Subdrift.

Legal

Privacy Policy

Last updated: 17 June 2026

1. Who we are

Subdrift (“we”, “us”) maintains a catalogue of B2B SaaS vendors and sends free email alerts when a vendor’s list of subprocessors changes. For the personal data described in this policy, the data controller is Subdrift, based in the United Kingdom. You can contact us about any privacy matter, including the rights set out below, by email at privacy@subdrift.co.

Given the small scale of our processing, we are not required to appoint a Data Protection Officer and have not done so.

2. The information we collect

We keep the data we hold deliberately small, and you provide all of it directly when you subscribe. We collect:

  • Your email address — so we can confirm your subscription and send the change alerts you ask for.
  • The vendor(s) you choose to follow — so we know which alerts to send you.
  • Subscription status and timestamps — when you subscribed, confirmed, and (if applicable) unsubscribed, plus the random tokens that secure your confirmation and one-click unsubscribe links.

We do not collect your name, postal address, phone number, payment details, or account password (the service has no login for subscribers), and we do not store your IP address against your subscription record.

Our hosting, email, and monitoring providers (below) do necessarily process technical connection data such as IP addresses in order to deliver and secure the service. We do not retain that data ourselves or use it to identify you.

3. Why we process it, and our lawful basis

Under the UK and EU GDPR we rely on two lawful bases:

  • Consent (Article 6(1)(a)) — for sending you the confirmation email and the change alerts. You give consent by subscribing and confirming. If you already have a confirmed subscription with us, any further vendors you follow are activated immediately on the basis of that existing confirmation, without a new confirmation email. You can withdraw consent at any time using the unsubscribe link in every email or by emailing us; withdrawing it does not affect alerts already sent.
  • Legitimate interests (Article 6(1)(f)) — for keeping the service running securely and reliably: protecting our forms from abuse, monitoring errors, and understanding aggregate usage. We balance these interests against your privacy and keep the data involved minimal.

4. Cookies and analytics

We do not use advertising or tracking cookies, and there is no cookie consent banner because we set no cookies or device identifiers for analytics. Our analytics (provided by Vercel) is cookieless and reports only aggregate, anonymised traffic and performance metrics.

Rather than storing anything in your browser, it counts a visit using a short-lived identifier derived from your request on the server and discarded after 24 hours. It does not retain your IP address and cannot follow you across other websites.

The only thing we store in your browser is a single local preference recording whether you chose light or dark mode. It never leaves your device and identifies no one.

5. Who we share it with

We never sell your data. We share it only with the service providers (“processors”) that operate the service on our behalf, under contracts that require them to protect it:

ProviderWhat it doesLocation
VercelHosting, content delivery, cookieless analytics, and performance monitoring (Speed Insights).United States / global edge
NeonManaged PostgreSQL database where your subscription record is stored.United States (AWS us-east-1)
ResendDelivery of the confirmation email and the change-alert emails you ask for.European Union (Ireland)
SentryError and performance monitoring. We attach only a one-way hash of your email and filter out email addresses before reports are sent.United States

We may also disclose data if required by law, or in connection with a merger, acquisition, or sale of assets — in which case we will tell you before your data becomes subject to a different privacy policy.

6. International transfers

Three of the providers above — Vercel, Neon, and Sentry — process data in the United States, so for those your data is transferred outside the UK and the European Economic Area (EEA). Each is certified under the EU–US Data Privacy Framework and its UK Extension, and each additionally maintains the EU Standard Contractual Clauses together with the UK International Data Transfer Agreement (or Addendum) as a fallback safeguard. Between them, these mechanisms are designed to give your data a comparable level of protection to that required in the UK and EEA. Resend processes your data within the EEA (Ireland), so it does not involve such a transfer. You can ask us for the specific mechanism relied on for any provider.

7. How long we keep it

We keep your subscription record only while your subscription is active. When you unsubscribe, we stop using it to send you anything and retain only your email address on a suppression list — the minimum needed to make sure we don’t email you again by mistake (a legitimate interest, and in the UK a duty under PECR).

We do not currently run an automatic deletion schedule, so if you want your data erased entirely rather than kept on the suppression list, email us at privacy@subdrift.co and we will delete it, subject to anything we must keep by law.

8. Your rights

Under the UK and EU GDPR you have the right to:

  • be informed about how we use your data (this policy);
  • access the data we hold about you;
  • have inaccurate data corrected;
  • have your data erased;
  • restrict or object to our processing;
  • data portability — receive your data in a portable format;
  • withdraw consent at any time.

Some of these rights apply only in certain circumstances and can be subject to legal limits; if an exception applies to your request, we will explain why.

To exercise any of these, email privacy@subdrift.co. We will respond within one month, though we may extend this by up to two further months for complex requests and will tell you if we do. There is no charge, and exercising your rights will never lead to worse treatment.

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.

9. How we protect it

All data is encrypted in transit (TLS). Confirmation and unsubscribe links use unguessable random tokens. In our error monitoring we identify you only by a one-way hash of your email, and we filter out email addresses before reports are sent, so we aim to keep your personal data out of those reports — though no such filter can be guaranteed perfect. No method of transmission or storage is completely secure, but we take reasonable steps to protect your data and to limit how much of it we hold.

10. Children

Subdrift is a tool for professionals and is not directed at children. We do not knowingly collect data from anyone under 16 (13 in the UK).

11. Changes to this policy

We may update this policy from time to time. The “last updated” date at the top reflects the latest version, and material changes will be reflected here before they take effect.

12. Contact and complaints

Questions, requests, or concerns: email privacy@subdrift.co.

If you are unhappy with how we have handled your data, you have the right to complain to a data-protection authority. In the UK that is the Information Commissioner’s Office (ICO) at ico.org.uk (opens in new tab). If you are in the EEA, you can complain to your local supervisory authority — find yours via the European Data Protection Board (opens in new tab). We would appreciate the chance to put things right first.

← Back to Subdrift