Recado

Privacy

What we do with personal information, said plainly. If anything here is unclear, ask us — an explanation nobody understands is not a disclosure.

Who is responsible

The trading entity is Recado — Tiago d'Aubigné, a sole trader in the United Kingdom rather than a company, so there is no company number. We are registered with the Information Commissioner’s Office under registration ZC211059. Write to hello@recado.co.uk about anything in this policy — including asking for your data, or asking us to delete it — and a person reads it. The postal address is Flat 111 Hersham Road, KT12 1RN, United Kingdom.

Recado and the business are jointly responsible for your testimonial. Not one or the other. The business asked you, chose the question and decides whether your words are published. We decide what is collected, what you are told, what you are asked to agree to, how long it is kept, and what happens when you ask us to remove it. Both of those are decisions about your data, so under UK data protection law we are what it calls joint controllers.

What that means for you in practice. You can go to either of us and you do not have to work out which. Write to hello@recado.co.uk and we will deal with it — including passing it on to the business where that is what needs to happen. You can also go straight to the business, and your rights are exactly the same either way. Neither of us may send you to the other and leave it there.

Who does what, in short. The business chooses who is invited, writes the prompt, and approves or rejects what comes in. Recado holds the data, decides what is asked for and what you are told, keeps your original words unchanged, holds the record of what you agreed to, answers requests about your rights, and decides how long things are kept. If either of us gets it wrong, you are not required to establish which of us it was.

This is our own reading of the Information Commissioner’s test for who is responsible for what, and we have asked the ICO to confirm it in writing. We have written out our reasoning rather than just the conclusion, so that it can be checked. If they tell us we have it wrong, this section changes and we will say so here.

If you left a testimonial

We hold what you typed — your words, your name, and your job title or company if you gave one — along with a record of the exact wording you agreed to, which version of that wording it was, and when you agreed. Not a tick box saying yes: the sentences you actually saw.

Your original words are kept unchanged, permanently. A business can correct a typo, and the limit is deliberately tight — no more than a tenth of the characters or twenty characters, whichever is smaller, always measured against what you originally wrote rather than against the last version. Every change is recorded with what it was before, what it became, who made it and when. You can ask us for that record at any time and we will show it to you.

Your words are not used to train anything. Recado does not generate, rewrite, improve, shorten or summarise a testimonial, and never will — the moment we did, the verified badge would be worthless.

While you are writing, a copy of your words and name is kept on your own device so a phone call does not cost you a paragraph. It never reaches us, it is scoped to that one business’s page, it clears when you send, and it disappears after a day. Your consent tick is never saved that way — a tick nobody made is not consent.

If you verified that you were a real customer

Verification is optional and always was. There are three ways to do it.

An order or invoice number. We never store the number itself, only a scrambled fingerprint of it that cannot be turned back into the original.

A link sent to your email address. We check the address against the ones the business already holds, then send you a link. Your address is handled by Resend, who send from Ireland but keep their account records and delivery logs in the United States. So your address leaves the EU, and there is no honest way to describe that as anything else. We send them nothing beyond the address and the link — not your testimonial, not what you wrote. What we do keep is the domain part of the address, never the address itself.

Matching a payment. The business imports, from Stripe, a list of which addresses paid them and when. We hold a scrambled fingerprint of each address and the date — never the amount, never card details, never a name. When you type the address you paid with, we scramble it the same way and look for a match. Stripe is a United States company and the business’s payment records are held there.

Sending us the £9 gift. Recado charges for nothing; the one thing that can be paid is a gift towards running costs. Onelink takes it as merchant of record and Stripe processes it, so your name, your email address and your payment details are held by them under their own terms. The payment is made to an account called shippedin12months — the umbrella these apps are built under, of which Recado is one — so that is the name on the record of it, and the name you are likely to see. We never see a card number, and we hold no key that could read your billing details back. Stripe sends us a message saying a payment arrived; that message carries the address used at checkout, and what we write down from it is that a gift arrived and when — no name, no address, and nothing tying it to an account, because a gift is not attached to one.

