Legal

Privacy policy

What personal data Booltspace collects, why we hold it, who else touches it and what you can ask us to do with it. Written to be read, not to be skimmed past.

Draft — not reviewed by a lawyer

This policy is a good-faith draft written by the Booltspace team as a starting point. No qualified lawyer has reviewed it. It is not legal advice and it should not be treated as a compliant or sufficient privacy notice yet.

Before Booltspace relies on this document commercially, it must be reviewed by a lawyer qualified in every jurisdiction the business actually operates in and sells into — at minimum Nigeria, and the EU/UK and United States if clients are accepted there. Every [bracketed placeholder] below is a real-world detail that is still missing and must be completed before publication.

Last updated: 18 September 2026

1. Who we are

Booltspace is a done-for-you growth service. We produce content, run lead generation, build and maintain websites, and manage brand and review presence for small and medium businesses, sold as monthly plans through the dashboard at this site.

The legal entity responsible for the personal data described here — the data controller, where we act as one — is [Registered company name], registered in [country of incorporation] under company number [Company registration number], with its registered address at [Registered business address].

For anything to do with your data, email hello@booltspace.com. Our named data protection contact is [Data protection contact — name and email]. If we are required to appoint a representative in the EU or UK, that is [EU/UK representative, if appointed].

2. What this policy covers

This policy covers three different groups of people, and the rules are not the same for each:

  • Visitors to the public Booltspace website, including anyone who submits the free audit or scope call form.
  • Clients and their team members who hold a Booltspace dashboard account.
  • Third parties whose data we handle for a client — mainly sales prospects in a lead generation campaign. For that data the client is the data controller and Booltspace is only a processor acting on their instructions. Section 3.3 explains what that means in practice.

It does not cover what a client does with data after we hand it to them, or what third-party platforms such as Google, Meta or a review site do with data you give them directly. Those are governed by their own policies.

3. The data we collect

3.1 If you only visit the website

You can read every public page without giving us anything. If you submit the free audit form or request a scope call, we collect the details you type in: your name, email address, business name, website address, phone number if you give one, the services you are interested in and any notes you add.

We use those details to answer that request and to follow up on it. We do not sell them, rent them, or share them with anyone outside the processors listed in section 7.

3.2 If you hold a dashboard account

Booltspace is invite-only. You create an account, then redeem a one-time access code that assigns your role — client, staff or admin. Depending on your role and what you use, the platform stores:

  • Identity and contact details: name, email address, company name and your preferred billing currency.
  • Commercial records: your plan, subscription status, credit balance, orders and their progress, invoices and payments.
  • Payment evidence: for manual bank transfers, the receipt file you upload, which a Booltspace admin reviews before activating or renewing your plan. Card payments are handled by a payment gateway — see section 7.
  • Work records: campaigns, briefs, style samples you upload, deliverables produced for you and your approvals or change requests.
  • Support records: tickets, chat messages and any files attached to them.
  • Social and outreach details: the handles of the accounts we work on for you, and the outreach details a campaign needs.

We never ask for, and the platform never stores, the passwords or backup codes to your social media accounts. See section 11.

3.3 Data we process on behalf of clients

Lead generation means we handle personal data about people who are not our clients — prospect names, business names, job titles, email addresses, phone numbers, social handles and the record of outreach sent to them.

For that data the client decides why it is collected and what happens to it, so the client is the controller and Booltspace is the processor. We act on the client's documented instructions, and we require the client to confirm they have a lawful basis for contacting those people. If you are a prospect and want to know who holds your data or wants it deleted, contact us and we will identify the client responsible and pass your request to them, or action it ourselves where we are permitted to.

3.4 Staff and admins

For people working on the Booltspace side we hold the account details above plus the role and job title attached to the invite code that was redeemed, and the record of work assigned to and completed by that person.

4. How we collect it

  • Directly from you: forms on the website, the sign-up and invite redemption flow, your dashboard, intake briefs, support chat and email.
  • From your instructions: the targeting criteria, account handles and brand assets you give us for a campaign.
  • Automatically, and minimally: our host records standard server logs such as IP address, timestamp and requested page, which exist for security and reliability.
  • From public and commercial sources, only for lead generation and only on a client's instruction: publicly listed business contact details and comparable sources.

Where the GDPR or UK GDPR applies, we rely on these legal bases. The Nigeria Data Protection Act 2023 recognises a closely similar set, and we apply the same reasoning under it.

  • Contract — to deliver the plan you bought: producing work, running campaigns, tracking credits, taking payment and supporting you.
  • Consent — when you submit a form asking us for an audit or a call, and if you ever opt in to marketing email. You can withdraw consent at any time without affecting what we did before you withdrew it.
  • Legitimate interests — keeping the platform secure, preventing fraud and abuse, fixing faults, and following up once on a request you made of us. We only rely on this where your rights and expectations do not override it.
  • Legal obligation — keeping accounting and tax records, and responding to lawful requests from a regulator or court.
  • On a client's instruction — for prospect data in a lead generation campaign. The lawful basis for that processing is the client's to establish and document, not ours.

