Last updated · 17 August 2026
Privacy Policy
TGM Studios Ltd (trading as Radr) is the data controller for the personal data described here. This policy explains what we collect when you use Radr, why, who helps us process it, how long we keep it, and the rights you have under UK GDPR and, where applicable, other privacy laws. Short version: we collect what we need to run the product and bill you, we do not sell data, and we do not run advertising or tracking.
1. What we collect
| Data | Examples | Why (legal basis) |
|---|---|---|
| Account | Email address, password (hashed by our auth provider), name, business name | To create and secure your account and to contact you about it (contract) |
| Profile | Country, home postcode / ZIP or town and its coordinates, search radius, niche, price list, day rate, deal range, portfolio URL and image links | To run searches around you and price your suggestions (contract) |
| Workspace | Businesses you save, pipeline status, notes, tags, follow-up dates, pitches you generate, saved radars | To provide the CRM features you asked for (contract) |
| Usage | Search count and other metered actions per month, timestamps, plan limits | To enforce plan limits, prevent abuse and control our costs (legitimate interests, contract) |
| Billing | Stripe customer ID, subscription ID and status, plan, renewal date, invoices (held by Stripe) | To charge you, issue refunds and keep tax records (contract, legal obligation). We never see or store your card number. |
| Technical | IP address, browser type, request logs, error logs, security events (rate-limit hits) | Security, debugging and abuse prevention (legitimate interests) |
| Support | Anything you send us by email | To help you (legitimate interests) |
2. Data about other businesses ("leads")
Radr shows you public information about local businesses — name, address, category, phone, opening hours, rating, review counts, photos, website and social links, and (for UK companies) incorporation details. It comes from Google Maps Platform, Companies House and the business's own public website. Some of this can be personal data where a business is a sole trader. We process it under our and your legitimate interests in finding and contacting local businesses about your services, we keep it only inside your workspace as a dated snapshot, and we do not build or sell a database from it. If you run a business that appears in Radr and want to be excluded, email us and we will suppress it.
3. Who processes data for us
We use a small number of well-known providers, each under a contract that limits what they may do with your data:
| Provider | What for | Where |
|---|---|---|
| Supabase | Database and authentication | EU (AWS Ireland) |
| Vercel | Hosting, edge network, firewall and logs | Global edge / US |
| Stripe | Payments, invoices, refunds, billing portal | US / EU (PCI-DSS) |
| Google Maps Platform | Business listings, details and photos | US / global — see Google's Privacy Policy |
| Anthropic | Drafting pitches and captions from the lead's public details and your profile. Data sent to the API is not used to train models. | US |
| Companies House, postcodes.io, Zippopotam, OpenStreetMap / Nominatim, OpenFreeMap | UK company data, postcode / ZIP lookup, map tiles | UK / EU / US |
Where data leaves the UK/EEA (for example to US providers) we rely on adequacy decisions, the UK International Data Transfer Addendum or EU Standard Contractual Clauses.
4. Cookies
Radr uses only strictly necessary cookies: the session cookies that keep you signed in. There are no advertising, analytics or tracking cookies, so we do not show a cookie banner. Stripe sets its own cookies on its checkout and billing pages under its own policy.
5. How long we keep it
- Account, profile and workspace data: for as long as your account exists, then deleted within 30 days of you closing it (or of us closing it).
- Billing records: 6 years, as UK tax law requires (held mainly by Stripe).
- Technical logs: typically 30 days.
- Backups: rolled over within 30 days.
6. Security
Data is encrypted in transit (TLS) and at rest. Every table is protected by row-level security so you can only ever read your own rows. Billing state can only be written by our payment webhook. API keys live on the server only. Access to production is limited to the founder. No system is perfectly secure; if we ever learn of a breach affecting you we will tell you and the ICO as the law requires.
7. Your rights
Under UK GDPR (and similar laws elsewhere) you can ask us to: access the personal data we hold about you; correct it; delete it (you can also delete your account yourself in Settings); export it in a portable format; restrict or object to processing based on legitimate interests; and withdraw consent where consent is the basis. Email edits@tobiasgravesmorris.com and we will respond within one month. You can also complain to the Information Commissioner's Office at ico.org.uk, or to your local supervisory authority.
8. Children
Radr is for adults running a business. We do not knowingly collect data from anyone under 18.
9. Marketing
We will email you about your account and about Radr itself (service notices, important changes). We do not share your details with third parties for their marketing. Any optional product news email will have an unsubscribe link.
10. Changes and contact
We will post updates here and, for material changes, tell you in the app or by email. Controller: TGM Studios Ltd, a company registered in England and Wales. Contact: edits@tobiasgravesmorris.com.
TGM Studios Ltd trading as Radr · Questions: edits@tobiasgravesmorris.com