Privacy Policy

Last updated: 1 July 2026

This Privacy Policy explains how CapoAI (“CapoAI”, “we”, “us”, “our”) collects, uses, stores, and protects personal data. CapoAI is operated by a sole trader based in the United Kingdom. We are committed to protecting your privacy and handling personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

If you have any questions about this policy or how we handle personal data, contact us at hello@capoai.org.

1. Who we are (Data Controller)

CapoAI is operated by an individual sole trader trading as “CapoAI”, based in the United Kingdom. For the purposes of data protection law, we are the “data controller” for personal data of our account holders (our customers), and — where applicable — a data controller and/or processor for lead data processed through the platform (see Section 6).

Contact for data protection matters: hello@capoai.org

We are registered with (or in the process of registering with) the UK Information Commissioner’s Office (ICO) as required for organisations that process personal data.

2. Scope of this policy

This policy covers:

  • Account holders — businesses and individuals who sign up for and use CapoAI.
  • Lead / prospect data — information about third-party businesses and individuals that our customers upload, import, or generate through the platform for outreach purposes.
  • Website visitors — people who visit capoai.org.

3. What personal data we collect

From account holders, we collect:

  • Name and email address (for account creation and login).
  • Billing information processed through our payment provider, Stripe (we do not store full card details ourselves).
  • Usage data — how you interact with the platform, including campaigns, agents, and outreach activity.
  • Communications you send to us (e.g. support requests).
  • Technical data — IP address, browser type, and device information.

Lead / prospect data processed through the platform may include:

  • Business names, business email addresses, phone numbers, website addresses, and location data.
  • Publicly available business information gathered through data sources and enrichment.

From website visitors, we collect:

  • Basic analytics and technical data (IP address, pages visited, browser type).

4. How we use personal data and our lawful basis

We process personal data on the following lawful bases under UK GDPR:

PurposeLawful basis
Creating and managing your accountPerformance of a contract
Processing payments and subscriptionsPerformance of a contract
Providing platform features (campaigns, agents, outreach)Performance of a contract
Sending you service and account-related emailsPerformance of a contract / legitimate interests
Improving and securing the platformLegitimate interests
Complying with legal and regulatory obligationsLegal obligation
Marketing our own services to you (where you have signed up)Legitimate interests / consent

Where we rely on legitimate interests, we have assessed that our interests do not override your rights and freedoms.

5. Third-party services and data sharing

To operate CapoAI, we share personal data with trusted third-party providers who act as our processors or sub-processors. These include:

  • Supabase — database and authentication hosting.
  • Vercel — application hosting.
  • Stripe — payment processing.
  • Resend — transactional and outreach email delivery.
  • Twilio — SMS and messaging delivery.
  • Google — Places API (business lead data) and Gmail integration (sending outreach on your behalf where you connect your account).
  • AI providers (including Anthropic, OpenAI, and Vapi) — to process content for features such as message generation, lead scoring, and voice/chat agents. Content submitted to these providers is processed to deliver the relevant feature.

We only share the data necessary for each provider to perform its function, and we require providers to protect personal data appropriately. Some providers may process data outside the UK/EEA; where they do, we rely on appropriate safeguards such as adequacy decisions or standard contractual clauses.

We do not sell personal data.

6. Lead data and outreach (important)

CapoAI enables our customers to store business lead data and send outreach communications. In relation to this data:

  • Our customers are responsible for ensuring they have a lawful basis to process the lead data they upload or generate, and for complying with applicable direct-marketing rules (including the Privacy and Electronic Communications Regulations, “PECR”) when sending outreach.
  • Where we process lead data on behalf of a customer, we act as a processor and process that data only as instructed by the customer through the platform.
  • If you have received outreach sent through CapoAI and wish to opt out or have your data removed, please use the unsubscribe option in the message, or contact us at hello@capoai.org and we will assist in routing your request to the relevant sender.

7. How long we keep data

We retain personal data only as long as necessary:

  • Account data — for as long as your account is active, and for a reasonable period afterwards to meet legal, accounting, or reporting requirements.
  • Lead data — for as long as the relevant customer maintains it in their account, subject to their deletion.
  • Billing records — as required by UK tax and accounting law (typically six years).

You can request deletion of your account and associated data at any time (see Section 8).

8. Your rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request erasure of your data (“right to be forgotten”).
  • Restrict or object to processing.
  • Data portability (receive your data in a portable format).
  • Withdraw consent where processing is based on consent.

To exercise any of these rights, contact hello@capoai.org. We will respond within one month.

You also have the right to lodge a complaint with the ICO (ico.org.uk) if you believe we have handled your data unlawfully, though we would appreciate the chance to address your concerns first.

9. Data security

We take appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, row-level security on our database, and signed/verified webhooks for payment processing. No system is completely secure, but we work to protect data against unauthorised access, loss, or misuse. In the event of a personal data breach that poses a risk to individuals, we will notify the ICO within 72 hours as required by law.

10. Cookies and analytics

Our website uses cookies and similar technologies for essential functionality and basic analytics. You can control cookies through your browser settings. Where required, we will seek your consent for non-essential cookies.

11. Children

CapoAI is a business tool and is not intended for use by anyone under 18. We do not knowingly collect personal data from children.

12. Changes to this policy

We may update this policy from time to time. The “last updated” date at the top reflects the latest version. Significant changes will be communicated to account holders where appropriate.

13. Contact

For any privacy-related questions or to exercise your rights, contact:

CapoAI
Email: hello@capoai.org

This policy is provided as a general template tailored to CapoAI’s activities and does not constitute legal advice. Given that CapoAI processes third-party personal data and facilitates direct marketing, we recommend obtaining independent legal review.