Legal
Privacy Policy
Last updated: 18 July 2026
Plain English summary
- — Your account data is stored in the EU (Frankfurt) and only you can read it.
- — The client data you enter is yours — we don't read it, sell it, or use it to train AI.
- — We use three sub-processors: Supabase (database), Vercel (hosting), and Google Workspace (email).
- — We don't use tracking or advertising cookies — only the session cookie needed to keep you logged in.
- — Email privacy@shardwell.io any time for a full export or deletion of your data.
1. Who we are
Shardwell is operated by 1Lab.io Ltd(“Shardwell”, “we”, “us”). For your account data (name, email, jurisdiction, subscription status), Shardwell is the Data Controller. For the client, engagement, proposal, and invoice data you enter into the platform, Shardwell acts as your Data Processor — you remain the controller of that data.
2. What we collect
- Account data: name, email address, password (hashed), jurisdiction, subscription and billing status.
- Content you enter: clients, leads, engagements, proposals, invoices, evidence trail entries, and practice profile content.
- Payment data: handled directly by Stripe — we store a Stripe customer reference, not your card details.
- Technical data: IP address and basic request logs, retained only as long as needed for security and abuse prevention.
3. How we use it
We use your data only to:
- Provide and maintain the Service, including your engagement and evidence records;
- Send transactional emails (welcome, trial reminders, payment and invoice notices, proposal-viewed alerts) — never your client content;
- Process payments and manage your subscription;
- Maintain security and prevent abuse of the Service.
We do not sell your data, and we do not use your account or client data to train shared AI models or to improve outputs for other users.
4. Legal basis for processing
We process your account data under contract (to provide the Service you signed up for) and, for security logging, under legitimate interest. Where you are in the EU or UK, you have the rights described in Section 7 regardless of the legal basis used.
5. Sub-processors
We share data with the following sub-processors, each acting under a data processing agreement:
- Supabase — database and authentication, hosted in the EU (Frankfurt).
- Vercel — application hosting and serverless functions.
- Google Workspace — transactional email delivery. Only your name and email address are shared — never engagement or client content.
- Stripe — payment processing. Stripe receives your billing details directly; we never see your full card number.
We will update this list and notify existing users by email before adding a new sub-processor that would materially change how your data is handled.
6. International transfers
Your account data is stored in the EU. If you are in the US or another jurisdiction outside the UK/EEA, using the Service involves a transfer of your account data to the EU, and any transfer of data back to a sub-processor outside the UK/EEA is protected by Standard Contractual Clauses or the UK International Data Transfer Agreement, as applicable.
7. Your rights
Depending on your jurisdiction, you have rights of access, rectification, erasure, restriction, portability, and objection, under the UK GDPR, the EU GDPR, and applicable US state laws including the CCPA/CPRA (California). To exercise any of these rights — including a full export or deletion of your data — email privacy@shardwell.io. We will respond within the timeframe required by the applicable law (generally within one month under UK/EU GDPR).
8. Cookies
We use only strictly necessary cookies — specifically, the authentication session cookie that keeps you logged in. We do not use advertising, analytics, or cross-site tracking cookies.
9. Data retention
We retain your account and engagement data for as long as your account is active, and for a limited period afterward to comply with legal and accounting obligations or to resolve disputes. On request, we will export or delete your data as described in Section 7, except where retention is required by law (for example, financial records related to payments already processed).
10. Security
Data is encrypted in transit (TLS) and at rest. Row-level security is enforced in the database so that no account can read another account's data. Your evidence trail records are append-only — they cannot be edited or deleted, by you or by us, once created.
11. Children's privacy
Shardwell is a B2B tool for independent management consultants and is not directed at, or knowingly used to collect data from, children.
12. Changes to this policy
We may update this policy from time to time. If a change is material, we will notify you by email before it takes effect.
13. Contact
Questions about this policy, or to exercise your data rights: privacy@shardwell.io.
Company details
1Lab.io Ltd
1Lab.io Ltd is a UK private limited company in the process of incorporation with Companies House. Registered office and company number will be added here once incorporation completes.