Privacy Policy
Last updated: 26 August 2026
1. Who is responsible
Red Salt Media (Liverpool, United Kingdom) is the data controller for personal data processed by Vantage (redsaltvantage.co.uk and app.redsaltvantage.co.uk). Contact us through the contact page.
2. What we collect
Account data (business name, your name, email, hashed password), team seats you create (name, email, hashed password), billing data handled by Stripe (we store a customer reference and subscription status, never full card numbers), the client-business profiles and content you create in the workspace, connections you authorise to services like Google (we store the tokens needed to act on your instruction), usage and technical logs (IP address, browser, pages requested) needed to run and secure the service, and messages you send us.
3. Why we use it
To provide the service you signed up for (contract), to take payment and keep accounts (legal obligation and contract), to secure the service, prevent abuse and fix problems (legitimate interests), and to send service emails such as receipts, password resets and important account notices. We do not sell personal data, and we do not send marketing email without your consent.
4. AI features
When you use AI features, the text you provide (such as a client-business profile and your inputs) is sent to our AI provider, Anthropic, to generate the output you asked for. We send only what the feature needs, and we do not use your content to train models.
5. Who we share it with
Service providers who process data for us: Stripe (payments), Anthropic (AI generation), Google (only for connections you authorise, such as Search Console, Google Ads and YouTube), our hosting providers, and an email delivery provider for service emails. Each processes data under its own safeguards and our instructions. Some providers are outside the UK; where they are, transfers rely on recognised safeguards such as adequacy decisions or standard contractual clauses. We may also disclose data where the law requires it.
6. Cookies
We use strictly necessary cookies only: a session cookie to keep you logged in and short-lived cookies for security (such as login throttling and form protection). We do not run advertising or cross-site tracking cookies on the site or in the app.
7. How long we keep data
For as long as your account is open, then for a short period afterwards so you can come back or we can meet legal duties (for example, billing records are kept for 6 years under UK tax rules). Workspace content is deleted after account closure once that period passes.
8. Your rights
Under UK GDPR you can ask for access to your data, correction, deletion, restriction, portability, and you can object to processing based on legitimate interests. Use the contact page and we will respond within a month. You can also complain to the ICO (ico.org.uk).
9. Security
Passwords are stored hashed, traffic is encrypted with HTTPS, access to production systems is restricted, and payments never touch our servers. No system is perfectly secure, but if a breach affects you we will tell you and the ICO as the law requires.
10. Changes
If we change this policy in a way that matters, we will flag it by email or in the product before it takes effect.