this policy.

14. Changes to this policy

We may update this policy from time to time. For material changes we will give notice (at least 30 days where the change materially affects you) and update the date at the top of this page.

15. Contact and complaints

Privacy queries and rights requests: [email protected]. Complaints: [email protected]. You may also complain to the Information Commissioner's Office at ico.org.uk.