Privacy policy
Last updated: April 2026
Who we are
solicitor.law is operated by Steven Mather through Kesters Nook Limited, registered in England and Wales. For the purposes of data protection legislation, we are the data controller in respect of your personal data when you use our service. Contact: steven@solicitor.law.
What personal data we collect
When you register for the service, we collect: your full name, email address, phone number, SRA number, regulated firm details, PII insurer details, professional bio, practice areas, and a professional photograph.
When you pay for the service, Stripe (our payment processor) collects your payment details. We do not store your card details directly.
How we use your data
We use your personal data to: build and maintain your website, verify your identity against the SRA register, process your subscription payments, send you service updates and monthly reports (Silver and Gold tiers), and communicate with you about your site.
Legal basis: The processing of your data is necessary for the performance of our contract with you (Article 6(1)(b) UK GDPR). Where we send you service-related communications, this is in our legitimate interest in providing and improving the service (Article 6(1)(f) UK GDPR).
Contact form data (your clients)
Where your site includes a contact form, enquiries submitted through that form are processed by us on your behalf. In this context, you are the data controller and we are the data processor. We process this data solely to deliver it to you and do not use it for any other purpose.
Contact form submissions are stored temporarily on our servers and forwarded to your email address. They are retained for 90 days for troubleshooting purposes, after which they are automatically deleted.
How we store your data
Your data is stored on Supabase (database hosting, EU region) and Vercel (website hosting). Payment data is processed and stored by Stripe. All processors are GDPR-compliant and maintain appropriate technical and organisational security measures.
Data retention
We retain your personal data for the duration of your subscription and for 12 months after cancellation (for accounting and regulatory purposes). After this period, your data is securely deleted. Contact form submissions from your site visitors are retained for 90 days.
Third-party processors
We share your data with the following third-party processors, solely for the purpose of delivering the service: Supabase (database hosting), Vercel (website hosting and analytics), and Stripe (payment processing). We do not sell your data to any third party.
Your rights
Under UK GDPR, you have the right to: access the personal data we hold about you, rectify inaccurate data, request erasure of your data, restrict processing, data portability, and object to processing.
To exercise any of these rights, contact us at steven@solicitor.law. We will respond within one month. If you are not satisfied with our response, you may complain to the Information Commissioner's Office (ICO) at ico.org.uk.
Cookies and analytics
The solicitor.law product site uses Vercel Web Analytics, which collects anonymous usage data without using cookies. Client sites on Silver and Gold tiers include analytics for reporting purposes. No personal data is collected through analytics.
Changes to this policy
We may update this policy from time to time. Material changes will be communicated to you by email. The latest version will always be available at this page.