Privacy policy
Last updated 1 July 2026
This policy explains how OnePot (“we”, “us”), operator of onepot.org.uk, collects and uses your personal data. We are the data controller for the purposes of the UK GDPR and the Data Protection Act 2018.
Data we collect
- Account data — when you sign up, we store your email address and, via our authentication provider, an account identifier. If you use Google sign-in, we receive your basic Google profile (name, email, avatar).
- Profile data — a username, and any optional display name, bio, avatar, affiliate IDs (Amazon Associate tag, Skimlinks ID), and social links you choose to add.
- Content — the bundles, items, reviews, likes, and saves you create.
- Usage data — aggregate bundle view counts and, where you consent, records of outbound affiliate link clicks used for revenue attribution.
How we use your data
- To provide the service — authentication, publishing bundles, and personalising your likes and saves.
- To attribute affiliate commissions to the correct creator.
- To understand which bundles are popular and improve the platform.
- To meet our legal and regulatory obligations.
Legal bases
We process account, profile, and content data to perform our contract with you (providing the service). We rely on your consent for non-essential cookies and affiliate click tracking, and on our legitimate interests for keeping the platform secure and measuring aggregate usage.
Cookies & tracking
We use a small number of essential cookies to keep you signed in — these do not require consent. With your consent, we also load Skimlinks, an affiliate network that may set cookies to attribute purchases you make after clicking a product link. You can accept or reject non-essential cookies via the banner shown on your first visit, and change your choice at any time by clearing the onepot-consent preference in your browser.
See our Affiliate disclosure for how affiliate links work.
Sharing & processors
We do not sell your personal data. We share it only with the processors that run the service on our behalf:
- Supabase — database, authentication, and file storage.
- Amazon Associates and Skimlinks — affiliate link networks.
- Our hosting provider for serving the site.
Retention
We keep your account and content data for as long as your account is active. If you delete your account, we delete or anonymise your personal data, except where we must keep it to meet a legal obligation.
Your rights
Under UK GDPR you have the right to access, correct, delete, restrict, or object to our processing of your data, and to data portability. To exercise any of these, email privacy@onepot.org.uk. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
Contact
Questions about this policy: privacy@onepot.org.uk.
This policy is a template provided for transparency and should be reviewed by a qualified adviser before launch; it does not constitute legal advice.