Privacy Notice
This notice explains what personal data Starlight Tech Limited collects when you use Compass, why we collect it, how we look after it, and the rights you have over it. It is written to be read. If anything here is unclear, email us and we will explain.
1. Who We Are
Compass is provided by Starlight Tech Limited, a company registered in England and Wales. We are the data controller for the purposes of the UK General Data Protection Regulation and the Data Protection Act 2018.
- Company name: Starlight Tech Limited
- Company number: 17175089
- Registered office: 71-75 Shelton Street, Covent Garden, London WC2H 9JQ
- Contact for data protection enquiries: privacy@starlighttech.ai
In this notice, "Starlight Tech", "we", "us" and "our" mean Starlight Tech Limited. "You" and "your" mean the person who creates an account or uses Compass.
2. The Personal Data We Collect
When you use Compass, we collect the following categories of personal data.
Account data. Your email address, a hashed version of your password, the name of your business if you provide one, your country, and the time zone we infer at sign-up.
Onboarding answers. The answers you give Compass during business setup, brand setup, audience setup, channel setup, and any other onboarding stage. These are the inputs that allow Compass to build your growth plan.
Plan outputs. The 90 Day Growth Plan, the Marketing Strategy, the daily tasks, and any other content Compass generates for you on the basis of your inputs.
What we work out about your business. When Compass researches your business, it reads your website and the social profiles you tell us about, all of them pages that are already public. From those we work out things like your brand colours, your fonts, your tagline and the way you write. We keep what we find and use it to build your plan, including the part that tells you where your brand could be stronger. We also use it to fill in your Brand section for you as a starting point, and nothing there is saved unless you choose to keep it.
Ask Compass conversations. When you use Ask Compass, we keep what you asked and what Compass answered, so that you can come back to it later and so that Compass can see what it has already written for you and stop repeating itself. It is held in our own database, scoped to your business, and no other customer's Compass can see it. You can delete any single message, or a whole conversation, whenever you like.
Data you upload. Where you upload data to Compass, for example a CSV of your audience or customer list, we use the fields needed to build your plan. You control what you upload and can delete it at any time in Settings.
Communications. Messages you send us, support tickets, and feedback you submit through the product.
Technical data. IP address, browser and device characteristics, pages loaded, errors encountered, and other product telemetry. Used to keep the service running and to spot bugs.
How we measure usage, which differs between our website and the product.
- On our website, and on the sign-up screens before an account exists, we use cookieless analytics (Ahrefs and PostHog). It sets no cookie and stores nothing on your device, it is aggregate, and it is not linked to your identity. This includes how a page is used, for example how far down it people read and where on it they click, counted per page rather than per person.
- Inside the product, once you have an account, we use PostHog to understand how signed-in users move through Compass so we can improve it. These analytics identify your account by a pseudonymous identifier, not your name and not your email. We only do this if you have agreed to it, and you can change your mind at any time in Settings. We never send your onboarding answers, your plan outputs, your uploaded data, or any special-category data to our analytics.
Form-protection data. When you use our contact, subscribe, or sign-up forms, Google reCAPTCHA receives technical information about your interaction to tell humans from bots. This is a fraud and security measure. Your use of reCAPTCHA is subject to Google's own Privacy Policy and Terms, as set out in the Cookie Notice.
Billing data. Where you subscribe to Compass Pro, your subscription metadata (plan, status, start date) is held by Compass. The payment instrument itself (card number, account details) is held by our payment processor, Stripe, and is never seen by Compass.
Waiting list and Beta Squad. Before launch, when you join our waiting list, we collect your email address and first name, your business type and business stage, and any other details you choose to give us (your business name, last name, town or city, country, and how and who you sell to). We use this to tell you when Compass opens and, where you have consented, to send you marketing. If you tick the Beta Squad box, we also use these details to consider your application and to pick a varied cohort. Your waiting-list details are held in our email platform, MailerLite. You can unsubscribe and ask us to delete them at any time.
We do not ask for and do not want special category data: information about your health, political opinions, religious or philosophical beliefs, biometrics, sexual orientation, racial or ethnic origin. Please do not enter such information into Compass.
3. Why We Collect Personal Data
We collect personal data for five purposes:
1. To run the service: provide your account, generate your plan, deliver the features you signed up for.
2. To improve the service: identify bugs, measure what works, fix what does not.
3. To stay in touch: send the transactional emails you need (receipts, password resets, security notices) and, where you have opted in, marketing emails about Compass.
4. To meet legal obligations: keep accurate financial records, respond to lawful requests from authorities, evidence consent where required.
