Privacy Policy
Last updated: 17 August 2026
This Privacy Policy explains how Candour IT Services Ltd ("we", "us", "our"), the provider of Reachlist ("the Service"), collects, uses, and protects your personal data. We are the data controller for the personal data described here and are committed to handling it in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
Reachlist is operated by Candour IT Services Ltd, a company registered in England and Wales (Company No. 9393510, VAT No. 207 4449 15). We are registered with the Information Commissioner's Office (ICO). You can contact us at any time at info@reachlistcrm.com.
2. The data we collect
Information you give us
- Account details, your name, email address, and password when you sign up.
- Business profile, information about your business that you enter so we can personalise the messages we generate for you.
- Your data within the Service, the leads, contacts, notes, pipeline stages, and messages you create and save.
- Payment information, handled by our payment processor. We do not see or store your full card details (see section 4).
Information we collect automatically
- Usage and device data, basic technical information such as your approximate location (derived from your IP address, to set sensible defaults), browser type, and how you interact with the Service.
Information from third parties
- Business search results, when you search, we retrieve publicly available business listing information (such as company names, addresses, phone numbers, websites, and ratings) and, where you request it, publicly available business email addresses.
3. How we use your data
- To provide, operate, and maintain the Service.
- To create your account and authenticate you securely.
- To generate outreach messages personalised to your business.
- To process your subscription and payments.
- To send you service-related emails (such as email verification and password resets).
- To improve the Service and provide customer support.
- To detect, prevent, and address technical issues, fraud, or misuse.
4. Legal bases for processing
We process your personal data on the following legal bases under UK GDPR: performance of a contract (to provide the Service you sign up for); legitimate interests (to operate, secure, and improve the Service, provided this does not override your rights); consent (where required, for example certain communications, which you may withdraw at any time); and legal obligation (for example, keeping records required by law).
5. Service providers we share data with
We use trusted third-party providers to run the Service. They only process your data on our instructions and under appropriate data protection terms:
- Supabase, database, authentication, and secure storage of your account and app data.
- Vercel, hosting and delivery of the application.
- Stripe, payment processing. Stripe handles your card details directly; we never see or store your full card number.
- Resend, sending service emails such as verification and password-reset messages.
- Google Places, retrieving public business listing information for your searches.
- Hunter, finding publicly available business email addresses when you request them.
- Anthropic, generating outreach message drafts. Content sent for message generation is processed to produce your draft and is not used to train their models under our business terms.
We do not sell your personal data to anyone.
6. International transfers
Some of our providers are based outside the UK. Where your data is transferred internationally, we rely on appropriate safeguards such as UK adequacy regulations or standard contractual clauses to ensure your data remains protected.
7. How long we keep your data
We keep your personal data for as long as your account is active. If you close your account, we will delete or anonymise your personal data within a reasonable period, except where we are required to retain certain information to meet legal, accounting, or reporting obligations.
8. Your rights
Under UK GDPR you have the right to access your data; to have inaccurate data corrected; to have your data erased; to restrict or object to processing; to data portability; and to withdraw consent where processing is based on consent. To exercise any of these rights, email us at info@reachlistcrm.com. You also have the right to lodge a complaint with the ICO at ico.org.uk.
9. Security
We take the security of your data seriously. We use encryption in transit, secure authentication, and access controls, and we follow recognised security practices. No method of transmission over the internet is completely secure, but we work to protect your data using appropriate technical and organisational measures.
10. Cookies
We use only essential cookies and similar technologies required to keep you signed in and to operate the Service. We do not use advertising or third-party tracking cookies.
11. Your responsibilities regarding others' data
Reachlist helps you contact businesses. When you use the Service to store contact details and send outreach, you are responsible for complying with applicable laws (including data protection and anti-spam laws such as UK GDPR and PECR) in how you contact those businesses. You should only contact people where you have a lawful basis to do so.
12. Children
The Service is not intended for anyone under 18, and we do not knowingly collect data from children.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version here and change the "Last updated" date. Significant changes will be communicated to you where appropriate.
14. Contact us
For any privacy questions or requests, contact us at info@reachlistcrm.com.