Privacy Policy
Last updated 2026-07-07
1. Who we are
Deload is a customer-relationship-management (CRM) platform for fitness businesses. It is operated by Cloud Lobsters Ltd, a company registered in England and Wales (company number 16016819) with its registered office at 71‑75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom ("Deload", "we", "us").
For any privacy question or request, contact privacy@deload.co.uk.
2. The two roles we play
We are the data controller for data about the people who deal with us directly: platform account holders and their team members, waitlist sign-ups, billing contacts, people who send us feedback, and visitors to this website.
We are a data processor for the CRM content our customers store in Deload: their leads, clients and members, message conversations, notes, bookings, and the details submitted through landing pages and lead forms they run. For that data, the business using Deload is the controller and we act on its instructions.
If you are a client or lead of a business that uses Deload and you want your data corrected or deleted, please contact that business directly — it controls the data. We will assist it in meeting your request, and if you contact us instead we will forward your request to it where we can. Business customers that require a data processing agreement (Article 28 UK GDPR) can contact legal@deload.co.uk.
3. Data we collect
Account and profile data
- Name, email address, and profile picture (if you upload one)
- Phone number, where provided, verified by a one-time SMS code
- Password — stored only as a cryptographic hash, never in plain text
- Two-factor authentication enrolment: authenticator-app secrets, backup codes, and trusted-device records
- Your role and organisation membership, and your notification preferences
- Session records, each with the IP address and browser user-agent it was created from
Organisation and CRM data (processed for our customers)
- Business details: name, locations and addresses, branding and logo
- Leads, clients and contacts: names, email addresses, phone numbers, notes, pipeline and deal history
- Message conversations sent and received through connected channels — email, SMS, WhatsApp, Facebook Messenger, and Instagram DM — including broadcasts and attachments
- Calendar events and meeting links created through connected calendar/video providers
- Submissions to landing pages and lead forms hosted for a customer: the details the visitor enters, plus the visitor's IP address and user-agent (used for rate limiting and abuse prevention)
- Leads delivered by Meta Lead Ads for campaign attribution, where a customer runs them
Integration credentials
When an organisation connects a third-party service (email, SMS/WhatsApp, Meta, Google, Microsoft, Zoom, Stripe, and similar), we store the OAuth tokens or API credentials needed to act on its behalf. These are encrypted at the application layer before being stored and are used only to provide the features the organisation asked for.
Billing data
Subscription plan, billing status, and Stripe customer and subscription identifiers. Card details are entered directly with Stripe and never touch our servers.
Waitlist data
If you join our waitlist: first and last name, email address, phone number and country code, account type (founder or agency), the timestamp of your consent, your browser's user-agent, and your IP address (kept for rate limiting and abuse prevention).
Feedback and support
If you send feedback from inside the product: your message, the page you were on, an optional screenshot captured from your current view (which may include data visible on screen at the time), and your IP address and user-agent.
Technical, security, and diagnostic data
- Server logs and system-event records, each tagged with a correlation ID
- Error reports from your browser when something breaks: the error message, stack trace, page URL, and user-agent. For signed-in users these are stored; for anonymous visitors they are only written to server logs
- Sign-in and administrative audit records including IP addresses. Where enabled, we derive an approximate location (country/region/city) from the IP address of sign-in events for security auditing — this lookup runs on our own servers against a local geolocation database; your IP address is not sent to a third party for it
- Rate-limiting counters keyed by IP address or account, for abuse prevention
- If you enable browser push notifications: your push subscription (endpoint and delivery keys)
4. How we use data and our legal bases
- To provide the service — running your account and organisation, storing and displaying CRM data, sending and receiving messages through the channels you connect, hosting landing pages, and delivering the notifications you have switched on. Legal basis: performance of a contract.
- Transactional communications — password resets, email verification, phone verification, and two-factor codes by email or SMS. Legal basis: performance of a contract.
- Billing — charging subscriptions, handling invoices and disputes. Legal basis: performance of a contract and legal obligation.
- Security and abuse prevention — session management, rate limiting, sign-in auditing, and investigating suspicious activity. Legal basis: legitimate interest in keeping the platform and its tenants safe.
- Diagnostics and service improvement — error tracking and operational logging so we can find and fix faults. Legal basis: legitimate interest.
- Waitlist — telling you about launch and estimating demand by country and segment. Legal basis: your consent, which you can withdraw at any time.
- Legal compliance — where we must retain or disclose data to comply with the law. Legal basis: legal obligation.
We do not sell personal data, we do not share it with advertisers or data brokers, and we do not use it to build advertising profiles. We do not make automated decisions about you that have legal or similarly significant effects.
5. AI features
Parts of Deload use large language models: the campaign coach and daily briefing, ad and campaign copy generation, landing-page generation and pre-publish review, drafting replies to messages, and the in-app assistant. When you use one of these features, the relevant context — for example campaign names and performance metrics, your brand kit, content from a website you ask us to import, or the conversation being replied to — is sent to a model provider to generate the output. For email threads, that conversation context can include messages synced from a connected Gmail account; this transfer happens only to provide the feature you invoked and is covered by the Limited Use commitments in section 12.
- Our default model provider is Anthropic; depending on configuration a request may instead be served by OpenAI, Google, or Groq. All act as our processors via their business APIs, under terms that do not permit them to train their models on your data.
