Privacy notice
Slashturn Studios
Last updated: 24 September 2026
Version: slashturn-privacy-v0.5
How did you get my email address?
That is almost certainly why you are here, so we will answer it first and we will answer it honestly.
We found your business on Google Maps. Our software reads Google Maps business listings in a web browser, the same listings you can look at yourself, and it looks for businesses that do not appear to have a website of their own. If yours came up, we then needed a way to contact you. Your email address reached us in one of three ways, and we record which one it was against your record:
- It was published on your Google Maps listing, or on a page linked from it.
- It was published somewhere else on the open web, and a service called Hunter found it for us.
- Hunter worked it out. In this case your address was not published anywhere. Hunter knows the pattern that other email addresses at your domain follow, for example firstname@yourbusiness.co.uk, and produced a likely address for you. It then checked with your mail server that an address in that form exists.
We want to be straight about the third one, because it is the one people find surprising. If your address reached us that way, then nobody published it. We inferred it. We do not describe an inferred address as “your published business contact”, because it is not.
If you want to know which route applies to you, ask us and we will tell you. We record the source code against your record. Email privacy@slashturn.com and we will send you what we hold, including the source.
Why did you email me?
Because our search suggested your business has no website, and we build websites for small businesses at a fixed price. We wrote to tell you what one would cost and, if you replied, to build you a real working one so you could see it before deciding.
That is the whole reason. We are not selling your details to anyone, we are not adding you to a mailing list that goes on forever, and we do not send you anything after you tell us to stop.
Who we are
The company responsible for your information (the “controller”, in the language of the law) is:
Slashturn Ltd
Registered in England and Wales, company number 15572184
Registered office: 56b Ridgway, London SW19 4QS
Slashturn Studios is a trading name of Slashturn Ltd. It is not a separate
company. When you deal with Slashturn Studios you are dealing with Slashturn Ltd. We
use two web addresses: slashturnstudios.com, which sends our email, and slashturn.com, which
hosts our site, the previews we build and our payment pages. Both are us.
How to contact us about your information:
- Email: privacy@slashturn.com
- Named contact: Ross Walker. If you would rather write to a person by name, write to Ross Walker at the registered office above, or email privacy@slashturn.com.
We do not have a Data Protection Officer. We are a small company and the law does not require us to appoint one. We are telling you this rather than leaving a gap, because the law requires us to give you a DPO’s details if we have one. Ross Walker is the person accountable for this, and the address above reaches him.
What we do with your information, and what allows us to do it
| What we do | What allows us to do it |
|---|---|
| Find businesses on Google Maps that appear to have no website, and record their public listing details | Our legitimate interests (see below) |
| Find or work out a contact email address for that business, and check it is a real working address | Our legitimate interests |
| Send you one cold pitch email and a short sequence of follow-ups if you do not reply | Our legitimate interests |
| Read and classify your reply, and keep a record of the correspondence | Our legitimate interests |
| Build you a preview website and send you the link, if you tell us you are interested | Our legitimate interests, and then taking steps at your request before entering a contract |
| Take payment and deliver what you bought | Performance of our contract with you |
| Keep records of sales, VAT and tax | A legal obligation we are under |
| Keep a permanent record of anyone who has told us to stop, so we never contact them again | A legal obligation, and our legitimate interest in not breaking the law twice |
| Keep evidence of what we showed you and what you confirmed at checkout, and of when an unsubscribe link was used | Our legitimate interest in being able to prove what happened, and a legal obligation |
The legitimate interests we actually rely on
The law lets us use “legitimate interests” as our reason, but only if we say what those interests are and only if they do not override your rights. Here they are, specifically.
- We are a new business and we need customers. Cold email to other businesses is how we intend to find our first ones.
- We only write to businesses that our search suggested have no website of their own. We think a plumber, a garage or a salon with no website is more likely than most people to want to know what one would cost. That makes the message commercially relevant to you rather than random.
- We want to tell you once, briefly, at a stated price, and, if you are interested, show you a real working site built for your business rather than a sales deck.
