Privacy Policy
Last updated: 29 June 2026
1. Who we are
CheckFirst (“we”, “us”) is operated by Chanikul Dechpholkrang, trading as CheckFirst, a sole trader based in the United Kingdom. Chanikul Dechpholkrang, trading as CheckFirst, is the data controller for the personal data described in this policy. We are registered with the ICO (ICO registration: ZC176732).
2. What we collect
- Marketing content you submit for scanning. This is analysed to produce your compliance grade. We hash your content and do not store the raw copy in our database — it is sent securely to our AI analysis provider to generate your result and is not retained by us.
- Your email address, if you choose to receive the full report. We store this to send you the report and related follow-up communications.
- Scan metadata and findings such as your grade, scores and issue counts. To let you open your full report from the link in your report email, we also store the report's findings — the specific flagged phrases, the policy each breaches and the suggested fixes, plus the per-platform AI-labelling result and your sector — keyed to a random scan ID. We do not store the raw copy you pasted (only the short flagged snippets needed to show you the issue), and this report is automatically deleted 30 days after the scan.
- Suggested rewrites (paid plans). If you generate a one-click compliant rewrite on a paid plan, we store the rewritten text with your report so you can copy it later. We store the rewrite only — never your original copy — and it is deleted with the report 30 days after the scan.
- Monitored assets (Pro, opt-in). Your pasted copy is never stored on a default scan (hash-only). If you explicitly choose to Save & monitor an asset on a Pro plan, we store that asset's text — encrypted at rest — so we can re-check it when the rules change and alert you if its grade drops. This is the only case in which we store the copy you pasted. You can delete any monitored asset at any time from your dashboard, which removes the stored text.
- Payment information, if you purchase a Compliance Snapshot — handled by our payment processor (Stripe). We do not store your full card details.
- Basic technical/usage data (e.g. IP address for rate-limiting and abuse prevention).
- Bot & abuse protection (Cloudflare Turnstile). To confirm that visitors running a check are human and to keep the service free of bots, we use Cloudflare Turnstile. It runs in the background and may process technical signals from your browser (such as your IP address and device/browser characteristics) for this purpose. Your use of Turnstile on our site is also covered by Cloudflare's Turnstile Privacy Addendum.
- Public certificate listing (opt-in only). If you choose to issue a Compliance Certificate and explicitly opt in to the public directory, the business name you provide is published on a searchable verify page alongside the certificate's grade and issue date. This is off by default — certificates are private and resolvable only by their unguessable ID unless you opt in, and no ad copy is ever published.
- Anonymised aggregate statistics. To publish our “State of UK Marketing Compliance” figures, we keep a monthly tally of counts only — how many checks fell into each grade, sector and breached rule category. This stream contains no personal data, no ad copy and no link back to an individual scan, and buckets below a minimum size are withheld. You can opt out of being included in these aggregates.
3. How and why we use it (legal bases)
- To run the scan and return your result — legitimate interests / performance of the service you request.
- To send the report and follow-up emails to the address you provide — consent.
- To take payment and provide the paid Snapshot — performance of a contract.
- To prevent abuse and keep the service secure (rate-limiting) — legitimate interests.
4. Who we share it with (processors)
We use trusted providers who process data on our behalf: Anthropic (AI content analysis), GoHighLevel (CRM and email delivery), Stripe (payments), MongoDB Atlas (database storage), Vercel (hosting), Clerk (authentication, where applicable), and Cloudflare (bot protection and human verification via Turnstile). Some of these providers are based outside the UK; where data is transferred internationally we rely on appropriate safeguards such as the UK International Data Transfer Agreement or Standard Contractual Clauses. We do not sell your personal data.
5. How long we keep it
Your per-scan report (the findings keyed to your scan ID) is automatically deleted 30 days after the scan. We keep your email address and basic scan metadata for as long as needed to provide the service and our follow-up communications, and then delete or anonymise it. Raw scanned content is not stored at any point. You can ask us to delete your data at any time (see section 7).
6. Cookies
We use only the cookies necessary to run the site and, where applicable, authentication.
7. Your rights
Under UK data protection law you have the right to access, correct, delete, or restrict the processing of your personal data, to object to processing, and to data portability. To exercise any of these, email us at privacy@checkfirstcompliance.co.uk. You also have the right to complain to the ICO (ico.org.uk).
8. Contact
Data controller: Chanikul Dechpholkrang, trading as CheckFirst. Email: privacy@checkfirstcompliance.co.uk. ICO registration: ZC176732.