Skip to main content
Before You Apply

Privacy notice

Privacy notice

Effective date: 2026-09-18 · Last updated: 2026-10-09

About this notice

This notice explains how the website currently handles personal data. We keep it under review as the site and its services change. Where provider locations, transfer arrangements or legal conclusions have not been independently verified, the relevant section says so plainly.

Who controls your data

Before You Apply is a UK educational publisher of mortgage preparation resources. It is not a lender, mortgage adviser or broker.

Data controller

Sarah Newbigging trading as Before You Apply

Lytchett House, 13 Freeland Park, Wareham Road, Poole, Dorset, BH16 6FA, United Kingdom

hello@before-you-apply.com

The controller is a sole trader, not a company, so there is no company number. No ICO registration number, VAT number or FCA authorisation is claimed anywhere on this site.

Correspondence addressLytchett House, 13 Freeland Park, Wareham Road, Poole, Dorset, BH16 6FA, United Kingdom
Privacy contact mailbox (hello@before-you-apply.com)Current contact

What we collect, and where it goes

This table is generated from our internal data-flow record, so it describes what the website actually does today rather than what it might do in future.

Contact enquiry form

Where: /contact

Why: Receiving and replying to a question about the website, tools, content corrections, media or accessibility.

Stored: In our hosted database (contact_submissions). Records are sent through BYA's trusted application boundary; ordinary browser roles cannot directly read, change or delete them.

Fields

  • name (as the visitor wishes to be addressed)
  • email address
  • telephone number (optional)
  • enquiry category
  • message (2,000 characters maximum)
  • page the form was submitted from
  • optional marketing consent, with timestamp
  • privacy notice version
  • random submission token

Keeping it: Kept for 12 months after the last meaningful contact about the enquiry, then deleted, subject to a genuine legitimate dispute or legal exception. Deletion is a documented manual review today; nothing is deleted automatically.

Marketing consent is a separate, optional tick box. It is unticked by default and never required.

Free resource request and download interest

Where: Free resource pages under /mortgages/resources/

Why: Recording a request for a free educational resource, and serving the file on screen where a configured file exists. Where no file exists the record is an expression of interest only.

Stored: In our hosted database (free_resource_requests). Records are sent through BYA's trusted application boundary; ordinary browser roles cannot directly read, change or delete them.

Fields

  • email address
  • first name (optional)
  • product slug requested
  • page the request came from
  • optional marketing consent, with timestamp
  • privacy notice version
  • random request token

Keeping it: Where no marketing consent was given, kept for 90 days and then deleted or anonymised. Where you have separately opted in to marketing email, that consent record is kept while we rely on it. Deletion is a documented manual review today.

Marketing consent is a separate, optional tick box. It is unticked by default and never required.

Tool summary waiting list (public collection disabled)

Where: Not currently rendered anywhere on the public site

Why: The public waiting-list form for a possible future emailed summary of a tool result band has been disabled. No summary feature exists, no email address is collected through this surface today, and none is delivered. The database table and the historic rows in it are unchanged; this entry documents that the collection form itself is switched off.

Stored: In our hosted database (tool_summary_requests). Records are sent through BYA's trusted application boundary; ordinary browser roles cannot directly read, change or delete them.

Fields

  • No fields are collected while this surface is disabled.

Keeping it: No new rows are created while the form is disabled. Any historic rows are kept for 90 days from capture, then deleted or anonymised as appropriate. Deletion is a documented manual review today.

First-party analytics events

Where: Whole site, only after analytics consent is actively accepted

Why: Understanding which pages and tools are used, so the site can be improved.

Stored: In our hosted database (analytics_events). Records are sent through BYA's trusted application boundary; ordinary browser roles cannot directly read, change or delete them.

Fields

  • event name
  • page path
  • content type label
  • tool name label
  • result band label
  • random rotating session label (not derived from any personal data)
  • consent version

Keeping it: Kept for up to 14 months in identifiable or pseudonymous form, then deleted or irreversibly anonymised. Analytics remains consent-gated, so nothing is recorded at all unless you accept it.

