This Privacy Policy describes how NQM Studio Ltd (“NQM Studio,” “we,” “us,” “our”) collects, uses, shares, and protects personal data when you visit our websites or use the products and services operated by us, including TrackRev (trackrev.io), Contant (contant.io), and the Linstagrow agency (linstagrow.com).
We are committed to handling personal data in accordance with the United Kingdom General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and where applicable the EU General Data Protection Regulation (EU GDPR).
1. Who we are
NQM Studio Ltd is a private limited company registered in England & Wales under company number 16935115. We are the data controller for personal data we collect through our corporate website and the products listed in section 2.
Registered office: 128 City Road, London, EC1V 2NX, United Kingdom.
Data-protection contact: maruf@nqmstudio.uk.
2. Scope of this policy
This policy applies to personal data processed by NQM Studio Ltd through:
- The corporate website at nqmstudio.uk.
- TrackRev — our link-attribution and affiliate platform at trackrev.io.
- Contant — our SaaS product at contant.io: an operating system for LinkedIn creators.
- Linstagrow — our growth agency at linstagrow.com.
- Our email, support, and sales communications.
Where a product publishes a more specific privacy notice on its own website, that product-level notice supplements (and, in case of conflict, overrides) this policy for that product.
3. What personal data we collect
3.1 Information you provide
- Account data: name, business name, email address, hashed password, profile picture if uploaded, role/job title.
- Billing data: billing name, billing address, tax/VAT identifier, last 4 digits of payment card, card brand, country of card issuance. We do not store full payment card numbers. These are processed directly by our payment providers (see section 6).
- Support & communications: the content of emails, chat messages, and tickets you send to us.
- Onboarding answers: business type, use case, and similar questionnaire responses.
3.2 Information we collect automatically
- Device & usage data: IP address, device type, operating system, browser, referrer, pages visited, features used, timestamps.
- Cookies and similar technologies: see section 10.
- Server logs: request metadata required to operate, secure, and debug the services.
3.3 Information from third parties
- Payment providers share limited billing metadata back to us (e.g. subscription status, charge success/failure, dispute notifications).
- Single sign-on providers (e.g. Google), if you choose to sign in with them, share basic profile information.
- Fraud-prevention services may share risk signals about an IP or device.
4. How we use personal data
We use personal data only for the purposes described below. We do not sell personal data, and we do not use customer data to train general-purpose AI models.
- Provide and operate the services — create and maintain your account, deliver the features you use, store your settings.
- Billing and payments — charge subscriptions, prevent fraud, comply with tax and accounting obligations.
- Customer support — respond to questions, troubleshoot issues, send service notifications.
- Service improvement — analyse aggregated, de-identified usage data to improve performance and features.
- Security and abuse prevention — detect and prevent unauthorised access, fraud, and breaches of our acceptable-use policy.
- Marketing — send product updates and offers to existing customers, with an unsubscribe option in every email. We obtain consent before sending marketing emails to non-customers where required by law.
- Legal compliance — comply with UK and other applicable laws, regulations, court orders, and lawful requests from authorities.
5. Legal bases for processing (UK GDPR Article 6)
| Activity | Legal basis |
|---|---|
| Providing the contracted service to you | Performance of a contract (Art. 6(1)(b)) |
| Billing and tax records | Contract & legal obligation (Art. 6(1)(b) & (c)) |
| Customer support | Contract / legitimate interests |
| Service improvement & analytics | Legitimate interests (improving the product), balanced against your rights |
| Marketing to existing customers | Legitimate interests, with opt-out (soft opt-in under PECR) |
| Marketing to non-customers | Consent |
| Fraud and security | Legitimate interests & legal obligation |
| Responding to legal requests | Legal obligation |
6. Who we share personal data with
We share personal data only with the categories of recipients listed below, under appropriate contractual safeguards.
- Payment processors — Stripe Payments UK Ltd (FCA-authorised, for UK card processing), Stripe Payments Europe Ltd (Ireland, for EEA card processing), Stripe, Inc. (United States, for global and Connect platform services), Paddle.com Market Ltd, and Lemon Squeezy by Tartan Equity LLC. They process payments, manage subscriptions, and operate Stripe Connect payouts to affiliates where applicable.