- We want to keep a permanent record of everyone who has said no, so that we can guarantee we never contact them a second time.
Why we think this does not override your rights
- We write to you in your business capacity, about your business, at the address your business can be reached on.
- We do not hold anything sensitive about you. No health data, no beliefs, no finances beyond what you pay us if you buy something.
- The volume is small and the sequence is short and capped. We are not sending you a newsletter for years.
- Stopping us takes one click and a button press, or one reply, and costs you nothing, and we act on it straight away rather than within the time the law allows.
- We never sell, rent, share or licence your details to anyone else for their marketing.
What we do NOT rely on
We do not say that because your details were public, you must be happy to receive marketing.
The Information Commissioner’s Office has said plainly that the public availability of someone’s
information is not agreement to direct marketing, and we agree with that. Putting a phone number
on a Google listing so customers can book a boiler service is not an invitation to receive sales
email. So being public is how we found you. It is not our justification for writing to you. Our
justification is set out above and it stands or falls on its own.
Exactly what we hold about you
Some of this is about your business rather than about you personally, but we are listing all of it, because a one-person business and the person running it are often the same thing.
From the Google Maps listing:
- business name, and your name where the listing or a page linked from it shows it
- postal address of the business, and its geographic coordinates and timezone (we use the timezone so we only email you during your own working hours)
- telephone number
- business category, for example “plumber” or “hair salon”
- the number of reviews the listing has and its star rating
- whether the listing showed a website and, if so, what kind (none, social media page only, a directory page, a booking platform page, or a dead site) and whether it was reachable
- a reference to the raw snapshot of the listing as we scraped it, and the listing’s own web address
Contact details:
- email address, and the domain it is on
- how we got that email address, recorded as one of the routes described at the top of this page
- whether the address was verified as deliverable, and a reference to that check
- whether your business appears to be a company or an individual trading in their own name. We record this because UK law protects sole traders more strongly than companies against marketing email, and we use it in deciding who we may write to
About our dealings with you:
- which of our three price offers you were shown. Each business is assigned one automatically, in a way that keeps the three offers evenly spread; the assignment takes nothing about you into account and is never re-rolled
- a log of every message we have sent you: when, the subject, and technical fingerprints of the exact message
- we do not track whether you opened our email. Our messages carry no tracking pixel and no hidden images
- your replies stay in our mailbox like any other email. Our records system keeps who each reply was from, when, its subject, our automated classification of it (for example “interested”, “not interested”, “asked a question”, “asked us to stop”), and a digital fingerprint of the text rather than a second copy of it
- your engagement state and where you sit in our process, for example “contacted, no reply yet”, “replied”, “preview site built”, “customer”, “expired”
- whether you are on our suppression list, and why, and when you went on it
- our own working references: internal record ids, email message ids, the address of any preview site we built for you and when it expires, payment link references, and an append-only audit trail of every change of state on your record. If we cannot match an email you sent us to any record, we keep the message itself until a person reviews it
If you use an unsubscribe or preview-restore link:
- the date and time, the IP address, and technical details of the request (such as the browser identifier and country). We keep these so we can tell a real person’s click from an automated email scanner, and so we can prove we honoured an opt-out
If you buy from us, we keep a record of the checkout itself. This is our evidence of what you agreed to, when, and on what terms, and the law effectively requires us to be able to prove it. It is a fuller record than most people expect, so here is all of it, grouped:
- What you agreed to: the version number of the terms you accepted, a digital fingerprint (a hash) of the exact terms file published at the time, a digital fingerprint of the block of information shown on screen immediately above the order button, and the exact wording that was on the order button itself
- The confirmations you gave at checkout, each with the time you gave it: that you agreed to the terms; that you understood placing the order meant you had to pay us; that you asked us to start straight away; that you consented to us supplying the website immediately; and whether you told us you were buying for your business or mainly for personal purposes
- What you bought: our internal reference for your record, which of our three offers you were on, the price, the currency, and whether that price included VAT
- When, and from where: the date and time of the order, and the IP address you placed it from
- The confirmation email: when we sent it and its message identifier. That email is the moment your contract with us starts, so we keep proof that it went
We do not hold your card details. If you buy, your billing details are handled by Stripe rather than held by us.
