Privacy Policy
Introduction and organisational info
We, at Tacit Labs Ltd, are dedicated to serving our customers and contacts to the best of our abilities. Tacit Labs Ltd is registered in England and Wales under company number 17110976, with its registered office at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, and is the data controller for the processing described in this policy. Part of our commitment involves the responsible management of personal information collected through our websites, tacitlabs.co.uk and refundmyrail.co.uk, and any related interactions. Our primary goals in processing this information include:
- Enhancing the user experience on our platform by understanding customer needs and preferences.
- Providing timely support and responding to inquiries or service requests.
- Improving our products and services to meet the evolving demands of our users.
It is our policy to process personal information with the utmost respect for privacy and security. We adhere to all relevant regulations and guidelines to ensure that the data we handle is protected against unauthorised access, disclosure, alteration, and destruction. Our practices are designed to safeguard the confidentiality and integrity of your personal information, while enabling us to deliver the services you trust us with.
- Should you have any questions or require further information about how we manage personal information, please feel free to contact us at privacy@tacitlabs.co.uk.
- Our representative in the European Union is Euverify Ltd (Ireland), Unit 3D North Point House, North Point Business Park, New Mallow Road, Cork, T23 AT2P, Ireland, appointed because we offer our services to people in the Union. If you are in the EU or the EEA, you can raise anything in this policy with them instead of with us: email gdpr@euverify.com, or use their secure request portal, which also lets you confirm for yourself that they really are our appointed representative.
Your privacy is our priority. We are committed to processing your personal information transparently and with your safety in mind. This commitment extends to our collaboration with third-party services that may process personal information on our behalf, such as in the case of delivering the emails you sign up for. Rest assured, all activities are conducted in strict compliance with applicable privacy laws.
Scope and application
Our privacy policy is designed to protect the personal information of all our stakeholders, including website visitors, registered users, and customers. Whether you are just browsing our websites, using our services as a registered user, or engaging with us as a valued customer, we ensure that your personal data is processed with the highest standards of privacy and security. This policy outlines our practices and your rights related to personal information.
This policy covers the pages of tacitlabs.co.uk, including the product pages within it; refundmyrail.co.uk, our product site for RefundMyRail; and the signup service at waitlist.tacitlabs.co.uk that handles every waitlist and newsletter form across our sites. The same policy is published on both sites, because the same things happen on both. Cookies, and the advertising and analytics that depend on your consent, are described in our Cookie Notice.
Data collection and processing
Our commitment to transparency and data protection extends to how we collect and use your personal information. Tacit Labs is a UK software studio building consumer apps, and we gather personal data when you sign up to hear from us through our website or provide information to us directly.
The following list details the types of personal information we may process:
- Email address, when you sign up to a waitlist or our newsletter, together with the choices you make on the form. Stored with these are which list you joined, the times of your signup and confirmation, the version of the consent wording you saw, and a coarse, non-identifying note of which page the signup came from.
- Only if you accept optional cookies, the providers in the table under Data sharing and disclosure also receive: device ID (cookie identifiers), IP address, IP-based approximate location, browser information and language, operating system and version, pages you visit on this site, and interaction logs (e.g., clicks, time spent on pages). We do not store these ourselves.
Please note, that we only process information that is essential for delivering our services, complying with legal obligations, or enhancing your user experience. Your privacy is paramount, and we are dedicated to handling your personal information responsibly and in accordance with all applicable laws.
At Tacit Labs Ltd, we believe in using personal information responsibly and ethically. The data we collect serves multiple purposes, all aimed at enhancing the services we offer and ensuring the highest level of satisfaction among our users, customers, and employees. Here are the key ways in which we use the personal information collected:
- Authentication and security
- Communication efforts
- Analytics and performance tracking
- Marketing and advertising
- Compliance with legal obligations
- User engagement and retention
- Content delivery
Your privacy is our priority. We process your personal information transparently and in accordance with your preferences and applicable privacy laws. We are committed to ensuring that your data is used solely for the purposes for which it was collected and in ways that you have authorised.
