Last updated: June 2026
The data controller is CheapSubs. You can contact us at cheapsubs@proton.me — for data-related requests, include “Data Request” in the subject line.
We collect the following categories of personal data:
| Category | Examples | When collected |
|---|---|---|
| Account data | Email address, display name | On sign-up |
| Order data | Order history, product names, amounts paid, delivery status | On purchase |
| Payment data | Payment method type, last 4 digits (tokenised by Whop — we never see full card numbers) | At checkout |
| Communications | Support messages, contact form submissions | When you contact us |
| Usage data | Pages visited, clicks, session duration, browser type, IP address | Automatically via analytics |
| Affiliate data | Referral link clicks, referred orders, commission balance | When you use the affiliate programme |
We do not collect special category data (health, biometric, political, religious, or criminal data).
| Purpose | Lawful basis |
|---|---|
| Processing and fulfilling your order | Contract (Art. 6(1)(b)) |
| Sending order confirmations and delivery notifications | Contract (Art. 6(1)(b)) |
| Responding to support messages and resolving disputes | Contract / Legitimate interest |
| Fraud prevention and platform security | Legitimate interest (Art. 6(1)(f)) |
| Analytics — understanding how the platform is used to improve it | Legitimate interest (Art. 6(1)(f)) |
| Sending marketing emails about new products and deals | Consent (Art. 6(1)(a)) — opt-in only |
| Complying with legal obligations (e.g. retaining financial records) | Legal obligation (Art. 6(1)(c)) |
We share personal data with the following third-party service providers only to the extent necessary for them to perform their services:
| Recipient | Purpose | Location |
|---|---|---|
| Whop | Payment processing | United States |
| Supabase | Database hosting and authentication | European Union |
| PostHog | Product analytics (pageviews, clicks, user behaviour) | European Union |
| Crisp | Live chat and support messaging | European Union |
We do not sell personal data to third parties. We do not use your data for targeted advertising.
Where personal data is transferred outside the UK (e.g. to Whop in the United States), we rely on Standard Contractual Clauses or the UK International Data Transfer Agreement as the transfer mechanism.
| Data category | Retention period |
|---|---|
| Order and payment records | 6 years from the order date (HMRC record-keeping requirements) |
| Account data | Until you delete your account, plus 30 days for backup expiry |
| Support messages | 3 years from resolution (for dispute evidence purposes) |
| Analytics data | 2 years (configured in PostHog) |
| Marketing consent records | Until consent is withdrawn |
Under UK GDPR, you have the following rights. To exercise any of them, email us at cheapsubs@proton.me with "Data Request" in the subject line. We will respond within one calendar month.
We use cookies and similar technologies for essential functions (authentication, session state) and analytics. See our Cookie Policy for a full list.
CheapSubs is not intended for users under 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data about a minor, please contact us and we will delete it promptly.
We may update this policy periodically. Material changes will be communicated by email before taking effect. The "last updated" date at the top of this page reflects the most recent revision.
If you have a concern about how we handle your data, please contact us first at cheapsubs@proton.me — we aim to resolve complaints within 30 days.
If you are not satisfied with our response, you have the right to lodge a complaint with the UK supervisory authority:
Information Commissioner’s Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
ico.org.uk/concerns | 0303 123 1113