Developers
Get access

1. Who we are

Web and IT Systems Ltd ("we", "us", "our") operates CheckMyStreet and is the controller of the personal data this notice describes. We are a company registered in England and Wales under company number 08312277, with our registered address at Union House, 111 New Union Street, Coventry, CV1 2NT. We are registered with the Information Commissioner's Office under registration number Z3557825.

This notice covers this developer site, the developer console and the Partner API. Your developer account is separate from any checkmystreet.co.uk account. Our main site has its own privacy and cookie policy.

Questions about this notice or your personal data: admin@checkmystreet.co.uk.

2. The personal data we collect

Sign-in profile
Your name, your email address, a sign-in id, how you sign in (Google, Microsoft, or an email address and a password), and when you created your sign-in and last signed in. If you sign in with Google, Google gives us your Google account's name, email address and profile picture link. If you sign in with Microsoft, Microsoft gives us your account's name and email address. If you use a password, Firebase Authentication keeps it in hashed form, and we never see it.
Access request
Your company, its website, what you are building, and how many API calls you expect a month. We add our decision, when it was made, who made it and any reason we gave, and whether your account is approved, declined or blocked.
Console activity
The logins you create and revoke, and when. We keep each client secret only as a one-way hash. We also keep your credit balance, its history and your daily limit.
Top-ups
Stripe takes your card details on its own checkout page, and we never see them. We keep the amount, the date, Stripe's payment id and the link to Stripe's receipt. We give Stripe your email address to start each checkout.
API request logs
For each call to the API and to the console's service: the IP address it came from, the time, the URL and the result status. The URL of a street analysis contains its postcode.
Stored results
What a partner sends in a request and what we return, kept for the periods in section 5. Our terms forbid personal data in requests (section 4).
Emails we send
Emails about your sign-in, your account and the service. For emails sent through our email service, we keep a record of each email and its delivery report. Where your email program allows it, the record also shows when the email was opened and which links were clicked.
What you send us
The emails you write to us, with anything attached, and our replies.

We get this data from you, from Google, Microsoft and Firebase Authentication when you sign in, and from Stripe when you pay. We do not run analytics on this site.

3. Why we use it, and our lawful bases

PurposeDataLawful basis
Sign you in, review your request, run your account and issue loginsSign-in profile, access request, console activityContract, where you are our customer yourself. Otherwise legitimate interests: providing the service your organisation asked for.
Take payments and keep your credit balanceTop-ups, console activityContract or legitimate interests, as above
Provide the API and its resultsAPI request logs, stored resultsContract or legitimate interests, as above
Keep the service secure, apply rate limits, and prevent fraud and abuseAPI request logs, sign-in profile, console activityLegitimate interests: protecting the service, our customers and our data providers
Send you service emails, and answer youSign-in profile, emails we send, what you send usContract or legitimate interests, as above
Improve the service, using counts of calls and error ratesAPI request logs, console activityLegitimate interests: improving our products
Keep accounting and tax recordsTop-ups, console activityLegal obligation
Establish, exercise or defend legal claims, and get professional advice and insuranceAny of the aboveLegitimate interests: protecting our business and our legal rights
Answer lawful requests from courts, regulators and the policeAny of the aboveLegal obligation

Service emails cover your sign-in, our decision on your request, your account, price changes, changes to our terms, and notices about the API. We do not send you marketing emails about our other products unless you ask us to.

We do not make decisions about you by automated means alone. A person reviews every access request.

4. Partner API requests

Our Partner API terms forbid partners from sending personal data in requests. The API needs only a postcode and a property's characteristics. The reference field is for a partner's own case or job number.

If you are a customer of one of our partners, the partner decides what it sends us, so ask the partner about your data first. If personal data reaches us in a request despite our terms, we handle it as the partner's processor, under section 13 of the terms, and delete it under the periods in section 5.

5. How long we keep it

DataHow long
Sign-in profile and account details, including your access request and our decisionWhile your account is open, then 12 months after it closes
A declined request, or a sign-in that never sent a request12 months after the decision, or after your last sign-in
Top-ups and your credit history6 years after the end of the financial year they belong to, for HMRC
API request logs30 days
Stored live valuations12 months
Stored street analyses30 days
Test results24 hours
Records of emails we send12 months
Emails you send usWhile your account is open, then 12 months after it closes. Without an account, 12 months after our last exchange.

