Prototype privacy position (October 2026): The notice builder runs within your browser. When you request checkout or a document, your form details are transmitted securely to our Cloudflare server for validation and PDF generation. If optional Cloudflare KV recovery storage is configured, the original draft and a cryptographically hashed private recovery token are retained for up to 30 days to allow recovery from another device. If KV is not configured, drafts are not intentionally stored on the server. Stripe receives a one-way hash of your draft, not the names or property addresses. Card details are handled by Stripe. This test deployment does not use analytics, advertising trackers or third-party fonts.
Information you enter
You may enter names, correspondence addresses, neighbouring property addresses, descriptions of building works and dates. This information is used to validate and assemble the draft. When you request checkout or download it is sent to the server and processed for that request. For enabled cross-device recovery, the draft is also saved to Cloudflare KV for up to 30 days, including if a checkout is abandoned; otherwise the draft is processed transiently. Your browser stores a draft in sessionStorage during checkout and a local backup of the draft and a Stripe Checkout session reference for up to seven days in localStorage for recovery if the tab closes. Where recovery storage is configured, a private recovery link can also be copied and used on another device within 30 days. Anyone who obtains that link may be able to access the document. You can clear this by clearing this website’s browser storage. Local browser drafts remain on your device. When cross-device recovery is enabled, the copy kept in Cloudflare KV is also available to our service. Names and addresses are not included in Stripe payment metadata.
Technical hosting data
Cloudflare, as the hosting provider if deployed there, may process standard technical request information such as IP addresses for security and service delivery. The exact hosting account settings and applicable privacy disclosures must be checked before launch.
Cookies and external links
No non-essential cookies are set by this website code. Stripe may set necessary checkout cookies and has its own privacy information. External GOV.UK links may have their own privacy practices when visited.
Before a live launch
This remains a test-phase privacy summary, not a final commercial privacy notice. Before taking real payments, add the operator’s trading identity and contact details, legal bases, processor information, retention periods and data subject rights, including details of any cross-device recovery storage.
Ready to prepare a notice draft?
Start with a free checker. No account needed to use the free checker.