Legal

Privacy Policy

Last updated: 10 June 2026

Summary. Memberra is the data controller for Operator (customer) accounts. For end customers who sign up through an Operator's portal, the Operator is the controller and Memberra is the processor. We never sell personal data.
1.

Who we are

Memberra Ltd ("we", "us", "our") is the controller of personal data we collect about Operators (our direct customers). For end-customer data flowing through Operator-branded portals, the Operator is the independent controller and Memberra acts as a processor on the Operator's documented instructions.
2.

Data we collect

  • Account data: name, email, hashed password, business name, billing address, VAT number, payment-method metadata (last four digits, expiry, brand — never full card numbers).
  • Operational data: server endpoints, API tokens (encrypted at rest), webhook URLs, automation configurations, audit logs, support correspondence.
  • Usage & device data: IP address, user agent, device, pages viewed, in-app actions, approximate location derived from IP, performance and crash diagnostics.
  • End-customer data (processed on behalf of Operators): email, display name, payment status, subscription state, invite tokens, server-account identifiers, watch-analytics events configured by the Operator.
  • Communications: emails, in-app messages and support tickets you send to us.
3.

How we use data

To provide and operate the Service; authenticate users and prevent fraud; process Operator subscription payments; deliver transactional emails; respond to support requests; comply with legal, tax and accounting obligations; investigate abuse and security incidents; produce aggregate, de-identified analytics to improve the product. We do not sell personal data and we do not use end-customer data for our own marketing.
4.

Legal bases (UK/EU GDPR)

  • Contract: account creation, service delivery, billing.
  • Legitimate interests: security, fraud prevention, product analytics, network and information security, direct B2B communication with Operators.
  • Legal obligation: tax, accounting, anti-money-laundering, responding to lawful requests.
  • Consent: marketing emails and non-essential cookies (withdrawable at any time).
5.

Subprocessors

We rely on Cloudflare (hosting, CDN, DDoS protection), Supabase (database, auth, file storage), Stripe (payment processing for Operator subscriptions), PayPal (payment processing), Resend (transactional email), and Discord (where Operators enable the Discord integration). A current list with locations is available on request and material changes are notified in advance to Operators with an opportunity to object.
6.

Data retention

Account data is retained for the life of your account, then for up to 7 years following closure for tax and accounting compliance. Operational logs are retained for 90 days. Security and audit logs are retained for up to 12 months. Backups are rotated on a 30-day cycle. End-customer data is retained for as long as the Operator's account is active and is deleted (or returned) on Operator instruction or within a reasonable window after account termination, subject to legal retention requirements.
7.

Your rights

Under UK/EU GDPR you have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data, and the right not to be subject to solely automated decision-making producing legal effects. To exercise these rights, email privacy@memberra.co.uk. End customers should contact the Operator they signed up with for requests relating to their account; Memberra will forward such requests if received in error. You may also complain to the UK ICO (ico.org.uk) or your local supervisory authority.
8.

International transfers

Personal data may be processed outside the UK/EEA by our subprocessors. Where this happens, we rely on the UK International Data Transfer Agreement (IDTA), EU Standard Contractual Clauses, UK Addendum, or an adequacy decision, together with appropriate technical and organisational safeguards.
9.

Cookies

We use essential cookies for authentication, session management and security. We use minimal first-party analytics cookies to understand product usage. We do not use third-party advertising cookies and we do not allow cross-site tracking. You can refuse non-essential cookies via the cookie banner at any time.
10.

Security

Encryption in transit (TLS 1.3) and at rest, role-based access control, least-privilege service accounts, audit logging, row-level security on tenant data, encrypted secrets storage, 2FA available on all accounts, and routine third-party security scanning. No system is 100% secure; we will notify affected users without undue delay of any breach materially affecting their personal data, as required by law.
11.

Children

The Service is not directed to children under 16 (or under 13 in the US). We do not knowingly collect data from children. Operators must not configure their portals to collect data from children except in compliance with applicable law.
12.

Changes to this policy

Material changes will be notified by email or in-app at least 30 days before they take effect. The "last updated" date above always reflects the most recent revision.
13.

Contact

Privacy questions: privacy@memberra.co.uk. See also our Terms and Disclaimer.
Fine print. Where this Policy describes a processor relationship, the corresponding Data Processing Addendum (DPA) between Memberra and the Operator governs the precise scope of processing. In case of conflict with marketing or in-product copy, this Policy controls. Memberra Ltd is registered in England and Wales.