Privacy policy

01Who we are

Spotlight is a trading name of Recoup Systems Inc. We build and run websites and advertising for local service businesses: plumbers, roofers, electricians and the like.

That means this policy covers three different kinds of person, and which parts apply to you depends on which one you are. If you filled in a form on a plumber’s website, section 3 is yours. If you pay us, section 5 is.

Questions, or a request about your data: privacy@spotlightbuilt.com.

02If you visited a website we run

We host websites and landing pages for our clients. If you visited one and did not fill anything in, here is everything that happened.

One cookie, and what is in it

We set a single cookie that records how you arrived: whether you came from a Google ad, a Facebook ad, a search result or a link, along with the campaign name if there was one. It holds no name, no contact details and no identifier for you personally. It lasts 90 days.

It exists so that when somebody does eventually get in touch, the business can tell which advertising actually produced that enquiry. Without it, a customer who clicks an ad on Monday and calls on Friday looks like they arrived from nowhere, and the business pays for advertising it cannot see working.

What we do not do

There is no Google Analytics, no Meta pixel, no session recording and no third-party tracker of any kind on the sites we run. Nobody is building a profile of you across other websites from anything we set.

03If you enquired with one of our clients

This is the part worth reading carefully, because it involves your contact details.

What we collect

  • Your name, phone number, email address and postcode, if the form asked for them
  • Whatever you typed in the message box
  • The page you submitted from and how you originally arrived at the site
  • The exact consent wording that was on screen when you submitted, and the time you submitted it
  • Your browser’s user agent, and a one-way scrambled version of your IP address. We use the scrambled version to stop the same machine flooding a form. The real IP address is never written down.

Texts and calls

Where a business has us handle follow-up, we may text you about your enquiry. Every message supports STOP and HELP. Replying STOP ends it immediately and permanently, and we honour that regardless of which business it came from.

If your submission looked like spam

Automated submissions are scored and set aside rather than deleted, and left out of the business’s counts. We keep them so that anything we did not count can be produced if somebody asks. If a real enquiry of yours was wrongly filtered, tell us and we will find it.

04If we called you, or you called us

The audio is held by Twilio, our telephone provider, and we keep a reference to it along with the two phone numbers, the time and how long the call lasted. We record that the announcement was played on each individual call, rather than assuming it from a setting.

We do not transcribe calls. There is no speech-to-text anywhere in our systems and no written record of what was said.

If you leave a voicemail on one of our numbers, that recording is kept the same way. If you would rather a recording of your call did not exist, email us and we will delete it: see section 8.

05If you are a Spotlight client

To run your account we hold:

  • Your business details, and the name, email and phone number of the people we deal with
  • Your personal mobile number, email address and business address, where you gave them for text-message registration. American phone carriers require a real person behind a business that sends texts. We ask for the last four digits of your EIN and never the whole number.
  • Your licence number, if you gave us one to put on your site
  • What you told us in your setup form, and anything you have written to support
  • Payment records: amounts, dates, and the reference numbers our payment processor gives us. We never see or store your full card number or bank account number. Those live with Stripe.
  • Photos you send us of your work

Your customers’ data is yours

The enquiries your site produces belong to you. You can export the lot as a spreadsheet from your account page at any time, and you keep that export if you leave.

06Who else sees any of this

We use a small number of companies to actually run the service. Each gets only what it needs to do its job.

We also share information where the law requires it, and if the business is ever sold the records would transfer with it.

07How long we keep it

Plainly: we do not currently delete things on a schedule. Records stay until somebody asks us to remove them, or until we no longer have a reason to hold them. We would rather say that than publish a retention period we do not actually enforce.

Some things we keep deliberately, and it is worth knowing which:

  • Records of who did what inside our own systems.Security and audit logs are append-only by design. That is what makes it possible to answer “who changed this” honestly.
  • Submissions we marked as spam.Kept so that anything left out of a client’s counts can still be produced.
  • Monthly reports. Frozen when generated and never recalculated, so a report you were sent in March still says in October what it said in March.

Call recordings are held under our account with Twilio and are governed by that account’s retention settings rather than by anything on our side.

08Getting a copy, or getting it deleted

Email privacy@spotlightbuilt.com and tell us what you want. You can ask us to send you a copy of what we hold about you, to correct something wrong, or to delete it.

We answer within 5 business days and complete the request within 30 days. We will ask you to confirm you are who you say you are, usually by replying from the email address or phone number on the record, because handing somebody else’s details to the wrong person is the failure that matters most here.

Full detail on what happens and what we cannot remove is on the deleting your data page.

If you are a Spotlight client, you can export your enquiry data yourself from your account page at any time without asking us.

09How it is protected

  • Everything travels over an encrypted connection, and our database is encrypted where it is stored
  • Sign-in links to client accounts are single-use and expire after 30 minutes
  • We store a scrambled version of sign-in tokens, never the token itself
  • Card and bank details never touch our systems; Stripe holds them
  • Access to client accounts is limited to the people who need it, and every administrative action is logged

As noted in section 5, photos you upload are stored privately and are served only after we have checked who is asking. The exception is a photo we have placed on your site, which is public because your site is.

10Children

Nothing we run is aimed at children, and we do not knowingly collect information from anyone under 13. If you believe a child’s information reached us, email us and we will delete it.

11Changes to this policy

When this changes, the date at the top changes with it. If a change materially affects how we handle a client’s information, we tell them rather than relying on them noticing a new date.