Privacy Policy
Last updated: 18 June 2026
This policy explains what personal data CrimeRisk collects and how it is used. We are the data controller for this data.
What we collect
- Account data: the email address you provide when signing up for an API key.
- Usage data: API request counts and timestamps used to enforce plan limits and prevent abuse.
- Billing data: handled by Stripe; we store only your Stripe customer and subscription identifiers, not card details.
Postcodes you query are not personal data and are used only to look up crime statistics.
How we use it
To provide and secure the Service, enforce plan limits, process payment, and contact you about your account. Our lawful bases are performance of our contract with you and our legitimate interest in running the Service.
Analytics & cookies
We use PostHog, a product-analytics tool, to understand how visitors use our website so we can improve it. PostHog records events such as the pages you view, clicks and similar interactions, your approximate location and device/browser type (derived from your IP address and request headers), and the site you arrived from. To do this it stores a small identifier on your device (using cookies or local storage) so it can recognise a browsing session.
If you reach our site by clicking a link in one of our outreach emails, that link carries a reference code so we can attribute the visit to that outreach and gauge interest. That is linked to the business email we contacted — we do not collect special-category data through analytics, and we never sell it.
Lawful basis: our legitimate interest (UK GDPR Article 6(1)(f)) in measuring and improving the Service. Your choice: we honour the browser “Do Not Track” signal, so enabling it stops analytics. You can also block or clear cookies, or email privacy@crimerisk.co.uk and we will exclude you from analytics.
Prospecting & marketing (how we contact businesses)
Separately from running the Service, we carry out occasional B2B outreach to UK letting and estate agencies to tell them about our area crime reports. This section explains how we handle that data.
- What we process: the agency name, a publicly listed business email address, and the business location (postcode or town). We keep this to the minimum needed to contact the business.
- Where it comes from: public sources only — OpenStreetMap and the agency's own public website. We do not collect it directly from any individual.
- Lawful basis: our legitimate interests (UK GDPR Article 6(1)(f)) in marketing a directly relevant product to relevant businesses. We have weighed this against the interests of the people concerned and keep the data minimal.
- What we do with it: we send occasional B2B outreach email. We may record whether a message was delivered or opened so we can gauge interest.
- Retention: we keep this data only for as long as it is useful for outreach, and we remove it as soon as you opt out.
Your choice — opt out at any time. You can object to this outreach or opt out whenever you like: reply “unsubscribe” to any of our emails, or email sam@crimerisk.co.uk. We will add you to a suppression list and never contact you again. You also have the usual rights to access or erase your data, and you may complain to the Information Commissioner's Office.
Sharing and processors
- Stripe — payment processing.
- PostHog — website and product analytics.
- Resend — sending our emails (account and outreach).
- Hosting / database providers — to run the Service.
We do not sell your personal data.
Retention
We keep account data while your account is active and for a reasonable period afterwards, and billing records as required by law (typically six years).
Your rights
Under UK GDPR you may request access to, correction or deletion of your personal data, and may complain to the Information Commissioner's Office. To exercise your rights, contact privacy@crimerisk.co.uk.
Data sources
Crime and location data come from public open datasets — see our Disclaimer for attribution.