Controller and contact
PAGEROOK LTD, company number 17415761 is the controller for the personal information described here. Registered office: 66 Paul Street, London, England, EC2A 4NA. Contact hello@pagerook.com for privacy requests, support, security, or abuse matters.
Information processed
- Account email, authentication, invitation, policy-acceptance, tier, and account-security records.
- Billing customer and checkout identifiers, subscription and invoice identifiers, trial and renewal dates, cancellation and payment status, base GBP price, provider-confirmed presentment amount and currency, customer country, billing address or tax ID where collected, and policy/offer consent evidence.
- Stripe or Link handles card, bank, Apple Pay, Google Pay, and other payment credentials. PageRook does not receive or store full card numbers, wallet credentials, or card security codes.
- Sites, files, deployments, brand assets, domain configuration, settings, and related metadata.
- MCP/OAuth client and authorisation records, token hashes, scopes, expiry/revocation state, and security audit events. Raw issued secrets and tokens are not stored in recoverable form.
- Hosted traffic totals, request paths and statuses, IP-derived security/rate-limit data, errors, and operational logs.
- Support, abuse, appeal, and security reports, including reporter contact, submitted evidence, affected owners/sites, decisions, notification history, and evidence hashes.
Purposes and lawful bases
- Contract: create and secure your account; store, preview, publish, serve, and delete content; provide connectors; enforce tier limits; create and administer subscriptions; reconcile payments, cancellations, and access; and communicate about requested service actions.
- Legitimate interests: operate and improve the service, diagnose faults, prevent fraud and abuse, protect customers and visitors, keep proportionate audit records, and establish or defend claims. PageRook balances these interests against affected people's rights.
- Legal obligation: retain or disclose information where applicable law validly requires it.
- Consent: where PageRook specifically asks for consent for an optional processing activity; consent can be withdrawn without affecting earlier lawful processing.
Claude and other MCP clients
An authorised client receives the tool results requested through it, such as selected site metadata or files. Each authorisation is tied to the PageRook account that completed consent; a shared directory credential is not treated as customer identity. The client provider handles information under its own terms. Disconnect there and revoke PageRook access in MCP settings to invalidate access and refresh tokens.
Read the Claude connector guideSharing and international transfers
PageRook may use hosting, database, email, monitoring, analytics, security, and support providers acting under appropriate instructions, and shares requested results with connectors you authorise. Information may be disclosed to advisers, authorities, or other parties where required by law, needed to protect rights and safety, or involved in a properly safeguarded business transaction. PageRook does not sell personal information.
Some providers may process information outside the United Kingdom. Where transfer rules apply, PageRook will use a recognised adequacy decision or appropriate contractual and supplementary safeguards. Contact PageRook for information about safeguards relevant to your data.
Stripe processes payment, billing-address, tax, fraud-prevention, invoice, refund, dispute, and customer-support information as described in its own privacy materials. Stripe Managed Payments, through Onelink, acts as merchant of record for covered transactions and provides Link customer management. PageRook exchanges only the identifiers and status needed to create Checkout, reconcile billing, support the account, and meet legal obligations.
Retention and deletion
- Deployment history is count-based by tier: Starter 3, Launch 10, Growth 20, Agency 30, and Dedicated 30 or a custom limit.
- Routine request/operational logs are targeted for 14 days unless an incident or legal need requires preservation.
- Abuse reports are targeted for 365 days and moderation evidence for 365 days after the latest final closure of the complete report-and-appeal family; an open or reopened case pauses that clock, and an active legal/evidence hold overrides routine deletion.
- Routine audit history is targeted for 730 days. Policy acceptance and material enforcement records may remain for the account lifetime plus 2190 days.
- Minimal webhook recovery payloads and routine billing logs follow the service-log target after replay and dispute usefulness has ended. Stripe event IDs, subscription history, invoices, consent evidence, refunds, disputes, tax evidence, and accounting records may be retained for the period required by applicable financial, tax, consumer, fraud, and legal obligations.
- Account deletion immediately cancels any active subscription before deletion proceeds, detaches retained billing records from the account where possible, minimises recoverable provider payloads, and removes payment-independent customer content under the normal purge workflow. Stripe or Link records may remain where Stripe or law requires them; PageRook will use the applicable provider deletion/support process for eligible data.
- Minimal PageRook/custom-hostname reservation ledgers may be retained indefinitely to prevent unsafe address reassignment.
PageRook does not currently operate production backups. Site deletion removes public roots and retires the address; eligible hard deletion removes the site's private storage root and database rows while approved ledgers, audit, billing evidence, and released evidence snapshots may remain. Oban job arguments, logs, and any future backups must follow the same minimisation and retention controls. Retention may be extended where required to investigate an incident, resolve a dispute, or comply with law.
Your rights and complaints
Depending on applicable law, you may ask for access, correction, deletion, restriction, portability, or an objection to processing, and may withdraw consent. PageRook may need to verify identity and can retain information where a legal exception applies. Contact hello@pagerook.com.
You may complain to the UK Information Commissioner's Office through ico.org.uk/make-a-complaint, or to another competent supervisory authority where applicable. PageRook would welcome the chance to address the concern first.
Security and updates
PageRook uses scoped access, hashed credentials, short-lived access tokens, rotating refresh tokens, validation, quotas, evidence holds, and audit records. No service can guarantee absolute security. See the Security policy for reporting instructions. Material notice changes will be posted here with a revised version and effective date.