Readiness checker answers

Where: /mortgages/tools/readiness-checker

Why: Letting a visitor pause and return to the educational checker without starting again. Answers are broad preparation choices only.

Stored: In your own browser only. It is never transmitted to us.

Fields

  • one of four broad answers per question (organised / partly / not yet / not sure)
  • which step the visitor reached

Keeping it: Stored only in the visitor's own browser until they clear it or select 'Start again'. The publisher never receives it.

Calculator, checklist and timeline inputs

Where: LTV calculator, document checklist builder, application timeline

Why: Producing an on-screen educational result.

Stored: Nowhere. The values exist only in your open browser tab.

Fields

  • figures or selections typed by the visitor for that calculation only

Keeping it: Discarded as soon as the page is closed or reloaded. Never stored or transmitted.

Save Plan and My Plan (saved preparation plan)

Where: Save Plan from the New Job & Probation preparation check, the /resume sign-in handover, and the signed-in /plan page

Why: Continuity you asked for: keeping the preparation plan you chose to save so you can sign in later and pick up where you left off.

Stored: In our hosted database (Supabase Auth identity, pending_plan_saves for the short-lived handover, and homebuyer_plans with related plan fact/action/derived-state tables for the durable saved plan). Account-based permissions control access to the saved plan; when signed in, you can view it and delete the plan and sign-in from your plan page.

Fields

  • the email address you give, used by our hosted authentication service to sign you in
  • the categorical employment-preparation answers you explicitly chose to save (broad options only)
  • which nation of the UK you are buying in
  • the preparation state and action codes worked out from those answers
  • tool name and version labels, and created/updated timestamps
  • a short-lived handover record for completing the save, holding the pending answers, a hashed one-time token and system record identifiers
  • only if you have already accepted analytics cookies: the coarse first-touch labels for how the visit began (channel category such as organic search or direct, any campaign labels in the link you arrived on, and the site page the save was started from), linked to the saved plan

Never included

  • No full web address you came from, no referring website address and no search terms
  • No question wording, message text or anything else you typed, and no advertising identifier
  • No acquisition labels at all if you have not accepted analytics cookies
  • No salary, income or any other figure
  • No employer name
  • No exact dates
  • No banking or payment details
  • No credit-report content or credit score
  • No uploaded documents
  • No health or other special-category information

Keeping it: Your saved plan and your sign-in are kept for 24 months after genuine inactivity, and you can delete them yourself from the plan page at any time before that. Any consent-gated first-touch acquisition labels are held on the same plan record, are recorded once only and are never overwritten by a later save, and they are deleted when you delete the plan. A `last_activity_at` inactivity signal and a separated retention-purge capability are being added to the system; automated inactivity deletion is scaffolded but is not yet running, so today deletion of an inactive plan still depends on manual review or your own self-service deletion. The short-lived handover record cannot be used after 60 minutes, the saved answers in it are wiped as soon as the save completes successfully, and a database job removes expired or already-consumed handover records on a 15-minute cadence, which continues to run.

Paid plan purchase and entitlement (New Job & Probation Mortgage Prep Plan)

Where: Checkout for the paid plan, when public checkout is switched on

Why: Taking payment for the one-off paid plan, recording the order, and granting time-limited entitlement to the paid content.

Stored: In our hosted database (order / entitlement records (created only once public checkout is switched on)). Account-based permissions control access to the saved plan; when signed in, you can view it and delete the plan and sign-in from your plan page.

Fields

  • email address associated with the sign-in / order
  • product identifier and price paid
  • order status and timestamps
  • entitlement start date and expiry date (12 months after grant)
  • Stripe's own reference for the payment (no card details ever reach our systems or database)
  • purchase terms and digital-content consent versions accepted, with timestamp

Keeping it: The order and accounting record is kept for the applicable legal and tax retention period, and that record is never deleted just because paid access to the plan itself expires after 12 months. Failed or abandoned checkout records, where stored, are kept for 30 days unless a completed order or another legal exception applies.