Our legal grounds
UK data protection law requires a legal basis for each thing we do with personal information. Ours are:
| What we do | Legal basis | Why |
|---|---|---|
| Waitlist and newsletter signups, and the emails they bring | Your consent | You opt in through the form and confirm by email, and you can withdraw at any time using the removal link in every email we send |
| The advertising tags, and the hashed-email signup reports to Meta, Google, Reddit and TikTok | Your consent | Nothing loads and nothing is sent unless you accept the Marketing category on the banner |
| Product analytics (PostHog) | Your consent | Loads only if you accept the Statistics category on the banner |
| Bot protection on our forms (Cloudflare Turnstile) | Our legitimate interests | An unprotected form fills with automated submissions, some of which send confirmation emails to people who never asked for them |
| Cookie-free site measurement (Cloudflare Web Analytics) | Our legitimate interests | Understanding and improving our own website; it stores nothing on your device and identifies nobody |
| Keeping the record of your consent choices | Legal obligation | We must be able to show that you were asked and what you answered |
Cookie-free site measurement
Every page of tacitlabs.co.uk and of refundmyrail.co.uk loads Cloudflare Web Analytics, a privacy-first measurement script operated by Cloudflare, Inc., the same provider that already serves both websites. It tells us in aggregate which pages are visited, roughly where in the world visits come from, and how quickly pages load, so that we can improve them.
That measurement sets no cookies, stores nothing on and reads nothing from your device, does not fingerprint you, and does not follow you to other websites. We receive only aggregate statistics: we never see your IP address or anything else that identifies you. As with any web request, Cloudflare transiently processes your IP address in order to deliver the script, exactly as it already does to serve every page of this site as our host, and we never receive or store it. We cannot stop counting one person on request, because we hold nothing that tells us which visits are yours; if you would rather not be counted, most content blockers block the script (beacon.min.js) without affecting how the site works.
Bot protection on our forms
Our signup forms use Cloudflare Turnstile to distinguish people from automated scripts. To perform that check, Cloudflare transiently processes signals from your browser together with your IP address, which we pass through to Turnstile's verification service on your behalf. Turnstile is a security control rather than a tracking tool: it sets no cross-site tracking cookies, and we never store your IP address or the signals it processes. Without a check like this, a signup form fills with automated submissions, some of which send confirmation emails to people who never asked for them.
The check keeps one item on your device, holding Turnstile's own state for it. It needs no permission from you, because it is part of doing the job you asked the form to do, and it stays until you clear this site's data. It is listed by name in the Necessary table of our Cookie Notice.
Data storage and protection
Data storage
- Personal information is stored on secure servers in Europe: signup data in Cloudflare's Western Europe region, email delivery in Resend's EU region, product analytics in PostHog's EU region, and consent records with Usercentrics in Denmark. Some of these providers are United States companies, and where their processing involves a transfer outside the UK, that transfer is protected by the safeguards described under International data transfers below.
- Data hosting partners: We partner with reputable data hosting providers committed to using state-of-the-art security measures. These partners are selected based on their adherence to stringent data protection standards.
Data protection measures
- Encryption: To protect data during transfer and at rest, we employ robust encryption technologies.
- Access control: Access to personal information is strictly limited to authorised personnel who have a legitimate business need to access the data. We enforce strict access controls and regularly review permissions.
- Security audits and monitoring: Regular security audits are conducted to identify and remediate potential vulnerabilities. We also monitor our systems for unusual activities to prevent unauthorised access.
