Crowdseek Ltd
Version 1.6 • Effective 7 September 2026 • Linked from the footer of our Privacy Policy
Crowdseek Ltd is the sole data controller for personal data we process in operating our website (crowdseek.com), the Crowdseek beta app (beta.crowdseek.com), pilot landing pages (sleep.crowdseek.com, pilot.crowdseek.com), and related services (together, the "Service").
We engage the third-party organisations listed below to process personal data on our behalf, or, in two specified cases, as joint controllers under UK GDPR Article 26. Each organisation is engaged under a written contract that includes the data protection terms required by UK GDPR Article 28 (for processors) or Article 26 (for joint controllers).
This Register is a living document. We may add, change or remove processors from time to time. We will keep this page up to date and, where the change is material, we will surface a notice through the Service. Material changes to which categories of data are processed, where they are stored, or who has access, will trigger a corresponding update to our Privacy Policy.
1. Controller
Crowdseek Ltd
Role: Sole Data Controller for all personal data processed by the Service.
Registered in England & Wales No. 09560574.
Registered address: 23 Westfield Park, Redland, Bristol, BS6 6LT, United Kingdom.
Privacy contact: privacy@crowdseek.com.
2. Processors (Article 28)
The following organisations process personal data on our written instructions under UK GDPR Article 28 terms.
Rocketmakers Ltd
Role: Web application development, build, and hosting of the original Crowdseek web app at app.crowdseek.com, which has been retired. Rocketmakers retains no role in the Crowdseek beta app.
Personal data processed: account and contact details, plan content (including Article 9 wellbeing data), usage and device data, log data.
Location: United Kingdom (build team and infrastructure).
Transfer mechanism: not applicable — UK-located.
Contract: CRS-26-003 master services agreement, with AI/IP side letter pending signature.
Sub-processors: cloud hosting provider used by Rocketmakers (currently AWS or equivalent — confirmed in their own sub-processor register).
Amplify Growth Ltd (trading as Amplify Growth, formerly Amplify Social)
Role: Pilot landing-page hosting (sleep.crowdseek.com, pilot.crowdseek.com); paid-media operations and account management for Crowdseek's Meta and Google Ads accounts; design and creative production for landing pages and ads.
Personal data processed: landing-page form submissions (name, email, optional fields) before they are transferred to the Crowdseek web app; ad measurement events at aggregate level.
Location: United Kingdom.
Transfer mechanism: not applicable — UK-located.
Contract: monthly retainer with separate landing-page build engagement; UK GDPR Article 28 data processing terms in place.
Evergreen
Role: Website infrastructure and IT support for crowdseek.com (currently hosted on WordPress) and related Crowdseek-owned IT systems.
Personal data processed: any personal data submitted via contact forms on crowdseek.com; administrative access to system configuration and content management.
Location: United Kingdom.
Transfer mechanism: not applicable — UK-located.
Note: Evergreen also previously held the legal-fix action list against the live website; that work transferred to the founder as part of the brand-site update programme.
Cookiebot by Usercentrics A/S
Role: Consent management platform — operates the cookie consent banner on sleep.crowdseek.com and pilot.crowdseek.com, records consent choices and timestamps, and provides the audit log of consent given for those pages. From 7 September 2026 crowdseek.com and beta.crowdseek.com use our own consent tool instead, and the record of those choices is held in our own database (see the Supabase entry). Cookiebot is being retired from the stack.
Personal data processed: IP address (truncated), consent identifier (random), consent choices, timestamp.
Location: European Union (Denmark / Germany).
Transfer mechanism: not applicable — EU-located, UK adequacy applies.
Klaviyo (Klaviyo, Inc.)
Role: Email service provider and lightweight B2C CRM for the founding-cohort programme — sends service notices, and the new-user email series and other marketing communications where the user has opted in; records open and click engagement for marketing emails; and stores profile properties (signup date, lifecycle stage, last-active date) and segment membership used to time the welcome and win-back flows. No third-party HubSpot CRM is used — HubSpot was removed from the Crowdseek stack on 2 June 2026 and Klaviyo is the sole email + CRM processor. Lead capture occurs via the app registration form and the Amplify-hosted landing-page forms (transferred into the Service); there is no separate third-party forms tool.
Personal data processed: first name, email address, sign-up date, marketing-consent flag and timestamp, and email engagement events (opens, clicks, bounces).
Wellbeing data is not transferred to Klaviyo in any form — neither as free text nor as codes. The outcome and reason a user chooses, and all other Article 9 plan content, remain inside Crowdseek's own systems and are never used to personalise email content. The only personal detail used to personalise an email is the user's first name.
