Privacy Policy
This policy explains how Milo ("Milo", "we", "us"), a service operated by IDML PRODUCTS LIMITED of 483 Green Lanes, London N13 4BS, collects and uses your personal data when you use heymilo.co and the member portal. We are the data controller. For any privacy question, contact milo@heymilo.co.
1. The data we collect
- Account data: your name, email address, and password (stored only in hashed form by our authentication provider).
- Usage data: the templates you download, any requests or messages you send us (for example Pro customisation requests or support questions), and your preferences such as language.
- Payment data: handled by our payment processor (Stripe). We do not see or store your full card details. We receive limited billing data such as your subscription status and the last four digits of your card.
- Technical data: IP address, browser type, and similar information collected automatically by our hosting and infrastructure providers for security and to operate the service.
2. How and why we use it
| Purpose | Lawful basis (UK GDPR) |
|---|---|
| To provide the service (your account, library access, downloads, customisation requests) | Performance of a contract |
| To take payment and manage your subscription | Performance of a contract |
| To secure, maintain, and improve the service | Legitimate interests |
| To send service emails (invites, password resets, important notices) | Performance of a contract |
| To send optional marketing or updates | Consent (you can opt out anytime) |
| To keep tax and accounting records | Legal obligation |
3. Who we share it with (our processors)
We do not sell your data. We share it only with the providers that help us run Milo, each acting under contract:
- Stripe: payment processing.
- Supabase: database, authentication, and hosting of your account and usage data.
- Netlify: website hosting and delivery.
- Resend: sending service emails.
We may also disclose data if required by law.
4. International transfers
Some of our providers process data outside the UK/EEA. Where they do, we rely on appropriate safeguards (such as the UK International Data Transfer Agreement, EU Standard Contractual Clauses, or an adequacy decision) to protect your data.
5. How long we keep it
We keep your account and message data for as long as you are a member and for a reasonable period afterwards. We keep payment and tax records for as long as required by law (generally six years in the UK). You can ask us to delete your data sooner (see your rights below).
6. Your rights
Under UK GDPR you have the right to access, correct, delete, restrict, or object to our use of your data, to data portability, and to withdraw consent at any time. To exercise any of these, email milo@heymilo.co. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
7. Cookies and local storage
We use only what is necessary to run the service: a secure session in your browser's local storage to keep you logged in, and standard requests to our font providers. We do not currently use advertising or third-party tracking cookies. If that changes, we will update this policy and, where required, ask for your consent.
8. Security
We protect your data with measures including encryption in transit, hashed passwords, and database-level access controls so members can only see their own data. No system is perfectly secure, but we take reasonable steps to keep your information safe.
9. Children
Milo is for people aged 18 and over and is not directed at children.
10. Changes
We may update this policy from time to time. We will post the new version here and update the date above.
11. Contact
Questions or requests: milo@heymilo.co.