Impersona
DocsPricing
On this page
  • 1. Data Controller
  • 2. Data We Collect
  • 3. Data We Do NOT Collect
  • 4. Legal Basis for Processing
  • 5. How We Use Your Data
  • 6. Data Sharing & Subprocessors
  • 7. Data Retention
  • 8. Your Rights (GDPR)
  • 9. International Data Transfers
  • 10. Cookies & Tracking
  • 11. Security Measures
  • 12. Changes to This Policy
  • 13. Contact
Legal

Privacy Policy

Last updated: May 2026

1. Data Controller

Impersona Ltd ("Impersona," "we," "us," or "our") is the data controller responsible for your personal data collected through the Impersona service.

Impersona Ltd
Registered in England and Wales
Company number: 16706750
Registered office: 71-75 Shelton Street, London WC2H 9JQ

Privacy contact: privacy@impersona.co.uk

2. Data We Collect

2.1 Waitlist Information

When you join the early access waitlist, we collect:

  • Email address
  • Form source, referrer, and campaign attribution parameters
  • Browser and device information needed to process the signup

2.2 Account Information

If you create an Impersona dashboard account, we collect:

  • Name and email address
  • Organization or team information
  • Authentication identifiers provided by our authentication provider
  • Billing information when you subscribe to a paid plan

2.3 Usage Data

We automatically collect:

  • SDK version and configuration
  • Feature usage patterns
  • Error logs and performance metrics
  • Session duration and frequency

2.4 Technical Data

Our servers may log:

  • IP addresses
  • Browser type and version
  • Operating system
  • Referring URLs

2.5 Support Communications

If you contact us for support, we retain the content of your communications to provide assistance and improve our service.

3. Data We Do NOT Collect

This is critical to understanding our service. Impersona is designed to protect user privacy by architecture. We do NOT collect, store, or process:

  • Impersonated user data: When you switch user contexts using our SDK, we do not see or store any data about the users being impersonated
  • Production credentials: We do not ask for or store production user passwords. If you configure token-passthrough presets, you control the development or test token values supplied for those presets
  • Application data: We do not access or log the data displayed in your application during impersonation sessions
  • Production user information: Our SDK is designed to operate only in development environments

Your user presets and integration choices remain under your control.

4. Legal Basis for Processing

Under GDPR, we process your personal data based on the following legal bases:

PurposeLegal Basis
Providing the ServiceContract performance (Article 6(1)(b))
Processing paymentsContract performance (Article 6(1)(b))
Waitlist and product updatesConsent (Article 6(1)(a))
Service improvementLegitimate interests (Article 6(1)(f))
Security monitoringLegitimate interests (Article 6(1)(f))
Legal complianceLegal obligation (Article 6(1)(c))

5. How We Use Your Data

We use collected data to:

  • Provide, maintain, and improve the Service
  • Process waitlist signups and send early access updates
  • Process subscriptions and payments
  • Send service-related communications
  • Respond to support requests
  • Analyze usage patterns to improve the product
  • Detect and prevent fraud or abuse
  • Comply with legal obligations

6. Data Sharing & Subprocessors

6.1 Third-Party Service Providers

We share data with the following categories of service providers:

Provider TypePurposeLocation
Cloud hosting (Cloudflare Workers and Vercel)Public site, dashboard, API hosting, and deploymentUS/EU
Authentication (Clerk)Dashboard account authenticationUS/EU
Database and waitlist storage (Supabase)Application database, waitlist signups, and service recordsUS/EU
Payment Processing (Stripe)Subscription billingUS/EU
Email Service (Resend)Transactional and waitlist emailsUS
Analytics (PostHog)Usage analyticsEU

We will notify customers at least 30 days before adding new subprocessors. You may object to new subprocessors within that period.

6.2 Legal Requirements

We may disclose data if required by law, court order, or governmental request, or to protect our rights, users, or the public.

6.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, user data may be transferred. We will notify you before your data becomes subject to a different privacy policy.

7. Data Retention

We retain data according to the following schedule:

Data TypeRetention Period
Waitlist signupsUntil you unsubscribe or ask us to delete the signup
Account informationDuration of account + 30 days
Billing records7 years where required by law
Usage analytics24 months
Support communications3 years
Server logs30 days unless needed for security investigation

8. Your Rights (GDPR)

Under GDPR, you have the following rights regarding your personal data:

  • Right of Access (Article 15): Request a copy of your personal data
  • Right to Rectification (Article 16): Correct inaccurate data
  • Right to Erasure (Article 17): Request deletion of your data ("right to be forgotten")
  • Right to Restrict Processing (Article 18): Limit how we use your data
  • Right to Data Portability (Article 20): Receive your data in a machine-readable format
  • Right to Object (Article 21): Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent at any time for consent-based processing

To exercise these rights, contact us at privacy@impersona.co.uk. We will respond within 30 days.

You also have the right to lodge a complaint with your local data protection authority. In the UK, this is the Information Commissioner's Office (ICO).

9. International Data Transfers

Your data may be transferred to and processed in countries outside the European Economic Area (EEA). When we transfer data internationally, we use appropriate safeguards, which may include:

  • EU-US Data Privacy Framework participation where available
  • Standard Contractual Clauses
  • Adequacy decisions

10. Cookies & Tracking

10.1 Essential Cookies

We use strictly necessary cookies for authentication and security. These cannot be disabled.

10.2 Analytics Cookies

With your consent, we use analytics cookies to understand how visitors interact with our website. You can opt out through your browser settings or by contacting us.

10.3 Advertising

We do not sell your data to advertisers. Campaign attribution parameters may be used to understand which marketing activity led to a waitlist signup.

11. Security Measures

We implement appropriate technical and organizational measures including:

  • Encryption in transit
  • Access controls and authentication requirements
  • Employee security training
  • Incident response procedures

While we strive to protect your data, no system is 100% secure. Please report any security concerns to security@impersona.co.uk.

12. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes by:

  • Posting the updated policy on our website
  • Sending an email to the address associated with your account
  • Displaying a notice in the dashboard

We encourage you to review this policy regularly. Your continued use of the Service after changes constitutes acceptance.

13. Contact

For privacy-related questions or to exercise your rights:

  • Privacy contact: privacy@impersona.co.uk

Impersona Ltd
Registered in England and Wales
Company number: 16706750
Registered office: 71-75 Shelton Street, London WC2H 9JQ

Impersona

Test any user role without logging out.

ProductFeaturesPricingDocumentationHow It Works
LegalTerms of ServicePrivacy Policy
ConnectTwitter
© 2026 Impersona. All rights reserved.Made in the UK