Stingray Software Ltd ("Stingray", "we", "us") builds bespoke and vertical software products, including cloud ERP and automation systems, for business clients ("Clients"). This Privacy Policy explains how we collect, use and protect personal data in connection with our website, our products, and the Services we provide to Clients.
This policy is written for individuals whose data we handle either directly (e.g. as visitors to our website, or contacts at a prospective or current Client) or on behalf of a Client (e.g. a Client's own customers, suppliers or staff whose data appears within a system we have built for that Client).
1. Who we are
Stingray Software Ltd, a company registered in England and Wales, company number 17176243. Contact for data protection matters: flynn.little@stingraysoftware.co.uk.
2. When we are the Controller vs the Processor
2.1 When we act as Controller: for data about our own website visitors, prospective clients, and the business contacts we deal with directly (e.g. names and emails of people at Client companies we correspond with), Stingray determines the purposes and means of processing and is the Controller.
2.2 When we act as Processor: where we build and operate software for a Client (for example an ERP system containing that Client's customer, supplier, order or invoice records), the Client is the Controller of that data and Stingray processes it only on the Client's instructions, under a separate Data Processing Agreement with that Client. If you are an individual whose data appears within a Client's system, you should direct data protection queries to that Client in the first instance; the relevant Client's own privacy notice will apply to that processing.
3. What data we collect
Depending on the context, this may include:
- • Contact details: name, business email, phone number, job title, company name
- • Account and usage data: login details, application usage logs, support tickets
- • Business data processed within Client systems: which may include names, contact details, order and invoice records, and other business records relevant to the Client's operations
- • Technical data: IP address, browser/device information, cookies and analytics data from our website
- • Communications: correspondence with us via email, forms, or support channels
We do not deliberately collect special category data (e.g. health, religious or biometric data) and do not expect our Clients' use of our products to require this; if a specific engagement does involve such data, this will be addressed in that Client's Data Processing Agreement.
4. How we use data and our lawful basis
- • To provide, operate and support our software products and Services — necessary for performance of a contract with the Client
- • To communicate with prospective and current Clients about our services — legitimate interests, or consent where required
- • To maintain the security, integrity and performance of our systems — legitimate interests
- • To comply with our legal and regulatory obligations, e.g. accounting and tax records — legal obligation
- • To improve our products and develop new features — legitimate interests, using data in a de-identified or aggregated form wherever possible
5. Sub-processors and third parties
To deliver our Services we use a limited number of trusted sub-processors, currently including:
- • Supabase — database hosting, authentication and file storage
- • Lovable — application development and hosting platform
- • Claude — application development
- • Anthropic (Claude API) and, where used, OpenAI — AI-assisted features such as document extraction and automation
- • Vercel and Railway — application deployment and hosting
We enter into appropriate data processing terms with each sub-processor. A current, Client-specific list of sub-processors is provided in the relevant Data Processing Agreement. We do not sell personal data, and do not share it with third parties for their own marketing purposes.
6. International transfers
Where any of our sub-processors store or process data outside the UK, we ensure an appropriate transfer mechanism is in place (such as an adequacy decision, the UK International Data Transfer Addendum, or Standard Contractual Clauses).
7. Data retention
We retain personal data only for as long as necessary for the purposes described in this policy, for the duration of our relationship with a Client, or as required by law (for example, UK accounting records are typically retained for 6 years). Data processed on behalf of a Client under a DPA is retained, returned or deleted in line with the terms of that agreement.
8. Security
We apply appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, access controls, and regular review of our systems. Further detail is available in the Data Processing Agreement applicable to a given Client engagement.
9. Your rights
Subject to applicable law, individuals have the right to request access to, correction of, or deletion of their personal data, to object to or restrict certain processing, and to data portability. Where we act as Processor for a Client, we will direct such requests to the relevant Client unless instructed otherwise. Where we act as Controller, requests can be made to the contact details in Section 1.
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk, or the relevant supervisory authority in your jurisdiction.
10. Changes to this policy
We may update this policy from time to time. The "last updated" date at the top of this document indicates when it was last revised. Material changes will be communicated to current Clients.
11. Contact us
For any questions about this policy or how we handle personal data, contact: flynn.little@stingraysoftware.co.uk.