Skip to content

Last updated: 29 March 2026

Privacy Policy

We care about your privacy. This policy explains what personal data Findstead collects, how we use it, and what rights you have over your information. It applies to all users of the Findstead platform and website.

1. Who we are

Findstead Ltd ("Findstead", "we", "us", or "our") is a company registered in England and Wales. We operate the Findstead platform — an AI-powered property search, analysis, and investment insights service for home buyers and property investors in the United Kingdom.

If you have any questions about this Privacy Policy or how we handle your data, you can contact us at [email protected].

2. What data we collect

We collect and process the following categories of personal data:

Account data: Your name, email address, and (where applicable) profile picture, provided when you create an account via email and password, Google sign-in, or Apple sign-in.

Preference data: Your property search criteria, budget, preferred locations, buyer type, must-have features, lifestyle preferences, and — for investor accounts — investment strategy selections, target yield, financing type, and acceptable property condition.

Financial data: If you subscribe to Findstead Premium, your payment is processed by Stripe. We store your Stripe customer ID and subscription status but never store your card details — these are held solely by Stripe in accordance with PCI DSS.

Usage data: Pages you visit, searches you perform, properties you view, save, or dismiss, AI chat messages, viewing requests, and interactions with the platform. This is collected automatically via server logs and, with your consent, analytics cookies.

Device data: Your IP address, browser type, operating system, and device identifiers.

Communications: Messages you send through our AI chat feature, contact form, or viewing request system.

3. How we use your data

We use your personal data to:

- Provide the service: Process your searches, generate AI-powered property recommendations, produce investment analysis and strategy scores, and personalise your experience based on your buyer profile. - Process payments: Manage your Findstead Premium subscription via Stripe, including checkout, renewal, and cancellation. - Communicate with you: Send account-related notifications, saved search alerts, viewing request updates, and (with your consent) product updates. - Improve our platform: Analyse anonymous usage patterns via PostHog analytics (EU-hosted) to improve search quality, fix bugs, and develop new features. Basic analytics operates in cookieless mode under legitimate interest; cross-session analytics cookies are only activated after you provide explicit consent. - Legal compliance: Meet our obligations under UK law, including UK GDPR, the Data Protection Act 2018, and applicable financial regulations. - Security: Detect and prevent fraud, abuse, and unauthorised access.

We do not sell your personal data to third parties. We do not use your data for advertising profiling.

5. Data sharing

We share your data with a limited number of trusted third parties solely to operate the platform:

- Google: For authentication services (Sign in with Google). - Apple: For authentication services (Sign in with Apple). - Stripe: For payment processing. Stripe processes your card details under its own privacy policy and PCI DSS certification. We share only your email and Stripe customer ID. - OpenAI: We send anonymised property search queries and property data to OpenAI's API to generate AI recommendations, natural-language explanations, and investment analysis. We do not send your name or contact details. - PostHog: With your consent, we use PostHog (EU-hosted) for privacy-preserving product analytics. PostHog does not receive your name or personal contact information unless you are logged in. - Brevo: For transactional emails (welcome emails, saved search alerts, viewing notifications). We share your email address and first name. - Infrastructure providers: Cloud hosting (Railway), image storage (Cloudflare R2), and databases operating under data processing agreements.

All third-party processors are contractually bound to process data only on our instructions and in accordance with UK GDPR.

6. Cookies

We use the following categories of cookies:

- Strictly necessary: Required for authentication and core functionality (e.g. session tokens). Cannot be disabled. - Analytics: We use PostHog (EU-hosted) for product analytics. By default, PostHog operates in cookieless mode — no cookies or local storage are used, and each page visit is anonymous with no cross-session tracking. If you accept analytics cookies, we enable persistent identifiers that allow us to understand usage patterns across sessions. You can withdraw consent at any time by clearing your browser cookies. - Preferences: Remember your settings, such as notification preferences and map view.

You can manage cookie preferences via our cookie consent banner. Rejecting non-essential cookies will not affect your ability to use Findstead.

7. Data retention

We retain your personal data for as long as your account is active, plus a reasonable period thereafter for legal and operational purposes. Specifically:

- Account data: Retained until you delete your account, plus 30 days. - Search and usage data: Retained for 24 months from collection. - Payment records: Retained for 7 years as required by UK tax law. - Support communications: Retained for 3 years. - Legal compliance records: Retained for 7 years as required by UK law.

You may request deletion of your data at any time (see "Your rights" below).

8. Your rights

Under UK GDPR, you have the following rights:

- Access: Request a copy of the personal data we hold about you. - Rectification: Ask us to correct inaccurate data. - Erasure: Request deletion of your data ("right to be forgotten"), subject to legal retention requirements. You can delete your account directly from your Profile settings, which will permanently remove your personal data and all associated records. - Portability: Receive your data in a machine-readable format. - Restriction: Ask us to limit processing of your data in certain circumstances. - Objection: Object to processing based on legitimate interests. - Withdraw consent: Withdraw consent for analytics cookies or optional communications at any time.

To exercise any of these rights, email [email protected] or use the self-service options in your account settings. We will respond within 30 days.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

9. Security

We take security seriously. Measures include:

- All data transmitted using TLS encryption. - Passwords hashed using bcrypt with salt. - Access controls limiting which team members can access personal data. - Rate limiting on authentication endpoints to prevent brute-force attacks. - Regular security reviews. - Breach notification procedures meeting ICO requirements.

No system is perfectly secure. If you believe your account has been compromised, contact [email protected] immediately.

10. Investment analysis disclaimer

Findstead provides investment analysis, strategy scores, deal calculators, and rental yield estimates for informational purposes only. This information does not constitute financial, investment, or tax advice. We are not regulated by the Financial Conduct Authority (FCA).

Property investment involves risk, including the potential loss of capital. You should seek independent professional advice from a qualified financial adviser, solicitor, or accountant before making any investment decision.

Data used in investment analysis — including comparable sales, rental estimates, and area statistics — is sourced from third parties and may not be complete or current.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page and, for material changes, notify you by email or in-app notification.

Your continued use of Findstead after changes take effect constitutes acceptance of the updated policy.

Questions about your data?

Contact our privacy team at [email protected] or use our contact form.