Privacy policy
Last updated 2 October 2026
This policy explains how Sales Base (“we”, “us”) handles personal data when you visit our website, create an account, or use Sales Base, our software for small businesses. We follow the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations.
1. Who we are
Sales Base runs Sales Base. You can contact us about anything in this policy at hello@salesbase.co.uk or through our contact form.
2. Our two roles
We hold personal data in two different ways, and the rules differ.
- As a controller, we decide why and how we use the personal data of people who visit this website, contact us, and create and manage an account (the “account holder”). This is the data described in sections 3 to 9.
- As a processor, we store and handle the personal data that a business (our “customer”) puts into Sales Base about its own clients, leads, staff and suppliers. The customer is the controller of that data and decides what goes in and what is done with it. We handle it only on the customer’s instructions. See section 10.
3. What we collect
- When you contact us: your name, email address, company, phone number (if you give one) and your message.
- When you create an account: your name, email address, password (stored only in a scrambled form we cannot read), your company’s name, web address, timezone and VAT details, and your role.
- When you use Sales Base: a history of actions taken in the account (who created or changed what, and when), so the company can see who did what, and technical records such as the time and the type of browser.
- When you use the chat box: the questions you type. They are used to produce an answer and are not kept by us after the answer is sent.
- Technical data that every website receives, such as your IP address and the pages requested, kept in server logs for security and to keep the service running.
We do not knowingly collect special category data about you, and Sales Base is not intended for anyone under 18.
4. Why we use it, and our lawful basis
- To provide Sales Base and run your account (including emails about your account, security and changes to the service). Lawful basis: performing our contract with you, or taking steps you ask for before one.
- To answer your questions through the contact form or chat box, and to tell you about the plan that suits you. Lawful basis: our legitimate interest in responding to enquiries and running our business.
- To keep the service secure, prevent abuse and fix faults. Lawful basis: our legitimate interest in protecting the service and its users.
- To meet legal duties, such as keeping accounting records. Lawful basis: legal obligation.
We do not sell personal data, and we do not use it for advertising or profiling that has legal or similarly significant effects. We do not send marketing emails unless you have asked us to.
5. Cookies
We use the cookies the service cannot work without: one that remembers your session (and that you are signed in, if you are) and one that protects forms from being submitted by other websites. These are “strictly necessary” and do not need your consent, so they cannot be switched off.
We may also use optional cookies on this website, for example to see which pages are read, so we can improve it. Nothing optional is switched on unless you accept it in the banner on your first visit. Your choice is kept in a small cookie of its own (sb_consent) for a year. You can change your mind at any time with “Cookie settings” in the footer. We do not use advertising cookies, and we do not use optional cookies inside the signed-in service. We do not use any optional cookies at the moment: this policy will list each one before it is used.
6. Who we share it with
We use a small number of other organisations to run the service, and they may handle personal data on our behalf:
- hosting and infrastructure providers, which store the data and run the software;
- an email delivery service, for emails we send (account emails and replies to you);
- AI providers, which power the AI features. When someone uses an AI feature, the text of the question and the facts needed to answer it are sent to the provider we have chosen, and the answer comes back. The assistants cannot see anything beyond what they are sent;
Payments are different. A customer connects its own Stripe, PayPal and GoCardless accounts, and its clients pay on those providers’ own pages. Card and bank details go to the provider, not to us, and the provider has its own privacy policy.
We make sure anyone who handles personal data for us does so under a written contract that requires them to protect it. We can give you a current list of them on request.
7. Sending data outside the UK
Some of our providers, including AI providers, may handle data outside the UK. When they do, we make sure it is protected by a recognised safeguard, such as the UK’s adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses.
8. How long we keep it
- Contact messages: for as long as it takes to deal with them and a reasonable time afterwards, normally no more than two years.
- Account data: while the account is open and for a short period after it closes, so we can deal with questions and disputes, then it is deleted or made anonymous. Records we must keep for tax purposes are kept for the period the law requires (currently six years).
- The activity history: for the period the company chooses, from six months to indefinitely, after which it is removed automatically.
- Backups: deleted data may remain in our own backups for a short time until they are replaced.
- Automatic backups a customer asks for: a customer can switch on a weekly backup of its own data. We keep its last four on our servers for it to download, delete the older ones as new ones are made, and delete them when the customer deletes them.
9. Your rights
Under UK data protection law you can ask us to: give you a copy of your personal data; correct anything wrong; delete it; restrict how we use it; hand it to you or another organisation in a portable format; and stop using it where we rely on our legitimate interests. You can ask by emailing hello@salesbase.co.uk. We will answer within one month, and we may need to check who you are first.
If you are not happy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint or on 0303 123 1113.
If you are the client of a business that uses Sales Base and want to see or change your data, please ask that company first, because it is the controller. We will help it to respond.
10. Customers’ data: our role as processor
When a customer puts personal data about its own clients, leads or staff into Sales Base, we act as its processor. We will:
- handle that data only on the customer’s documented instructions, which are the use of the service and its settings, unless the law requires otherwise;
- keep each customer’s data separate from every other customer’s, and keep it secure (see section 11);
- make sure the people who can access it are bound by confidentiality;
- use other processors (sub-processors) only under a written contract with equivalent protections, and give the customer a way to find out who they are;
- help the customer to respond to requests from the people the data is about, and with its own security and data protection duties, so far as we are able;
- tell the customer without undue delay if we become aware of a personal data breach affecting its data; and
- at the end of the service, return or delete the customer’s data as it chooses, unless the law requires us to keep it.
Our terms of service incorporate this section as our data processing terms. A signed copy is available on request.
11. How we keep data secure
We use measures suited to the risk, including a separate, private set of data for every company, access controlled by role, encryption of payment credentials and connections, a record of who changed what, and the encryption of data in transit between you and the service. No system is perfectly secure, so if something goes wrong we will act quickly and tell those affected, and the ICO where the law requires it.
12. Changes to this policy
We may update this policy as the service changes. The date at the top shows when it last changed, and we will tell account holders about important changes by email.