5. To protect the service and other users: detect abuse, fraud, and security incidents.
4. Lawful Basis for Each Purpose
| Purpose | Lawful basis under UK GDPR | Notes |
|---|---|---|
| Provide the service you signed up for | Article 6(1)(b), contract | Includes account creation, plan generation, billing, transactional emails |
| Improve the service | Article 6(1)(f), legitimate interests | Documented in our internal Legitimate Interests Assessment; includes cookieless, aggregate analytics on our website and sign-up screens (Ahrefs and PostHog), which sets nothing on your device and is not linked to you |
| Understand how signed-in users use the product | Article 6(1)(a), consent | In-product analytics identifying your account by a pseudonymous identifier, never your name or email. Agreed during onboarding, withdrawable any time in Settings |
| Marketing emails | Article 6(1)(a), consent | Captured when you join the pre-launch waiting list, at sign-up, on the blog subscribe form, and during onboarding; sent via MailerLite; withdrawable any time in Settings or via the unsubscribe link |
| Legal and regulatory compliance | Article 6(1)(c), legal obligation | Accounting records, tax, lawful requests |
| Protect the service | Article 6(1)(f), legitimate interests | Fraud and abuse prevention, including Google reCAPTCHA on our forms (which shares form-interaction data with Google) |
| Advertising measurement (Google Ads conversion import) | Article 6(1)(f), legitimate interests | So we can tell which ads bring people to Compass and stop paying for the ones that do not. We send the click identifier from your ad click, what you did, and when. No name, no email, no account details. We do not use it to show you ads anywhere, and we build no audience from it. Documented in our internal Legitimate Interests Assessment; Google acts as a controller for this data. You can object at any time and we will stop |
We do not rely on consent where another basis fits better. This keeps your rights clear and consistent.
5. AI Training
We do not use your data to train AI models. Not your onboarding answers, not your plan outputs, not anything you upload, and not the words you type into Compass. That is true of models we own and of models our sub-processors operate on our behalf, and it is true today regardless of any setting you have chosen.
There is one setting, and it is off unless you turn it on. During onboarding we ask whether you are willing to help us improve Compass. That setting governs a future possibility rather than anything happening now. If we ever did train a model to improve Compass, turning it on would let us include how you use Compass: which features you open and how you move through them, counted across all customers rather than tied to you.
Even then, we would never include anything you upload, your brand assets, your revenue, ad spend or any other figures you give us, the plans, strategies and tasks Compass writes for you, the words you type into Compass, or anything that identifies you, your business, or your customers.
You can change the setting at any time in Settings, and we will tell you before anything about it changes.
6. Who We Share Your Personal Data With
We share data only with the sub-processors listed at https://compassbystarlight.com/legal/sub-processors. Almost all of them are bound by a written agreement no less protective of your rights than this notice. One is not: our market-research search provider, Serper, does not offer such an agreement, which is why we are replacing them. That list says so, and says what we are doing about it. The current list covers our AI provider, our database and hosting providers, our payment processor, our transactional email provider (MailerSend), our contact-form email provider (Resend), our marketing email provider where you have opted in (MailerLite), our cookieless website analytics (Ahrefs and PostHog), our video delivery network (Bunny), our market-research search provider (Serper), and our bot and fraud protection on forms (Google reCAPTCHA).
Market research. When Compass researches your market, it sends search queries to our search provider, Serper, which passes them to Google to run the search. Those queries can include the name of your business, your location, and the names of competitors you tell us about. They do not include your email address, your account details, or anything else you have given us.
Video delivery. Pages that carry video load it from our video delivery network, Bunny. Bunny receives the technical information any content network needs to deliver a file to you, including your IP address. It does not build a profile of you and sets no cookie on our site.
Advertising measurement. If you reached Compass through a Google ad, we share a Google click identifier (GCLID) from that click, together with the action you took and the time you took it, with Google Ads. That is all we send: no name, no email, no account details, and nothing about your business.
We do this so we can tell which ads bring people who actually use Compass, and stop paying for the ones that do not. We are a small company spending our own money on advertising, and without it we are buying clicks blind.
We do not use it to show you ads anywhere, we do not build an audience from it, and we do not use it to contact you. Google handles this data as a controller under its own terms. We rely on legitimate interests for this rather than asking you to consent, because it is measurement of our own advertising rather than marketing directed at you. If you would rather we did not, email privacy@starlighttech.ai and we will stop for you.
We do not sell your data. We do not share your data with advertisers so they can market their own products to you. The only advertising-related sharing we do is the conversion measurement described above, and you can tell us to stop. We do not share your data with any third party other than the sub-processors above, except where we are required to by law.
