CompanyStack™
APISamplesPricingDocsGuides
Explore data

The register

IndustriesIndustries by SIC code: key figures, the largest companies by turnover and the newest.Towns and citiesCompanies registered in each UK town, its main industries and the newest arrivals.Constituencies and councilsCompanies in each constituency and council area: new companies, insolvencies, industries and filed accounts.New incorporationsThe companies formed each day, newest first, with their industry and town.Company status guidesWhat active, dissolved, liquidation and proposal to strike off mean for you.

Look closer

Search companiesAny UK company by name or number: profile, health score and filed accounts.Financial screenerFilter companies by the figures in their latest filed accounts.Sample outputsReal reports, exports and API responses to look through.
Log inCreate free account
APISamplesPricingDocsGuides

Explore data

IndustriesTowns and citiesConstituencies and councilsNew incorporationsCompany status guidesSearch companies
Log inCreate free account
  1. Home
  2. Legal
  3. Privacy Notice

Privacy Notice

Version 6 · Effective 5 October 2026

Contents
  1. Who we are
  2. Part A: customers and website visitors
  3. What we collect and why
  4. How long we keep it
  5. Who we share it with
  6. International transfers
  7. Newsletter and marketing emails
  8. Security
  9. Part B: people named in Companies House data
  10. Your rights
  11. Complaints
  12. Changes to this notice

This notice explains how we use personal data. Part A is for our customers and people who visit our website or contact us. Part B is for directors, secretaries, people with significant control, shareholders and others whose details appear in Companies House records that we republish.

1. Who we are

The controller of your personal data is CompanyStack ("we", "us").

Registration with the Information Commission in progress.

For anything about your personal data, email support@companystack.co.uk or use our contact page. Please say "Privacy" in the subject line so it reaches the right person quickly.

2. Part A: customers and website visitors

This part covers the people who create an account, buy a plan, use our API or website, join our newsletter or contact us. Most of our customers are businesses, so the personal data is usually a work email address and name.

3. What we collect and why

DataWhat we use it forLawful basis
Account data: name, email address, password (stored only as a secure hash), plan, team membership, API key names and prefixes (keys themselves are stored only as hashes)Creating and running your account, signing you in, sending service and security emailsContract
Your content: watchlists, alert rules, webhook settings, saved searches, team members you addProviding the features you useContract. For team members you add, we act on your behalf (see our Data Processing Addendum)
Billing data: billing name and address, subscription and invoice history, the last four digits and expiry of your cardTaking payment, issuing invoices, keeping accounting recordsContract; legal obligation (tax and accounting records)
One-off report purchases: the email address the report goes to; your name, your company and your own reference if you give them; the company or place the report is about; the payment and its invoice; and the IP address the order came fromProducing the report and sending you the link, invoicing, answering questions about the purchase, and recording the Terms you accepted when you pay (see Agreement records)Contract; legal obligation (tax and accounting records)
Agreement records: which version of our Terms of Service you accepted, when and how (at sign-up, at checkout or by accepting an updated version), with the IP address and browser type at the time; for a one-off report, the purchase it relates toShowing which terms apply to you if there is ever a question or dispute about themLegitimate interests in being able to show what was agreed
Usage logs: API requests (endpoint, time, response code, response time, IP address) and account activity (for example sign-ins, plan changes and key changes, with IP address and browser type)Enforcing plan limits, showing you your usage, security, preventing fraud and abuse, fixing faultsContract; legitimate interests in keeping the service secure and working
Enquiries: what you send through our contact form or by email: your name, email address and message, and if you give them your company, phone number and preferred call times; what the enquiry is about, the page you sent it from and any campaign parameters (utm_source and similar); and a one-way keyed hash of your IP address and browser user-agent, used only to stop spamAnswering you. Contact form messages are stored in our database and emailed to our support inbox, and we send you an automatic confirmation.Legitimate interests in responding to enquiries; or steps before a contract, if you ask about buying
Newsletter: email address, the wording you agreed to, when you agreed and confirmed, the page you signed up on, any campaign parameters and a keyed hash of your IP address as a record of your consentSending our monthly report newsletterConsent, which you can withdraw at any time
Company alerts: if you ask on a company page to be emailed about that company: your email address, the company, the wording you agreed to, when you agreed and confirmed, the page you asked on and a keyed hash of your IP address as a record of your consentEmailing you when that company files accounts or a confirmation statement, changes its name, registered office or status, or appears in a Gazette noticeConsent, which you can withdraw at any time
Analytics: pages viewed, clicks, device and browser, approximate location from IP address, errors, and recordings of some sessions with typed input masked. For signed-in users, your email address links this to your account.Understanding how the website is used, fixing problems and improving itLegitimate interests in running and improving the website. Our cookies page explains how to block it.
Error reports: when something on our website fails in your browser (our code hits an error, part of a page or a request to our API does not load, or our security settings block something), your browser sends us a report: what went wrong and where in our code, the page address with search terms and other typed values removed, how long after the page loaded it happened, your browser and operating system with their version numbers, whether you are on a phone, tablet or computer, the short reference shown to you on an error page, and a value made from your IP address with a key that changes every day, so we can count how many people were affected without keeping the address itself. If you are signed in, the report is linked to your account. The report is also linked to the analytics record of your visit (see Analytics above), so we can see what led to the fault.Finding and fixing faults on the websiteLegitimate interests in keeping the service working for you and other users