Who else sees it
We use other companies to run our business. Here is every one of them that can see your information, what they do, and where they are.
| Who | What they do with it | Where they are |
|---|---|---|
| Microsoft | Runs our email. Every message to and from you sits in a Microsoft 365 mailbox. | United States and Ireland, with UK data centres for mailbox storage |
| Composio | An email gateway our software uses to read our own mailbox, so the emails you send us pass through it. | United States |
| Hunter | Finds, verifies and enriches email addresses. We send them a business domain or name and they return an address and a confidence score. | Processing in the European Union (data stored in Belgium), operated by a United States company, with some United States sub-processing |
| Cloudflare | Runs our domain names, hosts our website, the preview sites we build, and the unsubscribe and contact-form endpoints. A contact-form message is held on their network only until our systems collect it, usually within a few minutes, backed by an automatic 30-day limit if that collection ever fails. | United States, with a global network including the UK |
| Stripe | Takes your payment if you buy from us. Stripe decides for itself how it uses payment data for fraud checks and its own legal duties, so for that data Stripe is responsible in its own right and not just working for us. | United Kingdom and United States |
| Anthropic | Provides the AI models that read and classify your reply and help draft our replies to you. Your reply text is sent to their model to be classified. | United States |
| OpenAI | Generates the placeholder images used on preview websites. Our tooling is blocked from putting your name or your business name into an image prompt, so no personal data is intended to reach it. | United States |
Google is not on that list, because we do not send Google anything. Google is where we found your listing, not somewhere we send your data.
We may also have to hand your information to our accountants, our lawyers, our insurers, or a public authority such as HMRC or the Information Commissioner’s Office, if we are legally required to or if we need advice. We do not sell your information, we do not rent it, and we do not pass it to anyone else for their own marketing.
Does my information leave the UK?
Yes, some of it does. Most of the companies above are American or have American parts. UK law allows that, but only if the information stays protected. Here is the basis for each one. We checked the certification claims below against the official Data Privacy Framework list on 31 July 2026, and we re-check them periodically.
| Who | Where it goes | What protects it |
|---|---|---|
| Microsoft | Ireland and the United States | UK adequacy regulations for the United States: Microsoft Corporation holds an Active Data Privacy Framework certification covering the UK Extension and non-HR data. Microsoft’s standard data protection terms, which incorporate the UK International Data Transfer Addendum, apply as well |
| Composio | United States | The UK International Data Transfer Addendum to the EU standard contractual clauses, supported by a transfer risk assessment |
| Hunter | European Union, with some United States sub-processing | UK adequacy regulations for the EEA cover the EU processing (data is stored in Belgium). For the United States element, Hunter’s data processing agreement applies the EU standard contractual clauses with the UK International Data Transfer Addendum |
| Cloudflare | United States and a global network | UK adequacy regulations for the United States: Cloudflare, Inc. holds an Active Data Privacy Framework certification covering the UK Extension, together with the UK International Data Transfer Addendum in Cloudflare’s data processing agreement |
| Stripe | United Kingdom and United States | Our UK contract is with Stripe’s UK entity. Onward transfer to the United States is covered by Stripe, LLC’s Active Data Privacy Framework certification covering the UK Extension, and Stripe’s own transfer safeguards including the UK International Data Transfer Addendum |
| Anthropic | United States | Anthropic is not certified under the Data Privacy Framework. Transfers rest on Anthropic’s data processing terms, which apply standard contractual clauses with the UK International Data Transfer Addendum, supported by a transfer risk assessment |
| OpenAI | United States | No personal data is intentionally sent, so no transfer safeguard is needed for it. If that ever changes, this table changes first |
In plain terms there are two protections in play. The first is that the UK government has decided that American companies which sign up to a scheme called the Data Privacy Framework give personal information enough protection, so transfers to those companies are allowed; where we rely on that, we have checked the company’s certification is active and covers the UK. The second, which we use as well as or instead of the first, is a standard set of contract terms (the International Data Transfer Addendum) which legally binds the receiving company to protect your information to a UK standard.
