Legal / Privacy

Privacy Policy

Last updated 17 September 2026

Who we are

subba.pro is a service operated by Polarize Ltd, a company registered in England and Wales under company number 12944077, with its registered office at 20-22 Wenlock Road, London, England, N1 7GU.

For the purposes of UK data protection law, Polarize Ltd is the data controller for this website and your account data, and our Information Commissioner’s Office registration number is ZA825619. For the contact-form enquiries and bookings we handle on your behalf as a business using subba, we act as your data processor and you remain the controller of your customers’ data.

What we process

Account data: when you sign in with Google we receive your email address, name, and a Google account identifier, which we store to create and secure your account.

Contact-form enquiries: when a visitor submits your form, we process their message to filter spam, classify the enquiry, and draft or send a reply. The submitter’s email is written to our append-only audit log only as a salted hash, never in plaintext; we keep the classification, intent, and status, not the raw message beyond what is needed to process and reply.

End-customer data: when a business uses subba, we hold personal data about that business’s customers on the business’s behalf, as its processor. This includes the name, email, and details of bookings, orders (click-and-collect), quote requests, subscriptions, and store credit. We do this to provide the service to the business; the business is the controller of this data.

Booking and order data: for a booking or order we store the customer name, email, chosen service or items, pickup or appointment time, amount, and status, to make and confirm it and place it in the calendar.

Activity log: we keep an append-only log of service activity (for example emails sent, with the recipient masked, and account changes) to run, support, and secure the service.

Calendar: if you connect Google Calendar, we store a refresh token so subba can create events on your behalf. We request the minimum scope needed (calendar events) and you can disconnect at any time.

Payments: booking payments are taken through Stripe into your own connected Stripe account, so you are the merchant of record. We store a Stripe customer or connected-account reference and your subscription status. We never see or store card numbers.

Technical data: standard request logs and security signals (such as IP address and rate-limit counters) used to run the service and prevent abuse.

AI processing

Enquiries are processed by a large language model (Anthropic Claude) to classify the enquiry and draft a reply in your business voice, using the knowledge you provide. We do not use your data or your customers’ data to train models, and our AI providers process it only to return a response to us.

Agent and API access

subba exposes a booking API and an MCP server so AI agents can, with a person’s direction, look up your services, check availability, and make a booking. These use the same booking data described above and are subject to the same safeguards; no additional personal data is collected by making subba agent-readable.

Cookies

Nothing non-essential loads until you choose. On your first visit a banner lets you accept all, reject all, or set preferences per category. Your choice is stored in a first-party cookie and recorded via AllowKit, and analytics are governed by Google Consent Mode v2, so tags stay denied until you opt in.

You can change your choice at any time:

CookiePurposeCategoryRetention
subba_consentRemembers your cookie choices so we do not ask againNecessary6 months
subba_sessKeeps you signed in to the dashboard at app.subba.proNecessary30 days
_ga, _ga_*Google Analytics 4: measures how the site is usedAnalyticsUp to 2 years
_clck, _clskMicrosoft Clarity: aggregated session insightsAnalyticsUp to 1 year

We also use local storage for two small values: subba_sid, a random id that links your consent record, and subba_theme, your light or dark preference. These stay on your device and are not sent to advertisers.

Sub-processors

We use the third parties below to process personal data on our behalf, each under its own data-processing terms. The voice and SMS providers apply only when a business uses those add-ons. We will tell you of material changes to this list, and a data processing agreement is available on request.

ProviderWhat they do for us
CloudflareHosting, edge network, database, and the email-sending domain that delivers each business’s customer emails and routes replies
Anthropic (Claude)AI that classifies enquiries and drafts replies, and powers the chat and phone assistant
StripePayment processing and payouts into each business’s own connected Stripe account (we never see card numbers)
BrevoTransactional email and SMS delivery (confirmations, reminders, and payment links)
GoogleSign-in (your account email, name, and an account id); if you connect it, Calendar events; and Google Analytics 4 for consent-gated analytics on this website
VapiRuns the phone assistant for the voice add-on (call handling and AI turns)
TwilioPhone numbers and call connectivity for the voice add-on
DeepgramSpeech-to-text for the phone assistant (voice add-on)
Microsoft (Clarity)Aggregated, consent-gated analytics on this website

Some of these operate outside the UK/EEA; see “International transfers” below for the safeguards that apply.

Legal bases

We rely on: performance of a contract (running the service and your account); legitimate interests (securing the service, preventing spam and abuse, and keeping an audit trail); and consent (analytics and marketing cookies). As a business using subba, you are responsible for the lawful basis to reply to and process your own customers’ data.

Retention

Account, enquiry, booking, order, and activity-log data are kept for the life of your account and for a reasonable period afterwards to meet legal and accounting obligations, then deleted or anonymised. Hashed submitter values cannot be reversed to an address. Draft replies and one-time codes are held only briefly and then expire.

International transfers

Some processors operate outside the UK/EEA. Where they do, transfers are protected by appropriate safeguards such as the UK International Data Transfer Agreement or Standard Contractual Clauses.

Security

API keys are stored only as salted hashes and verified in constant time. Submitter emails are hashed in the audit log. Transport is encrypted, requests are strictly validated and rate limited, sessions are signed, calendar and payment tokens are never exposed to the browser, and the submission log is append-only.

Your rights

You have the right to access, correct, delete, restrict, or object to our use of your personal data, to portability, and to withdraw consent at any time. To exercise any of these, or to opt out, email [email protected] and we will respond within the time the law allows.

End customers: if you are a customer of a business that uses subba and want your data accessed or deleted, you can email [email protected] and we will action it or pass it to that business as the controller.

If you are unhappy with how we have handled your data, you can complain to the Information Commissioner’s Office at ico.org.uk. We would welcome the chance to resolve it with you first.

Children

subba is a business tool and is not directed at children. We do not knowingly collect data from children through this service.

Changes and contact

We may update this policy; the version published here applies from the date shown above. All communications are by email only. Contact [email protected].