Privacy Policy
Last updated: 23 July 2026
BridgeMatch ("we", "us", "our") is operated by BridgeMatch Limited, a company registered in England and Wales (Company No. 17061771). We are committed to protecting your privacy and handling your data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
BridgeMatch Limited is the data controller for information processed through bridgematch.co.uk and auctions.bridgematch.co.uk. For data protection queries, contact us at hello@bridgematch.co.uk.
2. What Data We Collect
We collect the following personal data:
- Email address — when you sign up or sign in via magic link authentication
- Enquiry contact details — your name, email address and phone number when you submit the criteria-checking enquiry form
- Deal details — purchase price, deposit, calculated loan amount and loan-to-value, whether refurbishment is planned and whether you can cover its cost, estimated gross development value (GDV), exit strategy, and the resulting criteria count, indicative rate field and maximum LTV field
- IP address — recorded with activity events for security and rate limiting
- Campaign and attribution identifiers — UTM source, campaign and medium, lot reference and click identifier when these are present in the link you use
- Activity and conversation data — actions you take within the tools (searches, filter usage and lender contact clicks), session identifiers, and the content of AI chat messages and responses
- Payment data — if you subscribe, Stripe processes your payment details. We store only your Stripe customer ID and subscription status, never your card details.
3. Why We Collect It (Legal Basis)
- Contract performance and steps at your request — where necessary to provide an account or paid service you request, and to respond when you submit an enquiry
- Legitimate interests — where appropriate, to operate and improve the service, respond to enquiries, understand campaign attribution, monitor usage patterns, prevent abuse, and maintain security. We balance these interests against your rights and expectations.
- Consent — for any marketing communications (you can opt out at any time)
4. Third-Party Processors
We use the following third-party services to operate BridgeMatch:
- Supabase (authentication) — processes your email address and session tokens for account sign-in. Supabase does not process enquiry submissions. Supabase Privacy Policy
- Stripe (payments) — processes subscription payments. Stripe Privacy Policy
- Resend (email delivery) — sends magic-link emails and emails submitted enquiry details to the BridgeMatch team. Resend Privacy Policy
- Anthropic (AI) — powers the AI chat feature. Chat messages are sent to Anthropic's API for processing. Anthropic does not use API inputs to train models. Anthropic Privacy Policy
- Railway (hosting) — hosts our application infrastructure, including the application SQLite database in which enquiries are stored. Railway Privacy Policy
- Umami (public-page analytics) — helps us understand use of public pages and campaign attribution. Umami does not receive enquiry submissions. Umami Privacy Policy
- Google Fonts (web fonts) — this privacy page loads fonts externally from fonts.googleapis.com, which means your browser connects to Google when the page loads. Google Privacy Policy
Submitted enquiries are stored in the Railway-hosted application SQLite database, emailed through Resend and handled internally by the BridgeMatch team. They are not stored in Supabase or sent to Umami. We do not send enquiry details to lenders through this form.
5. How Long We Keep Your Data
We do not apply one fixed retention period to every record. We keep personal data only for as long as reasonably necessary for the purpose for which it was collected. The retention period is determined by the status and duration of your account or enquiry, whether follow-up remains reasonably necessary, security and abuse-prevention needs, applicable limitation periods, and legal, tax, accounting or regulatory obligations. We delete or anonymise data when it is no longer required under those criteria, subject to backups cycling out in the ordinary course.
6. Cookies and Local Storage
We use browser localStorage to maintain your authentication session (via Supabase). We also use privacy-focused website analytics to understand aggregate use of public pages. We do not use third-party advertising cookies. Your browser settings can be used to clear stored website data, although clearing essential authentication storage will sign you out.
7. Your Rights
Under UK GDPR, you have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — request deletion of your data ("right to be forgotten")
- Restriction — limit how we process your data
- Portability — receive your data in a machine-readable format
- Object — object to processing based on legitimate interests
To exercise any of these rights, email hello@bridgematch.co.uk. We will respond within 30 days.
8. Data Security
We protect your data with HTTPS encryption in transit, secure authentication via Supabase (no passwords stored by BridgeMatch), timing-safe token verification where applicable, rate limiting, CORS controls and security headers.
9. International Transfers
Some of our processors (Anthropic, Railway) are based in the United States. Transfers are protected by Standard Contractual Clauses (SCCs) or equivalent safeguards as required by UK GDPR.
10. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email to registered users. The "last updated" date at the top reflects the most recent revision.
11. Complaints
If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
12. Contact
BridgeMatch Limited
Email: hello@bridgematch.co.uk