What we never collect

These categories are collected nowhere on this site, and no form asks for them:

  • Health, disability, mental-health or neurodivergence information
  • Any other special-category data under UK GDPR
  • Bank account, card or sort code details
  • National insurance numbers or tax reference numbers
  • Passwords or account credentials
  • Uploaded documents such as payslips, bank statements or tax calculations
  • Credit report contents or credit scores
  • Date of birth or home address

In particular, we do not collect or infer anything about your health, mental health, disability or neurodivergence, and nothing on this site is personalised on that basis.

Storage in your own browser

This site sets no advertising cookies. The list below covers BYA feature/preference storage and the known first-party Google Analytics measurement cookies that can be set only after you accept analytics. See the cookies page for how to change or clear them.

  • bya.consent.v1 — Your analytics and marketing choices. Contains no personal information. Kept in local storage until you clear it or change your choice.
  • bya.session.v1 — A random, rotating label used to group events from one browsing session. Not derived from personal data. Session storage only — discarded when the browser tab is closed.
  • bya.checker.v1 — Your broad answers in the readiness checker, so you can pause and return. Local storage until you select 'Start again' or clear your browser storage.
  • bya.submit.v1 — Timestamps of your recent form submissions, used only to prevent accidental duplicate or flooded submissions. Session storage only — discarded when the browser tab is closed.
  • _ga, _ga_<stream> — Google Analytics 4 cookies, set only after you accept analytics. They distinguish visits and pages, and never carry your name, email, message text or any figure you type. Google documents a default expiry of up to 2 years. Withdrawing analytics consent stops further Google Analytics measurement from this site; clear site cookies in your browser if you want an existing Analytics cookie removed immediately.

Analytics

We use our own first-party analytics and, in addition, Google Analytics 4 loaded as a single Google Analytics tag. Both are strictly consent-gated: nothing is recorded, and no Google script or Google cookie is loaded, until you actively accept analytics in the consent banner. If you withdraw consent, no further events are sent to either.

Our own analytics events and the custom event parameters we deliberately send to Google do not contain your name, contact details, message text, readiness-checker answers or financial figures you type. Those custom parameters are short categorical labels such as page type, tool name, broad result band or resource identifier. Google Analytics' standard web measurement also collects technical and usage information described by Google, including session statistics, browser/device information and approximate geolocation, and can use a first-party client identifier when analytics storage is allowed. Advertising and personalisation storage stay denied, and there is no advertising pixel on this site. Google acts as our processor for this analytics data; see the cookies page for the detail.

Our lawful bases

This is our own record as controller of the lawful basis we rely on for each thing the site can actually collect today.

Contact enquiry form and replies

Basis: Legitimate interests

The person contacts us and asks for a reply, so replying is what they expect and want, and doing so is necessary to handle the enquiry. There is no reply-consent tick box on the form: ordinary replies are never presented as consent-based.

Still to do: A necessity and balancing assessment must be written up and reviewed as part of the outstanding independent data-protection review.

Free resource request and download interest

Basis: Steps taken at the request of the individual for the free resource they asked for; legitimate interests only where that is genuinely the better fit

The person actively asks for a specific free educational resource, and the record exists to answer that request. This is not marketing consent, and it must never be treated as one: any marketing email is a separate, optional, unticked consent.

Still to do: Confirm in the independent review whether request-based processing or legitimate interests is the correct framing for a free, no-contract resource.

Checker-summary waiting list

Not settled yet

Basis: Deliberately not stated yet, because it is genuinely unsettled.

The public form for this waiting list is disabled, so nothing is currently collected under this heading. Any historic rows remain governed by whatever basis applied at the time; that basis was never finally settled.

Still to do: Settle the basis for any historic rows in the independent review, or before this surface is ever re-enabled.

Site security and abuse prevention

Basis: Legitimate interests

Rate-limiting, duplicate-submission checks, honeypot fields and Cloudflare Turnstile protect the site and its public forms from automated abuse and flooding. Turnstile is used only as a security control, not for advertising or marketing.

Optional marketing email and direct marketing generally

Basis: Consent

Marketing is a separate, optional, unticked choice that can be withdrawn at any time, and it is never bundled with an enquiry or resource request.

First-party analytics and consent-gated Google Analytics 4

Basis: Consent

Nothing is recorded and no request is made to Google before analytics consent is actively granted, and withdrawal stops further analytics. Analytics storage stays denied by default.

