Privacy policy
Last updated 26 September 2026.
This policy explains how Indawo handles personal data, and your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Who we are
Indawo is operated from the United Kingdom. For the personal data of our own account holders we are the data controller. For the distribution data you upload about your stockists we act as a data processor on your instructions. You can reach us at sales@rienzitech.com.
Data we collect
Account and organisation data
Your name, email address, password (stored only as a hash), organisation name, organisation email, country, and optional telephone, company number and VAT number.
Content you upload
Details of your distribution locations, including business names, addresses, map coordinates and any contact details you choose to record. Where a location is a sole trader this may be personal data, and you remain responsible for having a lawful basis to provide it to us.
Billing data
Subscription status, plan and renewal dates. Card details are entered on Stripe and are never seen or stored by us.
Technical data
Server logs containing IP address, request path and timestamp, and counts of requests made to your embedded map so that we can apply plan allowances.
Why we use it, and our lawful basis
- To provide the service and your account - performance of a contract.
- To take payment and prevent fraud - performance of a contract, and legal obligation for tax records.
- To keep the service secure, diagnose faults and measure usage against plan limits - legitimate interests.
- To reply to enquiries you send us - legitimate interests.
- To send service emails such as email verification and password resets - performance of a contract.
We do not sell personal data, we do not use it for advertising, and we do not carry out automated decision making or profiling.
Cookies
We set one essential cookie, which holds your signed-in session and your light or dark theme choice. It is strictly necessary for the service to work, so it does not require consent. We use no advertising or analytics cookies.
Who we share it with
- Stripe Payments Europe, for subscriptions and payments.
- Our hosting provider, for running the service and storing your data.
- Our email provider, for service emails.
- Map tile providers. If your site uses OpenStreetMap or Google Maps, the visitor browser requests map tiles directly from that provider, which will see the visitor IP address under that provider own privacy policy.
- Public authorities, where we are legally required to disclose information.
Each of these acts under a written contract. Where data is transferred outside the United Kingdom we rely on UK adequacy regulations or the International Data Transfer Addendum to the EU Standard Contractual Clauses.
How long we keep it
- Account and content data, for as long as your account is open.
- After you close your account, up to 30 days in live systems and up to 90 days in backups, then deletion.
- Billing records, six years, to meet UK tax law.
- Server logs, 90 days.
- Contact form messages, 12 months.
Your rights
Under the UK GDPR you have the right to:
- be told how your data is used, and get a copy of it;
- have inaccurate data corrected;
- have data erased, where we have no continuing reason to hold it;
- restrict or object to how we use it;
- receive your data in a portable form;
- withdraw consent, where we relied on consent.
Email sales@rienzitech.com to exercise any of these. We will respond within one month. If you are not satisfied you can complain to the Information Commissioner Office at ico.org.uk or on 0303 123 1113.
Security
Traffic is encrypted in transit, passwords are hashed with Argon2, access to your data is limited to the users you invite to your site, and administrative access is limited to staff who need it.
Children
The service is for businesses and is not intended for anyone under 18.
Changes
If we change this policy we will update the date above, and for significant changes we will email account holders.