Our analytics tool, Rybbit, runs on our own server. We do not use advertising trackers and we do not sell personal data. We do not make decisions about you that have legal or similarly significant effects based solely on automated processing.

We send email from our own mail server. Your card number is entered directly into Stripe's checkout and never reaches our servers.

4. How long we keep it

DataHow long
Account data and your contentWhile your account is open. When you ask us to close your account, we delete it within 30 days, apart from billing records.
Usage logs (API and website requests)While your account is open, and deleted with your account. IP addresses in them are removed after 90 days. Requests made with the website's shared demo key, which are not linked to an account, are deleted after 30 days.
Account activity logsWhile your account is open. When you delete your account, we keep what happened and when, without IP addresses, browser details or other details, linked only to an account number with no name or email address.
RapidAPI usage, if you use our API through RapidAPIEach request is logged with your RapidAPI username and plan. IP addresses are removed after 90 days.
Billing records and invoices6 years from the end of the financial year they relate to, as tax law requires.
One-off report purchasesA purchase you paid for is a billing record: the email address, name, company and reference you gave are kept with it for 6 years from the end of the financial year it relates to. If you did not pay, they are removed after 30 days. The IP address the order came from is removed after 90 days, or straight away when you delete your account.
Agreement records (which version of our Terms you accepted)6 years after your account closes, or after the one-off report they relate to was bought, because a claim about the contract can be brought for that long.
Enquiries2 years from our last exchange, unless they become part of a customer relationship. Messages our spam checks flag are deleted after 30 days.
NewsletterWhile you are subscribed. If you never confirm, we delete the address after 30 days. If you unsubscribe, we delete it 30 days later; the gap lets us show that you unsubscribed if you ask.
Company alertsWhile you watch the company. If you never confirm, we delete the address after 30 days. If you stop the alerts, we delete it 30 days later; the gap lets us show that you stopped them if you ask.
Records of emails we send (the address, subject, time and whether it was sent)90 days, to deal with delivery problems and complaints, then deleted.
Analytics dataUp to 2 years, then deleted.
Error reports30 days, then deleted. We keep a count of how often each fault happened, with no link to you.
Sign-in, password reset and email verification linksThey expire after a short time and cannot be used again.

We may keep data for longer if we need it to deal with a legal claim or a regulator's request.

5. Who we share it with

We use these service providers. The full list is on our sub-processors page.