Some of those messages are about something other than Recado. The same Stripe account is used for more than one thing, so this site is told about payments that have nothing to do with it. Each one carries a label saying which product it was for. Where that is not Recado, nothing at all is taken from the message: we record that a payment for something else happened, and no name, address or amount from it is kept.

Both Resend and Stripe move information to the United States. Both rely on the standard legal safeguards for doing so — the UK International Data Transfer Addendum and the EU Standard Contractual Clauses, and both participate in the UK extension to the EU–US Data Privacy Framework.

Our own paperwork for these transfers is not yet complete. It is being done, and this paragraph comes out when it is.

The record that you were verified is kept for good

When a verification happens — or fails — we write down that it happened, which method was used, and the result. Those records are never edited and never deleted, including by us. That is the point of them: a badge saying somebody was a real customer is only worth anything if the business cannot quietly remove the attempts that did not go their way.

Those records contain nothing about you. Not your address, not your invoice number, not what you typed, and not a trace of anything you guessed wrong. A fingerprint of a successful match, the method, the result, the time. That is the whole of it, and it is why we are comfortable saying out loud that we keep them indefinitely.

The readable proof line under a badge — something like Verified · Payment · 9 Mar 2026 — goes when the testimonial goes.

If you joined the waitlist

This one is a mailing list, and we are going to call it that. Every other address in Recado is stored as a scrambled fingerprint that cannot be read back. This one is not: your address is held in a form we can actually write to, because the entire point of a waitlist is having somebody to tell when the thing opens. A list we could count but not contact would be a number, not a waitlist.

What we hold is your address, the date you asked, and the exact sentence you agreed to when you asked — the words themselves, not a tick. No name, no company, nothing about where you came from, and nothing that follows you anywhere.

You will get one email. It arrives when you join, to confirm you are on the list, and one more when Recado opens. No newsletter, nothing in between, and nothing passed to anybody else — not sold, not rented, not shared.

Every one of those emails carries a link that takes you off the list, and that link worked before the first one was ever sent. Leaving is final: nobody can put you back on, including us, and typing your address into the form again will not do it. If you want to rejoin after leaving, you have to ask us.

The address passes through Resend to reach you, so the same thing is true of it as of a verification email: it is handled by a company that keeps its records in the United States.

What allows us to hold any of this

The law does not let anybody hold information about you simply because it is useful to them. There has to be a reason of a particular kind, it has to be chosen before the information is collected, and it has to be told to you rather than produced later if anybody asks. Here are ours, and which part of Recado each one covers:

  • Your testimonial — because you agreed to it. You were shown the exact wording, you ticked the box, and the wording you saw is stored with what you wrote. You can withdraw that agreement and the testimonial comes down, and you can set a date after which it comes down on its own. Both are yours to do, from the link you were given when you wrote it — the business cannot set an end date on your agreement, because that would be them deciding how long you agreed for.
  • When something comes down, and what that means. Withdrawing removes it straight away. An end date you set removes it when next shown rather than at midnight on the day — a testimonial wall is built at the moment somebody looks at it, so yours stops being shown the next time anybody loads the page. In practice nobody reads it after the date you chose. We would rather say that than claim a precision we do not have.
  • If you ask us to email you that link. The link is written out on the screen after you send your testimonial, and we offer to email it to you as well, because a link on a screen is gone once the tab is closed. If you take that offer, your address passes through Resend, whose delivery logs are in the United States, exactly as it would for verification. The difference is what happens afterwards: we do not keep it. It is used for that one email and never written down, so there is no column anywhere holding it and nothing for you to ask us to delete. We send once and never again — not a newsletter, not a reminder, nothing. The email itself carries the link and the business’s name, and nothing you wrote.
  • Why consent and not something easier. Publishing somebody’s words because it suited us commercially is the thing consent exists to prevent.
  • Verifying you — because you chose to. Every route is optional and offered after you have already written your testimonial, never as a condition of leaving one. Not verifying costs you nothing.
  • The record that a check happened — because the badge is worthless without it. This one is not consent, and we would rather say so than blur it. A verification record that could be withdrawn would let somebody prove they were a real customer and then remove the proof, which is the same as there being no proof. So it is kept on the basis that it is a legitimate interest of ours and of anybody reading the wall. It holds nothing personal — no address, no name, no order number, only that a check of a stated kind succeeded and when. You can still object to it, and we will look at your particular circumstances rather than send you this paragraph again.
  • The waitlist — because you asked to be told. Consent, and the sentence you agreed to is stored with your address. The link that takes you off the list is in every email and worked before the first one was sent.
  • Counting submissions to stop a flood — a legitimate interest. A business whose form can be flooded has no usable form. What is stored is a scrambled fingerprint of a network address, never linked to a testimonial, deleted after an hour.
  • Running a business account — because there is a contract. We cannot provide something somebody has signed up for without holding their sign-in and the settings their account runs on.

