Natterio

Privacy Policy

Last updated: July 2026

This policy explains what personal data Natterio collects, why, and what your rights are under UK GDPR and the UK Data Protection Act 2018.

Who we are

Natterio (operated at natterio.com) is a trading name of Seamstack Ltd, a company registered in England and Wales under company number 17308485, with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. Seamstack Ltd is the data controller for the account data described in this policy.

Seamstack Ltd is registered with the Information Commissioner's Office (ICO) as required, registration reference ZC186082.

Two layers of data processing

Natterio operates two distinct roles depending on whose data is involved:

If you are a community owner looking for guidance on your members' data obligations, contact us at privacy@natterio.com.

What data we collect and why

Account and sign-in

If you sign in, we collect your email address and store a session record. We use this solely to authenticate you. We only send transactional, account-related, and platform-update emails; we do not send third-party marketing emails. The legal basis is the performance of a contract (providing you access to member features you have requested).

Server logs

Like all web servers, our hosting provider (Cloudflare) automatically records standard access logs (IP address, browser type, pages visited, timestamps). These are retained for up to 30 days for security and diagnostic purposes. The legal basis is legitimate interests.

Billing

If you subscribe to a paid plan, Stripe processes your payment. We store your Stripe customer and subscription identifiers and your plan status, but never your full card number. The legal basis is performance of a contract.

Consent records

When you create an account or import a site, we record that you accepted our terms — including the wording you agreed to, a timestamp, and the IP address and browser the request came from. We keep this as proof of consent. The legal basis is compliance with a legal obligation and our legitimate interest in maintaining accurate records.

Analytics

We collect basic first-party analytics — anonymous events such as page views, sign-ups, and feature usage — to understand how the platform is used and improve it. These events do not include your name or email and are not shared with any third-party analytics service. We do not use advertising or cross-site tracking cookies. The legal basis is legitimate interests.

Cookies

We use a single session cookie (authjs.session-token) if you sign in. This is a strictly necessary cookie and does not require your consent. We do not use advertising, analytics, or tracking cookies.

Who we share data with

We do not share your data with third parties, except with the trusted sub-processors listed below to provide the service. We never sell or rent your data. Our sub-processors are:

International data transfers

Some of our sub-processors (including Cloudflare, Stripe, Resend, and Anthropic) are based in, or process data in, the United States or other countries outside the UK and European Economic Area (EEA). Where personal data is transferred outside the UK/EEA, we ensure an appropriate safeguard is in place as required by UK GDPR — relying on UK ‘adequacy’ regulations where they apply, and otherwise the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses. We keep your account data in the EU region where the option is available (for example, our database is hosted in the EU).

How long we keep your data

Account data is kept for as long as you have an account. If you request deletion, we will erase your account and associated data within 30 days. Server logs are deleted after 30 days.

Your rights

Under UK GDPR you have the right to:

To exercise any of these rights, email us at privacy@natterio.com. We will respond within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with the ICO at ico.org.uk.

Security

We use HTTPS for all data in transit. Our database provider encrypts data at rest. We use passwordless authentication (magic links) so no passwords are ever stored. We review security practices regularly.

Changes to this policy

We will update this page if our practices change. Continued use of the site after a change constitutes acceptance of the updated policy.

This policy is provided for transparency. It is not professional legal advice. If you have questions, contact us at privacy@natterio.com.