  • Stripe processes card payments, subscriptions and invoices. Stripe is also a controller of some payment data for its own legal duties, such as fraud prevention.
  • Contabo provides the servers in Germany (EU) that host our database, API, website, mail server and analytics.
  • RapidAPI, only if you subscribe to our API through the RapidAPI marketplace. RapidAPI shares with us the details needed to provide the service, and handles billing under its own privacy notice.
  • OpenRouter and Anthropic, only when you ask for an Automated analyst view. We send your question and the data we hold about the company, which can include the names and roles of its officers and people with significant control, to OpenRouter, which passes it to the language model made and run by Anthropic (or we send it to Anthropic directly). They return the answer. We do not send your account, billing or contact details for this.
  • Anthropic, also when a member of our support team asks for a suggested reply to a support request you sent us. We send the conversation (your messages and our replies, not our internal notes), which can include anything you wrote in it, such as contact details in an email signature, and the account details a reply may need: your name, when the account was opened, your plans and subscription status, whether your email address is verified, usage counts, your lists and your three most recent invoices. We do not send your email address, password, API keys or card details. The suggestion is never sent automatically: a person reads it, checks it and decides what to send. Our lawful basis is our legitimate interests in answering support requests quickly and accurately.

We may also share data with professional advisers, with a buyer of the business (or with CompanyStack when the business transfers to it, if it does), or where the law requires it, for example to the police or HMRC.

6. International transfers

Our servers are in Germany. The UK recognises the EU as providing adequate protection, so no extra safeguards are needed for that. Stripe, RapidAPI, OpenRouter and Anthropic may process data in the United States. Where they do, the transfer is protected by the UK-US data bridge (for certified companies) or by the UK International Data Transfer Addendum to the EU standard contractual clauses. Ask us if you would like more detail.

7. Newsletter and marketing emails

We send our monthly report newsletter only to people who ask for it. After you sign up we email you a link (double opt-in), and nothing is sent until you confirm on the page it opens. Every newsletter has an unsubscribe link that works straight away.

Service emails, such as sign-in links, receipts, usage warnings and alerts you have set up, are part of the service and are not marketing.

Company alerts

On a company page you can ask us to email you about that company, without creating an account. We email you a link first and send nothing more until you confirm on the page it opens. After that you get at most one email a day, however many companies you watch, only about the companies you asked about, and every email has a link to stop the alerts, for one company or for all of them, which works straight away. We use your address for nothing else.

8. Security

We use encryption in transit (TLS), hashed passwords and API keys, access controls and logging. If a personal data breach is likely to put your rights at risk, we will tell you and the Information Commission as the law requires.

9. Part B: people named in Companies House data

This part is our notice under Article 14 of the UK GDPR to people whose details we obtain from Companies House rather than from them directly: company directors, secretaries, LLP members, people with significant control (PSCs), shareholders (members) named in the share filings companies make, and people named in disqualification records.

Where the data comes from

Companies House, from its public register, using its official data products and streaming service. The law requires Companies House to make this information public.

Shareholder information comes from the documents companies file at Companies House and that Companies House publishes: the subscribers listed when a company is formed, the shareholder lists in annual returns and confirmation statements, and the statements of capital and returns of allotment that record shares being issued, transferred or cancelled.

What we show

  • your name and any former names shown on the register;
  • your appointments: role, company, appointment and resignation dates;
  • nationality, occupation and country of residence;
  • month and year of birth (Companies House does not publish the full date of birth of directors);
  • your correspondence (service) address as filed;
  • for PSCs, the nature of your control over the company;
  • if you hold or held shares, the company, the class and number of shares and the dates of the filings that list them, with the percentage of the company this represents; we work this out from the filings described above, and say so wherever we show it, because the company's own register of members, not our reconstruction, is the legal record;
  • details of disqualification orders published on the register of disqualified directors;
  • whether you are linked, by name and month and year of birth, to other companies that have been dissolved, struck off or entered an insolvency process; we show such a match to signed-in customers as an item to check, with the reminder that it may be a different person, and it is not used in the Health Score; and
  • possible matches of your name against public sanctions lists and the register of disqualified directors, shown to our customers as possible matches to be checked, not findings.

We never show residential addresses. Companies House keeps them off the public register, and we do not collect them from anywhere else.

