Privacy
This is the practical version: what Rose-Brook stores, why it stores it, which processors are involved, and how to make a privacy request.
Data room summary
The app keeps account, hotel, audit, and billing status data so the workspace works properly. Stripe handles card details for checkout and subscription billing.
Card data
Handled by Stripe
Processors
Named in plain English
Requests
Routed through support
Evidence held
Rose-Brook stores the operational material needed to keep account access, hotel setup, benchmark history, billing status and support follow-up connected.
Questions or requests
Submit a support request and select Privacy / data request for privacy questions, access requests, correction requests, or deletion requests.
Use the support form
Rose-Brook will respond using the email address you provide in the request.
Submit a privacy requestFor the service rules around billing and access, read the terms.
Data we collect
01Rose-Brook stores account and contact details, hotel or company details, competitor and audit inputs, benchmark results, support messages, billing/subscription references from Stripe, and first-party acquisition data such as campaign parameters, a pseudonymous browser visitor ID, page and signup milestones, email preference status, and lifecycle-email delivery events. Technical logs and Vercel analytics may be used to keep the service reliable and secure.
Why we use it
02We use this data to provide the service, run benchmarks, manage accounts and subscriptions, send requested transactional emails, understand which public benchmark content leads to signup and activation, send lifecycle or benchmark updates only where the recipient opted in, suppress messages after unsubscribe, bounce or complaint events, improve reliability and security, and respond to support or privacy requests.
Lawful basis
03For UK GDPR purposes, the usual bases are contract for providing paid or requested services, legitimate interests for security and service improvement, consent where a non-essential preference or communication requires it, and legal obligation where records must be kept.
Payments
04Payments are handled by Stripe. Rose-Brook stores Stripe customer, subscription and billing-status references, but card details are handled by Stripe rather than stored in the app.
Processors
05The service uses Supabase for authentication, application data, acquisition attribution and email preferences; Vercel for hosting and analytics; Stripe for billing; Resend for transactional and opted-in lifecycle email, delivery events and suppression signals; and OpenAI or other configured AI model providers when benchmark prompts are sent for analysis. Rose-Brook also stores limited first-party public page and activation telemetry in Supabase for service and campaign insight.
Retention
06Workspace, benchmark, attribution and billing-status records are kept while needed to operate the service, preserve audit history, measure campaigns, meet legal obligations and handle support. Unsubscribe and delivery-suppression records may be retained so Rose-Brook does not send further marketing to that address. Submit a support request and select Privacy / data request for access, correction or deletion requests.
Your rights
07You can ask for access, correction, deletion, restriction, objection or portability where those rights apply. You can also complain to the UK Information Commissioner's Office if you are unhappy with how a request is handled.
Company details
AI benchmark data
Benchmark prompts may include hotel names, competitor names, location context, and commercial positioning details. When a model provider is enabled, that benchmark context is sent to the provider so Rose-Brook can capture and analyse the response.