Legal

Privacy Policy

Last updated: 24/06/2026

This Privacy Policy explains how ROOTSHELL TRADING GROUP LTD (Company number 14165761) ("we", "us", "our") handles personal data in connection with the DataStark platform (the "Service"). It is written to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Please read it together with our Terms of Service.

1. Who We Are

The data controller for personal data we hold about our account holders is ROOTSHELL TRADING GROUP LTD (Company number 14165761), a company registered in the United Kingdom. For any privacy matter, or to contact the person responsible for data protection, you can reach us at [email protected].

2. Two Distinct Categories of Data

It is important to distinguish between two very different categories of data involved in the Service:

(a) Your account data

Data we collect about you, our user in order to provide the Service. We are the data controller for this data and it is the focus of this policy.

(b) Third-party source data

Information surfaced in search results, which originates from external public datasets and previously disclosed breach collections that we do not create, own, or maintain. See Section 6.

3. Account Data We Collect

In the course of operating the Service we process:

  • Identity & account data – email address, hashed password, optional name and country, two-factor authentication settings, and the date and time of registration and last access.
  • Billing data – subscription plan, transaction status, and payment metadata (payments are handled by our third-party payment provider; we do not store or have access to full payment-card details).
  • Usage & technical data – search logs (the query terms you submit and result counts), quota usage, IP address, and timestamps, used for delivering the Service, security, rate limiting, and abuse prevention.
  • Support data – the content of any support tickets or correspondence you send us.

4. Lawful Bases

We rely on the following lawful bases under Article 6 UK GDPR:

  • Contract – to create and administer your account and provide the Service you have signed up for.
  • Legitimate interests – to secure the Service, prevent abuse and fraud, enforce quotas, and maintain audit and search logs.
  • Legal obligation – to comply with our legal and regulatory duties, including responding to valid requests from authorities and data subjects.

5. Retention

We retain account data for as long as your account is active and for a reasonable period afterwards to meet legal, accounting, security, and dispute-resolution requirements, after which it is deleted or anonymised. Search logs and technical data are retained only as long as necessary for the purposes described above. Some data may be retained for longer where required by applicable law.

6. Third-Party Source Data & Our Role

The Service searches across data that already exists in the public domain or within third-party datasets, made available through independent upstream providers. We do not create, originate, compile, or maintain this source data, and we do not build profiles of individuals on our own initiative.

We act as a neutral technical intermediary that enables a user to search these external sources. The user determines the purpose and means of any individual query and is solely and fully responsible for their own processing of any results, including compliance with all applicable law.

You are responsible for ensuring that your use of the Service is lawful and that you have an appropriate basis for any processing you carry out using results obtained through it. Without limiting your responsibility, you must not use the Service for any unlawful purpose or in any manner that infringes the rights of others, including but not limited to:

  • stalking, harassment, intimidation, threats, fraud, blackmail, or doxxing;
  • processing personal data without a valid lawful basis or in breach of UK GDPR or any other applicable law;
  • using results for consumer-reporting or eligibility decisions (such as credit, employment, housing, or licensing);
  • circumventing security controls, abusing rate limits, or reselling or redistributing the Service or its output without authorisation.

This list is illustrative only and is not exhaustive. Further restrictions on acceptable use are set out in our Terms of Service.

Because the source datasets indexed by the Service are not structured to allow us, on our own, to identify a specific individual or to confirm that a given record relates to a particular person, our ability to respond to certain requests (for example, an Article 15 access request directed at source data) is inherently limited. Notwithstanding this, we provide the suppression mechanism described in Section 10 so that individuals can request their identifiers be excluded from searches run through the Service.

7. Cookies

We use strictly necessary cookies only. We do not use advertising, analytics, or cross-site tracking cookies, so no cookie-consent banner is required. The cookies we set are:

  • access_token – a secure, HttpOnly session cookie that keeps you signed in.
  • csrf_token – a security cookie used to protect against cross-site request forgery.

8. Security

We apply appropriate technical and organisational measures to protect personal data, including one-way hashing of passwords and API keys, HttpOnly and SameSite session cookies, CSRF protection, rate limiting, two-factor authentication, and access controls. Data is held in secured systems with access restricted to authorised personnel. No method of transmission or storage is completely secure, but we work to protect your data and to respond promptly to any incident.

9. Data Breach Notification

In the event of a personal-data breach affecting your account data that is likely to result in a risk to your rights and freedoms, we will notify affected users without undue delay where the breach is likely to result in a high risk to them, and will take any other steps required by applicable law.

10. Suppression & "Right to be Forgotten" from Search

If you wish to have your information excluded from searches performed through the Service, you may submit a formal, written request by email to [email protected]. Upon validating your request, we will add the relevant identifiers to our suppression list so that they are stripped from, and return no results in, all future searches run through the Service.

Your written request should include:

  • the specific identifiers you want suppressed (for example, email address, username, phone number, or domain);
  • a clear statement that you are requesting suppression; and
  • information reasonably sufficient for us to verify that the request relates to you (or that you are authorised to make it).

We will action validated requests without undue delay and in any event within one month, as required by UK GDPR. Please note that suppression applies to the Service only: because we are not the source of the underlying data, we cannot remove it from the original third-party datasets, and you may need to contact those sources separately.

11. Your Rights

In relation to the account data we hold about you, you have the right under UK GDPR to: access your data; request rectification or erasure; restrict or object to processing; request data portability; and withdraw consent where processing is based on consent. To exercise any of these rights, contact [email protected]. These rights are subject to the conditions and exemptions provided by law.

For requests to be excluded from search results, please follow the suppression process in Section 10.

12. Third-Party Service Providers

We share account data with a limited number of third-party providers only where needed to operate the Service, under agreements that restrict their use of the data. These include:

  • Hosting & database infrastructure – to run the Service and store account data.
  • Payment provider – to process Plan payments; it handles card and financial data directly, and we do not receive or store it.
  • Upstream data providers – the independent OSINT/breach-intelligence sources the Service queries on your behalf.

We do not sell your personal data. We may disclose data where required by law or to respond to valid requests from law-enforcement or regulatory authorities, or to protect our rights and the security of the Service.

13. International Transfers

Some of the providers and infrastructure we rely on may process data outside the United Kingdom. Where personal data is transferred internationally, we take steps to ensure an appropriate level of protection, such as relying on adequacy decisions or standard contractual clauses (the UK International Data Transfer Agreement or Addendum) where applicable.

14. Changes & Contact

We may update this Privacy Policy from time to time; changes are indicated by the "Last updated" date above. For any questions about this policy, contact [email protected].