Try Pipit free for 7 days on every plan — no credit card required.

Last updated 16 July 2026

Privacy Policy

Pipit is a lead capture and follow-up service for business websites. This policy explains what personal data we collect, why, who we share it with, and the rights you have over it. We've written it to be read, not skimmed past.

1. Who we are

Pipit (“we”, “us”) is a trading name of Josh Sutheran, a sole trader based in the UK at 58 Romola Road, Herne Hill, London SE24 9AZ, United Kingdom — the controller of the personal data described in sections 3–5. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. For anything in this policy, contact us at hello@heypipit.co.uk.

2. The two ways we handle personal data

It matters who you are, because our role under data-protection law changes:

  • If you have a Pipit account (or visit heypipit.co.uk, or book a call with us): we are the controller of your data, and sections 3–5 describe what we do with it.
  • If you chatted with a Pipit-powered assistant on another business’s website: that business is the controller of your data and decides how it is used — we are their processor and act only on their instructions. Section 6 explains what we process for them; for anything else (including exercising your rights), their own privacy notice is the right place to look, and requests to us will be passed to them.

3. Data we collect about our users

  • Account data — your email address and password (stored only as a secure hash), plus the sign-up route you took so we know which of our pages convert.
  • Business details — what you tell us during onboarding and what our scan reads from your public website, documents you upload, and public reviews: business name, website, services, opening hours and similar. This is mostly company data, but can incidentally include personal data such as staff names that appear on your site.
  • Communications — emails and messages you exchange with us, and the details you provide when booking a discovery call (handled through Calendly).
  • Technical data — server logs (IP address, browser type, timestamps) kept for security and debugging.

We do not run third-party advertising or analytics trackers on our site, and we never sell personal data.

4. How we use it, and our lawful bases

  • To provide the service — creating your account, building your assistant from your website, delivering conversations and leads to your dashboard, and sending service emails such as confirmation links. Lawful basis: contract.
  • To run and improve Pipit — securing the platform, fixing bugs, understanding which sign-up routes work, and reviewing how the assistant performs. Lawful basis: legitimate interests.
  • To contact you about Pipit — product updates and launch-partner news you can opt out of at any time. Lawful basis: legitimate interests (existing customers) or consent.
  • To meet legal obligations — tax, accounting and responding to lawful requests. Lawful basis: legal obligation.

5. AI processing

Pipit uses Anthropic’s Claude models to read your website content and to answer visitor questions. Content sent to the model is limited to what’s needed for the task — the knowledge we compiled about the business and the conversation in progress. Under our commercial agreement, Anthropic does not use this data to train its models. The assistant is designed to answer only from the business’s own verified information and to decline sensitive or off-topic requests.

6. Data we process for our customers (website visitors)

When you talk to a Pipit assistant on a business’s website, we process on that business’s behalf:

  • Your conversation — the messages you exchange with the assistant, so the business can see and continue the enquiry.
  • Contact details you choose to share — name, email address, phone number and what you’re enquiring about, so the business can respond and arrange bookings.
  • Follow-ups — the business may use Pipit to follow up on your enquiry by email (with SMS and WhatsApp to follow). Every follow-up email includes a working unsubscribe link; using it stops further chasing immediately.

The assistant is deliberately limited: it captures enquiry-stage contact details only, and is instructed never to collect sensitive personal data (such as health or financial details). Please don’t type such information into the chat.

7. Who we share data with

Only service providers who help us run Pipit, each bound by contract to protect it:

  • Supabase — our database and account authentication.
  • Amazon Web Services — the servers and queues our platform runs on.
  • Vercel — hosting for our website and app.
  • Anthropic — the AI models described in section 5.
  • Postmark (ActiveCampaign) — sending our transactional and follow-up emails.
  • Calendly — scheduling discovery calls.

We may also disclose data if the law requires it, or as part of a company sale or restructuring (in which case this policy continues to apply to it).

8. International transfers

Some of these providers process data in the United States. Where personal data leaves the UK, we rely on UK-approved safeguards: the UK–US Data Bridge where the provider is certified, or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses otherwise.

9. How long we keep data

  • Account data — for as long as your account is active, then deleted within 90 days of closure (except records we must keep for legal or accounting reasons).
  • Conversations and enquiries — retained while the business we process them for remains a customer, and deleted on their instruction or within 90 days of their account closing.
  • Technical logs — kept for no more than 12 months.

10. Security

Data is encrypted in transit and at rest. Our database accepts connections only from our own API — never from browsers — and access to production systems is restricted to the people who need it. No system is perfectly secure, but if a breach ever puts your rights at risk we will notify you and the ICO as the law requires.

11. Your rights

Under UK GDPR you can ask us to:

  • give you a copy of your personal data (access);
  • correct it (rectification) or delete it (erasure);
  • restrict or object to how we use it, including for direct marketing;
  • hand it over in a portable format (portability);
  • withdraw consent, where consent is the basis we rely on.

Email hello@heypipit.co.uk and we’ll respond within one month. You can also complain to the Information Commissioner’s Office at ico.org.uk, though we’d welcome the chance to sort it out first.

12. Cookies

We use only strictly necessary cookies: the session cookies that keep you signed in to your account. No advertising or cross-site tracking cookies — which is why there’s no cookie banner. If that changes, this policy and the site will change with it.

13. Children

Pipit is a business tool and our services are not directed at children. We do not knowingly collect data from anyone under 18; if you believe we have, contact us and we will delete it.

14. Changes to this policy

When we make material changes we’ll update the date at the top and notify account holders by email. The current version always lives at this address, alongside our Terms of Service.