← BabyNamedBaby

Privacy Policy

Privacy Policy

BabyNamedBaby — privacy policy

Effective: 20 June 2026 · Last updated: 20 June 2026 · Template — review with counsel before relying on it.

BabyNamedBaby ("we", "us") provides a private baby-name registry for couples. This policy explains what personal data we collect, why, the legal bases we rely on, who we share it with, how long we keep it, and the rights you have under UK and EU GDPR.

0. Who we are (data controller)

[TODO: Legal entity name], of [TODO: registered address], [TODO: country], is the data controller for personal data processed through BabyNamedBaby. Contact us at privacy@babynamedbaby.com. We have not appointed a Data Protection Officer; privacy requests are handled by the founders.

1. Data we collect

Account data: email address, optional display name, and authentication identifiers.

Registry content: the baby names you and your partner add, your reactions, vetoes, comments, and which name you select as your final choice.

Cohort relationships: the invite link you used to join a partner or village.

Billing data (Premium only): handled by Stripe. We never see or store full card numbers.

Technical data: error reports, basic usage events, and the minimum logs needed to keep the service running securely.

2. How we use it & the legal basis

  • Operate the registry, matches and cohort sharing — performance of our contract with you (UK/EU GDPR Art. 6(1)(b)).
  • Discover AI name suggestions — contract (you ask us to generate them). Prompts contain the preferences you type; we do not send your partner's identity. Providers do not use your prompts to train their models.
  • Premium billing — contract and legal obligation (tax/accounting records).
  • Service security, abuse prevention, error logs, audit log of admin actions — our legitimate interest in running a safe service (Art. 6(1)(f)).
  • Product analytics (PostHog) — legitimate interest where allowed, or your consent where required. See the Cookies page.
  • Transactional and lifecycle email — contract; you can opt out of non-essential email at any time.

We do not carry out solely-automated decisions that produce legal or similarly significant effects about you (Art. 22).

3. Who we share it with (sub-processors)

We use a small number of vetted processors to run the product. The current list, with purpose and country, is published at /subprocessors and is updated when it changes.

We do not sell your data. We do not show advertising. We do not share your registry content outside your cohort.

4. International transfers

Some processors are located outside the UK / EEA (for example Stripe and our AI model providers in the United States). Where transfers occur, we rely on the UK International Data Transfer Addendum and/or the EU Standard Contractual Clauses with supplementary measures (encryption in transit and at rest, access controls). The per-processor location is listed on the Subprocessors page.

5. How long we keep it

  • Account and registry data: while your account is active. Deleted within 30 days of account deletion.
  • Billing records (invoices, tax data): retained 6 years after the relevant tax year, as required by HMRC and equivalent EU rules.
  • Admin audit log: retained 24 months in pseudonymised form (no email, no name) after a user is erased, to meet our accountability obligations under Art. 5(2).
  • Error and security logs: retained 30 days.
  • Aggregated/de-identified metrics: retained indefinitely (no longer personal data).

6. Your rights

Under UK/EU GDPR you have the right to access, rectify, erase, port, and restrict the processing of your personal data, and to object to processing based on legitimate interests. The fastest way to use most of these rights is the Privacy & your data panel on your Profile page — "Request my data" generates a machine-readable export, "Request account deletion" triggers automated erasure. We respond to all requests within 30 days.

If you are unhappy with how we have handled your data, you can complain to your local supervisory authority — in the UK, the Information Commissioner's Office (ICO).

7. Security & breach notification

Data is encrypted in transit (TLS) and at rest by our managed backend. Access is gated by row-level security and audited. See our Security page for detail. If a personal-data breach is likely to result in a risk to your rights and freedoms we will notify the relevant supervisory authority within 72 hours (Art. 33) and, where the risk is high, notify you directly without undue delay (Art. 34).

8. Children

BabyNamedBaby is intended for adults choosing a name for a future child. The service is not directed at children under 16, and we do not knowingly collect their data.

9. Changes to this policy

If we make material changes we will email registered users and update the "Last updated" date above. Continued use of the service after the change means you accept the updated policy.

10. Contact

Privacy questions or requests: privacy@babynamedbaby.com. Business users who need a Data Processing Addendum (DPA) can request one at the same address.