← WARROOM

Privacy Notice

Last updated: May 2026

1. Who we are

This service is operated by Dillon Connor (sole trader), trading as Warroom Digest ("we", "us"). We act as the data controller for personal data described in this notice.

2. What we collect and why

  • Account data (email, display name, password hash, OAuth identifiers): to create and secure your account. Legal basis: contract performance.
  • Briefing preferences (sector, tickers, competitors, keywords, digest hour): to personalise your daily briefing. Legal basis: contract performance.
  • Email engagement (delivery, bounce, unsubscribe events): to operate the briefing email service and honour opt-outs. Legal basis: legitimate interests and legal obligation.
  • Usage and telemetry (IP address, device, page views, error logs): for security, fraud prevention, and improving the service. Legal basis: legitimate interests.
  • Support messages: to respond to you and improve our support. Legal basis: legitimate interests.

Payment card data is collected directly by Paddle and is not stored on our servers.

3. Who we share data with

  • Paddle — Merchant of Record for sales, subscription management, payments, tax compliance, and invoicing.
  • Hosting and infrastructure — Lovable Cloud (Supabase, Cloudflare) for application hosting, database, and edge runtime.
  • Email delivery — our transactional and briefing emails are delivered via a third-party email provider.
  • AI processing — model providers used to generate briefings receive intelligence inputs but no PII beyond what you explicitly include in prompts.
  • Professional advisers — legal and accounting, where strictly necessary.
  • Authorities — where required by applicable law.

4. International transfers

Our subprocessors operate globally, including in the US. Where personal data of UK/EEA users is transferred outside that region, we rely on safeguards such as Standard Contractual Clauses or applicable adequacy decisions.

5. Retention

We keep account and preference data while your account is active and for up to 12 months after closure for accounting and legal records, after which it is deleted or anonymised. Email send logs are kept for 90 days. Suppression list entries are kept indefinitely so we don't email people who have unsubscribed.

6. Your rights

Depending on where you live you may have rights to access, rectify, erase, restrict, port, or object to processing of your personal data, and to withdraw consent. UK/EEA users also have the right to lodge a complaint with their supervisory authority. We respond to verified requests within one month.

Contact: privacy@warroomdigest.com

7. Security

We use appropriate technical and organisational measures including encryption in transit, hashed passwords, role-based access controls, and audit logging.

8. Cookies

We use essential cookies and local storage to keep you signed in and operate the service. We do not currently use marketing cookies. If that changes, we'll add a cookie banner so you can manage preferences.