6. How we use it

  • To create your account, assign your role and let you sign in.
  • To produce and deliver the work you have ordered, and to show its progress in your dashboard.
  • To bill you, confirm bank transfers, apply credits and issue receipts.
  • To answer support tickets, requests and emails.
  • To send service messages you cannot opt out of while you hold an account — renewal notices, receipts, approvals needed, security notices.
  • To run the lead generation campaigns a client has instructed, within the limits that client has set.
  • To keep the service secure and working, and to meet our legal and accounting obligations.

We do not sell personal data, and we do not share it with advertisers or data brokers.

7. Sub-processors

Running the platform means trusting a small number of service providers. They process data on our behalf, under their own contracts and security commitments, and only to do the job we use them for:

  • Clerk — authentication. Holds sign-in identity, email addresses and session data for dashboard accounts.
  • Convex — the application database and file storage. Holds account records, orders, campaigns, deliverables, support messages and uploaded files including bank transfer receipts.
  • Vercel — site and application hosting, including standard server logs.
  • Anthropic — the Claude API powers the AI support assistant. Content you send to the assistant is processed to generate its reply.
  • Payment gateways — card payments are processed by a gateway (we use [payment gateway — Paystack and/or Flutterwave, confirm which]). Full card numbers go to the gateway, never to Booltspace, and we do not store them.
  • Email delivery [email provider used for transactional email], for account and service emails.

We will update this list when it changes. If you want the current list in writing for your own compliance records, ask us.

8. International transfers

Booltspace serves clients in Nigeria and internationally, and the providers above operate globally, so personal data will be stored and processed outside your own country — in practice often in the United States and the European Union.

Where data leaves the EEA or the UK we rely on the safeguards our providers offer, normally Standard Contractual Clauses or the UK International Data Transfer Addendum. Where the Nigeria Data Protection Act 2023 applies, we transfer only on a basis that Act permits. We have not independently verified every provider's transfer paperwork against every jurisdiction we sell into — that verification is part of the legal review this document still needs.

9. Cookies and analytics

Being straight about this: the site currently uses only the essential cookies and browser session storage needed to sign you in and keep you signed in. There is no advertising pixel, no cross-site tracking and no analytics product running at the time of writing.

If we add analytics, a marketing pixel or any non-essential cookie, we will update this policy first, say exactly what it is, and ask for consent where the law requires it.

10. How long we keep data

  • Website enquiries: up to 24 months from your last contact with us, then deleted.
  • Account and work records: for as long as you hold an account, and for 12 months after you close it, so that deliverables and history can be recovered if you come back or dispute something.
  • Invoices, payments and receipts: for as long as tax and accounting law requires us to keep them, which is longer than the periods above.
  • Prospect data processed for a client: for the length of the campaign, then deleted or returned on the client's instruction.
  • Server and security logs: a short rolling window set by our hosting provider.

You can ask us to delete your data earlier. We will do it unless we are legally required to keep a record, in which case we will tell you what we are keeping and why.

11. How we protect it

The most important commitment first: Booltspace never stores passwords or backup codes for your social media or advertising accounts. The platform has no field for them, we will not ask for them in a ticket or an email, and if anyone claiming to be from Booltspace asks you for one, it is not us. We store account handles and the outreach details a campaign needs, and nothing that would let us or an attacker log in as you.

Beyond that:

  • Sign-in is handled by Clerk, so your Booltspace password is never stored in our own database.
  • Access is scoped by role. Staff see only the clients assigned to them and cannot see billing data.
  • The platform is invite-only. Accounts without a redeemed code have no access to any dashboard.
  • Data is encrypted in transit, and at rest by our providers.
  • Uploaded files, including payment receipts, are stored in access controlled storage rather than sent around by email.

No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant authority within the time limits the applicable law sets.

12. Your rights

Under the Nigeria Data Protection Act 2023, and under the GDPR and UK GDPR where they apply to you, you can ask us to:

  • Access the personal data we hold about you, and get a copy of it.
  • Correct anything inaccurate or incomplete.
  • Delete it, where we have no overriding legal reason to keep it.
  • Port it — receive it in a common machine-readable format, or have it sent to another provider where that is technically feasible.
  • Object to processing we base on legitimate interests, and to direct marketing at any time.
  • Restrict processing while a dispute about accuracy or lawfulness is resolved.
  • Withdraw consent where consent is what we relied on.

Email hello@booltspace.com and we will respond within one month. There is no charge unless a request is repetitive or excessive, and we will say so before doing anything.

If you are unhappy with how we handled a request, you can complain to a supervisory authority. In Nigeria that is the Nigeria Data Protection Commission (NDPC). In the EU it is the authority in the country where you live or work. In the UK it is the Information Commissioner's Office. We would rather you came to us first, but you do not have to.

If you are in the United States, your rights depend on your state. Several states, California among them, give residents rights to know what is collected, to delete it, to correct it and to opt out of its sale or sharing. Booltspace does not sell or share personal data for cross-context behavioural advertising. Send any state-law privacy request to the same address and we will handle it under the rules that apply to you.

13. Children

Booltspace is a business service and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us personal data, tell us and we will delete it.

14. Changes to this policy

When this policy changes we update the date at the top of the page. If a change materially affects how we use your data, we will tell account holders by email before it takes effect rather than relying on you to notice.

15. Contact us

Questions, requests or complaints about privacy go to hello@booltspace.com, or by post to [Registered company name], [Registered business address].

Our terms of service explain the commercial side of the relationship, including the data protection roles for lead generation campaigns.