1. Who we are
Web and IT Systems Ltd ("we", "us", "our") operates CheckMyStreet and is the controller of the personal data this notice describes. We are a company registered in England and Wales under company number 08312277, with our registered address at Union House, 111 New Union Street, Coventry, CV1 2NT. We are registered with the Information Commissioner's Office under registration number Z3557825.
This notice covers this developer site, the developer console and the Partner API. Your developer account is separate from any checkmystreet.co.uk account. Our main site has its own privacy and cookie policy.
Questions about this notice or your personal data: admin@checkmystreet.co.uk.
2. The personal data we collect
- Sign-in profile
- Your name, your email address, a sign-in id, how you sign in (Google, Microsoft, or an email address and a password), and when you created your sign-in and last signed in. If you sign in with Google, Google gives us your Google account's name, email address and profile picture link. If you sign in with Microsoft, Microsoft gives us your account's name and email address. If you use a password, Firebase Authentication keeps it in hashed form, and we never see it.
- Access request
- Your company, its website, what you are building, and how many API calls you expect a month. We add our decision, when it was made, who made it and any reason we gave, and whether your account is approved, declined or blocked.
- Console activity
- The logins you create and revoke, and when. We keep each client secret only as a one-way hash. We also keep your credit balance, its history and your daily limit.
- Top-ups
- Stripe takes your card details on its own checkout page, and we never see them. We keep the amount, the date, Stripe's payment id and the link to Stripe's receipt. We give Stripe your email address to start each checkout.
- API request logs
- For each call to the API and to the console's service: the IP address it came from, the time, the URL and the result status. The URL of a street analysis contains its postcode.
- Stored results
- What a partner sends in a request and what we return, kept for the periods in section 5. Our terms forbid personal data in requests (section 4).
- Emails we send
- Emails about your sign-in, your account and the service. For emails sent through our email service, we keep a record of each email and its delivery report. Where your email program allows it, the record also shows when the email was opened and which links were clicked.
- What you send us
- The emails you write to us, with anything attached, and our replies.
We get this data from you, from Google, Microsoft and Firebase Authentication when you sign in, and from Stripe when you pay. We do not run analytics on this site.
3. Why we use it, and our lawful bases
| Purpose | Data | Lawful basis |
|---|---|---|
| Sign you in, review your request, run your account and issue logins | Sign-in profile, access request, console activity | Contract, where you are our customer yourself. Otherwise legitimate interests: providing the service your organisation asked for. |
| Take payments and keep your credit balance | Top-ups, console activity | Contract or legitimate interests, as above |
| Provide the API and its results | API request logs, stored results | Contract or legitimate interests, as above |
| Keep the service secure, apply rate limits, and prevent fraud and abuse | API request logs, sign-in profile, console activity | Legitimate interests: protecting the service, our customers and our data providers |
| Send you service emails, and answer you | Sign-in profile, emails we send, what you send us | Contract or legitimate interests, as above |
| Improve the service, using counts of calls and error rates | API request logs, console activity | Legitimate interests: improving our products |
| Keep accounting and tax records | Top-ups, console activity | Legal obligation |
| Establish, exercise or defend legal claims, and get professional advice and insurance | Any of the above | Legitimate interests: protecting our business and our legal rights |
| Answer lawful requests from courts, regulators and the police | Any of the above | Legal obligation |
Service emails cover your sign-in, our decision on your request, your account, price changes, changes to our terms, and notices about the API. We do not send you marketing emails about our other products unless you ask us to.
We do not make decisions about you by automated means alone. A person reviews every access request.
4. Partner API requests
Our Partner API terms forbid partners from sending personal data in requests. The API needs only a postcode and a property's characteristics. The reference field is for a partner's own case or job number.
If you are a customer of one of our partners, the partner decides what it sends us, so ask the partner about your data first. If personal data reaches us in a request despite our terms, we handle it as the partner's processor, under section 13 of the terms, and delete it under the periods in section 5.
5. How long we keep it
| Data | How long |
|---|---|
| Sign-in profile and account details, including your access request and our decision | While your account is open, then 12 months after it closes |
| A declined request, or a sign-in that never sent a request | 12 months after the decision, or after your last sign-in |
| Top-ups and your credit history | 6 years after the end of the financial year they belong to, for HMRC |
| API request logs | 30 days |
| Stored live valuations | 12 months |
| Stored street analyses | 30 days |
| Test results | 24 hours |
| Records of emails we send | 12 months |
| Emails you send us | While your account is open, then 12 months after it closes. Without an account, 12 months after our last exchange. |
We keep data for longer only where the law requires it, or while we need it for a legal claim or a payment dispute.