Saved preparation plan (Save Plan and My Plan)

Basis: Legitimate interests

The person explicitly asks us to save their preparation plan and to create the sign-in that lets them return to it. Providing that continuity, and deleting or expiring it after genuine inactivity, is a legitimate interest balanced against the person's own right to delete the plan at any time. It is not marketing consent.

Still to do: A written necessity and balancing assessment for this basis is still to be completed in the outstanding independent data-protection review.

Paid plan purchase and digital-product delivery

Basis: Contract

Processing the payment and delivering the paid plan is necessary to perform the purchase contract the buyer enters into. Stripe processes the payment itself as our payment processor.

Tax and accounting records for completed orders

Basis: Legal obligation

Statutory tax and accounting rules require certain sales records to be kept for a defined period, independent of when paid access to the plan itself expires.

Checkout, payment security and debugging

Basis: Legitimate interests

Detecting and investigating failed payments, checkout errors and abuse of the checkout flow is necessary to run a working, secure payment process.

We also rely on legitimate interests for keeping the site secure, for example limiting abuse of the enquiry form, balanced against your rights.

How these bases are recorded

Operator/controller record only. Not an independent legal sign-off. Independent qualified data-protection review remains outstanding before broader or commercial activity.

How long we keep data

UK data-protection law does not set one universal retention period. The periods below are Before You Apply's own documented operational schedule, and we review them against the purpose the data serves and whether we still need it.

Contact enquiries

How long: 12 months after the last meaningful contact about the enquiry

Then: Deleted, subject to a genuine legitimate dispute or legal exception.

Free-resource requests with no marketing consent

How long: 90 days

Then: Deleted, or anonymised where an anonymised record is all that is still needed.

Checker-summary waiting list

How long: Not collected today — the public form is disabled

Then: No new rows are created. Any historic rows are kept for 90 days from capture, then deleted or anonymised.

Marketing subscribers

How long: Kept while the subscription is active

Then: On unsubscribe or withdrawal of consent, removed from active marketing, keeping only the minimal suppression/consent-evidence record needed to respect the opt-out.

Marketing consent evidence

How long: 3 years after withdrawal of consent or the end of reliance on it

Then: Deleted, keeping the minimum evidence needed to show the consent was validly given and later withdrawn.

First-party analytics events

How long: 14 months in identifiable or pseudonymous form

Then: Deleted or irreversibly anonymised. Analytics is only ever recorded after explicit consent.

Saved preparation plans and the linked sign-in

How long: 24 months after genuine inactivity, with earlier self-service deletion available at any time

Then: Deleted on request, by the person's own self-service deletion from the plan page, or by automated inactivity deletion once that runs. A `last_activity_at` inactivity signal and a separated retention-purge capability are being added; automated inactivity deletion is scaffolded but not yet running, so today an inactive plan still relies on manual review or self-service deletion. The short-lived handover record is unusable after 60 minutes, its answers are wiped on a successful save, and a database job removes expired or already-consumed handover records on a 15-minute cadence, which continues to run.

Records of data-subject requests

How long: 3 years after the request is closed

Then: Deleted, keeping only the minimal audit record of the request and its outcome. Copies of identity documents are not retained.

Completed orders and accounting/tax evidence

How long: The applicable legal and tax retention period

Then: Kept separately from preparation-content deletion. The expiry of paid access to the plan after 12 months never deletes the underlying order or accounting record.

Failed or abandoned checkouts, where stored in the BYA database

How long: 30 days

Then: Deleted, unless a completed order or another legal exception applies.

Most retention-point deletion is currently a documented manual review, so a record may exist for a short period after its retention point while that review is carried out. One narrow exception is the short-lived saved-plan handover record: it cannot be used after 60 minutes, its saved answers are wiped after a successful save, and expired or consumed handover records are removed automatically on a 15-minute cadence.

