Slips← Back to home

Slips — Privacy Policy

Last updated: [July 29, 2026]

This Privacy Policy explains how Slips Technology Ltd collects, uses, shares, and protects personal data when you use the Slips app and related services (the "Service").

We are the "controller" of your personal data. We are:

Slips Technology Ltd Registered in England and Wales, company number 17178759 Registered office: 7 Zetland Street, Southport, Merseyside, PR9 0SB Privacy contact: [PRIVACY EMAIL] ICO registration number: [ICO REGISTRATION NUMBER]

We handle personal data in line with the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR), and — because our users include people under 18 — the ICO's Age Appropriate Design Code (the "Children's Code").


In brief

  • Slips lets people answer curated questions anonymously about each other, and turns the answers into a personality "archetype".
  • This means we hold data about you that other people provide, as well as data you give us.
  • We profile you to generate your archetype — but only for the fun of the Service, never in a way that has a legal or similarly significant effect on you.
  • We do not sell your personal data. We can, and may, sell or share anonymised data that doesn't identify anyone.
  • If you're under 18, we apply extra protections and don't use your data for commercial profiling or marketing.
  • You can delete your account and data at any time — see section 12.

1. The personal data we collect

Data you give us:

  • Account details — such as your name or username, phone number, email address, and password.
  • Profile information you choose to add.
  • Your responses to questions about other people (drawn from our curated options).
  • Contact information you choose to share when inviting others.
  • Purchase records (the fact and type of a purchase; we do not receive your card details — see section 6).
  • Communications with us, including support requests and reports.

Data other people give us about you:

  • Anonymous responses that other Users submit about you, which we aggregate to build your archetype and scores. We collect this from other Users, not from you directly (see section 3).

Data we collect automatically:

  • Device and technical data — such as device type, operating system, app version, and identifiers.
  • Usage data — how you interact with the Service.
  • Approximate location (for example, from your IP address or the campus you select), not precise GPS location unless you separately consent.

We do not intentionally collect special category data (such as data revealing health, race, religion, sexual orientation, or political opinions). Please do not submit such data through the Service.


2. How we use your data, and our lawful bases

PurposeLawful basis
Creating and managing your AccountPerformance of our contract with you
Running the core Service — delivering questions, collecting responses, generating your archetype and scoresPerformance of our contract with you
Sending in-app notifications about activity relating to youPerformance of our contract / legitimate interests
Keeping the Service safe — moderation, anti-bullying, reporting, blocking, fraud preventionLegitimate interests, and legal obligation (including the Online Safety Act 2023)
Verifying or estimating age and preventing under-age accessLegal obligation / legitimate interests
Improving and developing the ServiceLegitimate interests
Marketing communications to youYour consent (which you can withdraw at any time)
Sharing personal data with third parties for their own purposesYour consent (which you can withdraw at any time)
Complying with law and responding to lawful requestsLegal obligation

Where we rely on legitimate interests, we have balanced those interests against your rights. You can ask us about this balancing exercise using the contact details above.


3. How Slips works with data about other people

Because Slips is a peer-feedback service, two things follow that you should understand clearly.

3.1 We hold data about you that comes from other people. When other Users answer questions about you, we collect and use that data to build your archetype and scores. Under data protection law, where we obtain data about you from someone other than you, you have the right to be informed — this Policy provides that information. The responses are presented to you anonymously (see section 4).

3.2 You may generate data about other people — including people who are not Users. If you answer questions about, or invite, someone who does not use Slips, we may process limited personal data about that person (such as a name or phone number) in order to operate the Service and, where relevant, to invite them. If you are a person who has been made the subject of responses and you are not a User, you have rights over that data, including the right to object and the right to have it deleted — please contact us at [PRIVACY EMAIL] and we will action valid requests.

We rely on Users to have the authority to provide other people's contact details, and to use invitation features responsibly and lawfully.


4. Anonymity — and its limits

Responses about you are presented anonymously, and in the ordinary course you will not learn which User gave which response.

However, anonymity is not absolute. We may access and, where necessary, disclose information that could identify a respondent where we reasonably need to: comply with a legal obligation, court order, or law-enforcement request; investigate breaches of our Terms, illegal content, or harm; protect the safety of any person; or establish, exercise, or defend legal claims. This mirrors section 8 of our Terms and Conditions.


5. Profiling and automated processing

We use your responses and those of others to generate your Slips archetype and dimension scores. This is a form of profiling under data protection law.

This profiling is for the entertainment and social purpose of the Service only. It does not produce legal effects or similarly significant effects on you, and we do not make solely automated decisions about you that would be restricted under Article 22 of the UK GDPR. Archetypes and scores are not assessments of your character, abilities, or fitness for any purpose.

For Users under 18, profiling is limited to what is necessary to provide the core Service, is not used for marketing or other commercial purposes, and any optional profiling is off by default (see section 8).


6. Payments

Purchases and subscriptions are processed by Apple (App Store) or Google (Google Play) through their in-app purchase systems. Those companies handle your payment details under their own privacy policies. We receive confirmation of a purchase and related records, but we do not receive or store your full payment card details.