7. International Transfers
Some sub-processors are located outside the United Kingdom. Transfers to them are protected by one of the following mechanisms:
- the UK adequacy regulations for transfers to the European Economic Area, Switzerland, the Crown Dependencies, and other adequacy-listed jurisdictions; or
- the UK International Data Transfer Addendum combined with the European Commission Standard Contractual Clauses for transfers to the United States and other non-adequacy jurisdictions.
There is one exception, and we would rather tell you than leave it out. Our market-research search provider, Serper, holds its log data in the United States and does not offer either of the protections above. We are replacing them for that reason, and the Sub-processor List sets out exactly what they receive.
A full schedule of transfer routes and mechanisms is in Schedule 4 of our Data Processing Agreement, available on request from privacy@starlighttech.ai.
8. How Long We Keep Your Personal Data
| Data | Retention |
|---|---|
| Account data | For as long as your account is active. On deletion, 30 days in soft-delete, then full deletion. |
| When you last used Compass | A single date and time, overwritten each time you use the product. We do not keep a history of your visits. For as long as your account is active. On deletion, 30 days in soft-delete, then full deletion. |
| Onboarding answers, research findings and plan outputs | For as long as your account is active. You can delete specific outputs in Settings. |
| Ask Compass conversations | For as long as your account is active. You can delete any single message, or a whole conversation, whenever you like. On account deletion, 30 days in soft-delete, then full deletion. |
| Data you upload | For as long as your account is active; you can delete it in Settings. On account deletion, 30 days in soft-delete, then full deletion. |
| Waiting-list and Beta Squad details | Until launch plus 12 months, or until you unsubscribe, whichever is sooner, then deletion. |
| Communications | 24 months. |
| Technical logs | 90 days. Authentication logs 12 months. |
| Billing records | 7 years from the end of the financial year in which the transaction occurred (HMRC requirement). |
| Consent records | 7 years from the most recent event on the consent record. |
We take daily backups, which are kept for 7 days and then overwritten. So when you delete something, it goes from the live service straight away, and any copy of it in a backup is gone within 7 days.
9. Your Rights
Under UK GDPR you have the right to:
- access the personal data we hold about you;
- correct data that is wrong or out of date;
- delete your data (the right to be forgotten);
- port your data to another provider in a structured, commonly used, and machine-readable format;
- restrict processing in certain circumstances;
- object to processing carried out under our legitimate interests;
- withdraw consent for any purpose where consent is the lawful basis;
- object to automated decision-making as set out in the AI Use and Automated Decisions Notice; and
- complain to the Information Commissioner's Office.
To exercise any of these rights, email privacy@starlighttech.ai or use the controls in the product under Settings, in the Your data section (consent log, export all data, erase my data). We respond within one calendar month. If we need longer we will tell you why within the first month.
To complain to the ICO: https://ico.org.uk/make-a-complaint/ or 0303 123 1113.
10. Cookies
Compass uses a small number of strictly necessary cookies to run the service (authentication, security, session state). These do not require consent under the Privacy and Electronic Communications Regulations 2003. Our website analytics is cookieless, so it sets no analytics cookie. Google reCAPTCHA sets a cookie when it loads on our forms, as a security measure, which we explain in the Cookie Notice. We do not use cookies for advertising or cross-site tracking, and we do not show a consent banner because there is no non-essential cookie to consent to. If you reached us through a Google ad, a Google click identifier (GCLID) from your ad click is read from the page address and held only in the page you are using. It is not a cookie, nothing is stored on your device, and it is gone as soon as you leave the page. It is used only to measure which ads bring people to Compass, as set out in section 6. The full cookie list is in the Cookie Notice.
11. Children
Compass is not directed at children under 18 and is not intended for their use. Our Terms of Service require you to be at least 18 years old to create an account, and you accept those Terms when you sign up. If you believe a child has supplied personal data to Compass, email privacy@starlighttech.ai and we will delete it.
12. Automated Decision-Making
Compass uses AI to generate growth plans, daily tasks, and other coaching outputs based on the information you give it. These outputs are advisory and informational. They do not produce legal effects or significantly affect you in the sense of UK GDPR Article 22(1). You always decide whether to accept, edit, or reject any Compass output before acting on it.
A fuller account of the AI inside Compass, including its limits and the oversight we apply, is in the AI Use and Automated Decisions Notice.
13. Security
We follow security practice appropriate to a SaaS product of our size. The current measures are listed in our Security Statement and in Schedule 2 of our Data Processing Agreement. No system is perfectly secure. If we ever suffer a personal data breach that puts your rights at risk, we will tell you and the Information Commissioner's Office within 72 hours of becoming aware.
