Legal

Privacy Policy

Your privacy matters to us. This policy explains what data we collect, how we use it, and the rights you have over your information.

Last updated: 25 March 2026

Introduction

Techno Believe Solutions Ltd (Company Number: 10866509), trading as Marketing So High ("MSH", "we", "us", or "our"), operates the website marketingsohigh.com and the application at app.marketingsohigh.com.

We are a company registered in England and Wales with our registered address at 128 City Road, London, EC1V 2NX, GB. The director of the company is Chetan Sroay.

This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our website and SaaS platform. We are committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

By using our services, you acknowledge that you have read and understood this Privacy Policy.

Data Controller

Techno Believe Solutions Ltd is the data controller responsible for your personal data under UK GDPR. If you have any questions about how we handle your data, you can contact our data protection team:

ICO registration: Registration is pending with the Information Commissioner's Office (ICO). This section will be updated with our registration number once issued.

1. Data We Collect

Account Information

When you create an account, we collect your name, email address, company name, job title, and billing information. If you sign up via a third-party provider (e.g. Google), we receive basic profile information from that provider.

Usage Data

We automatically collect data about how you interact with our platform, including pages visited, features used, session duration, browser type, device information, IP address, and referring URLs. This helps us understand how our product is used and where we can improve.

Content Data

When you use MSH to generate or manage marketing content, we process the content you create, edit, or publish through our platform. This includes blog posts, social media content, outreach messages, and any uploaded assets.

Connected Accounts & Email Data

If you connect external accounts (such as LinkedIn or email accounts for outreach), we access only the data necessary to provide our services. For email outreach, this includes the email addresses you send to, message content you compose through our platform, and delivery/engagement metrics. We do not read or store the contents of your personal inbox.

2. How We Use Your Data

We use the data we collect for the following purposes:

  • Providing our service — to operate the MSH platform, deliver AI-generated content, run outreach campaigns, and provide analytics dashboards.
  • Improving our product — to analyse usage patterns, identify bugs, optimise features, and develop new functionality based on aggregate trends.
  • Analytics & performance — to measure and report on the effectiveness of campaigns run through our platform.
  • Communication — to send you service-related notifications, updates, security alerts, and (with your consent) marketing communications.
  • Billing & support — to process payments, manage subscriptions, and respond to your support requests.

We process your data on the lawful bases of contract performance (providing the service you signed up for), legitimate interest (improving our product and ensuring security), and consent (where applicable, such as marketing emails).

3. Data Storage & Security

Your data is stored securely using cloud infrastructure powered by Supabase and other reputable cloud service providers. All data is encrypted in transit (TLS 1.2+) and at rest (AES-256).

We implement industry-standard security measures including:

  • Row-level security and access controls on all database tables
  • Regular security audits and vulnerability assessments
  • Secure authentication with hashed passwords and support for multi-factor authentication
  • Minimal access principles for our team — only authorised personnel can access user data, and only when necessary

While we take every reasonable step to protect your data, no system is completely secure. If we become aware of a data breach that affects your personal data, we will notify you and the relevant authorities in accordance with UK GDPR requirements.

4. Third-Party Services

To deliver our service, we integrate with the following third-party providers. Each processes data only as necessary and in accordance with their own privacy policies:

LinkedIn API

Used for publishing content to LinkedIn and retrieving engagement data from connected LinkedIn accounts. We access only the data you authorise through LinkedIn's OAuth consent flow.

Facebook Pages (Meta)

Used to publish content to Facebook Pages you administer and to report how those posts performed. Permissions we request: pages_show_list, pages_manage_posts, pages_read_engagement, read_insights. We list your Pages so you can choose one, publish only content you authored and approved, and read each post's own click and reaction counts (its post insights). We do not read, write or delete comments or messages, and we never publish without your approval.

Instagram (Meta)

Used to publish to Instagram Business and Creator accounts you connect, via Instagram Business Login. Permissions we request: instagram_business_basic, instagram_business_content_publish, instagram_business_manage_insights, instagram_business_manage_comments, instagram_business_manage_messages. We read your username so you can confirm which account is linked, publish images, carousels and Reels you authored and approved, and read each post's own insights. Comment replies: if you create a keyword rule, then when someone comments that keyword on one of your posts we publicly reply to their comment and send them one private message, such as a link they asked for. We read the comments on your own posts to find those keywords. A rule is created switched off, only you can switch it on, and it acts only on comments made after you did. We send at most one private message per comment, within the seven days Instagram allows, and never a follow-up. We never message anyone who has not commented, and we never read, list or store your direct-message inbox — the messaging permission is used for that single private reply and nothing else. We keep a log of what was sent, including the commenter's handle and comment text, for 30 days so you can see what the automation did, and then delete it. We do not use it to produce another customer's content, and we do not build profiles of the people who comment.

Threads (Meta)

Used to publish to the Threads profile you connect. Permissions we request: threads_basic, threads_content_publish, threads_manage_insights, threads_read_replies, threads_manage_replies. We read your username to label the connected profile, publish posts you authored and approved, and read each post's own view, like, reply, repost, quote and share counts to report its performance back to you. We also read the replies people leave on your posts so you can see and answer them from your inbox, and hide a reply when you choose to. About the replies other people write: we store a reply's text and the author's handle only for as long as you need it to answer, and we delete it after. We never request or store profile pictures, follower counts or verification status. Where we keep anything longer in order to improve the suggestions we give you, it is first de-identified — email addresses, handles, links, phone numbers and names are stripped out, and what remains cannot be linked back to the person who wrote it. We do not use one customer's replies to produce another customer's content, we do not build profiles of the people who reply to you, and we never sell or share any of it. Keyword search: with threads_keyword_search we search public Threads posts for the keywords you choose, so we can show you conversations you may want to join. We hold a matching post's text, its author's handle and its link, so you can read it and decide. Nothing is posted in reply unless you approve it — we never reply automatically. We do not rank or profile the people who wrote those posts, and candidates you do not act on are deleted.

