Privacy policy
Last updated: 3 August 2026
Ryan La is the data controller for AyediaBoard. This explains what we collect, why, how long we keep it and who else processes it. Questions go to support@ayediaboard.com.
1. What we collect
If you run a board
- Your email address and password hash, held by our authentication provider.
- Your board’s name, slug, tagline, category and settings, and the ideas, votes and boosts on it.
- Payout and identity information you give to Stripe when you connect an account. This goes to Stripe directly. We never see or store your bank details — we hold only your Stripe account id and whether it is verified.
If you sign in with Google
- Signing in with Google shares your name, email address and profile picture with AyediaBoard — the basic profile Google provides for sign-in, and nothing more.
- We use it for one thing: to create and identify your account. Your email addresses you about your board or your submission; your name is shown only if you choose to be credited on an idea.
- We request no access to Gmail, Drive, YouTube, Calendar, Contacts or any other Google service, and we never post or act on your behalf.
- We do not sell this data, use it for advertising, or share it with anyone beyond the processors listed in section 3. It is deleted when you delete your account, on the timetable in section 4.
- Google is the identity provider for this, so their handling is covered by the Google Privacy Policy. You can revoke AyediaBoard’s access at any time from your Google account permissions page, and you can use an email address and password instead if you would rather not connect a Google account at all.
If you submit or boost an idea
- The idea itself, and the display name you choose to be credited by.
- A contact email, used to tell you what happened to your submission. It is never shown publicly.
- For a boost: the amount and Stripe’s reference for the payment. We never receive or store your card details. They go from your browser to Stripe.
Automatically
- Server logs, including a request identifier, the page path, the response status and your IP address. We deliberately do not log query strings, because sign-in links can carry tokens in them.
- Product analytics, only if you accept them. See the cookie policy.
2. Why, and on what legal basis
| Purpose | Lawful basis |
|---|---|
| Running your account and your board | Performance of a contract |
| Taking payments and paying creators | Performance of a contract |
| Emailing you about your submission or account | Performance of a contract |
| Keeping records for tax and accounting | Legal obligation |
| Preventing fraud and abuse, keeping the service secure | Legitimate interests |
| Product analytics | Consent — and nothing loads until you give it |
3. Who else processes it
| Processor | What for | Where |
|---|---|---|
| Supabase | Database and authentication | EU (eu-west-1) |
| Sign-in, if you choose “Continue with Google” | US / global, under its own terms | |
| Stripe | Payments, payouts, identity verification | EU / US, under its own terms |
| PostHog | Product analytics, only with consent | EU |
| Namecheap (Private Email) | Transactional email | United States |
| Railway | Running the API | EU (Amsterdam) |
| Vercel | Serving the website | EU (London) |
We do not sell your data, and we do not share it for advertising. Where a processor is outside the UK or EEA, transfers rely on adequacy regulations or standard contractual clauses.
4. How long we keep it
- Account and board data — until you delete your account.
- Unfinished sign-ups — if you start creating a board and never name it, we do not keep the half-finished account indefinitely. Where a paid subscription was started, we cancel it after 3 days so you are not charged again for a board that does not exist. Where nothing was paid, the empty record is deleted after 30 days, together with any identity details Stripe was holding for the payout account you had begun setting up.
- Payment records — six years after the transaction, which we are required to keep for tax purposes. This is why deleting your account does not erase financial records. What remains is anonymised: the amounts and dates stay, the person does not.
- Server logs — 30 days, then discarded.
- Analytics — as configured in PostHog, and deleted if you withdraw consent.
5. Your rights
You have the right to access your data, correct it, delete it, restrict or object to how we use it, and receive a portable copy. Where we rely on consent you can withdraw it at any time — for analytics, using — without affecting what was done beforehand.
You can delete your account and everything attached to it from your account settings; it also cancels any subscription. For anything else, email support@ayediaboard.com and we will respond within one month.
If you think we have handled your data badly, please tell us first. You can also complain to the Information Commissioner’s Office at ico.org.uk.
6. Children
The service is not intended for children under 13, and you must be 18 to run a board. If you believe a child has given us personal data, contact us and we will delete it.
7. Security
Sessions are held in httpOnly cookies that page scripts cannot read, traffic is encrypted in transit, and card details never touch our servers. No system is perfectly secure, but we will tell you and the ICO about a breach affecting you where the law requires it.
8. Changes
We will update this page when what we do changes, and update the date at the top. Material changes are notified before they take effect.
9. Contact
Ryan La
Lytchett House Ltd, Unit 13, Freeland Park, Wareham Road, Poole, Dorset, BH16 6FH, UK
support@ayediaboard.com