How long we keep your information
We keep personal information only for as long as the purpose it was collected for requires. The automatic periods below are enforced by our signup service itself rather than by policy alone.
| What | Kept for |
|---|---|
| A signup you never confirmed | 30 days from submission, then deleted automatically |
| A confirmed product-waitlist signup | Until you remove yourself, or until shortly after the product launches: within 90 days of announcing a launch we delete that product's entire waitlist |
| A confirmed newsletter subscription | Until you unsubscribe |
| The advertising identifiers stored with a signup | 180 days from signup, then cleared automatically; the signup itself continues |
| The record of your consent | For as long as we hold the signup it relates to |
| Aggregate site measurement | Held by Cloudflare under their own retention; it identifies nobody and we keep no copy |
Retention for what you accept on the cookie banner, in summary. Every cookie's own lifetime is listed by name in our Cookie Notice:
| What | Kept for | Described in |
|---|---|---|
| The four advertising tags' cookies (Meta, Google, Reddit, TikTok) | From 90 days up to 2 years, per cookie | Cookie Notice, Marketing tables |
| PostHog session replays | 30 days | "Product analytics in detail: PostHog", below |
| PostHog events and browser profiles | Up to 7 years | "Product analytics in detail: PostHog", below |
| The cookie recording your banner answer | 12 months | Cookie Notice, Necessary table |
| Cookiebot's log of your answer | 1 year | The processor table below |
| What the advertising providers hold for themselves after a report arrives | Their own policies; we have no access and cannot delete it | "Who is responsible for the advertising measurement", below |
Data sharing and disclosure
At Tacit Labs Ltd, we are committed to safeguarding your personal information and ensuring it is treated with the utmost respect. This commitment extends to how we handle the sharing and disclosure of your data. Below we outline our practices in this area:
Sharing personal information
- Third-party service providers: We may share your information with third-party service providers who perform services on our behalf. Such trusted parties may have access to personally identifiable information on a need-to-know basis and will be contractually obliged to keep your information confidential. These partners are prohibited from using your personal information for any purpose other than to provide these services to Tacit Labs Ltd, and they are required to maintain the confidentiality of your information.
| Service | Provider | Purpose(s) | Collected personal data type(s) |
|---|---|---|---|
| TikTok (privacy policy) | TikTok Information Technologies UK Limited | Marketing and advertising; analytics and performance tracking | Email address (only ever as a SHA-256 hash, sent when you confirm a signup); device ID (cookie identifiers); IP address; browser information and language; ad click identifiers; pages you visit on this site |
| Reddit (privacy policy) | Reddit, Inc. | Marketing and advertising | Email address (only ever as a SHA-256 hash, sent when you confirm a signup); device ID (cookie identifiers); IP address; browser information and language; ad click identifiers; pages you visit on this site |
| PostHog (privacy policy) | PostHog Inc. | Analytics and performance tracking; user engagement and retention | Device ID (cookie identifiers); IP address (used to derive an approximate location, then discarded rather than stored); IP-based approximate location; browser information and language; pages you visit on this site; interaction logs (e.g., clicks, time spent on pages) |
| Resend (privacy policy) | Resend, Inc. | Communication efforts | Email address |
| Cookiebot (privacy policy) | Usercentrics A/S | Operating our consent banner and keeping the record of what you answered | Your banner answer; the date and time; your IP address with the final part removed so it no longer identifies your connection; your browser's user-agent string; the page you answered on; a random reference |
| Google Analytics (privacy policy) | Google Ireland Limited | Marketing and advertising; analytics and performance tracking | Email address (only ever as a SHA-256 hash, sent when you confirm a signup); device ID (cookie identifiers); IP address; IP-based approximate location; browser information and language; operating system and version; pages you visit on this site; interaction logs (e.g., clicks, scrolling, time spent on pages) |
| Google Ads (privacy policy) | Google Ireland Limited | Analytics and performance tracking; marketing and advertising | Email address (only ever as a SHA-256 hash, sent when you confirm a signup); device ID (cookie identifiers); IP address; IP-based approximate location; ad click identifiers; interaction logs (e.g., clicks, time spent on pages) |
| Cloudflare (privacy policy) | Cloudflare Inc. | Authentication and security; customising and adapting user experience | Device ID; IP address; operating system and version |
| Meta (privacy policy) | Meta Platforms, Inc.; Meta Platforms Ireland Ltd. for EU and EEA visitors | Analytics and performance tracking; marketing and advertising | Email address (only ever as a SHA-256 hash, sent when you confirm a signup); device ID (cookie identifiers); IP address; IP-based approximate location; browser information and language; operating system and version; ad click identifiers; pages you visit on this site; interaction logs (e.g., clicks, time spent on pages) |
Advertising measurement when you confirm a signup
While Marketing consent is active, the four tags report page views and a few named events from your browser: viewing a product page, submitting or confirming a signup, and clicking a store button. Those signals carry an event name and the app's name only, and never your email address or any other detail you typed. The Google tag alone also collects three standard interactions automatically: how far down a page you scroll; clicks on links that take you away from our site, which tells Google the address of the link you clicked; and, if we ever add a search box, the words you type into it. The Meta, Reddit and TikTok tags collect no equivalent.
