Privacy Policy
Last updated 23 July 2026
This Privacy Policy explains how Sonder Labs ("we", "us") processes personal data. It covers two categories of data: (1) account data about our customers and their team members, and (2) publicly available data used to derive audience insights.
1. Account data we collect
- Name, email address, and authentication credentials
- Workspace and team membership information
- Billing details, processed by Stripe (we don't store card numbers)
- Usage data: queries run, features used, questions asked
2. Audience data
We derive audience insights from publicly available online data. This is used only to produce aggregate, de-identified audience segments (a "panel") — not to build profiles of, or take action against, individuals.
- Individual-level lookup of the underlying source data is disabled at the product level; only segment-level, aggregate outputs are returned.
- Segment outputs are sanitized to remove identity-revealing details before being returned to customers.
- Data is retained for accuracy and audit purposes and is not sold or shared for advertising.
3. How we use data
- To provide and improve the Service
- To build and maintain audience panels
- To process payments and manage subscriptions
- To communicate with you about your account or the Service
- To comply with legal obligations
4. Legal basis (UK/EU GDPR)
- Account data: processed under contract (to provide the Service) and legitimate interest (product improvement, security).
- Audience data: processed under legitimate interest — limited to what was made publicly available, used only in aggregate/de-identified form, with individual-level access disabled.
5. Data sharing
We share data with the sub-processors listed on our Sub-processors page strictly to operate the Service (hosting, database, payments, AI inference, data collection). We do not sell personal data.
6. Data retention
Account data is retained for the life of your account plus a reasonable period after closure for legal and accounting purposes. Query/history results are retained on a rolling basis and may be deleted on request. Underlying data behind a deleted audience panel is removed from active systems when the audience is deleted.
7. Your rights
Depending on your location, you may have the right to access, correct, delete, or port your data, and to object to or restrict certain processing. Because individual-level source data is never surfaced through the product, requests relating to a specific individual should be sent to hello@sonderlabs.co.uk and will be handled case by case.
8. International transfers
Some of our sub-processors are located outside the UK/EEA (see the Sub-processors page). Where required, we rely on Standard Contractual Clauses or equivalent safeguards for such transfers.
9. Security
We use industry-standard technical and organisational measures, including access controls, encryption in transit, and workspace-level data isolation.
10. Changes to this policy
We may update this policy from time to time. Material changes will be notified via email or in-app notice.
11. Contact
Data protection queries: hello@sonderlabs.co.uk