On a company's page on our website, any visitor can see its three largest shareholders; customers on paid plans, our API and the reports we sell show every shareholder. We do not name individual shareholders in the versions of our pages that we serve to search engines, in our public samples or in our marketing: there each one appears as "Individual shareholder 1", "2" and so on, with their holding, while companies and other organisations that hold shares are named. Some older filings print a shareholder's address: we do not keep it.

For people on the register of disqualified directors, we copy the register from Companies House and keep the name, any other names the register gives, the month and year of birth and the details of each disqualification. We do not keep the full date of birth, the address or the nationality the register also publishes.

From The Gazette we hold company insolvency notices only. We do not hold notices about individuals, such as personal bankruptcy notices.

Identity verification of directors and people with significant control

For each company we show, we take from the Companies House register (its public data service, its streaming service and its bulk file of people with significant control) whether each current director, LLP member and individual person with significant control (PSC) has an identity verification statement on the register, the date it was supplied, the date by which one is due and, for PSCs, the window in which it can be supplied. Where an Authorised Corporate Service Provider carried out the identity check, we also take the date of the check, the provider's name and its anti-money laundering supervisor, as the register publishes them. For PSCs we keep the month of birth the register publishes, to work out the 14-day window that applies to them. We do not take or keep the "preferred name" Companies House holds, addresses or anything the register does not publish.

Why. To show this information on company pages and in our checker, and to give our customers verification dates and alerts for the companies they follow. Our lawful basis is our legitimate interests, and those of our customers, in knowing whether a company's officers and controllers have met a legal requirement that Companies House publishes so that others can rely on it (UK GDPR Article 6(1)(f)). We show facts from the register and the dates that apply; we do not make a finding about any person.

How long. For a PSC, details taken from Companies House's bulk file are kept while that person is a current PSC of the company: we refresh them each week from the new file and delete them when the person ceases to be a PSC. Other verification details are deleted 30 days after we last refreshed them from the register, and as soon as we learn that the appointment has ended. Results of checks made with our checker are deleted 48 hours after the check. Usage counters for the checker hold a daily, salted hash of the IP address (for IPv6, of its network prefix), never the address, and are deleted after 7 days.

Your rights. You can object to our use of this information or ask us to stop showing your name, using the contact details in this notice. When we accept an objection, it covers these details as it covers your other register details: where we withhold your appointments we stop showing your verification details at once and delete any we hold within a day, and where we withhold your name we show them without it. Companies House continues to publish the register itself.

Why we use it

To help businesses carry out due diligence on the companies they deal with, to support transparency about who runs and controls UK companies, and to help prevent fraud. These are the same reasons the register is public.

Lawful basis: legitimate interests

We rely on legitimate interests. In summary, our balancing test found that:

  • The purpose is legitimate. Due diligence, transparency and fraud prevention are recognised public and business interests.
  • The use is necessary. You cannot check a company properly without knowing who runs and controls it.
  • It does not override your interests. The data is already public by law, and people taking on these roles are told it will be published. We show what the register shows, and the indicators described above that we calculate from it, and nothing more sensitive, such as a residential address or full date of birth. We keep our copy in step with the register, honour suppression requests, and forbid customers from using the data for unsolicited marketing, harassment or unlawful profiling.

How long we keep it

We mirror the register. When Companies House changes or removes information, we update or remove our copy when we receive the change, which we do continuously through its streaming service.

Shareholder information is rebuilt from a company's filings when it files something new. An earlier reconstruction is deleted 30 days after a newer one replaces it, and the text we read from the filings is deleted once a company's reconstruction has not been rebuilt for 45 days.

Who we share it with

Our customers, through our website, API and reports, and people who visit our public company pages.

Correcting information

If something about you is wrong, please correct it at Companies House first, because it is the official source and we will otherwise copy the error back. Once the register is corrected, our copy updates automatically. If our copy differs from the register, tell us and we will fix it.

Objecting and suppression requests

You have the right to object to our use of your data. Email support@companystack.co.uk with your name, the company or companies concerned and your reasons. We will reply within one month. If your circumstances outweigh the reasons for showing the data, or if you have a safety concern, we will suppress it from our public pages, API and reports.

