IceFire privacy policy
Last updated 11 October 2026.
1. Who we are
This policy explains how IceFire ("IceFire", "we") looks after personal information. For the information described here we are the controller, unless we say otherwise below.
Questions, or want to use your rights? Email hello@icefire.ai. A real person reads it.
2. What we collect
Your account: your name, business name, email address, phone number if you give it, and your password, which is stored only as a one-way hash that nobody can read. If you turn on two-step sign-in, we store the link to your authenticator app, never the codes.
If you sign in with Google: the name, email address and profile picture Google shares with us. We never see your Google password, and we do not get access to your inbox, contacts or files.
Your brief and files: the answers you give about your business, and the customer, product and stock lists you upload.
Your sending addresses: the details we need to set up and look after them, such as the address, the domain and its sending health. We never ask for the password to your main inbox.
Billing: your plan and payment status. Card details are taken and held by our payment provider; we never see your full card number.
Prospects: the business contacts we research for your campaigns from public business sources - names, job titles, work email addresses and company details - and the history of our outreach to them, including replies and opt-outs.
Pack views: if you use tracked pack links, which pages each prospect opens and for how long, against their link only - no cookies, and nothing about their device.
Basic technical logs: such as when you signed in, kept to keep the service secure and working.
3. Why we use it, and our lawful basis
To provide the service you signed up for - your account, your brief, running your outreach and your dashboard: performance of our contract with you.
To take payment, keep accounts and meet our legal duties: contract and legal obligation.
To keep the service secure, prevent misuse and improve how it works: our legitimate interests.
To approach prospects in their professional capacity, about things relevant to their role: our and our clients' legitimate interests, in line with the Privacy and Electronic Communications Regulations. Every email offers a simple way to opt out, honoured across all campaigns, and we never cold-email individuals or sole traders who are not acting as a company.
For personal data inside the customer files you upload, you are the controller and we are your processor: we use it only on your instructions - for example, to keep your existing customers off every list.
We never sell personal information, and we do not use your material to train AI models.
4. Who helps us
A few specialist services run parts of IceFire for us: application hosting, our database and file storage, an AI model provider that helps us research and draft, an email-sending platform, and a payment provider. Each acts only on our instructions, under a data processing agreement.
The AI services we use are set not to train on your material, and each task carries only your own material.
Ask and we will send you the named list with our data processing agreement. We will tell you before we add a new one.
5. Where it is stored
Your brief, your files and your outreach history are kept in a private database in London, and the application that works on them runs in London too.
Some of the specialist services - AI, email sending and payments - are based in the United States, so they may handle data there. When they do, we rely on recognised safeguards: the UK-US data bridge where the provider is certified, or the UK's International Data Transfer Addendum to standard contractual clauses.
6. How long we keep it
While you are a client, for as long as the service runs.
When the service ends, we hand you your prospect list and outreach history if you want them, and delete your files and other data within 30 days - unless you ask us to return it, or the law requires us to keep something.
Invoices and payment records are kept for six years, as UK tax law requires.
Opt-outs are kept for as long as we run outreach, so we can keep honouring them.
7. Your rights
You can ask to see the personal information we hold about you, have it corrected, have it deleted, object to or restrict how we use it, and receive it in a portable format. Where we rely on consent, you can withdraw it at any time.
Prospects can opt out of our emails at any time, using the link in every email or by replying.
To use any of these rights, email hello@icefire.ai. We reply within one month.
If you are unhappy with how we have handled your information, please tell us first. You can also complain to the Information Commissioner's Office at ico.org.uk.
8. Cookies
We use only the essential cookies that keep you signed in. They are needed for the service to work, so we do not ask for consent. We use no analytics, advertising or tracking cookies.
Tracked pack links set no cookies at all.
9. Keeping it safe
Everything is encrypted while it travels and while it is stored. The database cannot be reached from a browser; every request is checked on our servers against who is asking, and one client can never see another's information.
Everyone at IceFire signs in with a password and a code from an authenticator app, and you can turn on the same two-step sign-in for your own account.
There is more on the security and trust page.
10. Changes and contact
If we change this policy, we will update the date below and, for anything significant, tell clients by email first.
Questions about privacy: hello@icefire.ai. See also our terms of service.