You can have a copy. Email privacy@slashturn.com and ask for the transfer safeguards, and we will send you the relevant clauses. We may redact commercial pricing, because that is not about you.
How long we keep it
We keep different things for different lengths of time. Here is the whole picture. Two kinds of record appear in it: ordinary records, which we delete on the schedule below, and evidence records, which are deliberately built so nothing can quietly edit or delete them, because their whole job is to prove later what happened and when.
| What | How long | Why |
|---|---|---|
| A business we found but never contacted | 90 days from the day we found it, then deleted | If we have not written to you in three months we are not going to, and there is no reason to keep the record |
| A business we contacted that never replied | 12 months from the last message we sent, then deleted | Long enough to stop us contacting you again by accident, short enough not to be a permanent file on you |
| Your replies and our correspondence, if you did not become a customer | 12 months from the last message either way | So we can answer a question or a complaint about what we said to you |
| Automated classifications, engagement state and offer variant | Deleted with the record they belong to, except where they sit inside an evidence record | They are notes about the correspondence, not a separate file |
| Evidence records: the audit trail of state changes, the fingerprint record of each reply, the send log, and the checkout record | 6 years | Six years is the period in which a contract claim can be brought in England and Wales, and these records are how we prove what was sent, what was agreed and what we did about your instructions |
| Records of anyone who told us to stop, or who bounced, or who said no | Permanently | See the note below |
| Unsubscribe links | They keep working indefinitely | The law requires the opt-out to keep working for at least 30 days after each message. Ours does not expire at all |
| The record made when an unsubscribe link is used (time, IP, technical details) | 6 years | So that if anyone ever says we did not honour an opt-out, we can prove we did |
| The record made when a preview-restore link is used | 90 days | To tell a real click from an automated scanner |
| A contact-form message sent through a site we built (your name, contact details, what you wrote, and some basic technical details about the request, like your IP address) | Deleted once it has been delivered to the business, and in any case within 30 days | It is not our message. We only pass it on, and the 30-day limit is an automatic backstop enforced by our hosting provider in case delivery ever fails |
| The record that we sent a contact-form message on (when, which site it came from, and the name of the person who wrote in, but never their email, phone number or message) | 6 years | So we can show a business what was sent and when, if they say a message never reached them. In the rare case a message cannot be delivered and someone has to resolve it by hand, we keep that full message as part of the record instead, for the same reason |
| Customer contracts, invoices, VAT and accounting records | 6 years after the end of the financial year they relate to | We are legally required to keep these |
| Anything we host for you as a customer | For as long as we host it, and deleted on request or within 30 days of the service ending | It is your data, not ours. The data processing terms in your contract govern it |
Why the suppression list is permanent
This is the one thing we keep forever, and we want to explain it rather than bury it.
If you tell us to stop, or your address bounces, or you tell us you are not interested, we put a record on a suppression list: your email address (or occasionally a whole email domain), the date, the reason, and a short note of what prompted it. Every single message we send is checked against that list first, and the check is built to fail safe: if the list cannot be read, nothing sends.
That record has to be permanent, because the moment we deleted it we would lose the only thing that guarantees we will never write to you again. If we deleted it and then found your business on Google Maps a year later, we would have no way of knowing you had already said no. Keeping the record is how we honour your objection, not a way around it.
We keep the record as it was made, including your address in readable form, because the list only works if it can be checked before every send. If you would rather we did not, say so and we will discuss it with you. But be aware that the alternative is that we cannot promise never to contact you again.
YOUR RIGHT TO TELL US TO STOP
You have an absolute right to object to us using your personal information for direct marketing. You do not have to give a reason. We do not get to weigh it against our own interests. We cannot refuse.
