Privacy Policy
Last updated: 31 August 2026
1. Who we are
CentralContacts is a shared contact directory and contact-hygiene service for teams. It is operated by Towpath Digital Ltd ("we", "our", or "us"), a company registered in England & Wales (company number 16913912), registered office Huntingdon Boathaven, The Avenue, Godmanchester, Huntingdon PE29 2AF. We are registered with the UK Information Commissioner's Office (ICO) under reference ZC210106.
This policy explains what personal data we handle, why, on what legal basis, who we share it with, how long we keep it and the rights you have. It applies to our website, the CentralContacts application and related services. If you do not agree with this policy, please do not use the service.
2. Our role: controller and processor
CentralContacts is used by businesses to hold and maintain their own contact records, so our role under UK GDPR depends on whose data it is:
- We are the controller of the data of our account holders — the name, email, password, organisation and billing details you give us to open and run your account — and of website security logs and any marketing we send you. We decide how that data is used.
- We are a processor of the contact records you load into and manage in your directory. For that data you (the customer) are the controller: you decide what to store and why, and we process it on your documented instructions to provide the service. If you need a Data Processing Agreement (DPA) to cover this, we can put one in place — see section 7.
- When one of your contacts uses their self-service portal to review or correct what you hold, you remain the controller of that record; the contact is the data subject exercising their rights.
You remain responsible for having a lawful basis to hold and contact the people in your directory. CentralContacts gives you the tools and the records to do that well; it does not make you compliant on its own.
3. Information we collect
3.1 Account information
When you register for an account, we collect:
- Email address
- Full name
- Password (stored only as a secure one-way hash, never in readable form)
- Organisation name (if applicable)
- Job title and department (optional)
- Phone number (optional)
3.2 Contact data you hold
As you use the service you input and maintain contact records. You are the controller of this data (section 2). It may include:
- Contact names, email addresses and phone numbers
- Company, job title and department
- Tags and categorisation
- Internal notes and activity/audit logs
- The lawful basis and provenance of a contact (when and how they were added)
3.3 Data specific features process
- Contact hygiene. Checks the phone numbers and details already in your directory for format, plausibility, duplicates and gaps. The check is a silent lookup against carrier and network data: nothing is sent to the contact, no call or message is made, and the number is hashed before it is cached. Verification is positive-only: we confirm that a number is current — we never label a number as bad, and unconfirmed simply stays unverified.
- Campaigns and QR capture. When someone submits their details through a capture link or QR code you have shared, we record what they enter (such as name, email, phone and any consent they give) into your directory, together with when and how they submitted it, so you can evidence how you obtained the contact.
- Contact portal and portal analytics. The portal lets a contact see what you hold and review, correct or request removal of it. We record portal activity (for example whether a contact opened their portal and confirmed their details) so you can see adoption. This is a record of activity on the portal, not tracking elsewhere, and confirming details is verification, not consent to any particular use of the data.
- Contact notes. Free-text notes your team keeps against a contact. They are internal to your team and are not shown in the contact's self-service portal.
- Tasks and calendar sync. Dated tasks you create against a contact. If you connect Google Calendar, these appear as calendar events (see section 8).
3.4 Information collected automatically
When you use our platform, our servers and infrastructure record limited technical data:
- IP address and approximate location
- Browser type and version, and device information
- Pages visited and time spent
- Referring website
We use this to keep the service secure and reliable and to understand, in aggregate, how it is used. We do not build advertising profiles and we do not sell this data.
4. How we use your data, and our lawful bases
We process personal data for these purposes, on these UK GDPR lawful bases:
- Providing the service (contract). Running your account, authentication, storing and maintaining your directory, sending service messages and processing payments.
- Keeping things working and secure, and improving the product (legitimate interests). Protecting the platform, preventing abuse, keeping business contact directories accurate, and understanding usage in aggregate. Where we rely on legitimate interests we have weighed them against your rights.
- Consent. Where you connect a third-party account (such as Google or Microsoft), and where an individual submits their details through a capture form or QR code or confirms them through the portal. You can withdraw consent at any time.
- Legal obligation. Meeting tax, accounting and other legal requirements, and responding to lawful requests from authorities.
Where we act as your processor (section 2), the lawful basis for processing the contacts in your directory is the one you rely on as their controller.
5. Storage, security and retention
5.1 Where your data is stored
Your directory and account data are stored in our database, which is hosted in the United Kingdom (London) on Supabase's managed infrastructure. Backups and redundancy are kept within the same region. Some subprocessors that support the service operate outside the UK; see sections 6 and 10.
5.2 Security measures
- TLS encryption for all data in transit
- Encryption of data at rest
- Passwords stored only as a secure one-way hash (bcrypt)
- Row-level security policies that isolate each organisation's data
- Access tokens for connected accounts stored encrypted and used only server-side
- Least-privilege access controls and audit logging
5.3 Retention
- Account data: kept while your account is active. If you close your account we delete your account data within 30 days, except where we must keep it for legal reasons.
- Contact data you control: kept until you delete it or close your account, on your instruction as controller.
- Billing and tax records: kept for 6 years, as required by UK law.
- Consent and audit records: kept for the life of the account so you can evidence how a contact was obtained and maintained.
