Privacy Policy
Plain English explanation of data collection on Scrimpr, usage, and your rights under GDPR.
Last updated: 6 April 2026
About This Policy
This privacy policy explains what data Scrimpr collects, how it’s used, and your rights regarding your personal information. I’ve written this in plain English to make it actually readable.
Scrimpr collects some data – through its own analytics system and Google Analytics for website improvement, payment processing for services, and basic account information if you choose to sign up. Everything is explained below.
What Data I Collect
Scrimpr’s Own Analytics
Scrimpr runs its own privacy-focused analytics system on its own servers. This collects:
- Pages you visit and in what order
- Anonymous visitor ID – a random UUID stored in a cookie, with no connection to your identity
- Approximate country – detected from your IP address using a local database (your IP address is never stored)
- Device and browser type – e.g. mobile/desktop, Chrome/Safari
- Referrer – how you found the site (Google search, direct visit, etc.)
- Outbound link clicks – which affiliate and external links you click, to understand which tools are most useful
Google Analytics
I also use Google Analytics as a secondary analytics tool. This uses cookies to automatically collect:
- Your IP address (automatically anonymized by Google)
- Browser and device information
- Pages you visit and how long you spend on them
- Approximate location (usually just country/city)
- How you found the site
For full details about all cookies used on this site, see the Cookie Policy.
User Accounts
If you create an account on Scrimpr (via Google or Facebook login), I collect:
- Your name – as provided by your social login provider
- Email address – for account identification and communication
- Profile picture – if provided by your social login provider
Account creation is optional. All comparison tools and guides are available without an account.
Payment Data (Stripe)
If you use my direct debit service, I collect:
- Your name (required for direct debit mandates)
- Email address (for payment confirmations and communication)
- Bank account details (processed securely by Stripe)
- Payment history (for record-keeping and customer service)
What I DON’T Collect
- Your IP address – used momentarily for country detection, then discarded. Never stored.
- Email newsletters – I don’t have a mailing list
- Comments or personal content – No comment system
- Social media tracking – No Facebook pixels or similar
- Advertising data – No tracking for ad targeting purposes
How I Use Your Data & Who I Share It With
Scrimpr’s Own Analytics
All data from Scrimpr’s analytics system stays on Scrimpr’s own servers. It is not shared with any third party. It’s used solely to understand which tools and content are most useful so I can improve the site.
Google Analytics
Google receives anonymized data about your website usage. They use this for their own analytics purposes. You can opt out using Google’s opt-out tool.
Stripe (Payment Processor)
Stripe processes all payments and handles your bank details securely. They’re a regulated payment processor used by millions of businesses. See Stripe’s privacy policy.
Social Login Providers
If you sign in with Google or Facebook, they receive confirmation that you logged in to Scrimpr. See their respective privacy policies for details.
Affiliate Partners
When you click affiliate links, the destination website may receive information about your visit (like that you came from Scrimpr). Each partner has their own privacy policy.
What Doesn’t Happen With Your Data
- No data sales – Never, to anyone
- No sharing of personal information – Only with service providers mentioned above
- No marketing emails – No email address collection unless you create an account or pay for services
- No advertising tracking – No tracking for ad targeting purposes
Your Rights & Data Retention
Your Rights (GDPR)
You have the right to:
- Access your data – Ask what information I have about you
- Correct your data – Fix any incorrect information
- Delete your data – Ask me to remove your information
- Delete your account – Request full account deletion
- Port your data – Get a copy of your data in a readable format
- Object to processing – Ask me to stop using your data for specific purposes
- Withdraw consent – Stop me using data you previously agreed to
How Long I Keep Your Data
- Scrimpr Analytics: Raw visitor data (pageviews, clicks) is automatically deleted after 90 days. Aggregated daily statistics (no personal data) are kept indefinitely.
- Google Analytics: Data is kept for 26 months, set to automatically delete.
- Account Data: Kept until you request deletion or delete your account.
- Payment Data: Kept for 7 years as required by UK tax law, then automatically deleted.
- Cookie Data: Most cookies expire automatically. See the Cookie Policy for specific durations.
Data Security
I take reasonable steps to protect your data:
- HTTPS everywhere – All connections to Scrimpr are encrypted
- Secure payments – Bank details handled by Stripe’s PCI-compliant system
- IP addresses not stored – Used momentarily for country detection, then discarded
- Password-free login – Social login means no passwords stored on Scrimpr
- Hashed identifiers – Where click tracking uses IP addresses, they’re immediately hashed (one-way encrypted) so the original IP cannot be recovered
- Automatic data deletion – Raw analytics data purged after 90 days
Contact Me & Legal Information
Contact Me
Questions about privacy, want to exercise your rights, or just want to chat about data protection?
Email: hello@scrimpr.co.uk
Subject line: Use “Privacy Request” so I don’t miss it
Response time: Within 7 days for privacy requests, usually much faster
What to include:
- What you want (access data, delete data, delete account, etc.)
- Any relevant dates or services you’ve used
- Proof of identity if requesting sensitive information
Right to complain: If you’re not satisfied with how I handle your privacy request, you can complain to the Information Commissioner’s Office (ICO) at ico.org.uk.
Legal Basis for Data Processing
For the legally-minded, here’s why I process your data under GDPR:
- Scrimpr analytics: Legitimate interests (improving the website)
- Google Analytics: Legitimate interests (understanding traffic patterns)
- User accounts: Consent (you choose to sign up)
- Payments: Contract performance and legal obligations
- Affiliate tracking: Legitimate interests (funding the website)
- Essential cookies: Necessary for website functionality
Third-Party Websites & Policy Changes
Scrimpr contains links to other websites (banks, investment platforms, comparison sites). Each has their own privacy policy, and I’m not responsible for their data practices.
I’ll update this privacy policy when needed (new tools, different data collection, legal changes). Major changes will be noted at the top of this page with the date.
This privacy policy is written in plain English because legal jargon helps nobody. If you spot anything unclear or have suggestions, let me know at hello@scrimpr.co.uk