- Hosting and infrastructure — Vercel Inc. (United States, with EU/UK edge regions) for application hosting and content delivery; Supabase Inc. (EU- or US-region managed Postgres, configurable per product) for database and authentication.
- Email and communications — transactional and support email is delivered through reputable email service providers.
- Analytics — we use privacy-preserving analytics to understand aggregate usage. We do not use analytics services that build cross-site advertising profiles of you.
- Professional advisors — accountants, auditors, and lawyers, bound by duties of confidentiality.
- Authorities — where required by law, court order, or to protect the rights, property, or safety of NQM Studio, our customers, or others.
- Successors — in connection with a merger, acquisition, or sale of assets, subject to confidentiality and continued application of equivalent privacy protections.
A full, up-to-date sub-processor list with regions and DPA references is available on request from maruf@nqmstudio.uk. We give business customers reasonable advance notice of material sub-processor changes.
7. International transfers
Some of our service providers are located outside the United Kingdom — principally in the European Economic Area (EEA) and the United States. Where personal data is transferred outside the UK, we rely on one or more of the following safeguards:
- UK adequacy regulations (for transfers to the EEA and other adequate jurisdictions).
- The UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs).
- The UK extension to the EU–US Data Privacy Framework, where the recipient is self-certified.
A copy of the safeguards in place for a specific transfer is available on request to maruf@nqmstudio.uk.
8. How long we keep personal data
We retain personal data only for as long as is necessary for the purposes for which it was collected, including legal, accounting, or reporting requirements.
- Account data: for the duration of your account, and for a reasonable period after closure (typically up to 24 months) to allow account re-activation and to resolve disputes.
- Billing & tax records: 6 years after the end of the relevant financial year, as required by UK tax law.
- Support records: typically 2 years after the last interaction.
- Marketing preferences: until you unsubscribe, plus a suppression record so we honour your preference.
- Server logs: typically up to 90 days, longer where required for security investigations.
9. Your rights under UK GDPR
Subject to the conditions in the UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete personal data.
- Erase personal data (the “right to be forgotten”), in defined circumstances.
- Restrict processing of your personal data.
- Object to processing based on legitimate interests, including direct marketing.
- Data portability — receive your data in a structured, machine-readable format.
- Withdraw consent at any time, where processing is based on consent.
- Not be subject to a decision based solely on automated processing that has legal or similarly significant effects on you.
To exercise any of these rights, email maruf@nqmstudio.uk. We will respond within one month, as required by UK GDPR. We may need to verify your identity before processing your request.
10. Cookies and similar technologies
We use cookies and similar technologies for the following purposes:
- Strictly necessary — authentication, session management, security, and load balancing. These cannot be disabled.
- Functional — remembering preferences (e.g. UI settings).
- Analytics — understanding aggregate usage of our websites and products. Where required, we ask for your consent before setting these cookies.
- Attribution — in TrackRev specifically, our customers use first-party cookies (such as a visitor identifier) to attribute conversions. The customer is the controller of that data.
You can manage cookies through your browser settings. Blocking some cookies may affect the functionality of our services.
11. Security
We use technical and organisational measures designed to protect personal data, including:
- Encryption in transit (TLS) and at rest.
- Role-based access controls and least-privilege principles for internal access.
- Vendor due diligence and contractual data-protection commitments.
- Regular software updates and dependency monitoring.
- Incident response procedures and breach notification.
No method of transmission or storage is 100% secure. Please use a strong, unique password and enable any account-protection features we offer.
12. Children
Our services are not directed to children under 16, and we do not knowingly collect personal data from children under 16. If you believe we have collected personal data from a child, please contact us so we can delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page reflects the latest revision. For material changes, we will provide reasonable notice (for example, by email to account holders or a prominent notice on our website) before the changes take effect.
14. Contact us & the right to complain
For any privacy question, request, or complaint, please contact:
- Email: maruf@nqmstudio.uk
- Phone: +44 7456 339 125 (Mon–Fri 09:00–18:00 UTC)
- Post: Data Protection, NQM Studio Ltd, 128 City Road, London EC1V 2NX, United Kingdom
You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at any time:
https://ico.org.uk/make-a-complaint/ — helpline 0303 123 1113.
ICO registration: registration with the UK Information Commissioner’s Office is in progress; the registration number will be added to this policy on confirmation.