Decisions we have not made yet

We would rather list these openly than imply a level of maturity we have not reached. Each is an open task:

  • Independent review of our lawful-basis record and wording by a suitably qualified adviser, before any broader or commercial activity
  • Verification of the remaining processors: Google's processing locations, Cloudflare Turnstile's deployment-specific processing/sub-processor locations, and our domain, mailbox and outbound-email provider and their terms (the production database region is verified as London, UK, eu-west-2)
  • International transfer positions and any safeguard relied on, which we have not verified and therefore do not claim
  • Verify Hostinger's currently applicable hosting and mailbox data-processing terms, whether a separate DPA is required, and the actual processing and transfer arrangements before commercial expansion; do not assume coverage or absence of a DPA
  • ICO registration and data protection fee reassessment, immediately before commercial go-live or first genuine trading
  • Independent factual review of the launch guides
  • Switch on the automated inactivity cleanup for saved preparation plans: the 24-month period and the separated purge function are in source control, but the scheduled destructive run is deliberately not enabled until a genuine 30-day advance warning email to the person can be sent and evidenced
  • Confirm the lawful-basis framing for the saved preparation plan and the sign-in that supports it, in the same outstanding independent review
  • Our complaints wording checked against current UK guidance by a qualified adviser

What we do not do

  • We do not sell personal data to anyone.
  • We do not run advertising trackers or third-party advertising cookies.
  • We do not share your data with lenders, advisers or brokers.
  • We do not use automated decision-making or profiling.

Who processes data on our behalf

These are the providers we actually use, what they do, and exactly how far our checks have gone. Where we have not verified something, we say so rather than assume it.

Database provider (production BYA database)

Recorded

Database processor for enquiry, resource-request, waiting-list, analytics, order/entitlement records, and the hosted authentication and saved-plan store behind Save Plan and My Plan.

Data involved: Name, email address, optional telephone number, enquiry text, consent records, analytics events, order/entitlement records, the sign-in identity created for Save Plan, and the categorical saved preparation plan linked to it.

Processing terms: Data processing terms for this database provider have not been separately re-verified for this note.

Where: London, UK (eu-west-2) — verified for the production database.

Cloudflare Turnstile

Details to verify

Security and abuse-prevention service for the public contact form. The browser obtains a Turnstile token and BYA's trusted server validates that token with Cloudflare Siteverify before accepting the enquiry. Cloudflare's Turnstile Privacy Addendum says Cloudflare is a processor for Signals used to protect customer websites and a controller for Signals it uses to improve Turnstile's bot-detection capabilities.

Data involved: Turnstile security Signals associated with the visitor, device and browser that are necessary to distinguish humans from automated traffic, plus the challenge token and validation metadata. BYA's Siteverify request does not send the enquiry name, email address, telephone number or message to Cloudflare.

Processing terms: Cloudflare Customer Data Processing Addendum version 6.4, effective 3 April 2026, applies where Cloudflare processes personal data as a processor on behalf of a customer. Cloudflare's Turnstile Privacy Addendum separately describes its processor and controller roles for Turnstile Signals.

Where: Cloudflare operates a global service. BYA has not yet mapped the deployment-specific Turnstile processing and sub-processor locations, so that remains to verify.

Hostinger

Details to verify

Domain registration, public mailbox and production Node hosting for before-you-apply.com. The public website runtime is deployed to Hostinger from BYA's Production branch; the application database remains the separate Supabase production project.

Data involved: Email correspondence sent to and from the public mailbox, plus ordinary web-hosting request/runtime data processed when visitors use the public site. Application records are stored in the separate Supabase production database rather than intentionally being used as a Hostinger application-data store.

Processing terms: Provider hosting/mailbox processing terms have not yet been separately re-verified for this note.

Where: Deployment-specific hosting/logging processing locations and retention remain to verify; no unsupported location claim is made here.

UK Postbox

Recorded

Business-address and postal handling for the correspondence address published in this notice.

Data involved: Physical mail addressed to the published business correspondence address.

Processing terms: Provider terms not separately verified for this note.

Where: United Kingdom.

Google (Google Analytics 4)

Details to verify

Consent-gated third-party analytics, stream G-FGC8H43MHT loaded directly. No Google Tag Manager container is loaded at runtime.

