Privacy Policy
Last updated: February 2026 · Applies to all Insidr services
Insidr is built on a foundational belief: brands should be able to learn from the people who know them best — without ever knowing who those people are. This policy explains how we collect, use, and protect information across our platform.
Our Anonymous Architecture
Privacy isn't a compliance checkbox for us — it's the core design principle that makes Insidr possible. Real identities never reach the brand. Here's how it works:
Consumer
What they provide
Real identity enters here
Consumer Cloud
What the brand sees
Anonymous #4471
No name. No email. No personal ID.
- Identities pseudonymised before entering the research layer
- Brands see consumer attributes, never personal identifiers
- All responses aggregated before surfacing to brands
- No third-party data sharing or data broker relationships
- Participants can view, export, or delete their data at any time
- Designed to be GDPR and CCPA compliant by default
1. Who We Are
Insidr (operating as insidr.club) is a consumer insights platform that connects brands with their internal communities — employees, loyalty members, retail partners, and brand ambassadors — to conduct anonymous research. We are the data controller for personal data collected through our platform.
2. Information We Collect
From brands (enterprise customers)
- Account information: name, email address, company, role
- Billing and payment details (processed by our payment provider)
- Research content: questions, concepts, materials uploaded to the platform
- Usage data: how you interact with the Insidr dashboard
From community participants
- Onboarding data: provided by the brand (e.g., loyalty programme membership) used solely to create the anonymous profile
- Survey and research responses submitted through missions and interviews
- Consumer attributes derived from responses (e.g., "health-conscious", "price-sensitive") stored against the anonymous profile
- Platform usage metadata (session timestamps, response times)
We do not collect biometric data, financial account information, government-issued IDs, or sensitive special-category data as defined under GDPR.
3. How We Use Information
For brands
- To provide and improve the Insidr platform
- To deliver research results in aggregate and anonymised form
- To send service-related communications and product updates
- To comply with legal obligations
For participants
- To build and maintain their anonymous consumer profile
- To match them to relevant research missions within their community
- To calculate and deliver rewards or incentives
- To improve the research experience over time
4. Legal Basis for Processing
We process personal data under the following legal bases:
- Contract: processing necessary to deliver the Insidr service to brands
- Legitimate interests: improving platform functionality and preventing fraud
- Consent: where participants have explicitly opted in to a community
- Legal obligation: where required by applicable law
5. Data Retention
Brand account data is retained for the duration of the contract plus 2 years. Anonymous participant profiles are retained for as long as the participant remains active in a community. Upon withdrawal or deletion request, profiles are fully purged within 30 days.
6. Data Sharing
We do not sell personal data. We may share data with:
- Sub-processors who help us operate the platform (cloud hosting, payment processing, analytics) — all bound by data processing agreements
- Law enforcement or regulatory authorities, where required by law
- Acquirers or successors, in the event of a merger or acquisition
7. International Transfers
Data may be processed in countries outside your own. Where we transfer data outside the UK or EEA, we rely on Standard Contractual Clauses or other approved transfer mechanisms to ensure adequate protection.
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data ("right to be forgotten")
- Object to or restrict certain processing
- Request portability of your data
- Withdraw consent at any time (where processing is consent-based)
To exercise any of these rights, email us at hello@insidr.club. We will respond within 30 days.
9. Security
We implement industry-standard security measures including encryption in transit (TLS 1.2+) and at rest, access controls, regular security audits, and incident response procedures. No method of transmission over the internet is 100% secure, but we take every reasonable precaution.
10. Cookies
We use strictly necessary cookies to operate the platform and, with your consent, analytics cookies to understand how the platform is used. You can manage cookie preferences at any time through your browser settings.
11. Children
Insidr is not intended for users under 16 years of age. We do not knowingly collect data from children.
12. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email to registered users. The "last updated" date at the top of this page reflects the most recent revision.
13. Contact Us
For privacy-related questions, requests, or concerns:
- Email: hello@insidr.club
- Website: insidr.club