Privacy

Clear by design.

Bot Ledger collects only what it needs for access requests, paid reservations and the demo dashboard. This notice explains the actual data flow.

Last updated: 4 September 2026 · Privacy contact: Brad@PivotnPlane.co.uk

Who is responsible

The controller is Pivot&Plane Ltd, Company No. 17202414, trading as Bot Ledger. Registered office: Brown & Rear Accountants, 838 Ecclesall Road, Sheffield, England, S11 8TD. Email Brad@PivotnPlane.co.uk for privacy questions or requests.

Access requests and reservations

When you submit the access form, we collect the email address you enter, the plan selected, the page source and a random request reference. We also use a one-hour pseudonymised counter derived from your IP address to limit automated abuse. We do not collect broker credentials, trading-account details or card information in this form.

Why and lawful basis

  • Copy and Audit: to take steps you request before entering the subscription, confirm the reservation and arrange manual onboarding. Lawful basis: steps at your request before a contract.
  • Ledger: to manage limited early access, confirm the request and contact you when access opens. Lawful basis: legitimate interests in operating a controlled product-access list. You can object at any time.
  • Abuse prevention: to protect the form and service. Lawful basis: legitimate interests in security and service availability.

You do not have to provide this information, but we cannot record or fulfil an access request without an email address and plan.

How long we keep it

Access records and their email lookup index expire automatically after 12 months. The anti-abuse counter expires after one hour. We may keep transaction and accounting records for longer where required by law. You may ask us to remove an unneeded access record sooner.

Privacy complaints

If you use the privacy complaint form, we collect your email address, the complaint text, any Bot Ledger reference you provide, a complaint reference and a one-hour pseudonymised abuse-prevention counter. We use this information to investigate, respond to and learn from the complaint. The lawful bases are compliance with our data-protection obligations and legitimate interests in resolving complaints and improving our handling of personal information. The structured Cloudflare complaint record expires after 12 months. A notification copy is sent to the privacy lead's business mailbox and is deleted under the same 12-month schedule, unless a live dispute, regulatory matter or legal obligation requires longer retention.

Payments

Paid reservations continue to Stripe. Stripe collects payment, billing, fraud-prevention and subscription information on its own checkout and acts as an independent controller for that processing. Bot Ledger receives a checkout status, Stripe session identifier and the random request reference for reconciliation, but not full card details. A paid reservation starts a recurring subscription immediately; software access is onboarded manually when your place opens.

Emails

Resend processes your email address and confirmation content to deliver service messages. Access and reservation emails are not permission for unrelated marketing. If Bot Ledger later offers marketing emails, they will require a separate choice where the law requires it.

Dashboard device storage

The demo dashboard stores two small first-party preferences in your browser: whether you dismissed the first-run guide and the newest event you have seen. They stay on your device until you clear site storage, are not advertising identifiers and are not used to track you across sites.

Providers and international transfers

Cloudflare hosts and protects the website and stores expiring access records. Resend delivers service emails. Stripe handles subscriptions and payments. These providers may process information outside the UK. We rely on their contractual transfer safeguards, including relevant standard contractual clauses and UK addenda, where adequacy regulations do not apply. You can ask the privacy contact for more information about those safeguards.

Cookies and automated decisions

Bot Ledger does not use advertising cookies, cross-site tracking or behavioural analytics. The current site does not make decisions about you using automated profiling. Stripe may use automated fraud-prevention tools under its own privacy information.

Your right to object to the Ledger access list

You can object at any time to our use of legitimate interests for the free Ledger access list. Email the privacy contact or use the complaint form. We will stop this use unless we have a compelling lawful reason to continue.

Your rights

Depending on the circumstances, you can ask for access, correction, deletion, restriction or portability of your personal information, and object to processing based on legitimate interests. Email the privacy contact and include the address used for the request. We may need to verify that you control it.

To complain directly to us, use the electronic privacy complaint form. We will record, investigate and respond without undue delay.

If you remain concerned, you can complain to the Information Commissioner’s Office. You can use the complaint service at ico.org.uk, call 0303 123 1113, or write to the ICO at Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.

Correct, remove or complain

Email from the address you used and state whether you want access, correction or deletion. No account login is required.

Open the privacy complaint form →

Or email the privacy contact