Data involved: Categorical events and Google's own analytics identifiers only, after consent. No name, email, free text, figures or raw checker answers.

Processing terms: Google's standard analytics terms apply. Not separately reviewed by or for the operator.

Where: Google processing locations not verified in project records.

Stripe

Details to verify

Payment processor for paid purchases of the plan, when public checkout is switched on. Handles card details directly; no card details reach our own systems or database.

Data involved: Payment details, billing email address and order amount, processed by Stripe directly at checkout.

Processing terms: Stripe's standard processor terms apply. Not separately reviewed by or for the operator.

Where: Stripe's own processing locations not verified in project records.

Order confirmation email

Recorded

Not active. A paid-order confirmation email is being built, but it stays configuration-gated and disabled today: no order confirmation email is sent.

Data involved: None today.

Processing terms: Not applicable until a provider is actually engaged and the feature is switched on.

Where: Not applicable.

International transfers

Partly verified

Our production database runs in London, in the United Kingdom, so the information you save is stored here. We do not treat that on its own as proof that no data ever leaves the UK: a provider's own support or sub-processor arrangements can involve access from elsewhere, and we assess each provider separately and rely on the appropriate safeguard where a transfer does arise. We have not yet finished verifying where every other provider above processes data, so we do not claim a position for them. We will state it accurately once checked, and before any broader or commercial activity.

Your rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you
  • Have inaccurate data corrected
  • Ask us to delete data, in some circumstances
  • Restrict or object to certain processing
  • Withdraw consent at any time, without affecting past processing
  • Request a copy of your data in a portable format, where applicable

To exercise any of these rights, email us at hello@before-you-apply.com or use the contact page.

How we handle your request

  1. A request can arrive at the canonical business mailbox, hello@before-you-apply.com, or via the contact form.
  2. Log the date the request was received and the right being exercised.
  3. Acknowledge the request to the person who made it.
  4. Verify identity only where it is genuinely necessary, and proportionately; no copies of identity documents are kept unnecessarily.
  5. Locate the relevant data across the enquiry, resource-request, waiting-list, analytics and saved preparation plan records, including the sign-in identity linked to a saved plan.
  6. Note that a signed-in person can delete their own saved plan and sign-in from the plan page, so a manual request may already have been satisfied by self-service deletion.
  7. Assess the right requested and any exceptions that apply.
  8. Action the relevant systems and, where used, any processor.
  9. Respond within the applicable legal deadline, generally within one month, handling and documenting any lawful extension where one applies.
  10. Record completion, retaining only a minimal audit record of the request and outcome.

We keep a short register of requests so we can show they were handled properly. It records only: request id, date received, type of request, systems checked, identity-verification status, action taken, date and form of response, date closed. We do not keep copies of identity documents unnecessarily.

Complaints

If you are unhappy with how we handle your data, or with anything else about this site, we would like the chance to put it right. This is how a complaint is handled:

  1. A complaint can be sent to the public business mailbox, hello@before-you-apply.com, or raised through the contact form.
  2. Log the date received, how to reply to the person, and what the complaint is about.
  3. Acknowledge the complaint promptly, so the person knows it has been received and is being looked at.
  4. Investigate it fairly, looking at what actually happened and what the site or its records show.
  5. Respond with the outcome and any corrective action taken or planned.
  6. Keep a minimal record of the complaint, the outcome and any action, and nothing more than is needed.
  7. For a complaint about how personal data has been handled, explain that the person can also complain to the Information Commissioner's Office (ICO) at any time, whether or not they raise it with us first.

We keep a short complaints record so we can show it was handled properly. It records only: complaint id, date received, how the complaint arrived, contact details for the reply, summary of the issue, date acknowledged, investigation notes, outcome and any corrective action, date and form of response, date closed.

You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), at any time, whether or not you raise it with us first.

ICO data protection fee

Current position

Before You Apply reviews its data-protection fee obligations as its processing activities evolve. No current fee determination or exemption is claimed on this page.

Review the fee position whenever processing activities materially change, including before any commercial launch, and register and pay the fee if the current assessment requires it.

We hold no ICO registration number and claim none. If registration becomes required, we will state the actual position here.