Privacy Policy
Last updated: [DATE]
1. Who we are
This policy explains how JustAsk.com ("JustAsk", "we", "us", "our"), branded Elevate — Your Personal Concierge, collects and uses personal data when you use our website and app to submit, track, and pay for purchase requests.
We are the "data controller" for the personal data described in this policy — see "How to contact us" at the end of this page for privacy questions or to exercise your rights.
2. What we collect
We only collect what we need to source, quote, pay for, and deliver your requests, plus the minimum needed to run an account and keep the service secure.
| Data | When |
|---|---|
| Your name | Every request, whether you're signed in or a guest |
| Your email address | Optional on a guest request (for order updates); required if you create an account |
| Account password | If you create an account — stored as a salted hash, never in plain text |
| Item details you provide | What you'd like us to source: description, product link/details, quantity, budget preference, and any notes |
| Recipient name and delivery address (including postcode) | Every item, so it can be delivered — the recipient doesn't need to be you |
| Requested delivery date and speed | Every item |
| Messages you send us in-app | If you message us about an order |
| Payment information | Handled directly by our payment processor, Stripe — see section 4. We don't receive or store your full card details ourselves. |
| Push notification subscription details | Only if you opt in to push notifications for an order, via your browser or device |
| IP address | Used only to rate-limit the FAQ chat assistant and protect against abuse |
| Basic device/technical information (browser type, device type) | Automatically, as part of normal web/app requests |
3. How we use it
- To source items and prepare quotes for your requests
- To take payment and confirm your order
- To arrange delivery, including sharing recipient and address details with the courier or supplier fulfilling that specific item
- To keep you updated on your request or order — by email, in-app message, or push notification if you've enabled it
- To let you sign in and track requests across devices, if you create an account
- To answer questions through our FAQ chat assistant
- To detect and prevent fraud, abuse, and misuse of the service
Our legal basis for most of this is that it's necessary to perform the contract with you — sourcing, quoting, taking payment, arranging delivery, and running your account all fall under this. Detecting fraud and abuse (including rate-limiting the chat assistant) relies on our legitimate interest in keeping the service secure and working properly. Push notifications rely on your consent, since you opt in separately for each order.
4. Who we share it with
We don't sell your personal data. We share it only where it's needed to run the service:
- Stripe (our payment processor) — handles your payment directly; we don't see or store your full card number.
- The supplier or courier fulfilling a specific item — only the recipient's name, delivery address, and what's being delivered, as needed to complete that delivery.
- Anthropic (maker of the Claude AI models) — when our team uses the sourcing tool to help find an item, the item description is sent to Claude's web search to help find real, current options. If you use the in-app FAQ chat assistant, the text of your questions is sent to Claude to generate an answer. Neither use sends your name, email, address, or payment details.
- Push notification infrastructure (e.g. Apple, Google, or Mozilla's push services, depending on your browser or device) — only if you opt in to push notifications for an order; this is how your browser/device actually delivers the notification.
Postcode lookup (autocompleting your address from a postcode) isn't currently switched on. If we turn it on in future, we'll use a licensed UK address-data provider and update this section to name them before doing so.
Stripe and Anthropic both process some data outside the UK/EEA (in the US). Both have data processing agreements in place incorporating the UK International Data Transfer Addendum and EU Standard Contractual Clauses, which is the standard legal safeguard for this kind of transfer.
5. How long we keep it
We keep:
- Order and payment records for 6 years after the end of the tax year they relate to, in line with UK tax record-keeping requirements.
- Account details for as long as your account is active, and for 3 years after your last sign-in if it becomes dormant, after which we delete or anonymise it.
- Guest requests (not tied to an account) for 12 months after the request is completed or cancelled, then delete them.
6. Cookies and local storage
We don't use tracking or advertising cookies. The app stores a small amount of information directly in your browser or device (not as a traditional cookie) to make it work:
- A sign-in token, if you're signed in, so you don't have to log in again on every visit
- A note that you're using "guest mode," and the IDs of guest requests you've submitted, so you can find them again on the same device
- Your light/dark theme preference
- Items you've added to your basket but not yet submitted
None of this is shared with third parties for advertising purposes. Clearing your browser's site data will remove it.
7. Your rights
Under UK data protection law, you have the right to:
- Ask what personal data we hold about you, and get a copy of it
- Ask us to correct inaccurate data
- Ask us to delete your data, where we're not required to keep it (for example, for tax records)
- Ask us to restrict or object to certain processing
- Ask for your data in a portable format
- Complain to the Information Commissioner's Office (ICO) at ico.org.uk if you're unhappy with how we've handled your data
To exercise any of these, use the contact details at the end of this page.
8. Children
This service is not directed at, and should not be used by, anyone under 18.
9. Keeping your data secure
We take reasonable technical and organisational steps to protect your data:
- Passwords are stored as salted, one-way hashes — never in plain text, and never visible to our staff.
- We never see or store your full card details ourselves — payment is handled directly by Stripe.
- All traffic to and from the app is encrypted (HTTPS).
- Signed-in sessions expire automatically rather than staying valid indefinitely, and a password reset signs out any other device using that account.
10. Changes to this policy
We may update this policy from time to time, for example as the service changes. We'll update the date at the top of this page when we do.