6. Who we share it with
These providers run parts of the service for us. They process personal data on our instructions, under contracts that require them to protect it.
| Provider | What they do for us | Where |
|---|---|---|
| Microsoft | Azure hosting for the API, the console's service, their database and their logs. This site's pages, through Azure Static Web Apps. Email delivery, through Azure Communication Services. Microsoft account sign-in, if you choose it. | Hosting, data and logs in the UK South region. Email data held in the UK. This site's pages are served from Microsoft's global network. |
| Firebase Authentication: sign-in, and the emails that verify your address and reset your password. Google sign-in, if you choose it. | United States and other countries | |
| Stripe | Card payments for top-ups, and receipts | United States and other countries |
Stripe is also a controller of the card and payment data it collects, under its own privacy policy. Google is the controller of your Google account, and Microsoft of your Microsoft account, each under its own privacy policy.
We may also share personal data with:
- our professional advisers and insurers;
- courts, regulators and the police, where the law requires it;
- a buyer of our business, who would have to use it as this notice says.
We do not sell personal data.
7. Transfers outside the UK
Our hosting, database, logs and email data are in the UK. Google and Stripe process some personal data outside the UK, mainly in the United States. Microsoft may also reach data from outside the UK to support and secure its services.
Where personal data leaves the UK, one of these protects it:
- UK adequacy regulations, including the UK Extension to the EU-US Data Privacy Framework, for US companies certified under it;
- the Information Commissioner's International Data Transfer Agreement;
- the UK Addendum to the EU standard contractual clauses.
8. Cookies and browser storage
This site uses no analytics, advertising or tracking cookies, and its pages load no scripts from other sites. The console's sign-in page loads Google's sign-in helper so that you can sign in with Google or Microsoft.
The site keeps these items in your browser:
| Name | Kind | What it does | How long |
|---|---|---|---|
cms-theme | Local storage | Remembers the light or dark theme you chose | Until you clear it |
cms-code-lang | Local storage | Remembers the language you chose for code samples | Until you clear it |
cms-console-user | Local storage | Your email address, so that each page's header shows you are signed in | Until you sign out, or your sign-in ends |
cms-console-token | Session storage | A short-lived token the console uses to reach our API | Until you close the tab |
firebaseLocalStorageDb | IndexedDB, or local storage if IndexedDB is not available | Firebase Authentication's record of your sign-in, so that you stay signed in | Until you sign out |
When you sign in, Firebase's sign-in frame, served from checkmystreet-developers., and Google's or Microsoft's sign-in window, if you choose one, may store data in your browser for sign-in, under that company's privacy policy. When you top up, Stripe's checkout page sets its own cookies for payment and fraud prevention, under Stripe's privacy policy.
These items are needed for a service you asked for, or remember a choice you made, so we do not ask for consent to them. You can clear them in your browser's settings. You will then need to sign in again.
9. How we protect it
This site and the API are served only over HTTPS. We keep client secrets only as one-way hashes, so we cannot read them back. Our database accepts only our own services' identities and named staff, with no shared keys. Only the people who run CheckMyStreet can see account details, and only when they need to.
10. Your rights
Under the UK GDPR you have the right to:
- ask for a copy of your personal data;
- have inaccurate data corrected, and incomplete data completed;
- have your data erased;
- restrict how we use your data;
- object to how we use your data where we rely on legitimate interests;
- receive the data you gave us in a machine-readable form, where we rely on contract;
- not be subject to decisions made by automated means alone that significantly affect you.
Some rights apply only in some circumstances. For example, we must keep payment records for HMRC even if you ask us to erase them. If you ask us to erase the account owner's details while your organisation's account is open, your organisation will need to name a new account owner, or we will close the account.
To use any of these rights, write to admin@checkmystreet.co.uk. We may ask you to confirm who you are. We reply within one month, or tell you within that month if we need up to two more months for a complex request. We do not charge, unless a request is clearly unfounded or excessive.
11. Complaints
If you are unhappy with how we use your personal data, write to us first at admin@checkmystreet.co.uk. We acknowledge every complaint within 30 days and tell you what we will do.
You can also complain to the Information Commissioner's Office at ico.org.uk, or by phone on 0303 123 1113.
12. Children
The Partner API is for businesses. The person who signs in must be 18 or over. We do not knowingly collect personal data about children.
13. Changes to this notice
We may update this notice. The version and date at the top show when it last changed. If a change significantly affects how we use your personal data, we will tell account owners by email before it takes effect.
14. Contact
Web and IT Systems Ltd, Union House, 111 New Union Street, Coventry, CV1 2NT. Email admin@checkmystreet.co.uk.