Privacy
What we collect, why we need it, and every company that touches it. Written from the code rather than from a template, so each line can be checked against what the service actually does.
Updated
Contents
- Who we are
- The short version
- Analytics, and the choice you were given
- When something breaks
- What we collect, and why
- The contract you upload, and the model that reads it
- Cookies and what is stored in your browser
- Who handles data for us
- Where it lives
- Email we send you
- How long we keep things
- Your rights
- Changes
Who we are
Draymere is a service of DDDEV LTD, a private limited company registered in England and Wales, company number 16374016, registered office C/O Schoolgate Accounting Services, 46–50 Coombe Road, New Malden, London, England KT3 4QF. We are the controller of the personal data described here.
For anything about your data — a question, a correction, a copy, a deletion — write to hello@draymere.com. We answer within one month.
The short version
We count how the site is used, once you have answered the bar that asks. When you ask for a price we hold what you told us about the property. When you become a client we hold what is needed to visit it and report on it: the address, your contract, the photographs, the visit dates.
We do not sell your data. We do not show your report to your developer. An agent never sees a private client's report.
Analytics, and the choice you were given
PostHog measures both this site and the app. Google Analytics counts pages on this site only — it is not loaded in the app, where the screens carry what you told us about your property and where nobody reads page counts anyway. Neither is loaded until you answer the bar at the foot of the page. Before that answer nothing of theirs is fetched, and nothing is written to or read from your browser. With scripting off they never run at all.
There are two things to answer for, and only one of them is a question. What the service cannot work without — the cookies that keep you signed in, the one that carries you back from the payment page, the one that names this browser, and the record of the answer itself — is not asked about. Measurement is.
Accept and both products run as described below, each keeping its own identifier in your browser. Refuse and Google Analytics is never loaded, and PostHog runs without storing anything on your device: it still counts that a page was opened and that a step was taken, and it cannot tell that today's visit and last week's were the same person. Nothing on the site works differently either way, and refusing is one click, the same click as accepting.
The answer is kept in one cookie on draymere.com, so it holds on the app as well and you are asked once. It records what you chose, when, and which version of the wording you were shown; if that wording changes, you are asked again rather than carried over. To change your mind, theCookies link in the footer of any page — here and in the app — puts the same question back. Turning measurement off deletes what it left behind.
What measurement receives:
- The pages you open, when, in what order, and the site that sent you.
- Your device type and browser, and — only if you accepted — an approximate location worked out from your IP address. After a refusal your address is used to build the daily identifier and then dropped, and no location is recorded.
- A handful of named steps: the price page opened, the calculator submitted, the district, the property type and the size band you chose, a checkout started, a payment completed.
- Once you sign in, your account identifier — so the visit that read a guide last week and the account that ordered today are one person. If you refused, this one does not happen: there is nobody to attach.
- The address of the page. On this site that is the whole address, campaign marks and all. In the app the question mark and everything after it is cut off before the event is sent, so a filter, a search box or a link you were following cannot ride along in it.
What it never receives:
- Your email address, your name or your phone number.
- The contents of a report, a photograph, or your contract.
- Anything you typed into the note field, or the name of the developer.
- The name you gave your property, its street address or its point on the map. These used to travel in the page address so that signing in half-way through the form did not lose them, which put them in front of measurement; they are now held in the tab instead, and the address carries only the screen to return to.
When something breaks
If a script on a page throws an error, PostHog records it. This is the same script and the same company as the counting above, not a separate service, and it is what tells us that a screen is broken for somebody who will not write to say so.
A report of that kind holds:
- The address of the page it happened on — trimmed in the app, as above.
- Your browser, its version and your operating system.
- The error's own type and message, as the browser or our code wrote it.
- The stack trace: the files, functions and line numbers our code was in at that moment.
The message is written by the code, not by you. Ours quote a choice or a status code — a district, a size band, a failed request — and we have not written one that repeats what you typed. We cannot promise the same of a message the browser writes itself, which may quote the value it choked on. The page address that goes with the report is the trimmed one in the app, and nothing you type reaches an address there any more. That is the honest limit here.
It follows the same answer you gave the bar, because it is the same script: accept, and an error report carries the same identifier as everything else; refuse, and it is still sent — with nothing stored on your device, unjoined to any other visit, exactly like the counting. Crash reports are not exempt from the choice, and they do not switch off with it either. A browser that blocks PostHog blocks this as well.
What we collect, and why
- Asking for a price. The district, the property type and the floor area you entered. If you tick the box, your email address as well, so we can write to you once if you do not finish. We record which version of that wording you agreed to and when. Unsubscribing deletes the record outright. We also store your measurement identifier on that record, so the reminder can be told apart from a fresh visit. Your email address does not go to the measurement products, but in our own database those two sit on the same row until the record is deleted.
- Signing in. Your email address and a six-digit code sent to it. There is no password unless you work for us.
- Your devices. Every signed-in request records the browser you are using and the last IP address it came from, against an identifier we set in a cookie. It is there because a subscription is sold to an office, not passed around a group chat, and counting devices is how that is enforced.