Where we have said “a legitimate interest”, that is a judgement that our reason outweighs the intrusion, and it is one you are entitled to challenge. Like the split described in “Who is responsible”, these are our own reading and a solicitor has not yet confirmed them.

How long we keep things

  • Testimonials — until the business deletes them or closes their account. Then erased.
  • Verification records — indefinitely, for the reason above. They hold nothing personal.
  • Verification links — 24 hours, then dead. Single use.
  • A draft on your device — 24 hours, or until you send. It never reaches us.
  • Anti-spam counts — one hour. We count how many times one internet connection has submitted, so nobody can flood a business’s form. What is stored is a scrambled fingerprint mixed with a secret the database never sees, it is never linked to a testimonial, and it is deleted as soon as it stops counting.
  • Your business account — while it is open, and for a short period after you close it.
  • A waitlist address — until Recado opens and the one email telling you so has been sent. Then the list has done its job and is deleted. If you leave the list, your address is not deleted with it. It is kept, marked as having left, and that is deliberate: it is the only way to make sure nobody — including us — can put you back on by typing it in again. If you would rather it were gone entirely, ask us and we will erase it, and then only the form itself stands between you and being re-added by somebody else.

Where it lives

Testimonials, names, consent records and verification records are stored in the European Union, on Cloudflare’s infrastructure, in a database created under EU jurisdiction — a setting that can only be chosen when the database is made and can never be added afterwards.

That claim is about the testimonial, and we will not let it stretch. An email address used for verification passes through a company that keeps its logs in the United States, and payment records are held by Stripe. Both are true at the same time as the first sentence, and saying only the first would be a half-truth we would not accept from a competitor.

A waitlist address is the one exception to how addresses are stored here. It sits in the same EU database as everything else, but in a form we can read and write to rather than as a scrambled fingerprint, because a list nobody can email is not a waitlist. It leaves the EU for the same reason any of our email does — it passes through Resend to reach you.

Counting visits to this website

We use Sereno to count visits to Recado’s own pages, so we know which ones people read and whether anything we write reaches anybody. It runs on our pages only — the landing page, this one, the terms, signing in, signing up, the dashboard, and the page where you write a testimonial.

It sets no cookie and stores nothing on your device — nothing at all, not an identifier, not a visit count, not a preference. That is why there is no banner asking you about it: there is nothing on your device to ask about.

Sereno is ours too. It is a separate product with its own name and its own website, and the same person builds both. You should not have to work that out, so it is said here rather than left to look like an outside supplier we chose.

The page itself sends five things:

  • The path of the page you are on — /privacy, never the part of the address after a question mark.
  • The website that sent you here, as a domain name only, and nothing at all if you came from another Recado page.
  • Campaign labels, if the link you followed carried any — the utm_ parameters some links have.
  • How wide your browser window is, flattened to one of four words: small, medium, large or extra large.
  • That the site was Recado.