This is separate from every other right on this page, and the law requires us to bring it to your attention explicitly and separately, which is what this block is for.
Three ways to use it. Any one of them is enough.
- Use the unsubscribe link at the foot of any email we send you. The link opens a page with one button; press it and it is done. If your email app shows its own unsubscribe button, that works in one press with nothing else to do. No form, no login, no reason, and the link never expires.
- Reply to any email from us and say stop. Those words are enough. You do not need to be polite about it.
- Email privacy@slashturn.com.
What happens then:
- We stop emailing you. We act on it straight away, not within the time the law allows.
- Your address goes on our permanent suppression list, so no future campaign can reach you.
- We delete the rest of what we hold about you within 30 days, keeping only the suppression record and the evidence records described above.
- You get no confirmation email, because you have told us to stop emailing you and we take that literally. The web page confirms it instead.
You can also object to anything else we do with your information, not just the marketing. That right is not absolute in the same way: we have to stop unless we can show compelling legitimate grounds that override your interests. Tell us and we will look at it properly and answer you.
Your other rights
Each of these is a right you have under UK data protection law. To use any of them, email privacy@slashturn.com. We will respond within one month, and it is free.
- The right to be told what we hold. You can ask for a copy of the personal information we hold about you, including the exact source of your email address.
- The right to have it corrected. If anything we hold about you is wrong or incomplete, tell us and we will fix it.
- The right to have it deleted. You can ask us to delete your information, and where we are relying on our own legitimate interests rather than a legal duty we will normally do so.
- The right to have us pause. You can ask us to stop using your information while we deal with a dispute about whether it is accurate or whether we should be using it at all.
- The right to take it with you. This one has limits. It only applies where we are using your information because you consented or because we have a contract with you, so it applies to your customer data if you buy from us, and it does not apply to the outreach data we gathered before you had any dealings with us.
- The right to object. Set out in full in the block above.
- The right to withdraw consent. We do not rely on consent for our outreach, so there is usually nothing to withdraw. Where we do ask for consent, for example for non-essential cookies, you can withdraw it at any time and it is as easy to withdraw as it was to give.
Complaining about us
If you are unhappy with how we have handled your information, please tell us first. Email privacy@slashturn.com. We would rather fix it than have you go elsewhere.
You do not have to come to us first, though. You can complain directly to the UK regulator at any time:
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
Online: https://ico.org.uk/make-a-complaint/
The ICO’s online complaint form takes about five minutes. The ICO cannot award you compensation, but it can look at what we did and tell us to change it. If you want compensation, that is a claim you would bring in court, and you should take your own advice before doing that.
Automated systems and AI
We are telling you this because you should know, not because we have to bury it in a footnote.
Almost all of this is automated. Software, not a person:
- decides which businesses to contact, by looking for Maps listings with no website
- assigns each business one of our three price offers, automatically and permanently, in a way that keeps the three offers evenly spread and takes nothing about you into account
- decides when to send, so that the message arrives during your working hours
- writes the message from a fixed, pre-approved template with your business details merged in
- reads your reply and classifies it, for example as interested, not interested, a question or an opt-out
- decides whether to send a follow-up, and when to stop
- decides whether to build you a preview site and send you a payment link
A contact-form message is handled differently: it is passed on, not read or classified. If you write to a business through a contact form on a site we built, no automated system decides anything about your message or acts on what it says. Software works out which mailbox it should go to and sends it there. That is the whole of the automation on that path.
Sophie is an AI assistant, not a person. She is operated by Slashturn Studios and her messages are our messages. If you would rather deal with a human being at any point, reply and ask for one, and Ross Walker will pick it up. Some things always go to a human: anything that looks like a complaint, a negotiation, a legal question, or a request we have not planned for.