- If you ask Deload to import branding from a website, we fetch that site's public content through Firecrawl, a web-scraping service.
- We record operational traces of AI calls — timing, token usage, the feature involved, and the inputs and outputs of the call — in Langfuse, an EU-hosted observability service, so we can monitor quality, cost, and abuse. Traces are tagged with organisation and user identifiers, retained for a limited period, and accessible only to our team.
- AI outputs are drafts and suggestions. Nothing is sent to your contacts or published without an action by you or an automation you configured, and no AI feature makes decisions with legal or similarly significant effects about anyone.
7. International transfers
Deload is hosted in the United Kingdom (AWS London). Some of the providers listed above — for example Stripe, Twilio, and the AI model providers — process data in the United States or other countries. Where that happens we rely on UK GDPR-recognised safeguards: the UK Extension to the EU–US Data Privacy Framework, the UK International Data Transfer Agreement/Addendum, or standard contractual clauses, as applicable to each provider.
8. How long we keep data
- Account and organisation data — kept while the account is active. When an organisation closes its account, we delete its data within a reasonable period, and always within one month of a verified deletion request.
- CRM data — kept until the controlling organisation edits or deletes it, or its account closes, per the above.
- Email captured from connected mailboxes (e.g. Gmail) — kept as part of your CRM conversation history while the account is active. When you disconnect a mailbox integration you can choose to immediately and permanently delete every message and attachment captured from it, and you can request deletion of captured email at any time (section 12).
- Billing records — kept for six years after the transaction, as UK tax law requires.
- Waitlist records — kept until we have contacted you about launch or you ask us to delete them, whichever comes first.
- Logs, error reports, and AI traces — kept for short, rolling operational windows and then aged out automatically.
- Sessions — expire automatically; expired session records are cleaned up routinely.
9. Security
All traffic to Deload is encrypted in transit (TLS). Passwords are stored only as cryptographic hashes. Credentials for connected integrations are additionally encrypted at the application layer before storage. Access to customer data inside the product is governed by per-organisation isolation and attribute-based access control; access by our own team is restricted and audited. Two-factor authentication is available on every account (authenticator app, with backup codes and SMS fallback). Uploaded files are validated by content type and size and stored in private object storage accessible only through short-lived signed URLs.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant supervisory authority as the law requires.
10. Your rights
Under the UK GDPR (and, where it applies, the EU GDPR) you have the right to:
- Access the data we hold about you
- Have inaccurate data corrected
- Have your data deleted ("right to be forgotten")
- Receive a copy of data you provided in a portable format
- Restrict or object to our processing, including any based on legitimate interests
- Withdraw consent at any time, where processing is based on consent
Email privacy@deload.co.uk to exercise any of these rights; we respond within one month. Remember that for CRM data a business stores about you, that business is the controller (see section 2). You can also complain to the UK Information Commissioner's Office (ico.org.uk) or, in the EU, to your local supervisory authority.
12. Google user data
If you connect a Google account, Deload requests your basic profile (email) plus the Gmail (gmail.modify) and Google Meet (meetings.space.created) scopes so the product can send, receive, and organise email and create meeting links on your behalf. We access this data only to provide those features at your direction; we do not use it for advertising, sell it, or transfer it to others except as needed to provide the service or as required by law, and no human reads it except with your consent, for security purposes, or to comply with the law.
Deload's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never used to develop, improve, or train generalised AI or machine-learning models. Where an AI feature you invoke (such as drafting a reply to an email thread) sends synced Gmail content to a model provider, that provider acts as our processor under business-API terms that do not permit training on your data, as described in section 5.
Retention and deletion. Emails captured from your Gmail account are kept as part of your CRM conversation history while your account is active. When you disconnect the Google Workspace integration, Deload revokes its access token with Google and deletes the stored credentials; you can also choose, at disconnect, to permanently delete every email and attachment captured from that mailbox (this removes Deload's copies only — the original messages remain in your Gmail account). You can revoke access at any time from your Google account's security settings or from Settings → Integrations in Deload, and you can request deletion of captured Google user data at any time by emailing privacy@deload.co.uk.
13. Meta platform data
If your organisation connects WhatsApp Business, Facebook Messenger, Instagram, or Meta Ads, we receive data from Meta to provide those features: message content and delivery events for connected numbers and pages, lead submissions from Meta Lead Ads, and campaign structure and performance metrics for connected ad accounts. We use this data solely to provide the connected features at the organisation's direction, in accordance with the Meta Platform Terms, and we do not use it for any independent purpose. Disconnecting the integration stops the data flow; you can also revoke Deload's access from your Meta Business settings.
14. Children
Deload is a business tool. Accounts are for adults (18+) acting for a business, and we do not knowingly collect data from children. CRM records a business stores about its own clients are that business's responsibility as controller.
15. Changes to this notice
When we materially change how we handle personal data, we will update the "last updated" date above and notify account holders by email or in the app before the change takes effect. Non-material clarifications may be made by updating this page alone.
16. Contact
Cloud Lobsters Ltd, 71‑75 Shelton Street, Covent Garden, London, WC2H 9JQ, United
Kingdom.
Privacy requests: privacy@deload.co.uk · Legal: legal@deload.co.uk