7. Marketing and communications

We will only send you marketing messages where you have consented, and you can opt out at any time — through your device settings, an unsubscribe link, or by contacting us. Service messages that are necessary to operate your Account (such as security or transactional notices) are not marketing.

Where we use third-party messaging services (such as the WhatsApp Business Platform) to send invitations or notifications, those messages are also subject to the third party's terms, and we handle contact data in line with PECR and this Policy. You should only invite contacts who are happy to be contacted.


8. Children and users under 18

Our minimum age to use the Service is [16]. We take the following measures in line with the Children's Code:

  • We do not use the personal data of under-18 Users for commercial purposes, targeted advertising, or marketing.
  • We do not sell or share under-18 Users' personal data with third parties for their own purposes.
  • Optional profiling and non-essential data uses are off by default for children.
  • We aim to present privacy information in a way that is accessible to younger users.
  • We apply data-minimisation and default privacy-protective settings.

⚠️ DECISION POINT — resolve with your solicitor. The [16] age threshold determines the extent of your Children's Code obligations and should be finalised alongside section 3 of the Terms and Conditions. A large-scale service that profiles children and is likely to be accessed by them will normally require a Data Protection Impact Assessment (DPIA) before launch — this is a legal requirement, not optional.


9. Who we share data with

We share personal data only as set out below, and only where we have a lawful basis:

  • Service providers who process data on our behalf to run the Service — including our hosting and database provider (Supabase), analytics providers, messaging providers, and moderation tools. They act on our instructions under contract.
  • Our corporate group — other companies within our group, for the purposes described in this Policy.
  • App stores — Apple and Google, in connection with distribution and payments.
  • Third parties, with your consent — where you have given specific, informed consent for us to share your personal data with a third party for that third party's own purposes. You can withdraw this consent at any time.
  • Legal and safety recipients — law enforcement, regulators, courts, or others where we are legally required or permitted to disclose, or to protect safety and rights.
  • Business transfers — a buyer or successor in the event of a merger, acquisition, or reorganisation, with notice where required.

What we do NOT do

  • We do not sell your personal data. Consistent with app-store requirements, we do not exchange or transfer your personal or sensitive personal data to a third party for monetary consideration.
  • We do not monetise children's personal data.

Anonymised and aggregated data

We may create anonymised, de-identified, and aggregated data and insights that do not identify you or any individual. This is not personal data. We may use, share, licence, sell, and otherwise commercialise anonymised and aggregated data for any purpose, including analytics, research, and commercial arrangements — provided it has been anonymised to a standard at which individuals cannot reasonably be re-identified. This mirrors section 10.5 of our Terms and Conditions.


10. International transfers

We are based in the UK. Some of our service providers may process data outside the UK — for example, depending on the region in which our hosting provider stores data ([Supabase hosting region — confirm]). Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, such as UK adequacy regulations, the International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses. You can contact us for details of the safeguards we use.

If you use the Service outside the UK (for example, in the United States), your data will be processed as described in this Policy.


11. How long we keep data

We keep personal data only for as long as necessary for the purposes described in this Policy, then delete or anonymise it. In particular:

  • Account data is kept while your Account is active and deleted after closure, subject to the exceptions below.
  • Responses that have been aggregated into another User's archetype may be retained in de-identified form so that other Users' results are not affected.
  • We may retain certain records where required by law (for example, tax and transaction records) or to resolve disputes, prevent fraud, or enforce our agreements.

See our Delete Your Account page for how deletion works and timeframes.


12. Your rights

Under UK data protection law you have the right to: be informed; access your data; have inaccurate data corrected; have your data erased; restrict or object to processing; data portability; and withdraw consent at any time. You also have rights in relation to profiling.

To exercise any of these rights, contact us at [PRIVACY EMAIL], or delete your account directly (see the Delete Your Account page). We will respond within one month. We do not charge for this unless a request is manifestly unfounded or excessive.

If you are unhappy with how we handle your data, you can complain to the UK's supervisory authority, the Information Commissioner's Office (ICO) — ico.org.uk — though we would welcome the chance to resolve your concern first.


13. Cookies and similar technologies

Our website and Service may use cookies and similar technologies. Non-essential cookies are used only with your consent. See our Cookie Notice for details.


14. Security

We use appropriate technical and organisational measures to protect personal data, including encryption in transit and access controls. No system is completely secure, but we work to protect your data and to respond promptly to any incident, including notifying you and the ICO where required.


15. Changes to this Policy

We may update this Policy from time to time. We will change the "Last updated" date above and, where changes are material, take reasonable steps to notify you.


16. Contact us

Slips Technology Ltd 7 Zetland Street, Southport, Merseyside, PR9 0SB Privacy contact: [PRIVACY EMAIL] Data protection / privacy lead: [DPO OR PRIVACY LEAD, IF APPOINTED]


This is a draft prepared for review and is not legal advice. Given that Slips profiles individuals, is likely to be accessed by children, processes data about non-users, and uses contact-based invitations, it should be reviewed and finalised by a qualified solicitor or data protection specialist, and supported by a Data Protection Impact Assessment (DPIA) before launch. Keep it consistent with your Terms and Conditions, Website Terms of Use, Delete Account page, and Cookie Notice.

HomePrivacy PolicyTerms of UseDelete AccountContact Us