If you accepted the Marketing category on our cookie banner and then join a waitlist or the newsletter, one more thing is shared, and it is the only time anything you typed reaches an advertising provider. When you confirm your signup, our server tells Meta, Google, Reddit and TikTok that a confirmation happened, so we can tell which advertising was worth paying for. Each report carries a SHA-256 hash of your email address, a fixed-length scramble of it, together with the identifiers that provider's own cookies placed in your browser when you first submitted the form and any advertising click identifier you arrived with. The provider compares our hash against a hash of the addresses it already holds, which tells it whether you are one of the people it showed our ad to. We send it from our server rather than your browser for a plain reason: you confirm by clicking a link in an email, often on a different device, where those browser identifiers no longer exist.
Three limits on that. The hash is the only form of your address we send. We do not send your IP address or your browser's user-agent string, even though all four providers accept both. And if you refused the banner, or never answered it, none of this happens: we record none of the identifiers a report needs, we make no report, and your signup works exactly the same way.
One thing refusing afterwards cannot reach, and we would rather say so than let you find out: if you accepted, submitted a signup, and have not yet clicked the confirmation link, the details needed to report that one confirmation were recorded when you submitted the form, and confirming later will still be reported. If you would rather it were not, do not click the confirmation link, or use the removal link in the same email, which deletes the signup outright and prevents any report. The next section sets out who is responsible for which part of this measurement.
Who is responsible for the advertising measurement
Responsibility for the four advertising providers splits by stage, and the split decides who you can take a complaint to:
| Stage | Who is responsible | What that means for you |
|---|---|---|
| While the data is being collected and sent | We and the provider are joint controllers: we chose to place the tags and decide which events they report; the provider supplies the tag and defines what it can send | Exercise any of your rights for this stage against either of us, without working out which: privacy@tacitlabs.co.uk, or our European representative named at the top of this policy |
| Once it has arrived | The provider alone, as an independent controller: what it does next is its own decision, taken for its own purposes, and it may combine the data with your account and use it for advertising | We have no access to that copy and cannot delete it for you. Exercise your rights through your account with the provider, or by contacting it directly |
The essence of the joint arrangement, which we are required to make available to you, is this: the provider is responsible for telling you how it processes the data and for handling your rights once it holds it, and we are responsible for having legal grounds for the collection, which is your consent, and for asking you first. You can hold either of us to our half. Each provider sets its half out in its own terms:
| Provider | Its privacy policy | Where its half of the arrangement is set out |
|---|---|---|
| Meta | Data Policy | Controller Addendum (EEA) and UK Controller Addendum, both within its Business Tools Terms |
| Privacy Policy | Ads Data Processing Terms | |
| Privacy Policy | Advertising Agreement and its Advertising Data Processing Agreement | |
| TikTok | Privacy Policy | Business Products Terms |
Google fills two roles, and the split runs between them rather than between Google and the other three. For ordinary Google Analytics measurement, Google acts as our processor rather than a controller, meaning it handles that data only on our instructions. That holds because the setting which would share it into Google's own advertising products is switched off, and we say so here because if we ever switched it on this paragraph would stop being true. The confirmation report above is the ordinary case: joint while the conversion is being reported, and Google's own decision afterwards.
