Privacy Policy
Last updated: 24 May 2026Refine Bridge ("we", "us", or "our") operates the platform at refinebridge.com. Refine Bridge is a trading name of Richard John, operating as an independent sole trader. The service is provided globally via the internet.
We are the data controller for personal data you provide directly to us, such as your account and billing data. For personal data you route through the Service into connected third-party platforms (such as business records imported from source providers or uploaded files into a CRM), you are the data controller and Refine Bridge acts as a data processor acting on your documented instructions.
1. Information We Collect
Account and Identity Data
When you create an account, we collect your name and email address. Authentication is handled via WorkOS, which processes your login credentials. If you use Google login, Google provides us with your name and email address.
Billing Data
Billing for subscriptions and one-time credit pack purchases is processed by Lemon Squeezy. We receive confirmation of your payment, subscription, and order status. Payment card details are processed directly by Lemon Squeezy and are not stored on our systems.
Usage and Configuration Data
We store the configuration data you create within the Service, including Import Flow configurations, task settings, source requests, uploaded file metadata, mapping choices, and connected account credentials (API keys for third-party data source and destination platforms you choose to connect). API keys and credentials are stored using encryption at rest and are rotated and managed securely. They are used solely to execute your configured pipelines.
Pipeline and Run Data
We store logs of pipeline executions including run timestamps, status, result summaries, and error information. We do not permanently store the underlying contact data passed through your pipelines beyond what is necessary for operational purposes such as processing, retry handling, and short-term execution support. See Section 6 for retention details.
Technical Data
We may collect technical data such as IP address, browser type, and usage patterns to operate and improve the Service and maintain security.
2. Legal Basis for Processing
We process your personal data on the following lawful bases:
- Performance of a contract: to provide, operate, and maintain your paid access, credit purchases, subscriptions, and the Service
- Legitimate interests: to improve the Service, ensure security, prevent abuse, and communicate essential service information
- Legal obligations: where required by applicable law
3. How We Use Your Data
We use your data to:
- Create and manage your account
- Process and manage subscriptions, credit pack purchases, and billing status
- Operate the pipeline Service and execute your configured tasks
- Store your Import Flow and task configurations
- Communicate essential service-related information including billing notifications, security alerts, and service updates
- Investigate and resolve technical issues
- Comply with legal obligations
4. Data Sharing
We do not sell or rent your personal data.
We share data with the following third-party service providers solely as necessary to operate the Service:
- WorkOS — authentication and identity management
- Lemon Squeezy — subscription, credit pack, and payment processing
- Railway — backend infrastructure and database hosting
- Vercel — frontend hosting
- Cloudflare — content delivery and network services
Each provider acts as a data processor on our behalf and is subject to contractual obligations to protect your data. We do not share your personal data with any other third parties except where required by law or with your explicit consent.
5. Third-Party Integrations
The Service connects to third-party platforms you authorise, including data source platforms and destination platforms. It may also use Refine Bridge-managed source access for source requests you configure or approve. When you connect platforms, you provide API credentials which we store encrypted, rotate securely, and use solely to execute your configured pipelines. Your use of connected platforms is subject to their own privacy policies and terms of service.
Refine Bridge processes data through your pipelines as a technical conduit and workflow operator. This includes manual runs, scheduled runs, retries, uploaded files, and future tasks under an Import Flow. You remain the data controller for any personal data belonging to third parties that passes through your pipelines. You are responsible for ensuring you have the appropriate legal basis for processing that data and for your CRM processing, outreach compliance, unsubscribe and opt-out handling, and destination system use.
Refine Bridge does not verify the accuracy, legality, or origin of data processed through user-configured pipelines.
6. Data Retention
We retain your account data for as long as your account is active. If you cancel your subscription and close your account, we will delete your personal data within a reasonable period except where we are required to retain it by law (for example, for tax or accounting purposes).
Pipeline execution logs are retained for a period consistent with your account access, plan, or service configuration to support retry, review, and audit functions, after which they are deleted automatically.
Transient pipeline data (contact data passing through your pipelines) is not permanently stored and is discarded once the pipeline execution is complete, subject to short-term operational retention for retry purposes.
You may request deletion of your account and data at any time by contacting us at support@refinebridge.com.
7. Cookies and Similar Technologies
We use essential cookies to maintain your authenticated session and enable core Service functionality. These cookies are required for the Service to operate and cannot be disabled without losing access to the Service.
We do not use advertising cookies, cross-site tracking, or share data with advertising networks.
8. International Data Transfers
As we operate internationally and use service providers based in various countries, your personal data may be processed or stored outside your country of residence, including outside the United Kingdom and the European Economic Area.
Where personal data is transferred internationally, we rely on appropriate safeguards in accordance with applicable data protection laws, including standard contractual clauses or equivalent mechanisms where required. Our key providers (WorkOS, Lemon Squeezy, Railway, Vercel, Cloudflare) maintain their own compliance frameworks for international transfers.
9. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These include encrypted data storage, secure API credential handling, and access controls.
No method of transmission or storage is completely secure. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority as required by applicable law.
10. Your Rights
Depending on your location and applicable data protection laws, you may have the following rights regarding your personal data:
- Access: request a copy of the personal data we hold about you
- Correction: request correction of inaccurate or incomplete data
- Deletion: request deletion of your personal data
- Restriction: request that we restrict processing of your data
- Objection: object to processing based on legitimate interests
- Portability: request your data in a portable format
- Withdraw consent: where processing is based on consent, withdraw it at any time
If you are based in the UK, you also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
If you are based in the EU, you have the right to lodge a complaint with your local supervisory authority.
To exercise any of these rights, please contact us at support@refinebridge.com. We will respond within the timeframe required by applicable law.
11. Children's Privacy
The Service is not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
12. Updates to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by displaying a notice within the Service. The latest version will always be available at refinebridge.com/privacy-policy.
13. Contact
For privacy-related questions or to exercise your data rights, please contact:
Richard John trading as Refine Bridge
support@refinebridge.com