Skip to content

    Trust & security

    How we keep your contacts — and the people who share their details with you — safe. Plain English, no jargon.

    Where your data lives

    Your profile, cards, leads and account data are held in a UK-region database (Supabase, on Postgres) and served over HTTPS through Cloudflare. Payments are handled by Stripe — we never see or store your full card number.

    Who can see what

    Every account is isolated at the database level with row-level security: you can only ever read your own profile, cards and leads. Contact-back leads are visible only to the cardholder who captured them, and team data is scoped to your organisation, controlled by its owner. There is no shared pool where one customer can reach another's contacts.

    Your data, your control

    You can export everything you hold — profile, cards, leads and orders — as a single JSON file from your dashboard, any time. You can delete an individual lead, or delete your whole account and its data, yourself; organisation owners can purge an entire team. Per-field privacy controls let you decide exactly what each card shows.

    The people who share their details with you

    When someone sends their details back through your card (contact-back), we show them a short privacy note first, so they know their details go to you. For those records you are the data controller and Universal Contacts is your processor, as set out in our Terms. We process them only to run the service, keep them confidential, and delete or return them when you delete a lead or close your account.

    Who else touches your data

    We use a small, named set of sub-processors for hosting, payments and email — each listed in our Privacy Policy and bound by contract. Where data is processed outside the UK, we rely on UK adequacy or Standard Contractual Clauses with the UK International Data Transfer Addendum.

    Compliance and certifications — honestly

    We are UK GDPR-aligned and registered with the ICO (registration ZC210106). We do not currently hold formal certifications such as SOC 2 or ISO 27001 — we're an independent UK company rather than an enterprise vendor, and we would rather tell you that than imply otherwise. What we do have is a small, auditable system: row-level isolation, encrypted transport, least-data collection, and one-tap export and deletion. If a certification is a requirement for you, tell us — it helps us prioritise.

    Report a security issue

    Found something that looks wrong? Email hello@universalcontacts.co.uk and a real person will look into it.

    Related pages