Four more are worked out from the request itself, the way any web server can, and are recorded alongside those:

  • Your country, and the region within it — England, Bavaria, Texas. Never the city.
  • Your browser and operating system, kept deliberately blunt: Chrome 131 and macOS, never the exact version string your browser actually sends. The precise one identifies a device; the rounded one describes a population.
  • Whether you are on a phone, a tablet or a computer.
  • A daily visitor code, described in full below, because it is the part of this that deserves more than a line.

The daily visitor code, said plainly. To tell one person reading four pages from four people reading one page each, there has to be something that is the same across those four requests. So a code is worked out by scrambling your network address and browser description together with a secret and today’s date. Your address and your browser description are used to make it and are then thrown away — neither is ever written down.

What that code can and cannot do, both. Within one day, on this site, it does join your page views together — that is the entire reason it exists, and we will not describe it as anything softer. What it cannot do is carry into tomorrow: the secret changes every night, so the same person on the same device gets a completely different code, and yesterday’s cannot be matched to today’s. It is different again on any other site that uses Sereno, so it cannot follow you between them. And it is not reversible — it cannot be turned back into your address, and it names nobody.

Your network address is never stored. Neither is the full description your browser sends. Both arrive with the request, as they do at every website you have ever visited, and both are used and discarded rather than kept. Nothing here sets a cookie or stores anything on your device.

Nothing counts visits to a business’s own website. The walls we host for businesses and the widget they put on their own pages carry no analytics whatsoever — no script, no counting, nothing. If you are reading testimonials on a company’s site, or on a wall we host for them, we do not know you were there. The only way you reach anything counted here is by choosing to come to Recado yourself.

The quiet “Collected with Recado” line at the foot of those pages is a link, and if you follow it you arrive here carrying a label saying it was a badge click, which is then counted exactly like any other visit to this site — the same five things, the same daily code, nothing extra. The label says a badge was clicked and which kind of page it was on; it does not say which business.

It does not run at all if your browser sends a Do Not Track signal.

Where this is held, stated as precisely as we can. Sereno runs on Cloudflare, like Recado. But the claim made above about testimonials — that they are in a database created under EU jurisdiction — cannot be made about the visit counts. They are written to Cloudflare’s Analytics Engine, which offers no equivalent setting, so they are held across Cloudflare’s network rather than pinned to the EU. Saying “our data is in the EU” and quietly meaning only the testimonials is exactly the half-truth this policy refuses elsewhere, so it is refused here too.

What we do not do

  • No advertising, no advertising networks, no tracking pixels. One third-party script, and only one — the visit count described above.
  • No open tracking in our emails. Knowing whether you opened one would mean an invisible image, and the number it produces is not even reliable.
  • No selling, renting or sharing personal information with anybody.
  • No newsletter. The waitlist gets one email when you join and one when Recado opens, and that is the whole of it.
  • No profiling, and no automated decisions that affect you.
  • No cookie banner on the page where you write a testimonial, because nothing is stored there except your own draft, on your own device, for a day. The visit count stores nothing on your device at all.

Your rights

You can ask for a copy of what we hold, ask us to correct it, ask us to delete it, object to what we are doing with it, or withdraw a consent you gave. Withdrawing consent for a testimonial takes it down — that is what the consent was for.

Ask us at hello@recado.co.uk and we will answer within a month. If your testimonial was collected by a business using Recado, you can ask either of us; if you ask us, we will tell them.

If we get it wrong you can complain to the Information Commissioner’s Office at ico.org.uk. We would rather you told us first, but you do not have to.

Changes

If we change how any of this works, this page changes with it and the date below moves. If a change matters — a new company handling your information, or something kept for longer — we will say so rather than hope you re-read the page.

Last updated: not yet published.