Privacy Policy#
This policy is a good-faith draft intended to be accurate and fair. It is not a substitute for legal advice tailored to your situation. If you have specific concerns about how your data is handled or your rights under this policy, please contact us at hello@actionready.co.uk.
Who we are#
ActionReady is a free web-based tool for aspiring UK property investors.
For this policy, "ActionReady", "we", "us" and "our" mean the person or business operating the ActionReady service.
Contact: hello@actionready.co.uk
ActionReady is the controller of the personal data collected through the service.
What we collect#
We only collect data that is needed to run the product, send your action, improve reliability, and respond to you.
Account and sign-in data#
We collect your email address so you can sign in and receive service emails.
If you sign in with Google, we may also receive your name and profile picture, depending on what your Google account shares with us.
If you sign in with Apple, we receive your email address (which may be Apple's private-relay forwarding address ending in privaterelay.appleid.com, if you chose that option) and, on your first sign-in only, your name. Apple does not share a profile picture. The relay address is a real, working email — Apple forwards messages from us to your real inbox. We treat it as your account email.
We use this data to:
- create and manage your account
- authenticate you
- send verification codes
- send your assigned action and follow-up check-ins
- help you access your saved action history
Questionnaire data#
When you use ActionReady, we collect the answers you give in the questionnaire. This may include:
- your chosen strategy: buy-to-let, rent-to-rent, serviced accommodation, or deal sourcing
- your target location
- your available cash band
- your confidence level
- your main blocker
- strategy-specific answers, such as whether you have spoken to brokers, letting agents, landlords, or other relevant people
We use this data to suggest one practical action that fits your current situation.
Action and progress data#
We store the action assigned to you and whether you mark it as done, blocked, or left.
We use this to show your progress, support follow-up emails, and understand whether the product is useful.
Contact form data#
If you contact us through the contact form, we collect the information you submit, such as your name, email address, and message.
We also process a hashed version of your IP address for abuse prevention. We do not store your raw IP address in contact form submissions.
We use contact form data to respond to your message and protect the service from spam or abuse.
Email data#
We send transactional emails, including verification codes, assigned action notifications, and 7-day follow-up check-ins.
Email delivery data may be processed by Resend, our email provider. Resend keeps email logs according to its own retention settings and legal terms. You can read Resend's current information here:
Technical and security data#
Our hosting, security, authentication, and email providers may process basic technical data needed to deliver the service, protect it, and keep it reliable.
This may include request metadata, device or browser information, and security signals used to detect bots or abuse.
Analytics and session replay data#
We use PostHog for privacy-conscious product analytics so we can understand how people move through ActionReady and where they get stuck.
Basic analytics run by default unless you opt out. This may include page views, route changes, referrer category, device and browser information, approximate technical metadata, performance information, strategy selection, questionnaire progress, action status events, and contact form submission status.
If you explicitly allow replay, we may also use masked session replay and richer click analytics to diagnose product friction.
We configure analytics to mask form inputs and elements that may contain personal details. We do not intentionally send email addresses, names, messages, verification codes, unsubscribe tokens, or questionnaire free-text answers as analytics event properties.
If you opt out, PostHog is not used for future events on that browser unless you clear or change your preference.
What we do not collect#
We do not intentionally collect special category data, such as health information, political opinions, religion, biometric data, or information about your sex life or sexual orientation.
Please do not include sensitive personal information in your target location field, questionnaire answers, or contact form message.
How we use your data#
We use your data to:
- provide the ActionReady service
- authenticate your account
- assign one practical action based on your answers
- send service emails
- let you track whether an action was done, blocked, or left
- respond to contact form messages
- prevent spam, abuse, and automated misuse
- maintain and improve the service
- understand product usage and improve user journeys, unless you opt out of analytics
- comply with legal obligations
We do not sell your personal data.
We do not use advertising cookies.
We do not use affiliate tracking.
Legal basis for processing#
We process personal data under the UK GDPR and Data Protection Act 2018, as amended. Where EU data protection law applies, we aim to handle data in a consistent way.
Our main legal bases are:
| Purpose | Legal basis |
|---|---|
| Creating and managing your account | Contract |
| Sending verification codes | Contract |
| Collecting questionnaire answers and assigning an action | Contract |
| Sending assigned action emails and 7-day check-ins | Contract and legitimate interests |
| Storing action status and progress | Contract |
| Responding to contact form messages | Legitimate interests |
| Preventing spam, bots, abuse, and security issues | Legitimate interests |
| Basic statistical analytics to improve the product | Legitimate interests and the statistical purposes exception under PECR, where applicable |
| Enhanced analytics and masked session replay | Consent |
| Handling deletion, access, or rights requests | Legal obligation and legitimate interests |
| Optional Google sign-in | Contract, with your choice to use Google as the sign-in method |
| Optional Apple sign-in | Contract, with your choice to use Apple as the sign-in method |
"Legitimate interests" means we have a practical reason to use the data in a way that is expected, limited, and not overridden by your rights.
