Legal

Privacy Policy

Last updated: 15 August 2026

Onboard (“we”, “us”, “our”) is committed to protecting your personal data. This policy explains what data we collect, why we collect it, and your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

We are the data controller for personal data processed through our platform. If you have questions, contact us at support@onboardmy.site.

1. Data we collect

Account and billing data

  • Name, email address, and password (stored as a salted hash)
  • Organisation name and billing address
  • Payment method details (handled by Stripe — we never store card numbers)
  • Subscription and invoice history

Usage data

  • Pages visited, features used, and timestamps
  • IP address, browser type, and device information
  • Error logs and performance metrics

Client data you provide

When you use Onboard to onboard your clients, you may input data about those clients (names, email addresses, project details). You are the data controller for that data; we process it on your behalf as a data processor under Article 28 UK GDPR.

Data collected through client portals

  • Files and documents uploaded by your clients
  • OAuth tokens for connected accounts (Google Analytics, Meta, etc.)
  • Form responses and credentials submitted through portal steps

2. How we use your data

  • To provide the service — creating accounts, processing onboarding requests, delivering client portals
  • To process payments — billing, invoicing, and subscription management
  • To communicate with you — transactional emails, support responses, service notices
  • To improve the platform — aggregated analytics and error monitoring
  • To comply with legal obligations — tax records, fraud prevention, regulatory requirements

3. Legal basis for processing

We process your personal data under the following legal bases (Article 6 UK GDPR):

  • Contract — processing necessary to perform the contract with you (providing Onboard)
  • Legitimate interests — improving the service, preventing fraud, security monitoring
  • Legal obligation — complying with tax and financial regulations
  • Consent — marketing communications (you may withdraw at any time)

4. Third parties we share data with

  • Supabase — database and authentication infrastructure (data hosted in EU)
  • Vercel — application hosting and content delivery
  • Stripe — payment processing (PCI DSS compliant)
  • Resend / email provider — transactional email delivery

We do not sell your personal data to third parties. We do not use your data for advertising purposes.

5. International transfers

Some of our sub-processors operate outside the UK. Where data is transferred internationally, we ensure appropriate safeguards are in place, including UK International Data Transfer Agreements (IDTAs) or adequacy decisions.

6. Data retention

  • Account data — retained for the duration of your subscription plus 7 years (for financial records)
  • Client portal data — retained until you delete the client record or close your account
  • Usage logs — retained for 90 days
  • Backups — purged within 30 days of deletion

7. Your rights under UK GDPR

You have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — ask us to correct inaccurate or incomplete data
  • Erasure — request deletion of your data where there is no overriding legal obligation to retain it
  • Restriction — ask us to limit processing in certain circumstances
  • Portability — receive your data in a structured, machine-readable format
  • Objection — object to processing based on legitimate interests
  • Withdraw consent — where processing is based on consent, you may withdraw it at any time

To exercise any of these rights, email support@onboardmy.site. We will respond within one calendar month.

8. Cookies

We use strictly necessary cookies to maintain your authenticated session. We do not use advertising or tracking cookies. No cookie consent banner is required for strictly necessary cookies under the UK PECR.

9. Security

We use industry-standard security measures including TLS encryption in transit, AES-256 encryption at rest, row-level security on all database tables, and regular access reviews. API keys are stored as SHA-256 hashes only.

10. Complaints

If you are unhappy with how we handle your data, you may lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

11. Changes to this policy

We may update this policy from time to time. We will notify you of material changes by email or via an in-app notice at least 14 days before they take effect.