Location: United States.
Transfer mechanism: EU-US Data Privacy Framework (Klaviyo is self-certified to the DPF) and the UK Extension to the DPF (the "UK Data Bridge"); Klaviyo’s Data Processing Addendum also incorporates the EU Standard Contractual Clauses and the UK International Data Transfer Addendum (the "UK IDTA") as a backstop where the DPF does not apply.
Status: confirmed as the email service provider for the pilot by founder decision on 28 May 2026 (supersedes the earlier Mailchimp candidate selection recorded in v1.0 of this Register).
Customer support and email delivery tooling
Role: Inbound email handling for support@crowdseek.com and privacy@crowdseek.com (currently Microsoft 365), and the outbound transactional email pipeline used by the web app for sign-in and account notices. For the Crowdseek beta app this is Resend, sending one-time sign-in codes; magic-link sign-in is no longer used. The legacy pipeline for the original app (Amazon SES via Rocketmakers' infrastructure) is being retired.
Personal data processed: email address, message content and metadata.
Location: European Union (Microsoft 365 UK / EU tenant) and United States (Amazon SES, with EU regional storage where supported).
Transfer mechanism: where US-based, UK IDTA and SCCs incorporated into provider terms.
Privacy-focused analytics, error monitoring and performance tools
Role: aggregate measurement of how the Service performs, with a privacy-first posture (IP anonymisation, no third-party advertising integration).
Personal data processed: aggregated usage and performance signals; truncated IP address; device and browser metadata.
Location: as configured at the time of selection — preference for UK / EU regional storage. Current provider listed in the linked sub-processor register on confirmation of supplier.
Transfer mechanism: SCCs / UK IDTA where the provider is located outside the UK or EEA.
Supabase (Supabase, Inc.)
Role: Database, authentication and application data storage for the Crowdseek beta app (beta.crowdseek.com), and the destination for one anonymous event sent from our brand website (crowdseek.com). Holds the account record, the plan seed (chosen outcome, reason, wind-down time and action cues), the record of consents given, and product usage events. Issues and verifies the one-time sign-in codes. From 7 September 2026 it also holds the record of cookie consent choices made on our own banner: a random consent identifier, the categories chosen, how they were chosen, the version of the wording shown, the domain and page, the date and time, and the browser user agent string. That record carries no name, email address or account identifier. From 29 August 2026 it also receives, from crowdseek.com, a count of how many of five general statements a visitor recognised, with the campaign labels they arrived on. That event carries no account, no identifier for the person, and none of the statements themselves.
Personal data processed: email address, first name, account identifier, plan seed values, an optional indication of how the user wishes to be pictured, consent records with timestamps, and product usage events consisting of codes, counts and yes/no values.
Special-category data: none stored. The night log, and how a night felt, remain on the user's own device and are not transmitted to us.
Location: European Union (Ireland).
Transfer mechanism: not applicable — EU-located, UK adequacy applies.
Railway (Railway Corp.)
Role: Application hosting for the Crowdseek beta app — serves the application to the user's browser.
Personal data processed: no application data is stored by Railway; standard server and request logs may include IP addresses.
Location: United States.
Transfer mechanism: standard contractual clauses / UK Addendum under the provider's data processing agreement.
Resend (Resend, Inc.)
Role: Transactional email delivery — one-time sign-in codes, and the service check-in emails (an evening wind-down prompt and a morning invitation to log the night) where the user has switched them on. Marketing email is not sent through Resend.
Personal data processed: email address, first name, and the content of the message sent.
Location: United States, delivering via Amazon SES in the European Union (Ireland).
Transfer mechanism: standard contractual clauses / UK Addendum under the provider's data processing agreement.
Cloudflare, Inc.
Role: Content delivery and bot protection in front of crowdseek.com. Sets one strictly necessary cookie, __cf_bm, which distinguishes people from automated traffic and expires after 30 minutes.
Personal data processed: IP address and request metadata, held briefly for security and delivery.
Location: United States, with global edge locations.
Transfer mechanism: standard contractual clauses / UK Addendum under the provider's data processing agreement.
GoDaddy (managed WordPress hosting for crowdseek.com)
Role: Hosting and content delivery for our brand website, including its contact form.
Personal data processed: server and request logs which may include IP addresses; any details submitted through the website contact form.
Location: United States / European Union depending on the data centre serving the request.
Transfer mechanism: standard contractual clauses / UK Addendum under the provider's data processing agreement.
