Privacy Policy

Last updated: 4 October 2026

This policy explains what personal data the audit tool at audit.theuxhive.com collects, why, who we share it with, and your rights.

1. Who is responsible for your data

Carl Borg Bartolo, trading as The UX Hive, a sole trader registered in Malta (VAT MT29089817), is the controller of your personal data. Contact: carl@theuxhive.com.

2. What we collect

  • Account details — your email address and a securely hashed password (or your Google account's email and name, if you sign in with Google), and whether you've agreed to receive product updates.
  • Your audits — the addresses you scan, the options you choose (site type, device, market), the reports we produce, and the page text and screenshot we capture for each scan.
  • Plan and payments — your plan, credits and purchase history. Stripe processes your card details; we receive a customer reference and payment records, never your full card number.
  • How you use the site — pages you visit and actions you take (for example running a scan or opening the pricing page), your browser, device type and approximate country, and recordings of how you move through the site. Text you type into form fields is masked in recordings, and we don't store IP addresses in our analytics.
  • Messages — anything you send us by email.

Pages you scan may contain other people's personal data, such as names in testimonials. We process it only to produce your report.

3. Why we use it, and our legal basis

  • To provide the Service — your account, scans, reports, payments and support. Legal basis: performing our contract with you.
  • To keep it secure and fair — preventing abuse, fraud and automated misuse. Legal basis: our legitimate interests.
  • To improve the Service — understanding how people use it, through analytics and session recordings. Legal basis: our legitimate interests. You can object at any time (section 8).
  • Product updates and the newsletter by email — only if you ticked the box. These may be tailored to how you use the tool (for example your plan, the kind of site you audit and when you last scanned). Legal basis: your consent, which you can withdraw at any time with the unsubscribe link in any email, from your account page, or by emailing us.
  • To meet legal obligations — such as keeping tax and accounting records. Legal basis: legal obligation.

We don't sell your data, use it for advertising, or make decisions about you based solely on automated processing that have legal or similarly significant effects.

4. Who we share it with

We use these service providers, who process data on our behalf under data-processing agreements:

ProviderWhat forWhere
SupabaseDatabase, sign-in and file storage (your account, reports, screenshots)EU (Ireland)
AnthropicAI analysis of the pages you scan, and copy suggestionsUnited States
FirecrawlLoading the pages you scan and taking screenshotsUnited States
StripePayments, invoices and subscription managementEU (Ireland) and United States
PostHogProduct analytics and session recordingsEU
VercelHosting the websiteGlobal, including the United States
ResendSending account emails (sign-up confirmation, password reset)United States
BrevoProduct updates and the newsletter, only if you opted inEU (France)
GoogleSign-in, only if you choose "Continue with Google"Global, including the United States

We may also share data where the law requires it, or with a buyer if the business is ever sold (we'd tell you first). If you turn on sharing for a report, anyone with its link can view that report.

5. Transfers outside the EU

Some providers above process data in the United States. Those transfers are protected by the EU–US Data Privacy Framework where the provider is certified, or by the European Commission's Standard Contractual Clauses. You can ask us for details.

6. How long we keep it

  • Account, audits and screenshots — while your account is open. When you close it, we deactivate it straight away and keep the data for up to 12 months in case you want it back, then delete it. You can ask us to delete it sooner.
  • Payment and invoice records — as long as Maltese tax and accounting law requires.
  • Session recordings — 30 days.
  • Analytics events — up to 12 months.
  • Emails with us — as long as needed to deal with your request.

7. Cookies and similar technology

We don't use advertising or tracking cookies, and our analytics doesn't store anything on your device. When you sign in, your browser's local storage keeps you logged in; this is strictly necessary for the site to work.

8. Your rights

Under the GDPR you can ask us to:

  • give you a copy of your data, or send it to another provider in a portable format;
  • correct data that's wrong;
  • delete your data, or restrict how we use it;
  • stop using it for analytics or other purposes based on our legitimate interests;
  • stop sending you product updates (you can also untick this in your account).

Email carl@theuxhive.com and we'll reply within one month. If you're unhappy with how we've handled your data, you can complain to Malta's Information and Data Protection Commissioner (idpc.org.mt) or the data-protection authority where you live.

9. Security

Data is encrypted in transit and stored with providers that encrypt it at rest. Access is restricted to what each part of the Service needs. Screenshots are kept private and only shown to you, or to people you share a report with.

10. Children

The Service is for people aged 18 and over. We don't knowingly collect data from children.

11. Changes

We'll update this policy when how we handle data changes, and tell you by email or in the app about important changes. See also our Terms of Service.