We keep data for longer only where the law requires it, or while we need it for a legal claim or a payment dispute.

6. Who we share it with

These providers run parts of the service for us. They process personal data on our instructions, under contracts that require them to protect it.

ProviderWhat they do for usWhere
MicrosoftAzure hosting for the API, the console's service, their database and their logs. This site's pages, through Azure Static Web Apps. Email delivery, through Azure Communication Services. Microsoft account sign-in, if you choose it.Hosting, data and logs in the UK South region. Email data held in the UK. This site's pages are served from Microsoft's global network.
GoogleFirebase Authentication: sign-in, and the emails that verify your address and reset your password. Google sign-in, if you choose it.United States and other countries
StripeCard payments for top-ups, and receiptsUnited States and other countries

Stripe is also a controller of the card and payment data it collects, under its own privacy policy. Google is the controller of your Google account, and Microsoft of your Microsoft account, each under its own privacy policy.

We may also share personal data with:

We do not sell personal data.

7. Transfers outside the UK

Our hosting, database, logs and email data are in the UK. Google and Stripe process some personal data outside the UK, mainly in the United States. Microsoft may also reach data from outside the UK to support and secure its services.

Where personal data leaves the UK, one of these protects it:

8. Cookies and browser storage

This site uses no analytics, advertising or tracking cookies, and its pages load no scripts from other sites. The console's sign-in page loads Google's sign-in helper so that you can sign in with Google or Microsoft.

The site keeps these items in your browser:

NameKindWhat it doesHow long
cms-themeLocal storageRemembers the light or dark theme you choseUntil you clear it
cms-code-langLocal storageRemembers the language you chose for code samplesUntil you clear it
cms-console-userLocal storageYour email address, so that each page's header shows you are signed inUntil you sign out, or your sign-in ends
cms-console-tokenSession storageA short-lived token the console uses to reach our APIUntil you close the tab
firebaseLocalStorageDbIndexedDB, or local storage if IndexedDB is not availableFirebase Authentication's record of your sign-in, so that you stay signed inUntil you sign out

When you sign in, Firebase's sign-in frame, served from checkmystreet-developers.firebaseapp.com, and Google's or Microsoft's sign-in window, if you choose one, may store data in your browser for sign-in, under that company's privacy policy. When you top up, Stripe's checkout page sets its own cookies for payment and fraud prevention, under Stripe's privacy policy.

These items are needed for a service you asked for, or remember a choice you made, so we do not ask for consent to them. You can clear them in your browser's settings. You will then need to sign in again.

9. How we protect it

This site and the API are served only over HTTPS. We keep client secrets only as one-way hashes, so we cannot read them back. Our database accepts only our own services' identities and named staff, with no shared keys. Only the people who run CheckMyStreet can see account details, and only when they need to.

10. Your rights

Under the UK GDPR you have the right to:

Some rights apply only in some circumstances. For example, we must keep payment records for HMRC even if you ask us to erase them. If you ask us to erase the account owner's details while your organisation's account is open, your organisation will need to name a new account owner, or we will close the account.

To use any of these rights, write to admin@checkmystreet.co.uk. We may ask you to confirm who you are. We reply within one month, or tell you within that month if we need up to two more months for a complex request. We do not charge, unless a request is clearly unfounded or excessive.

11. Complaints

If you are unhappy with how we use your personal data, write to us first at admin@checkmystreet.co.uk. We acknowledge every complaint within 30 days and tell you what we will do.

You can also complain to the Information Commissioner's Office at ico.org.uk, or by phone on 0303 123 1113.

12. Children

The Partner API is for businesses. The person who signs in must be 18 or over. We do not knowingly collect personal data about children.

13. Changes to this notice

We may update this notice. The version and date at the top show when it last changed. If a change significantly affects how we use your personal data, we will tell account owners by email before it takes effect.

14. Contact

Web and IT Systems Ltd, Union House, 111 New Union Street, Coventry, CV1 2NT. Email admin@checkmystreet.co.uk.