Meta also fills two roles, split along a different line. The hashed email address in the confirmation report is matched by Meta acting as our processor, on our instructions under its Data Processing Terms; the joint-then-independent arrangement above covers the event data. And because we are a UK business, our counterparty for all of this is Meta Platforms, Inc., while the joint controllership for our EU and EEA visitors sits with Meta Platforms Ireland Limited. PostHog is the contrast: our processor for everything it holds, described in the next section, so there is no second party for you to take a complaint to.
Product analytics in detail: PostHog
When you accept the Statistics category, we load one tool. PostHog is operated by PostHog Inc., 2261 Market Street #4008, San Francisco, CA 94114, United States. It is product analytics, measuring how this site is used; it is not advertising and sends nothing to any advertising platform. PostHog is our processor: it holds this data only on our documented instructions, under a data processing agreement that also forbids it from selling or sharing the data and from using it to train AI models, so every right you have about it is exercised against us at privacy@tacitlabs.co.uk.
When active, PostHog receives the address of each page you view, standard browser and device information, and your IP address, which is used to work out an approximate location, never finer than a city or district, and is then discarded rather than stored. It records which pages you view, clicks and interactions with our own page elements, where your pointer moves and where on a page you click, clicks that landed on something which turned out not to be clickable, that a form was submitted but never the values typed into it, page performance, unhandled page errors, and a masked replay of the visit: every value you type and every piece of text on the page is masked, and web addresses inside a replay have their query strings stripped, so a replay shows the shape of a visit and not its content.
PostHog keeps a profile for each browser, so that a returning browser can be told from a new one. It holds the identifiers PostHog set, the properties above, and the approximate location both as it stands now and as it was on your first visit. It holds no name and no email address, and we deliberately never attach either. Session replays are deleted after 30 days, a period we set rather than one PostHog's plan decides. Everything else is held for up to seven years, and you can ask us to delete it sooner at any time. Feature flags let us show part of a page to some visitors and not others without publishing a new version of the site; they read the browser profile described above and collect nothing beyond it. Surveys let us ask you a question on the page; what you answer goes to PostHog attached to that browser profile, and you are free to dismiss the question without answering.
Data processing agreements
When we share your data with third-party service providers, we do so under the protection of Data Processing Agreements (DPAs) that ensure your information is managed in accordance with GDPR and other relevant data protection laws. These agreements mandate that third parties implement adequate technical and organisational measures to ensure the security of your data.
Transparency and control
We believe in transparency and providing you with control over your personal information. You will always be informed about any significant changes to our sharing practices, and where applicable, you will have the option to consent to such changes.
Your trust is important to us, and we strive to ensure that your personal information is disclosed only in accordance with this policy and when there is a justified reason to do so. For any queries or concerns about how we share and disclose personal information, please reach out to us at privacy@tacitlabs.co.uk.
International data transfers
We may transfer your personal information to locations outside of your country of residence, including to countries with different data protection laws than your own. Every such transfer is protected by a recognised safeguard, and this table names each recipient, where it processes, and what protects the transfer. What data each recipient receives is set out in the tables under Data sharing and disclosure.