3. Joint controllers (Article 26)
The following organisations process personal data in joint-controller arrangements with Crowdseek, governed by UK GDPR Article 26. The essence of these arrangements is summarised in Section 6B of the Privacy Policy.
Meta Platforms Ireland Ltd (Facebook / Instagram)
Role: Joint controller for Meta Pixel events fired on Crowdseek's pilot landing pages and the web app, where the user has given consent for advertising cookies. From 1 September 2026 we also send sign-up events to Meta from our own server through the Meta Conversions API, where the user has given consent for advertising cookies. Those events carry a hashed email address, a hashed account identifier and the Meta click identifier, and no plan, outcome, reason or free-text content.
Personal data processed: Meta Pixel events tied to a hashed user identifier; ad conversion measurement.
Location: European Union (Ireland), with onward transfer to the United States.
Transfer mechanism: SCCs and EU-US Data Privacy Framework, as published by Meta. UK component covered by the UK Addendum.
Crowdseek's responsibility: deciding which audiences to target and which conversions to measure, and gating the Pixel on user consent.
Meta's responsibility: operating the advertising platform and processing data on Meta's infrastructure.
Google (Google Ireland Ltd / Google LLC)
Role: Joint controller for Google Ads tags fired on Crowdseek's pilot landing pages and the web app, where the user has given consent for advertising cookies. Where Google Analytics is configured separately, Google acts as a processor under its Data Processing Terms.
Personal data processed: Google Ads conversion measurement events; (separately) Google Analytics usage events.
Location: European Union (Ireland), with onward transfer to the United States.
Transfer mechanism: SCCs and EU-US Data Privacy Framework, as published by Google. UK component covered by the UK Addendum.
Crowdseek's responsibility: deciding which campaigns to run and which conversions to measure, and gating the tags on user consent.
Google's responsibility: operating the advertising platform and processing data on Google's infrastructure.
4. Other recipients (for completeness)
The organisations below receive personal data from Crowdseek in limited circumstances. They act as independent data controllers in their own right — they are listed here for transparency.
Crowdseek's professional advisers (legal, accounting, IP)
Role: where Crowdseek instructs external counsel (for example, Wynne-Jones IP for trade-mark filings, or external solicitors for review-only legal work), limited personal data — typically Crowdseek's own contact details and registered company details — may be shared. These advisers act as independent controllers for their own client records, not as our processors.
Banking, payments, and statutory authorities
Role: where required for billing, tax, regulatory or lawful enforcement reasons.
5. How we maintain this Register
This Register is reviewed and refreshed at least every six months and on every material change of processor. Each change is logged in our internal Cowork change log alongside the corresponding planner item (canonical: crowdseek_central_planning_tracker_assigned.xlsx).
To request more detail about any entry, or to ask about a specific data flow, contact privacy@crowdseek.com.
Document version: v1.6, updated 7 September 2026 (Cookiebot narrowed to the pilot landing pages and marked for retirement, because from 7 September 2026 crowdseek.com and beta.crowdseek.com run our own consent banner; Supabase entry widened to record the consent log our own banner writes; Meta entry widened to record the server-side Conversions API events begun on 1 September 2026). Previously v1.5, updated 29 August 2026 (Cloudflare added — it sits in front of crowdseek.com and sets the one strictly necessary cookie a first anonymous visit receives, and it was not previously listed; Supabase entry widened to record that crowdseek.com now sends it one anonymous event, described in that entry). Previously v1.4, updated 28 July 2026 (Klaviyo entry narrowed — Crowdseek no longer transfers outcome and reason codes, gender or wind-down time to Klaviyo; wellbeing data is now excluded from the email service provider in every form, and email personalisation uses first name only). Previously v1.3, updated 28 July 2026 (added Supabase, Railway, Resend and GoDaddy for the beta app and brand site; corrected Klaviyo entry — sign-in emails now sent by Resend as one-time codes, not magic links; recorded beta.crowdseek.com as a controller surface). Previously v1.2, updated 6 June 2026 (confirmed HubSpot fully removed from the stack; Klaviyo recorded as both email service provider and the founding-cohort B2C CRM; lead-capture path described; no change to the categories of data processed or to transfer mechanisms). Previous: v1.1, 28 May 2026 (Mailchimp candidate replaced with Klaviyo; DPF/UK Data Bridge added with SCCs/IDTA backstop). First publication 27 May 2026. Hosted on Crowdseek pilot landing pages during the pilot; canonical version may move to crowdseek.com post-pilot.