Legal
Privacy
Data controller: Northstar Infinity Works Ltd (trading as PromptFiling), company no. 17326480, registered office C/O ELSG Ltd, Regus, Building 2, Marlins Meadow, Watford WD18 8YA. Contact: [email protected].
What we process, and why
- Company data — names, numbers, registered addresses, filing deadlines. This is public record, published by Companies House. We use it to show deadlines, to send letters to companies whose deadlines approach (our legitimate interest as a filing service; see Why did I get a letter?), and to prepare filings you ask for. Every letter carries a one-click, permanent opt-out.
- Your e-mail address — only if you give it to us: for deadline reminders (consent; every e-mail has a one-click unsubscribe) and for your account (contract).
- Your Companies House authentication code — only if you enter it to authorise a filing. Stored encrypted (AES-256-GCM); decrypted only at the moment of submission; never logged, never shown to anyone, including our own staff. A build-time guard fails our releases if code ever routes it toward a log.
- Payments — handled by Stripe. Card numbers never touch our servers; we hold the payment reference and the invoice.
- First-party analytics — page views on the public site go to our own database (path, traffic source, country, coarse device class, and a visitor identifier hashed with a salt that rotates daily — irreversible tomorrow, even for us). Letter-link scans are recorded server-side the same way, with letter tokens masked before storage. The analytics itself sets no cookies and stores no IP or user-agent at rest; signed-in customers and our own staff are excluded. Legitimate interest: knowing whether the site works. Separately from analytics, the site keeps three pieces of functional state: your theme choice (in your browser's localStorage), a coarse location hint used only to time the automatic day/night theme (pf-geo cookie), and a signed-in navigation hint (pf_in cookie). None of them identify you.
- Weekly portfolio digest — customers watching two or more companies get a Monday summary e-mail (mutable in one click from the e-mail itself); it replaces the 30-day per-company accounts reminder rather than adding to it.
- Technical logs — IP-derived security counters are stored as salted hashes, not addresses.
Who processes it for us
Vercel (hosting), Supabase (database and first-party analytics, EU region), Stripe (payments), Resend (e-mail), Cloudflare (DNS and edge performance metrics). Each processes only what its job needs.
How long
Reminder subscriptions: until you unsubscribe — unsubscribing also erases the signup record behind them. Analytics rows carry no identity by design. Accounts: until you delete yours. Filings, invoices and their audit-chain entries: kept as accounting records (6 years, as HMRC requires of us). Letter opt-outs: kept forever — that is the point of them.
Your rights
Access, correction, deletion, objection, portability — write to [email protected] and we act on it. Deleting your account removes your personal data; statutory accounting records (invoices) are retained as the law requires. If we disappoint you, you can complain to the ICO at ico.org.uk.
What we never do
No selling of data, no advertising trackers, no marketing to your customers, no use of your data to train anything. The full security architecture — including the public audit chain you can verify without trusting us — is on the security page.