Legal

Privacy Policy

Last updated: 26 August 2026

1. Who is responsible

Red Salt Media (Liverpool, United Kingdom) is the data controller for personal data processed by Vantage (redsaltvantage.co.uk and app.redsaltvantage.co.uk). Contact us through the contact page.

2. What we collect

Account data (business name, your name, email, hashed password), team seats you create (name, email, hashed password), billing data handled by Stripe (we store a customer reference and subscription status, never full card numbers), the client-business profiles and content you create in the workspace, connections you authorise to services like Google (we store the tokens needed to act on your instruction), usage and technical logs (IP address, browser, pages requested) needed to run and secure the service, and messages you send us.

3. Why we use it

To provide the service you signed up for (contract), to take payment and keep accounts (legal obligation and contract), to secure the service, prevent abuse and fix problems (legitimate interests), and to send service emails such as receipts, password resets and important account notices. We do not sell personal data, and we do not send marketing email without your consent.

4. AI features

When you use AI features, the text you provide (such as a client-business profile and your inputs) is sent to our AI provider, Anthropic, to generate the output you asked for. We send only what the feature needs, and we do not use your content to train models.

5. Who we share it with

Service providers who process data for us: Stripe (payments), Anthropic (AI generation), Google (only for connections you authorise, such as Search Console, Google Ads and YouTube), our hosting providers, and an email delivery provider for service emails. Each processes data under its own safeguards and our instructions. Some providers are outside the UK; where they are, transfers rely on recognised safeguards such as adequacy decisions or standard contractual clauses. We may also disclose data where the law requires it.

6. Cookies

We use strictly necessary cookies only: a session cookie to keep you logged in and short-lived cookies for security (such as login throttling and form protection). We do not run advertising or cross-site tracking cookies on the site or in the app.

7. How long we keep data

For as long as your account is open, then for a short period afterwards so you can come back or we can meet legal duties (for example, billing records are kept for 6 years under UK tax rules). Workspace content is deleted after account closure once that period passes.

8. Your rights

Under UK GDPR you can ask for access to your data, correction, deletion, restriction, portability, and you can object to processing based on legitimate interests. Use the contact page and we will respond within a month. You can also complain to the ICO (ico.org.uk).

9. Security

Passwords are stored hashed, traffic is encrypted with HTTPS, access to production systems is restricted, and payments never touch our servers. No system is perfectly secure, but if a breach affects you we will tell you and the ICO as the law requires.

10. Changes

If we change this policy in a way that matters, we will flag it by email or in the product before it takes effect.