| Recipient | Function | Location of processing | Legal basis | Transfer safeguards |
|---|---|---|---|---|
| Cloudflare, Inc. (USA) | Hosts our sites, the signup service and its database; the Turnstile bot check; cookie-free site measurement | Data at rest in Cloudflare's Western Europe region | Needed to run the service you asked for; our legitimate interests for the security check and measurement | EU-US Data Privacy Framework and its UK Extension; standard contractual clauses incorporating the UK International Data Transfer Addendum, in Cloudflare's data processing addendum |
| Resend, Inc. (USA) | Delivers the emails the signup service sends you | Resend's EU region | Your consent, given at signup | EU-US Data Privacy Framework and its UK Extension; standard contractual clauses incorporating the UK Addendum, in Resend's data processing agreement |
| Usercentrics A/S, Havnegade 39, 1058 Copenhagen (Denmark) | Operates the consent banner and holds the consent record | Denmark | Our legal obligation to evidence your consent | None needed: no third-country transfer |
| PostHog Inc., 2261 Market Street #4008, San Francisco, CA 94114 (USA) | Product analytics, if you accept Statistics | Stored in PostHog's EU region; processing also in the United States and at its subprocessors' locations | Your consent, via the banner's Statistics category | European Commission standard contractual clauses with the UK Addendum; PostHog also participates in the EU-US Data Privacy Framework, its UK Extension and the Swiss-US Framework |
| Meta Platforms, Inc. (USA), our counterparty as a UK business, and Meta Platforms Ireland Ltd. (Ireland) for our EU and EEA visitors | Advertising measurement, if you accept Marketing | United States; Ireland for EEA matters | Your consent, via the banner's Marketing category | Meta Platforms, Inc.'s certification under the EU-US Data Privacy Framework and its UK Extension; Meta's UK Data Transfer Addendum, incorporated into its Data Processing Terms |
| Google Ireland Limited (Ireland) | Google Analytics and Google Ads, if you accept Marketing | Ireland, with onward transfer to Google LLC (USA) | Your consent, via the banner's Marketing category; for ordinary Analytics measurement Google acts as our processor | EU-US Data Privacy Framework and its UK Extension; standard contractual clauses incorporating the UK Addendum |
| Reddit, Inc. (USA), our counterparty as a UK business under its data processing agreement | Advertising measurement, if you accept Marketing | United States | Your consent, via the banner's Marketing category | Reddit's compliance with the EU-US Data Privacy Framework, its UK Extension and the Swiss-US Framework, with standard contractual clauses incorporating the UK International Data Transfer Addendum as the fallback, both in Reddit's Advertising Data Processing Agreement |
| TikTok Information Technologies UK Limited (UK) | Advertising measurement, if you accept Marketing | United Kingdom, with transfers to other TikTok group companies including in the United States | Your consent, via the banner's Marketing category | Standard contractual clauses incorporating the UK Addendum, as set out in TikTok's business products terms. TikTok is not certified under the Data Privacy Framework, so there is no second safeguard here |
You can ask to see any of these safeguards. Where a transfer rests on standard contractual clauses or the UK International Data Transfer Addendum, you are entitled to a copy of the terms it rests on, and asking is the whole procedure: write to privacy@tacitlabs.co.uk and we will send you the relevant clauses or point you to where that provider publishes them. Certification under the Data Privacy Framework is a matter of public record, and you can look any of these companies up yourself on the Data Privacy Framework list without asking anyone.
User rights and choices
At Tacit Labs Ltd, we recognise and respect your rights regarding your personal information, in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws. We are committed to ensuring you can exercise your rights effectively. Below is an overview of your rights and how you can exercise them:
Your rights
- Right of access (Art. 15 GDPR): You have the right to request access to the personal information we hold about you and to obtain information about how we process it.
- Right to rectification (Art. 16 GDPR): If you believe that any personal information we hold about you is incorrect or incomplete, you have the right to request its correction or completion.
- Right to erasure ('right to be forgotten') (Art. 17 GDPR): You have the right to request the deletion of your personal information when it is no longer necessary for the purposes for which it was collected, among other circumstances.
- Right to restriction of processing (Art. 18 GDPR): You have the right to request that we restrict the processing of your personal information under certain conditions.
- Right to data portability (Art. 20 GDPR): You have the right to receive your personal information in a structured, commonly used, and machine-readable format and to transmit those data to another controller.
- Right to object (Art. 21 GDPR): You have the right to object to the processing of your personal information, under certain conditions, including processing for direct marketing.
- Right to withdraw consent (Art. 7(3) GDPR): Where the processing of your personal information is based on your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
- Right to lodge a complaint (Art. 77 GDPR): You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal information violates applicable data protection laws.