- Your property. Its name, address, map point, project, developer, type and floor area. When you drop a pin, the coordinates go to Google's geocoding service and come back as an address you can edit. When you search for a project or a street, what you typed goes there too. The key stays on our server: your browser never talks to Google directly for this.
- Paying. Card details are entered at Stripe and never reach us. Stripe receives your email address, the billing address it asks you for, and — if you fill them in — a company name and a tax number. If you told us which payment milestone the visit is about, that line goes to Stripe as a reference. We keep the payment identifier, the amount, the currency and whether it succeeded.
- Being a client. Your contract if you upload one, the payment milestones read out of it, the dates of visits, the photographs taken at your property, and what our people wrote about it.
- Being an agent. Your team, the markets your access covers and the dates it runs between, and invitations you sent or received.
- Email settings. Whether you want the digest and how often, and when we last sent one.
The contract you upload, and the model that reads it
A purchase contract is the most private thing you give us, so this is spelt out.
The file is stored at Bunny.net under a path only we can build, and it is never public: each time you or one of our staff opens it, a fresh link is signed that expires. Nobody else — not an agent, not the person who visits your property — can see the file. The specialist who attends gets one line: the name of the milestone you asked about.
Once, when you upload it, the whole file is sent to a model to find the payment milestones in it. It goes through OpenRouter, which passes it to Google's Gemini. What comes back is a list of milestone lines, and only those lines are saved. The text of your contract is not stored anywhere but the file itself. It is read once; there is no second pass.
Two other things go to the same model. Before a visit, up to four photographs from the last visit to your property are sent so it can suggest what to look at this time. When a report is published, the written comment is sent to be translated into your language.
We do not sell what you upload, license it, or build a dataset out of it. What OpenRouter and Google keep on their own side is governed by their terms, not ours.
Who handles data for us
- Supabase Ireland. The database. Accounts, properties, orders, reports and everything else we keep. It also sends your sign-in code.
- Vercel United States, running in Dubai. Hosts the site and the app. Every request passes through it, so it sees addresses of pages and network details.
- Stripe United States and Ireland. Takes the payment. Your card is entered on their page, not ours.
- Bunny.net Europe, served worldwide. Stores photographs, uploaded contracts and the map tiles. Files are not public; every link is signed and expires.
- Resend United States. Sends our email: the digest, the note when a report is ready, a team invitation, and the one reminder.
- PostHog European Union. Counts how the site and the app are used, and receives a report when a script on a page fails. If you refused, both still happen, but without storing anything in your browser.
- Google United States. Google Analytics counts page views on this site, and only if you accepted; it is not loaded in the app at all. The Geocoding API turns a map point into an address, and an address into a map point — from our server, so your browser never talks to Google for it.
- OpenRouter United States. Passes what we send to the model that reads contracts, and returns its answer.
Nobody else. There is no advertising network on this site and no data broker. Error reports go to PostHog, which is already on this list, and to nobody else.
Where it lives
Accounts, orders and reports are stored in Ireland. The code that serves you runs on Vercel in Dubai. Measurement is processed in the European Union. Photographs, contracts and map tiles are stored in Europe and served from whichever edge is nearest you.
Supabase, Vercel, Bunny, Stripe, Google, PostHog, Resend and OpenRouter are outside the United Kingdom, and the Vercel machines that serve you are in the United Arab Emirates. Where data leaves the UK we rely on the adequacy decisions and standard contractual clauses those companies offer.
Email we send you
- The code you asked for when signing in.
- A link back into your account after you have paid, because the payment often finishes on a different device from the one you bought on.
- A note when one of your reports is published.
- A digest of what happened on the projects you watch, daily or weekly, as you set it.
- An invitation, if a colleague sent you one.
- A warning before an access you bought runs out, so it does not end without notice.
- One reminder, and only one, if you asked for a price, ticked the box and did not finish. Every one of those carries an unsubscribe link that deletes the record.
There is no marketing list beyond that.
How long we keep things
- A sign-in code: minutes.
- A price enquiry you did not finish: until you unsubscribe, or until you order, whichever comes first.
- A device record: one row per browser, holding only the last IP address it was seen from, not a history.
- An uploaded contract: until you delete it. Deleting removes the file itself, not only the row.
- Your account, your reports and the payment records behind them: while you are a client, and afterwards for as long as we must keep financial records.
- Measurement: under the retention settings of PostHog and Google Analytics.
Your rights
You can ask for a copy of what we hold, ask us to correct it, ask us to delete it, ask us to stop or restrict what we do with it, and object to processing we do on grounds of legitimate interest. Where the law gives you portability, you can ask for your data in a form you can take elsewhere.
Write to hello@draymere.com. We may need to check that you are who you say you are before we act.
If you are unhappy with how we handled it, tell us first. You also have the right to complain to the Information Commissioner's Office, the UK regulator, atico.org.uk, or to the regulator in the country you live in.
Changes
When we change what we collect or who handles it, we change this page and the date at the top. See also our terms of service, which this page is part of.