Your data,
handled straight.
Plain English on what we collect, why, and the read-only Google access behind your monthly report. No selling your data, no surprises.
Effective 27 June 2026
This policy explains how The Start-Up Academy (“we”, “us”, “our”) collects, uses and protects personal information across everything we do.
We build and host websites for local businesses, and we provide — now or as we grow — related services including customer-management (CRM) tools, training and our academy programme, and mentoring and consultancy. This policy covers all of them.
The Start-Up Academy is a business registered in the United Kingdom and is registered with the Information Commissioner's Office (ICO). We are the data controller for the information described here.
- Contact
- hello@thestart-upacademy.com
This policy applies to everyone whose information we handle across all of our services, including:
- Customers and clients who use any of our services — websites, hosting and care, our CRM, training and academy programme, or mentoring and consultancy.
- People who enquire through, or simply visit, our website.
- People who apply to join us or work with us as sales representatives, team leaders, affiliates or staff.
- Businesses we contact to introduce our services.
What we hold depends on your relationship with us:
- Customers & clients: your name, business name, email and phone number; the content, photos, logos and brand details you provide; your domain name; your billing details (card payments are handled securely by Stripe — we never store your full card number); and any information you put into the services you use with us, such as your CRM or training account.
- Website performance data: for our website care plan, aggregated, non-identifying statistics about how your site performs and how visitors use it — and, only if you choose to connect it, read-only Google Search Console and Analytics data (see section 05).
- Website visitors & enquiries: anything you send us through our contact form, plus limited analytics about your visit.
- People who work with us: the details in your application, identity and right-to-work information, your agreement with us, and the bank or payment details we need to pay your commission.
- Businesses we contact: publicly available business information — such as a business name, public contact details, and information from public sources like Companies House and business or social listings — which we use to introduce our services.
We use information for the purposes below, each with a lawful basis under UK data protection law:
- To provide, run and improve our services — building, hosting and maintaining websites, producing your monthly report, and operating our CRM, training, academy and mentoring services (to perform our contract with you, and our legitimate interest in running and improving what we offer).
- To take payment, issue invoices and receipts, pay commission to our people, and keep proper records (contract and our legal obligations).
- To recruit, manage, train and support the people who work with us (contract and legitimate interests).
- To contact businesses we believe could benefit from our services, using publicly available information (legitimate interests — see section 06).
- To provide support, keep our services secure, and prevent fraud or misuse (legitimate interests).
- To compile your monthly report from your connected Google data, where you have connected it (your consent).
If you're on our website care plan, connecting your Google account is optional. If you choose to connect it from your dashboard, you grant us read-only access to two Google services, for your own website only: Google Search Console and Google Analytics.
We use this access for a single purpose: to compile the figures in your monthly SEO and performance report — the search terms you rank for, how often you appear and are clicked in Google, your average positions, and your visitor numbers. The access is strictly read-only: we never make changes to your Google account, and we never access any other Google service or product.
So your reports can run automatically each month, we store a securely encrypted authorisation token. We never see or store your Google password. The Search Console and Analytics figures are retrieved when each report is produced and are presented to you within that report.
You can disconnect at any time using the Disconnect button on your dashboard, or by removing our access at myaccount.google.com/permissions. When you disconnect, we delete the stored authorisation token, and your reports simply continue to run without Google data.
We grow partly by contacting local businesses we believe could benefit from our services. We use only publicly available business information to do this, and we contact businesses about services relevant to them — permitted under UK rules on business-to-business marketing and our legitimate interests.
If you'd prefer we didn't contact you, just tell us and we'll stop straight away and keep a note so we don't contact you again.
We do not sell your personal information. We share it only with the trusted providers that help us run our services, and only as far as they need it to do their job:
- Stripe — payments, subscriptions and commission payouts.
- Google / Firebase — website hosting, our database, and the Search Console & Analytics APIs.
- Resend — sending emails such as receipts and notifications.
- Namecheap — registering and managing domain names on your behalf.
- Telegram — internal operational notifications to our team.
- Providers that support our CRM, training and similar services as we roll them out.
We may also disclose information where we are legally required to, or where necessary to protect our rights, our users or the public.
Your information is held on secure, access-controlled systems, and sensitive items — such as your Google authorisation token or payment details — are encrypted or handled by specialist providers.
We keep your information for as long as you have a relationship with us, and for as long afterwards as we need to meet our legal, accounting and regulatory obligations, after which we delete or anonymise it.
Some of our providers (such as Google and Stripe) operate outside the UK. Where your information is transferred internationally, we rely on appropriate safeguards — such as UK adequacy regulations, Standard Contractual Clauses or the UK International Data Transfer Addendum — to keep it protected.
Under UK data protection law you have the right to access, correct, delete, restrict or object to our use of your personal information, the right to data portability, the right to withdraw consent at any time, and the right to opt out of marketing. To exercise any of these, email us at hello@thestart-upacademy.com.
You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk or 0303 123 1113 — though we'd appreciate the chance to put things right first.
Our website uses essential cookies to function and a small amount of analytics to understand how it is used. You can control cookies through your browser settings.
Our services are for businesses and are not directed at children under 18. We do not knowingly collect their information.
We may update this policy from time to time. When we do, we will revise the effective date below and post the new version on this page.
Questions about this policy or your information? Email us at hello@thestart-upacademy.com.