Privacy Policy
Last updated: 19 August 2026
1. What this page is
This is how OVERLORD Team LTD ("OVERLORD," "we," "us," or "our") handles personal data on overlord.team, the signed-in client portal, and the work we do for clients. If you are not happy with that, do not use those services.
2. Who is responsible
Controller: OVERLORD Team LTD, United Kingdom.
Email: info@overlord.team
Website: https://overlord.team
3. Data we collect
Account and profile
If you register or edit your profile we may hold: name, email, hashed password, optional company name, avatar URL, whether the email is verified, and optional TOTP / backup-code settings for two-factor login.
Google or GitHub sign-in
If you use Google or GitHub (when we have that switched on), we get the identifiers and profile fields they send — usually name, email, and a photo — so we can create or link the account.
Portal / project records
The portal stores service requests and briefs; project records, statuses, milestones, and tasks; comments; tickets and messages; files you or we upload; billing notes, paid/outstanding flags, billing history, and invoice summaries; in-app notifications; and, if you turn them on, web-push subscription endpoints.
Contact form
The public form can take name, email, subject, and a message. Cloudflare Turnstile sits on that form to cut bots. We may forward the message to an internal channel (Telegram, when configured) so someone actually replies.
Newsletter
If you subscribe, we store your email, the form source (homepage or footer), confirm/unsubscribe timestamps, and send status. Signup is double opt-in: we email a confirm link before you join the list. Every marketing mail includes a physical mailing address (CAN-SPAM) and an unsubscribe link; one-click unsubscribe is honoured. You can also write info@overlord.team. Mail: OVERLORD Team LTD, 31 Lairg Road, Newbold on Avon, CV21 2YL, United Kingdom, or whatever address we print in the mail footer.
Technical and usage data
- IP address, browser/user-agent, and a rough location from the IP
- Device and session data we need to keep sign-in honest
- Server logs, security audit events, and crash reports via Sentry and GlitchTip (stack traces, request metadata, browser/device context)
- Google Analytics on the public site (measurement ID in the page)
- If you open the office map on the contact section, Mapbox loads tiles in the browser and sees your IP plus the request metadata it needs to serve those tiles
Work you send us
Paid work often includes code, configs, credentials you choose to share, and business notes. We use that to do the job, under the confidentiality we already owe you.
4. Why we process it
- Contract / pre-contract: accounts, the portal, the project, tickets, billing records, and replies to service requests.
- Legitimate interests: keep the box from being abused, fix bugs, and talk about work that is already open.
- Consent: optional marketing, non-essential cookies / analytics where the law wants a click, and optional push notifications.
- Legal obligation: tax, accounting, and other legal/regulatory records we must keep.
5. Cookies
- Essential: Better Auth session cookies, CSRF/security, load balancing. Turn these off and you will not stay signed in.
- Security: Cloudflare Turnstile tokens on forms and auth.
- Analytics: Google Analytics cookies. Block them in the browser if you want; the site still works.
6. Who else sees data
We do not sell personal data. We pass it to processors only when the product needs them:
- Hosting & database: the hosts that run the app and MariaDB (currently Hostinger).
- Email: SMTP for password resets, verification, transactional mail, and newsletter confirm / marketing sends if you subscribed.
- Cloudflare: Turnstile, and CDN/security where the zone uses it.
- Google / GitHub: only if you pick OAuth.
- Google Analytics: public-site traffic counts.
- Sentry & GlitchTip: errors so we can fix them.
- Mapbox: contact-page map tiles, requested from your browser.
- Telegram: contact-form or ops alerts, if we have a bot configured.
- Push: browser push vendors if you subscribe (we store the endpoint keys on the account).
- Payoneer: hosted Request a Payment pages (name, email, company, amount). We do not store card numbers.
- Advisors / police: when the law requires it, or to protect people and the company.
Client invoices can be paid on Payoneer's page. Payoneer runs that checkout under its own terms.
7. International transfers
Hosts and processors can sit outside your country, including outside the UK/EEA. Where UK/EU law requires it, we rely on standard contractual clauses or the provider's equivalent terms.
8. How long we keep it
- Account: while the account exists, then delete or anonymise after a reasonable wait unless the law says keep it.
- Projects, tickets, files, billing: through the job and a while after, for support, disputes, and accounts.
- Contact-form mail: long enough to answer, then we clear it in the usual sweep.
- Security / audit logs: for the window we still need them to investigate.
9. Security
TLS in transit. Passwords hashed. Sessions and roles (client vs admin). Optional 2FA. Turnstile on public forms. Logs when something looks wrong. None of that is magic. Use a unique password and turn 2FA on.
10. Your rights
Under UK GDPR / EU GDPR you can usually ask to see, correct, erase, restrict, or object to processing, get a portable copy (data portability), or withdraw consent. You can also complain to your regulator (ICO in the UK).
Most profile fields you can edit yourself. For the rest, email info@overlord.team. We try to answer within 30 days.
11. Children
This is a business site and a client portal. We do not knowingly collect data from anyone under 18. Write to us if you think we have.
12. Other people's sites
Trustpilot, social links, OAuth, Payoneer — those pages are theirs. Their policies apply there, not this one.
13. Changes
We change this page by posting a new version and moving the date at the top. If it matters for people already using the portal, we will try to email or put a notice in the product.
14. Contact
Using the site
Using the website or portal means you have seen this policy. The contract language sits in the Terms of Service.
Privacy questions? Contact us