6. Subprocessors we use
We use a small number of trusted providers to run the service. They act on our instructions under a contract that requires them to protect your data and use it only to provide their service to us:
- Supabase — database, authentication and file storage. Hosted in the United Kingdom (London).
- Resend — sending transactional and notification email (invitations, verifications, alerts). Processes in the United States under appropriate safeguards (section 10).
- Stripe — processing payments for paid subscriptions. We do not store full card details; Stripe handles them and also acts as an independent controller for payment and fraud-prevention purposes.
- Twilio — telecoms services: checking whether a phone number is a live, valid line for contact hygiene (via Twilio Lookup), and delivering any one-time SMS codes. Numbers are checked against carrier and network data; the hygiene check sends no message to the person. Processes internationally under appropriate safeguards (section 10).
- Google and Microsoft — only where you choose to connect your own account. Data flows to and from your own third-party account under that provider's terms (section 8).
We keep this list current. If we add or change a subprocessor that materially affects business customers, we will update this page.
7. Data Processing Agreement (DPA)
Because we act as your processor for the contacts in your directory (section 2), and your organisation needs a Data Processing Agreement (DPA) to cover it, we will put one in place. It would set out the processing terms required by Article 28 UK GDPR, name our subprocessors, and cover the UK International Data Transfer Addendum and the EU Standard Contractual Clauses for any transfers outside the UK/EEA. To arrange this, contact us at dpo@centralcontacts.co.uk.
8. Data sharing and disclosure
We do not sell your personal data. Beyond the subprocessors in section 6, we may share data only:
8.1 Within your organisation
If you are part of an organisation on CentralContacts, contacts marked "organisation-wide" are visible to other members of your organisation, according to their role. Personal contacts remain private to you.
8.2 Legal requirements
We may disclose data where required by law or in response to a valid request from a court or public authority.
8.3 Business transfers
In a merger, acquisition or sale of assets, personal data may transfer. We will give notice before your data becomes subject to a different privacy policy.
9. Google and Microsoft integrations
CentralContacts lets you optionally connect third-party accounts — including Google and Microsoft — so your address book and your task calendar can stay in step with the tools you already use. Connecting is always your choice, happens only after you grant consent on the provider's own screen, and can be undone at any time. When you connect your Google account, one or more of the following apply, depending on the features you use:
- Importing contacts. With the read-only Google Contacts scope (
contacts.readonly) and your email address (userinfo.email), we read your Google contacts' names, email addresses, phone numbers, organisations and postal addresses solely to display them for your review and to import the ones you choose into your CentralContacts directory. - Saving a contact to your Google address book. When you select "Add to Google Contacts" on a contact, we use the Google Contacts scope (
contacts) to create that person in your own Google Contacts, and to keep that entry up to date if you later edit it in CentralContacts. This is one-way, from CentralContacts to Google, and only for the individual contacts you have explicitly added this way — we never bulk-write your directory into your Google account. - Syncing your tasks to your calendar. When you connect Google Calendar, we use the Calendar events scope (
calendar.events) to create, update and remove calendar events that correspond to your dated CentralContacts tasks, so your follow-ups appear in your own calendar and stay current. - Scope of access and protection. In every case we access only the data in your own connected account, and only for the feature you have enabled. Access tokens are stored encrypted and used only by our server; your browser never sees them. We do not use Google user data for advertising, we do not sell it, and we do not transfer it to others except as necessary to provide these features to you or as required by law.
- You can disconnect at any time — from within CentralContacts, or from your Google Account's security settings (Third-party access) — and you control which imported contacts, saved Google contacts and synced calendar events to keep or remove.
CentralContacts's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
10. Your rights
Under UK GDPR you have the right to:
- Access a copy of your personal data
- Rectification of inaccurate data
- Erasure of your personal data
- Restrict processing
- Data portability — receive your data in a portable format
- Object to certain processing, including direct marketing
- Withdraw consent at any time
To exercise these rights, contact us at dpo@centralcontacts.co.uk. If you are one of our customers' contacts, you can also use the self-service portal, or raise your request with the business that holds your details (the controller); we will support them in handling it. You also have the right to complain to the ICO at ico.org.uk.
11. International data transfers
Your directory and account data are stored in the UK (section 5). Some subprocessors process data outside the UK/EEA — in particular Resend (email) and Twilio (telecoms lookup and SMS) in the United States, and Stripe globally. Where data is transferred outside the UK/EEA we rely on appropriate safeguards, principally the UK International Data Transfer Addendum and the EU Standard Contractual Clauses, together with the provider's own security commitments.
12. Cookies and tracking
We use essential cookies for core functionality such as authentication and session management. We keep non-essential tracking to a minimum; where we use analytics it is to understand aggregate usage of the service. You can control cookies through your browser settings, though disabling essential cookies may affect functionality.
13. Children's privacy
CentralContacts is a business tool and is not intended for children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, contact us and we will remove it.
14. Changes to this policy
We may update this policy from time to time. We will post the new version here and update the "Last updated" date; for significant changes affecting how we use your data, we will give additional notice.
15. Contact us
Questions about this policy or your data:
- Data protection contact: dpo@centralcontacts.co.uk
- General enquiries: hello@centralcontacts.co.uk
- Controller: Towpath Digital Ltd, company no. 16913912, Huntingdon Boathaven, The Avenue, Godmanchester, Huntingdon PE29 2AF, United Kingdom. ICO registration ZC210106.