14. Changes to This Notice
If we make a material change to how we handle personal data we already hold about you, we will give you reasonable advance notice, normally at least 14 days, before it takes effect. We always update this notice when it changes; the current version is at https://compassbystarlight.com/legal/privacy and the change log sits at the bottom of this page.
15. Contact
For data protection enquiries, email privacy@starlighttech.ai.
For general enquiries, email hello@starlighttech.ai.
Change Log
- v1.8, 5 September 2026. Two things. First, we have set out what Compass works out about your business. When it researches you it reads your website and the social profiles you tell us about, all of them already public, and works out things like your colours, fonts, tagline and the way you write. We keep that and use it to build your plan, including the part that tells you where your brand could be stronger. It also fills in your Brand section as a starting point, and nothing there is saved unless you choose to keep it. This was already happening and this notice had not said so, which is the gap we are closing. Second: Ask Compass now keeps your conversations. A customer told us she was copying Compass's writing out into another tool to keep it, which is a fair complaint and we have fixed it. Since 19 August 2026, what you asked and what Compass answered have been saved, so you can come back to them and so Compass can see what it has already written for you and stop repeating itself. It is held in our own database and nothing about it goes to anyone else. No other customer's Compass can see your conversations, and we do not use them to train AI models. Section 5 already covered that and it has not changed. You can delete any single message, or a whole conversation, whenever you like, and it is in your data export.
- v1.7, 15 August 2026. Changed how we justify one thing, and explained it better. When you arrive from one of our Google ads, we tell Google that the click led to a signup, so we can see which ads work and stop paying for the ones that do not. We used to do this only for people who had also opted in to marketing emails, which was the wrong question to attach it to: agreeing to receive emails and agreeing to let us measure an advert are two different things, and we were using one tickbox for both. We now rely on legitimate interests instead, and we have written down the assessment behind that. What we send has not changed and has not grown: the click identifier, what you did, and when. No name, no email, no account details. We do not use it to show you ads anywhere and we build no audience from it. You can tell us to stop at any time by emailing privacy@starlighttech.ai. This applies to ad clicks from today onwards; we are not going back over clicks from before this date. We also stopped storing the Google click identifier on your device: it is now held only in the page you are using and nothing is written to your browser.
- v1.6, 14 August 2026. Corrected three things and added one, none of which changes what we do with data we already hold. The addition: we now record a single date and time showing when you last used Compass, so we can see how many people are getting value from the product. It is one value, overwritten each time, and we keep no history of your visits; it is in the retention table above and in your data export. The corrections: Two statements stopped being true once we established the position with our search provider: we no longer say that every provider on our list is covered by a written agreement, and the international-transfers section now names the one provider that is not covered by either protection. We also said plainly that Serper passes our search queries to Google to run the search. Separately, we rewrote the AI training section, which described the setting as opt-out when the product is opt-in, and described the opt-in as something we might offer one day when it has been in onboarding for some time. It now leads with the plain fact that we do not train AI models on your data at all, and lists exactly what would stay out if we ever did.
- v1.5, 12 August 2026. Added detail to the description of our website measurement: it includes how a page is used, for example how far down it people read and where on it they click, counted per page rather than per person. Still cookieless and aggregate, nothing is stored on your device, and it is not linked to you.
- v1.4, 10 August 2026. Explained how we measure usage in two places rather than one: cookieless and not linked to you on our website and sign-up screens, and, inside the product, analytics that identify your account by a pseudonymous identifier where you have agreed to it and can withdraw at any time in Settings. Added the matching lawful-basis row. This describes measurement already running in the product that this notice had not previously set out.
- v1.3, 3 August 2026. Corrected the statement about how we keep under-18s off Compass: eligibility is set by our Terms of Service, which you accept at sign-up. Disclosed three providers already used by the service: MailerSend (transactional email), Bunny (video delivery), and Serper (market-research searches), and corrected the description of Resend, which delivers contact-form email. No change to what we do with your data.
- v1.2, 18 June 2026. Added PostHog as a cookieless, aggregate analytics provider for the marketing site, alongside Ahrefs. No cookie, no device storage, IP discarded. No change to any other processing.
- v1.1, 14 June 2026. Added a disclosure that, where you reached Compass through a Google ad and consented to marketing, we share a Google click identifier (GCLID) with Google Ads to measure which ads bring people to Compass. Added the matching lawful-basis row (consent) and a cookie-notice clarification. Clarified the change-notice wording in section 14. No change to any other processing.
- v1.0, 10 June 2026. First publication.
Starlight Tech Limited, company number 17175089, registered office 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, registered in England and Wales.