Exercising your rights
To exercise any of these rights, please contact us at privacy@tacitlabs.co.uk. If you are in the EU or the EEA, you can also exercise any of them through our European representative, named at the top of this policy. We will respond to your request in accordance with applicable data protection laws and within the timeframes stipulated by those laws. Please note, in some cases, we may need to verify your identity as part of the process to ensure the security of your personal information.
We are committed to facilitating the exercise of your rights and to ensuring you have full control over your personal information. If you have any questions or concerns about how your personal information is handled, please do not hesitate to get in touch with us.
Cookies and tracking technologies
At Tacit Labs Ltd, we value your privacy and are committed to being transparent about our use of cookies and other tracking technologies on our websites. These technologies play a crucial role in ensuring the smooth operation of our digital platforms, enhancing your user experience, and providing insights that help us improve.
Understanding cookies and tracking technologies
Cookies are small data files placed on your device that enable us to remember your preferences and collect information about your website usage. Tracking technologies, such as web beacons and pixel tags, help us understand how you interact with our site and which pages you visit.
How we use these technologies
Our consent banner, operated for us by Cookiebot, groups cookies into four categories:
- Necessary: Required for the website to function: the cookie that records your consent choice itself, the bot-protection check on signup pages, and two small working items of our own. These do not require consent and cannot be switched off.
- Preferences: The colour tint you can pick for these pages. It is stored only at the moment you pick it, at your request, rather than when you consent.
- Statistics: Loads our product analytics tool, PostHog, which measures how this site is used and reports to nobody else.
- Marketing: Loads the four advertising tags named in the table above, from Meta, Google, Reddit and TikTok, used to measure whether our advertising works.
Your choices and consent
Upon your first visit, our website presents you with the cookie consent banner, showing a toggle for each optional category and three choices:
- Deny: No optional category loads, and the site stays cookie-free apart from the necessary cookie that records your refusal.
- Allow selection: Only the categories you toggled on load.
- Allow all: All four categories load.
If you never answer the banner, nothing optional loads, exactly as if you had denied.
Changing your mind
You can review or change your choice at any time, one category at a time, and refusing takes effect immediately rather than on your next visit. If you refuse Marketing, we tell each provider already running to stop, delete everything its tags stored on your device, cookies and other storage alike, discard any advertising click reference we were holding, and reload the page so that nothing any of them loaded is still running. If you refuse Statistics, the same happens for PostHog, including PostHog's own record of the refusal. The clearing works by name pattern rather than against a fixed list, so it still holds if a later version of a tag stores more, and it happens whether or not the provider's code is running at the time. Refusing one category leaves the other exactly as it was.
Withdrawing does not affect what a provider lawfully processed while your consent was active. For Meta, Google, Reddit and TikTok, their own copies are theirs: exercise your rights through your account with that provider or by contacting it directly. PostHog is different, because it holds its copy for us: ask us at privacy@tacitlabs.co.uk and we can have it deleted, and anything not deleted sooner expires on the retention schedule above.
Changes to our cookie use
We may update our use of cookies and tracking technologies to improve our services or comply with legal requirements. We will notify you of any significant changes and seek your consent where necessary.
For more detailed information about the cookies we use, their purposes, and how you can manage your preferences, please visit our detailed Cookie Notice.
Should you have any questions or concerns about our use of cookies and tracking technologies, please do not hesitate to contact us at privacy@tacitlabs.co.uk. Your privacy and the integrity of your personal data are of utmost importance to us.
Children's privacy
Our website, waitlists and newsletter are not aimed at children, and we do not knowingly collect personal information from anyone under the age of 13. If you are under 13, please do not sign up or send us personal information.
If we become aware that we have collected personal information from a child under 13, we will delete it promptly. If you are a parent or guardian and believe a child under 13 has signed up, contact us at privacy@tacitlabs.co.uk and we will delete their signup.
Direct marketing and communications
At Tacit Labs Ltd, we may use your personal information to send you direct marketing communications about our products, services, promotions, and other relevant information that we believe may be of interest to you. We are committed to ensuring that our direct marketing practices are transparent, lawful, and in compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR) and the ePrivacy Directive.