Google APIs

When you connect your Google account, MSH requests access to specific Google services on your behalf using OAuth. The scopes we request and what each is used for:

  • Google Sign-In (openid, email, profile) — to authenticate you when you log into MSH.
  • Google Search Console (https://www.googleapis.com/auth/webmasters) — to read your site's search performance data (impressions, clicks, queries, page rankings) so MSH can show you SEO insights, AND to submit XML sitemaps on your behalf so Google can discover refreshed content faster. We never delete sites you own; we only read performance data and submit sitemaps you explicitly request.
  • Google Analytics 4 (https://www.googleapis.com/auth/analytics.readonly) — to read your traffic and engagement metrics (pageviews, sessions, sources, conversions) so MSH can show you analytics dashboards. We never modify your GA4 properties or delete data.
  • Google Indexing API (https://www.googleapis.com/auth/indexing) — to submit individual URLs for re-crawling after MSH refreshes a piece of content, so updates appear in Google search results faster. Used only when you publish or refresh content via MSH.

MSH's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke access at any time at myaccount.google.com/permissions, which stops all further data access.

Google user data — Limited Use. The Google user data MSH receives is used only to provide and improve the features you connected it for, as described above. We do not sell Google user data, we do not use it for advertising, and we do not transfer it to third parties except to the sub-processors listed on this page who host or deliver the service on our behalf, or where you direct us to, or where the law requires it. No human at MSH reads your Google user data except where you ask us to for support, where it is necessary for security, or where the law requires it. Revoking access at myaccount.google.com/permissions stops all further access immediately, and you can ask us to delete what we already hold.

Resend

Used as our email delivery provider for transactional emails and outreach campaigns. Resend processes recipient email addresses and message content on our behalf.

Supabase

Our primary database and authentication provider. Supabase hosts your account data and application data in secure, SOC 2-compliant cloud infrastructure.

Stripe

Our payment processor for subscription billing, invoicing, and payment card handling. Your payment card details are never stored on our servers — they are handled entirely by Stripe, which is PCI DSS Level 1 compliant. Stripe processes your name, email, payment card details, and billing address.

Vercel

Our hosting and deployment platform for the MSH website and application. Vercel may process your IP address, browser information, and request metadata as part of serving our application. Vercel is SOC 2 Type II compliant.

We do not sell your personal data to any third party.

5. How We Share Your Data

We do not sell your data, and we never have. We share it only in these four situations:

  • Sub-processors — the providers listed in section 4, who host the service, deliver email or process payments on our behalf, under contract and only for that purpose.
  • Where you direct us — when you connect an account or ask MSH to publish something, we send exactly what that action requires to the platform you chose.
  • Legal obligation — where we are required to by law, a court, or a regulator, and where we are permitted to we will tell you first.
  • A change of ownership — if the business is sold or merges, data may transfer to the buyer, who would remain bound by this policy. You would be told before that happens.

We do not share your data with advertisers, data brokers, or for training third-party AI models.

6. Cookies

We use cookies and similar technologies to keep you signed in, remember your preferences, and understand how you use our platform. The cookies we use fall into these categories:

  • Essential cookies — required for the platform to function (e.g. authentication tokens, session management). These cannot be disabled.
  • Analytics cookies — help us understand usage patterns and improve the product. You can opt out of these at any time.
  • Preference cookies — remember your settings and choices (e.g. theme, language).

You can manage your cookie preferences through your browser settings. Disabling essential cookies may prevent the platform from functioning correctly.

7. Your Rights (GDPR)

Under the UK GDPR, you have the following rights over your personal data:

Right of Access

Request a copy of the personal data we hold about you.

Right to Rectification

Correct any inaccurate or incomplete personal data.

Right to Erasure

Request that we delete your personal data, subject to legal obligations.

Right to Data Portability

Export your data in a structured, commonly used, machine-readable format.

Right to Restrict Processing

Request that we limit how we use your data in certain circumstances.

Right to Object

Object to processing based on legitimate interest or for direct marketing purposes.

To exercise any of these rights, email us at privacy@marketingsohigh.com. We will respond to your request within 30 days.

8. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes outlined in this policy:

  • Account data — retained for the duration of your account and deleted within 90 days of account closure, unless required by law.
  • Usage data — retained in anonymised/aggregated form for up to 24 months for analytics purposes.
  • Content data — retained for the duration of your account. You can delete individual content items at any time from within the platform.
  • Billing data — retained for up to 7 years after your last transaction to comply with UK tax and accounting regulations.

9. Children's Privacy

MSH is a business-to-business service and is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a minor, we will delete it promptly.

10. International Data Transfers

Some of our third-party service providers may process data outside the United Kingdom. Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or transfers to countries with an adequacy decision from the UK government, to ensure your data is protected to the same standard as under UK GDPR.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make significant changes, we will notify you via email or through a notice on our platform. We encourage you to review this page periodically.

12. Contact Us

If you have any questions about this Privacy Policy, your personal data, or wish to exercise your rights, please contact us:

Techno Believe Solutions Ltd

Trading as Marketing So High (MSH)

Company Number: 10866509

Director: Chetan Sroay

128 City Road, London, EC1V 2NX, GB

Right to Complain

If you are unhappy with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection:

  • Website: ico.org.uk
  • Helpline: 0303 123 1113
  • Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

We would appreciate the chance to address your concerns before you contact the ICO, so please reach out to us first at privacy@marketingsohigh.com.