Privacy Policy
Last updated: 30 March 2026
This privacy policy explains how Bontra collects, uses, and protects your personal data when you sign up to our waitlist. This is a pre-launch privacy policy covering waitlist data collection only. It will be replaced with a full product privacy policy when Bontra launches.
1. Controller Identity
Bontra is operated by Harry McAlister (Data Controller and Data Protection Officer). You can contact us at [email protected].
2. What Data We Collect
When you sign up to the Bontra waitlist, we collect:
- All signups: Email address and an optional free-text message
- Candidates: Full name (optional), current/most recent job title (optional), current employer (optional)
- Companies: Full name, job title, company name
- Technical data: Your IP address at the time of signup (for consent audit trail), timestamp of consent
3. Why We Collect This Data
We collect your data to:
- Notify you when Bontra launches and send you an invitation to create an account
- Understand our early user base and the insurance recruitment market
- Prioritise outreach based on role type and signup category
4. Lawful Basis
We process your waitlist data based on your consent (Article 6(1)(a) UK GDPR). You give consent by submitting the waitlist signup form. The consent notice is displayed alongside the submit button. You may withdraw your consent at any time by contacting us (see section 10).
Website analytics and error monitoring are processed under legitimate interest (Article 6(1)(f) UK GDPR). Our legitimate interest is maintaining a functional website and understanding aggregate usage patterns to improve the service. We use cookieless analytics (no persistent identifiers stored on your device) to minimise the impact on your privacy.
5. How We Store Your Data
Your data is stored in a PostgreSQL database hosted on Railway (US-based infrastructure provider). The UK-US Data Bridge provides adequacy for transfers of personal data from the UK to the US, ensuring your data is protected to UK GDPR standards.
Data is encrypted in transit (TLS) and at rest. Access is restricted to authorised personnel only.
6. Data Retention
Waitlist data is retained until 6 months after Bontra launches. If you do not create a Bontra account within that period, your waitlist data will be permanently deleted. If you do create an account, your data will be governed by the full product privacy policy (which you will be asked to consent to separately).
7. Who Has Access
Only Harry McAlister and George Shirley (co-founders of Bontra) have access to waitlist data. No other employees, contractors, or third parties have access to individual signup records.
8. Third Parties
We share your data with the following third parties, strictly for operational purposes:
- Railway - hosting and database infrastructure (US)
- Resend - email delivery (when emails are sent, e.g., launch invitations)
- PostHog - website analytics and error monitoring (EU — Frankfurt, Germany). We use PostHog to understand how visitors use our website (e.g., which pages are visited) and to detect technical errors. PostHog operates in cookieless mode on our site — no cookies or persistent identifiers are stored on your device. Data collected includes pages visited, browser type, device type, and referral source. No personally identifiable information from your waitlist signup is sent to PostHog. Analytics data is stored in the EU and does not leave the European Economic Area.
We do not share your data with any other third parties.
9. Your Rights
Under UK GDPR, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict processing
- Data portability - receive your data in a structured format
- Withdraw consent at any time
To exercise any of these rights, email [email protected].
10. How to Request Deletion
To have your waitlist entry deleted, email [email protected] with the subject line "Waitlist deletion request". We will delete your data within 30 days and confirm by email.
11. No Selling of Data
We will never sell your personal data to third parties. Your data is used solely for the purposes described in this policy.
12. Updates to This Policy
This privacy policy may be updated when the full Bontra product launches. When you create your account, you will be asked to review and consent to the updated privacy policy. We will not apply any new terms retroactively without your explicit consent.
13. Complaints
If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's data protection authority.