Obtaining consent for direct marketing
- Opt-in consent: We will obtain your explicit opt-in consent before sending you direct marketing communications, and we evidence it through double opt-in: after you submit a signup form we email you a confirmation link, and we treat your signup as complete only once you click it. If you never confirm, your email address is deleted automatically 30 days after you submitted the form.
- Unsubscribe option: Every email we send carries a removal link. It opens a confirmation page, and one press there deletes that signup immediately and entirely. Withdrawing does not affect the lawfulness of anything done while your consent was active.
- Independent lists: Your product-waitlist signups and your newsletter subscription are independent. Joining or leaving one never changes the other, each has its own consent and its own removal link, and we never use a product-waitlist signup to market a different product to you.
Types of direct marketing communications
We may use your personal information to send you direct marketing communications via various channels, including:
Managing your preferences
You have control over the direct marketing communications you receive from us. You can manage your communication preferences by using the unsubscribe link provided in every email we send.
Data breach notification procedures
At Tacit Labs Ltd, we understand the importance of protecting your personal information and take proactive measures to safeguard it. In the event of a data breach that poses a risk to your privacy rights and freedoms, we have established clear procedures for promptly identifying, assessing, and mitigating the impact of the breach. Our data breach notification procedures are designed to comply with applicable data protection laws and regulations, including the General Data Protection Regulation (GDPR).
Detection and assessment
- Internal monitoring: We employ robust security measures and monitoring systems to detect and respond to potential data breaches promptly.
- Assessment of breach impact: Upon discovery of a data breach, we will conduct a thorough assessment to determine the nature and scope of the breach, including the types of personal information involved and the potential impact on affected individuals.
Notification obligations
- Regulatory authorities: Where a breach is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of becoming aware of it, as UK data protection law requires.
- Affected individuals: If a data breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, providing clear and concise information about the breach, the types of personal information affected, and the steps you can take to protect yourself.
Communication channels
- Email notification: We may notify affected individuals via email, using the contact information provided to us, if feasible and appropriate.
Support and assistance
In the event of a data breach, we are committed to providing affected individuals with the support and assistance they need, including guidance on steps they can take to mitigate the potential risks associated with the breach.
Point of contact: If you have any questions or concerns about a data breach or believe you may have been affected, please contact us immediately at privacy@tacitlabs.co.uk.
Policy updates and changes
At Tacit Labs Ltd, we are committed to keeping you informed about how we handle your personal information and any changes to our privacy practices. We may update this privacy policy from time to time to reflect changes in legal requirements, industry standards, or our business operations. We want to assure you that any updates will be communicated transparently and in accordance with applicable data protection laws.
Notification of changes
- Notification process: In the event of significant changes to our privacy policy that may affect your rights or the way we handle your personal information, we will provide notice through prominent means, such as email, website notifications, or other appropriate channels. We will also indicate the effective date of the updated policy at the top of the document.
- Reviewing changes: We encourage you to review our privacy policy periodically to stay informed about how we collect, use, and protect your personal information. If a change is material to what you originally consented to, we will seek your fresh consent rather than relying on the old one.
Opt-in consent for material changes
For material changes to our privacy policy that require your consent under applicable data protection laws, such as the General Data Protection Regulation (GDPR), we will seek your explicit opt-in consent before implementing the changes. You will have the opportunity to review the updated policy and provide your consent before any changes take effect.
This policy replaced an earlier notice
This policy replaces our Waitlist & Newsletter Privacy Notice with effect from 2026-08-18. That notice covered the signup forms alone and was retired at its version v1.5.0; everything it said is carried into this policy, unchanged in substance. If you signed up before that date, the notice you agreed to was the one in force at the time, and the version recorded against your signup identifies it.
Contact us
If you have any questions or concerns about our privacy policy or any updates to it, please don't hesitate to contact us at privacy@tacitlabs.co.uk. We are here to address any inquiries you may have and to ensure that you have the information you need to feel confident about how your personal information is handled.
Powered by Usercentrics.