Stellora Intelligence
Privacy Policy
Last updated: August 2026
If you have questions about this policy please contact us at stelloradata.com/contact
This Privacy Policy explains how Stellora Intelligence collects, uses, stores, and protects your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
Stellora Intelligence is a business intelligence platform for women's sport sponsorship analytics, operated as a sole trader business in the United Kingdom.
For the purposes of UK GDPR, Stellora Intelligence is the Data Controller for personal data collected through the platform at stelloradata.com.
| Detail | Information |
|---|---|
| Business name | Stellora Intelligence |
| Website | stelloradata.com |
| Contact email | Via stelloradata.com/contact |
| Country of operation | United Kingdom |
| Data Controller | Stellora Intelligence (sole trader) |
2. What data we collect
2.1 — Account and contact data
When you request access to Stellora or when an account is created for you by our team we collect:
- Full name
- Email address
- Organisation name (club, brand, or agency)
- Role or job title
- Contact telephone number (if provided)
2.2 — Payment and billing data
We use Stripe to process all payments. When you subscribe to Stellora:
- Your payment is processed directly by Stripe — we do not store your card number, CVV, or full payment details on our systems
- We receive and store: your Stripe customer ID, subscription ID, subscription tier, billing period, and payment status
- Stripe may collect additional data as their own data controller — see Stripe's privacy policy at stripe.com/privacy
2.3 — Platform usage data
As you use the Stellora platform we collect:
- Match data you or your club submits (dates, opponents, attendance figures, competition details)
- Sponsorship exposure data (asset types, duration, visibility, calculated values)
- Social media metrics you submit or that are collected via connected accounts (follower counts, post impressions, engagement rates)
- Video files uploaded for logo detection analysis
- Reports generated and sent
- Log data including IP address, browser type, pages visited, and timestamps
2.4 — Social media data
If you connect your social media accounts to Stellora via OAuth we collect:
- Platform account identifiers and display names
- Follower and subscriber counts
- Post reach, impressions, and engagement metrics
- Access tokens (stored securely and used only to retrieve your data)
We collect this data only from accounts you explicitly authorise. We never post to your accounts or access data beyond what you permit.
2.5 — Market research data
Stellora maintains a market research database of publicly available information about women's sport properties and sponsorship deals. This database may include:
- Public information about sports clubs and properties sourced from official announcements, league websites, and reputable trade publications
- Publicly disclosed sponsorship deal values from press releases and media reports
- Aggregated and anonymised benchmarking data
This data is sourced entirely from public information and does not include private or confidential commercial arrangements without explicit consent.
2.6 — Communications data
When you contact us via the contact form or by email we collect your name, email address, and the content of your message.
2.7 — Cookie data
We use cookies and similar technologies on our website. Please see our Cookie Policy for full details.
3. Why we collect your data
3.1 — Lawful bases under UK GDPR
We rely on the following lawful bases to process your personal data:
| Purpose | Lawful basis |
|---|---|
| Providing the Stellora platform and services | Contract — processing is necessary to perform our contract with you |
| Processing subscription payments via Stripe | Contract — necessary to fulfil the subscription agreement |
| Sending service emails (payment confirmations, reports) | Contract — necessary to fulfil our obligations |
| Responding to enquiries and discovery call requests | Legitimate interests — to communicate with prospective customers |
| Improving the platform and fixing bugs | Legitimate interests — to maintain and develop our services |
| Security and fraud prevention | Legitimate interests — to protect our systems and users |
| Complying with legal obligations | Legal obligation — where required by law |
| Marketing communications (if you have consented) | Consent — only where you have explicitly opted in |
4. Who we share your data with
4.1 — Third party processors
We share your data with carefully selected third party processors who help us deliver the Stellora service. All processors are bound by data processing agreements and may only use your data as instructed by us.
| Processor | Purpose and data shared |
|---|---|
| Supabase (Supabase Inc, USA) | Database hosting and authentication. All platform data is stored on Supabase infrastructure. Data is encrypted at rest and in transit. Supabase processes data under Standard Contractual Clauses for international transfers. |
| Stripe (Stripe Inc, USA) | Payment processing. Receives billing contact details and processes subscription payments. Stripe is an independent data controller for payment data. See stripe.com/privacy. |
| Resend (Resend Inc, USA) | Transactional email delivery. Receives recipient email addresses and email content to deliver system notifications, reports, and confirmations. |
| Anthropic (Anthropic PBC, USA) | AI processing for video logo detection, Ask Stellora queries, and content analysis. Video frames and text queries are sent to Anthropic's API for processing. Data is not used to train Anthropic's models under our API agreement. |
| Google (Alphabet Inc, USA) | Google Analytics integration and YouTube OAuth. Used only when you explicitly connect your Google account. Governed by Google's privacy policy. |
| Meta Platforms (Meta Inc, USA) | Instagram and Facebook OAuth integration. Used only when you explicitly connect your social media accounts. |
| Mailchimp (Intuit Inc, USA) | Mailchimp OAuth integration. Used only when you explicitly connect your Mailchimp account to sync email campaign statistics. |
4.2 — International transfers
Several of our processors are based in the United States. We ensure appropriate safeguards are in place for all international transfers of personal data, including Standard Contractual Clauses approved by the UK Information Commissioner's Office where applicable.
4.3 — We do not sell your data
Stellora Intelligence does not sell, rent, or trade your personal data to any third party for their own marketing or commercial purposes.
4.4 — Legal disclosure
We may disclose your data to law enforcement or regulatory authorities where required to do so by law, court order, or to protect our legal rights.
5. How long we keep your data
| Data type | Retention period |
|---|---|
| Account data (name, email, organisation) | Duration of your subscription plus 2 years after account closure |
| Match and exposure data | Duration of your subscription plus 2 years |
| Payment records | 7 years (required for UK tax and accounting purposes) |
| Video files uploaded for analysis | Deleted automatically after analysis completes (typically within 24 hours) |
| Video frame extractions | Deleted immediately after AI analysis (temporary processing only) |
| Social media access tokens | Until you disconnect the account or your subscription ends |
| Contact and enquiry data | 2 years from last contact |
| Cookie consent records | 1 year from consent date |
| Log and security data | 90 days |
When your account is closed we will delete or anonymise your personal data within 60 days unless we are required to retain it for legal or tax purposes.
6. Your rights under UK GDPR
You have the following rights regarding your personal data:
| Right | What it means |
|---|---|
| Right of access | You can request a copy of all personal data we hold about you |
| Right to rectification | You can ask us to correct inaccurate or incomplete data |
| Right to erasure | You can ask us to delete your data where there is no legitimate reason to keep it |
| Right to restrict processing | You can ask us to limit how we use your data in certain circumstances |
| Right to data portability | You can ask for your data in a structured, machine-readable format |
| Right to object | You can object to processing based on legitimate interests |
| Right to withdraw consent | Where we rely on consent you can withdraw it at any time |
| Right to complain | You can complain to the ICO at ico.org.uk if you believe we have breached your rights |
To exercise any of these rights contact us using the form at stelloradata.com/contact. We will respond within 30 days.
7. Data security
We take the security of your data seriously and implement appropriate technical and organisational measures including:
- All data encrypted in transit using TLS
- All data encrypted at rest by our hosting provider
- Row-level security policies restricting data access to authorised accounts only
- API keys and secrets stored securely and never exposed in client-side code
- Access to the admin platform restricted to authorised personnel only
- Regular security checks using automated testing
In the event of a data breach that is likely to result in a risk to your rights and freedoms we will notify you and the ICO within 72 hours of becoming aware of the breach.
8. Children's data
Stellora is a business-to-business platform intended for use by organisations and their representatives. We do not knowingly collect data from individuals under the age of 18. If you believe a minor has provided data to us please contact us immediately.
9. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify active subscribers of any material changes by email at least 30 days before they take effect. The current version is always available at stelloradata.com/privacy.
10. Contact us
For any questions about this Privacy Policy or to exercise your data rights please contact us at stelloradata.com/contact. We aim to respond to all enquiries within 5 working days.
If you are not satisfied with our response you have the right to complain to the Information Commissioner's Office (ICO): ico.org.uk · Helpline: 0303 123 1113