Automated recommendations#
ActionReady uses your questionnaire answers to suggest one action.
This is an automated content recommendation. It does not make legal, financial, mortgage, tax, or similarly significant decisions about you.
You are responsible for deciding whether to take the suggested action.
Who we share data with#
We share data only with service providers needed to run ActionReady.
| Provider | Purpose |
|---|---|
| Vercel | Website hosting and deployment |
| Neon | Postgres database hosting in the London region |
| Resend | Transactional email sending and delivery logs |
| ImprovMX | Email forwarding for ActionReady email addresses |
| Google OAuth sign-in, if you choose to use it | |
| Apple | Sign in with Apple, if you choose to use it (including the optional Apple private-relay forwarding service) |
| Cloudflare Turnstile | Bot protection on the contact page and contact form |
| PostHog | Product analytics by default unless you opt out; masked session replay only if you allow replay |
These providers process data so the service can work. They are not allowed to use ActionReady user data for their own unrelated purposes.
International transfers#
Some of our providers are based outside the UK or EU, or may process data outside the UK or EU.
Vercel is US-based and may process data in the United States, while also using European edge regions. Other providers, including Resend, Google, Apple, Cloudflare, ImprovMX, and PostHog, may also process data internationally. We configure PostHog to use its EU ingestion host where available.
Where personal data is transferred outside the UK or EU, we rely on appropriate safeguards where required. These may include adequacy regulations, the UK Extension to the EU-US Data Privacy Framework, standard contractual clauses, the UK international data transfer addendum, or equivalent protections used by our providers.
How long we keep data#
We keep data only for as long as needed for the purposes described in this policy.
| Data type | Retention |
|---|---|
| Account data | Kept while your account is active. Deleted on request, unless we need to keep limited records for legal or security reasons. |
| Questionnaire answers | Kept while your account is active. Deleted on request. |
| Assigned actions and progress status | Kept while your account is active. Deleted on request. |
| Contact form submissions | Kept for 90 days. |
| Hashed IP address linked to contact form submissions | Kept for 90 days. |
| Email delivery logs | Kept according to Resend's retention settings and legal terms. |
| Authentication session cookies | Kept only for as long as needed to manage your logged-in session. |
| Analytics preference | Kept in your browser until you clear it. |
| Product analytics and optional session replay data | Kept according to PostHog project retention settings. |
If you ask us to delete your account, we will delete your account data, questionnaire answers, assigned actions, and progress data unless we are required to keep limited information for legal, security, or abuse-prevention reasons.
Emails and unsubscribe choices#
We send service emails needed to operate ActionReady, including verification codes and assigned action emails.
You can unsubscribe from non-essential follow-up emails or ask us to stop sending them by contacting hello@actionready.co.uk.
Verification code emails are necessary if you choose to sign in by email.
Cookies#
ActionReady uses cookies and browser storage for authentication session management and to remember your analytics preference.
These cookies help keep you signed in and keep your account secure.
PostHog may use cookies or browser storage to measure product usage. You can opt out using the analytics notice. Masked session replay is only enabled if you explicitly allow replay.
We do not use advertising cookies, affiliate cookies, or ad tracking.
Children#
ActionReady is for adults only.
You must be at least 18 years old to use the service. We do not knowingly collect personal data from minors.
If you believe a minor has provided personal data to ActionReady, contact hello@actionready.co.uk and we will take appropriate steps to delete it.
Your rights#
Depending on where you live and the basis on which we process your data, you may have the right to:
- be informed about how your data is used
- access the personal data we hold about you
- correct inaccurate or incomplete data
- ask us to delete your data
- restrict how we process your data
- object to certain processing
- receive a portable copy of data you provided to us
- withdraw consent where processing is based on consent
- complain to the UK Information Commissioner's Office
These rights are not always absolute, but we will respond fairly and in line with applicable law.
How to exercise your rights#
Email hello@actionready.co.uk.
Please tell us what you are asking for and include enough information for us to identify your account.
We may need to verify your identity before acting on a request.
Security#
We use reasonable technical and organisational measures to protect personal data.
No online service can be completely secure. You are responsible for keeping access to your email account secure, because your email may be used to sign in to ActionReady.
Changes to this policy#
We may update this policy when the product, providers, or legal requirements change.
If we make a significant change, we will take reasonable steps to make it clear, such as updating the policy page or emailing users where appropriate.
Contact#
For privacy questions, data requests, or deletion requests, contact: