Last updated 14 June 2026. Draft for review by counsel before launch.
1. Controller
The data controller is Videos on Tap Ltd ([Company No. — to be confirmed]), registered in England & Wales, registered office [Registered office, England — to be confirmed]. For privacy matters contact privacy@videosontap.com. We are registered with the UK Information Commissioner's Office (ICO), [ICO registration ref — to be confirmed].
2. What we collect
Account & contact: name, email, login metadata. Order & brief: your niche, brand details, requests. Billing: handled by Stripe — we store order records and a Stripe customer reference, never full card numbers. Support: messages you send us. Tools: the inputs you submit to a free tool. Voice clone (optional): the audio samples you choose to upload. Technical: IP address, device/browser data, and cookie/analytics data (see §6).
3. How we use it & legal bases
To perform our contract (produce & deliver your videos, run your account & billing, support you); for our legitimate interests (improving the service, security, fraud/abuse prevention, aggregate analytics); with your consent (marketing email, non-essential cookies/ad pixels, voice cloning); and to meet legal obligations (tax, accounting, responding to lawful requests).
4. Who we share it with (processors & sub-processors)
We don't sell your personal data. We share it only with vetted providers that run the service, each under a data-processing agreement and, for transfers outside the UK/EEA, appropriate safeguards (UK IDTA / EU Standard Contractual Clauses). The current list:
| Provider | Purpose | Data shared | Region | Privacy |
|---|---|---|---|---|
| Stripe | Payments & billing | Name, email, billing address, card details (tokenised — we never store card numbers), transaction history | EU/US (SCCs) | policy |
| Clerk | Authentication & accounts | Email, name, login metadata, session tokens | US (SCCs) | policy |
| Neon | Application database (hosted Postgres) | Account, order, brief, support and billing records | EU/US | policy |
| Vercel | Hosting & edge delivery | IP address, request logs, basic device data | Global edge | policy |
| Cloudflare | CDN, WAF, Turnstile bot-protection, R2 storage & Stream video | IP address, request metadata, challenge tokens, delivered files | Global | policy |
| Microsoft Azure (Communication Services) | Transactional & marketing email | Email address, message content, delivery/engagement events | EU/US | policy |
| Google Analytics 4 | Web & conversion analytics (consent-gated) | Cookie IDs, IP (anonymised), page/event data | US (SCCs) | policy |
| PostHog | Product analytics, funnels, A/B flags (consent-gated) | Pseudonymous IDs, event & session data | EU/US | policy |
| Snap / TikTok / Meta (Conversions APIs) | Ad attribution (consent-gated, server-side) | Hashed email, event & conversion data | US (SCCs) | policy |
| OpenRouter & Z.ai | AI generation for the free tools & video production | The prompt/inputs you submit to a tool (not your account data) | US/Global | policy |
| ElevenLabs | AI voice & optional voice clone | Script text; for clones, the voice samples you upload with consent | US (SCCs) | policy |
5. International transfers
Some providers above process data outside the UK/EEA (notably the US). Where they do, we rely on the UK International Data Transfer Agreement / Addendum or EU Standard Contractual Clauses, plus the providers' own certifications, to keep your data protected to UK/EU standards.
6. Cookies & tracking
Essential cookies always run. Analytics and advertising trackers (Google Analytics, PostHog, and Snap/TikTok/Meta pixels) only load after you accept them — we use Google Consent Mode v2, so tags stay denied by default until you opt in. Manage your choice anytime via the cookie banner. Full detail in our Cookie Policy.
| Cookie(s) | Category | Purpose | Expiry |
|---|---|---|---|
| vot-skin, vot-theme, vot-consent, vot-dash-collapsed | Essential / preferences | Remember your chosen site mode, light/dark theme, cookie choice and dashboard layout. No tracking. | Up to 180 days |
| __clerk / __session | Essential | Keep you securely signed in (Clerk). | Session / short-lived |
| vot-ref | Functional | Attribute a referral so your friend gets credit. | 90 days |
| _ga, _ga_* | Analytics (consent) | Google Analytics — aggregate traffic & conversions. | Up to 24 months |
| ph_* | Analytics (consent) | PostHog — product analytics & experiments. | Up to 12 months |
| Ad pixels (Snap/TikTok/Meta) | Marketing (consent) | Measure ad performance; only set if you accept marketing cookies. | Varies by provider |
7. Your voice data
Voice samples are used solely to build your voice model for your videos. They're never shared, never used for other customers, and are deleted on request or when you close your account.
8. Retention
We keep account and order records for as long as needed to provide the service and meet legal obligations (e.g. tax records for the statutory period). Delivered files are retained for 90 days (about 3 months) then deleted. Marketing data is kept until you unsubscribe.
9. Your rights (UK/EU GDPR)
You can access, correct, erase, port or restrict your data, object to processing based on legitimate interests, and withdraw consent at any time. Use the data-export/deletion tools in your dashboard, the email preference centre, or email us. You can complain to the ICO (ico.org.uk), though we'd like the chance to help first.
10. California & other US residents
If you're in California or another US state with privacy rights, see our California & US State Privacy Notice for your CCPA/CPRA rights, including the right to know, delete, correct, and opt out of "sharing" for cross-context advertising.
11. Security & children
We use industry-standard safeguards (encryption in transit, access controls, a WAF), though no system is perfectly secure. The service isn't for under-18s and we don't knowingly collect their data.
12. Contact
Privacy questions or requests: privacy@videosontap.com, or write to us at [Registered office, England — to be confirmed].