Privacy Policy
Last updated 19 June 2026
This policy explains what personal data Skedlark collects, why, who we share it with, and the rights you have over it. It is written for the pre-launch site and founding pre-order; a product privacy notice will follow at launch.
This document is maintained in English.
01Who we are
Skedlark is operated by AI Merge Studio Ltd, a private limited company registered in England & Wales (company no. 16370224), with its registered office at 71-75 Shelton Street, London, WC2H 9JQ, United Kingdom. For the purposes of the UK GDPR and the EU GDPR, AI Merge Studio Ltd is the data controller for the personal data described here.
We are UK-based, but we host data in the EU and serve users in the EU, so both the UK GDPR and the EU GDPR apply. You can reach us about anything in this policy at hello@skedlark.com.
This is a pre-launch policy. Today, Skedlark is a marketing site offering a paid founding pre-order, plus a free interest list for the next cohort once the founding seats sell out. The product that connects to your social accounts is not yet live, so we do not yet process your social media content or OAuth tokens. When the product launches we will publish a product privacy notice covering that processing, and we will tell pre-order customers before it takes effect.
02What data we collect
If you join the next-cohort interest list
- Your email address, and any name you choose to give us.
- If and when we email you about the launch, basic delivery metadata such as whether a message bounced.
If you buy a founding seat
- Your email address and the details needed to fulfil the order.
- Payment is handled entirely by Stripe. We never see or store your full card number — Stripe returns only a token and limited metadata (such as card brand, last four digits, and country) that we use for billing and fraud prevention.
When you visit the site
- Server logs: IP address, user agent, pages requested, and timestamps, generated automatically by our hosting and used for security, debugging, and abuse prevention.
- Analytics: we use Google Analytics 4 with Google Consent Mode. Analytics cookies and the data they collect are only set after you accept our cookie banner. If you reject, the tag runs in a cookieless mode that does not store identifiers on your device.
We do not collect special category data, and we do not run third-party advertising or cross-site tracking cookies.
03Why we use it, and our lawful basis
- Fulfilling your founding pre-order and providing access at launch — performance of a contract (Art. 6(1)(b)).
- Sending you the launch and product updates you asked for — your consent (Art. 6(1)(a)), which you can withdraw at any time via the unsubscribe link.
- Analytics cookies — your consent (Art. 6(1)(a)), managed through the cookie banner and the 'Cookie settings' link in the footer.
- Server logs, security, fraud prevention, and defending legal claims — our legitimate interests (Art. 6(1)(f)) in running a secure service, balanced against your rights.
- Meeting our legal, tax, and accounting obligations — compliance with a legal obligation (Art. 6(1)(c)).
06International transfers
Your data is stored in the EU. Some processors, such as Stripe and Google, are headquartered in the United States and may process limited data there. Where data leaves the UK or EEA, we rely on appropriate safeguards — the UK International Data Transfer Agreement (IDTA) or Addendum, and the EU Standard Contractual Clauses — together with the supplementary measures those providers offer.
07How long we keep it
- Interest-list and launch-update contacts: until you unsubscribe or ask us to delete you, after which we suppress your address only to honour your opt-out.
- Founding pre-order and payment records: kept for as long as needed to provide the service, then retained for up to six years to meet UK accounting and tax obligations.
- Server logs: rotated and deleted on a rolling basis, typically within 90 days, except where retained longer to investigate a specific security incident.
08How we protect it
All traffic runs over TLS. Sensitive secrets, including the OAuth tokens the product will hold at launch, are encrypted at rest with AES-256-GCM. Hosting is EU-only, internal access follows least privilege, and admin access is protected with two-factor authentication. Our full approach is on the security page at skedlark.com/security.
09Your rights
Under the UK and EU GDPR you have the right to access your data, correct it, erase it, restrict or object to processing, withdraw consent, and receive a portable copy. To exercise any of these, email hello@skedlark.com. We will respond within one month, and we will not charge you or make you jump through hoops to leave.
If you think we have handled your data wrongly, you can complain to the UK Information Commissioner's Office (ico.org.uk). If you are in the EU, you may instead complain to your local supervisory authority.
10Children
Skedlark is a business tool not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
11Changes to this policy
We may update this policy as the product evolves, most notably when we publish the product privacy notice at launch. We will change the 'last updated' date above, and for material changes that affect you we will give notice by email before they take effect.
Questions about this page? Email hello@skedlark.com.
← Back to home