The logic, in plain terms. There is no scoring of you as a person and no profile of your character. The system looks at whether your listing shows a website, what category of business you are, where you are, whether we can find a working email address, and whether your business appears to be a company or an individual trading in their own name (because the law protects the second group more strongly, and we use that in deciding who we may write to). The price offer you see is assigned automatically as part of a test of which of our three offers works best, and it is not based on anything about you. The consequence of all this is that you receive an email, or you do not. Nothing else happens to you either way.
Does the law’s special protection for automated decisions apply here? From 5 February 2026, the Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with new Articles 22A to 22D. Those rules give you extra rights where a decision is made about you entirely by machine and it has a legal effect on you, or an effect that is similarly significant.
Our honest view is that they do not apply to what we do, because sending you a marketing email and quoting you one of three prices does not have a legal or similarly significant effect on you. You can ignore it. You can say no. Nothing follows.
We have written that reasoning down rather than assuming it, because it is a judgement and not a certainty. If you think a decision our system made about you was significant and you want a human being to look at it again, ask, and a human will.
Do you have to give us anything?
No. You did not give us your details in the first place, so there is nothing you are required to provide and no consequence if you provide nothing. You can ignore our email entirely and nothing happens. If you decide to buy something from us, we will need your billing details in order to take payment and deliver, and if you do not give them we cannot sell you anything, which is the only consequence.
Cookies, and the websites we build
This page and our outreach. This notice covers our cold outreach and the people we contact, our customers, and anyone who fills in the contact form on a site we’ve built, whether or not it has been sold yet. The site you are reading it on uses only the cookies that are strictly necessary to serve the page. We do not run advertising trackers on it and we do not need your consent for strictly necessary cookies.
If you have just filled in a contact form. Here is what happens to your message, in plain terms. It reaches us first, not the business: we operate the form so that it keeps working even when the business is not looking at their inbox, and our systems pass your message straight to them by email, usually within a few minutes. Nobody at Slashturn reads it as a matter of course, and nothing automated acts on what it says beyond working out which mailbox it should go to and sending it there. We keep the message itself (your name, contact details, what you wrote, and some basic technical details about the request) only until it has been delivered, and delete it automatically within 30 days regardless, because it is the business’s message to answer, not ours. We keep a short record that we sent it, so we can show what happened if the business ever says your message did not arrive, but that record does not carry your email address, phone number or what you wrote, only your name, when, and which site. We will not add you to a mailing list, use your details to market to you, or pass them to anyone else. If you want to know more, or want to ask us about what we hold, email privacy@slashturn.com.
Preview sites we build for you. If we build you a preview at yourbusiness.slashturn.com, that site is ours until you buy it, it is covered by this notice, and it carries no advertising or third-party tracking cookies: even the fonts are served from the site itself rather than from anybody’s tracking network. Our hosting provider keeps its own short-term security logs for the network it runs, and if you use a link we sent you to restore an expired preview, we keep the record of that use for 90 days as described above.
Sites we host for you as a customer. Once you are a customer and we are hosting your site, the position flips for everything except the contact form described above. You become responsible for the personal information your own visitors give you in any other way, and we are simply following your instructions as your supplier. That is dealt with in the data processing terms in your contract with us, not in this notice, and you will need your own privacy notice for your visitors. We will tell you that at the time. The contact form is the one exception: because we operate it and decide how long a message is kept, we tell the person who wrote in directly, above, rather than leaving it to your own notice to cover.
Changes to this notice
If we change how we use your information, we will update this page and change the version number at the top. Every version is kept, so you can see what the notice said on the day we wrote to you. If we make a change that materially affects people we are still in contact with, we will tell them.
Contact us
- Email: privacy@slashturn.com
- Post: Ross Walker, Slashturn Ltd, 56b Ridgway, London SW19 4QS
- Regulator: Information Commissioner’s Office, https://ico.org.uk/make-a-complaint/, 0303 123 1113
Version slashturn-privacy-v0.5. Page generated 2026-09-24. Every version of this document is kept, so you can see what it said on the day we wrote to you. The version string and a hash of the published file are at /legal/versions.json.