If Companies House has suppressed or protected your information (for example, because you are at risk), tell us and we will suppress it too.

This applies to shareholdings in the same way. If you object to being named as a shareholder, the shareholding stays in the company's table so that the percentages still add up, but your name is replaced by "Name withheld" on our pages, in our API and in our reports.

Once your details are suppressed we do not show them anywhere, including in KYB results and their certificates. KYB checks help our customers meet their own legal duties, such as customer due diligence under the Money Laundering Regulations 2017, so when a customer runs a KYB check on a company you are connected with, we still check you against the register of disqualified directors and the sanctions lists. The result shows you only as "a person whose details are withheld" and does not say which entry you matched.

10. Your rights

You have the right to:

  • ask for a copy of your personal data;
  • ask us to correct data that is wrong;
  • ask us to delete your data;
  • ask us to restrict how we use it;
  • object to our use of it where we rely on legitimate interests;
  • receive data you gave us in a portable format; and
  • withdraw consent (for example to the newsletter) at any time.

Some rights have limits. For example, we may need to keep billing records. To use any right, email support@companystack.co.uk. We will reply within one month, and we may ask you to confirm your identity.

11. Complaints

Please contact us first so we can try to put things right. You can also complain to the Information Commission, which replaced the Information Commissioner's Office (ICO) on 30 September 2026, at ico.org.uk/make-a-complaint or on 0303 123 1113.

12. Changes to this notice

We will update this notice when our use of personal data changes, and show the new effective date and version at the top. If a change affects customers significantly, we will email them.

Version history

  • Version 6, effective 5 October 2026 (this version)
  • Version 5, effective 5 October 2026
  • Version 4, effective 4 October 2026
  • Version 3, effective 4 October 2026
  • Version 2, effective 3 October 2026
  • Version 1, effective 2 October 2026

Data from Companies House. Contains public sector information licensed under the Open Government Licence v3.0. CompanyStack is not affiliated with or endorsed by Companies House.

The same data is available through the CompanyStack API (OpenAPI spec). Company status meanings · Data freshness

CompanyStack

The UK company register, made useful. Company profiles, health scores and financials in the web app, and the same data through the CompanyStack API.

Talk to us

CompanyStack web app

  • Dashboard
  • Financial screener
  • Watchlist and alerts
  • Map
  • Web app pricing
  • Create a free account

CompanyStack API

  • UK company data API
  • API documentation
  • API explorer
  • API pricing
  • Signals add-on
  • Get a free API key
  • Enterprise and bulk data

Built for

  • Accountants and bookkeepers
  • Compliance and procurement
  • Lenders and credit
  • Sales and business development
  • Investors and corporate finance
  • Insolvency and business recovery
  • Developers and data teams
  • Recruitment agencies

See the data

  • Sample outputs
  • Guides
  • Data sources
  • Book a 20-minute call
  • Monthly UK company report
  • UK private company data
  • Company status meanings
  • SIC codes list
  • Compare providers
  • Built in Scotland, UK
  • Servers in the EU (Germany)
  • Two-step sign-in
  • Nightly backups
  • No advertising trackers
  • Payments by Stripe

Company data from Companies House, company insolvency notices from The Gazette, locations from the ONS Postcode Directory and sanctions data from official sanctions lists, including those of the UK (FCDO, with UN designations), the EU, the US, Canada, Australia, New Zealand and France. Contains public sector information licensed under the Open Government Licence v3.0. Contains OS data © Crown copyright and database right 2026. Contains Royal Mail data © Royal Mail copyright and database right 2026. Source: Office for National Statistics licensed under the Open Government Licence v3.0. Accounts figures and register details are each company's own filings, shown as filed; CompanyStack does not audit or verify them. CompanyStack is not affiliated with or endorsed by Companies House. Nor is it endorsed by any other public body whose data it uses. Every source and its licence.

© 2026 CompanyStack.

TermsPrivacyCookiesRefundsLegalTrust and securityBrand and pressAboutHelp centreContactDocs