Privacy Policy

Last updated: June 2026

1. Who we are

Praesago (“we”, “us”, “our”) is a UK property intelligence platform available at praesago.com. We are the data controller for personal information collected through the site. For any data enquiry, contact support@praesago.com.

2. What we collect

  • Account data: email address, name, hashed password or OAuth display name
  • Billing data: subscription tier and billing dates via Stripe. Card details are held by Stripe, not by us.
  • Usage data: watchlist postcodes, generated reports (postcode, type, timestamp), activity logs
  • Technical data: IP address for rate limiting and fraud prevention (not stored long term)

3. How we use your data

  • Providing the platform and your account (contract)
  • Processing payments via Stripe (contract)
  • Transactional emails such as password resets (contract)
  • Rate limiting, fraud prevention, and enforcing report quotas (legitimate interest)
  • Newsletters and product updates where you have opted in (consent)

4. Third parties

  • Stripe processes payments and receives your email.
  • Resend delivers transactional emails.
  • Mapbox serves map tiles. Your browser makes direct requests to Mapbox when viewing the map.
  • Sentry captures error reports to help us fix bugs. These may include request metadata but not personal content.
  • Google / GitHub authenticate you via OAuth if you choose to sign in that way.

We do not sell personal data.

5. Retention

  • Account data: retained while your account is active
  • Generated report PDFs: 30 days, then deleted
  • Activity logs: 12 months
  • Subscription records: up to 7 years for accounting

6. Cookies

We use a single essential session cookie (NextAuth.js) to keep you signed in. We store UI preferences (e.g. onboarding tooltip dismissed) in your browser's localStorage. We do not use advertising or third party analytics cookies.

7. Your rights

Under UK GDPR you can:

  • Access, correct, or delete your personal data
  • Request data portability
  • Object to processing based on legitimate interest
  • Withdraw consent for newsletters at any time

You can delete your account and all associated data from Settings. For anything else, email support@praesago.com. We will respond within 30 days. You also have the right to complain to the ICO.

8. Security

Passwords are hashed with bcrypt. Database connections use TLS. Authentication endpoints are rate limited.

9. Changes

We may update this policy. Material changes will be communicated by email to registered users.