Legal
Privacy notice
Last updated 19 August 2026
This notice explains how SharedStatus handles personal data. It is written for the people who use the product — including firms who share a page with their clients.
Who is responsible
SharedStatus is operated by Flava Digital Ltd, a company registered in England and Wales (company number 10694772), based in Wellingborough, NN8 2QH.
Flava Digital Ltd is the data controller for the SharedStatus service. Questions about this notice, or requests about your data, should go to support@sharedstatus.com.
What this notice covers
It covers the SharedStatus website, accounts, status pages, the Email Assistant, and related emails we send when you ask us to (for example a sign-in code or a client update).
What data we collect
Depending on how you use SharedStatus, we may hold:
- Account email — you sign in with a one-time code sent to your email. There is no password. You may also add a business name and a default logo.
- Page content you type — titles, stages, latest updates, logos and notes. This can include client names, addresses and matter details if you put them on a page.
- Client email addresses — only if you choose to send a welcome or progress-update email, or if someone asks to be notified from a public page.
- Emails you paste into the Email Assistant — used to draft a status page. Do not paste anything you are not prepared to store and process.
- Feedback you send us — name, email and message if you include them.
- Standard server, security and usage logs — for example technical request data, hashed IP addresses used for rate limiting and abuse prevention, and first-party analytics events such as page views.
Public pages
Each status page has a public link in the form /s/{publicCode}.
Anyone who has that link can read the page. It is not a private portal
and it is not encrypted in a way that only the intended client can open it. Treat the
link like a document you have chosen to share: only put information the client has
agreed you may share, and do not put special-category data on it.
Cookies and analytics
SharedStatus does not currently show a cookie banner. The live site uses the following:
- Google Analytics 4 — to understand how marketing and product pages are used.
- Microsoft Clarity — session analytics that help us see how people use the site (including things like clicks and scrolling).
- First-party cookies we set — a sign-in session cookie if you log in
(
SharedStatus.User, kept for about 30 days), a first-party analytics session cookie (ss_analytics_session), and standard security cookies used by the website (for example to validate form submissions).
You can block or delete cookies in your browser. If you do, some features (including staying signed in) may not work.
Why we use the data
- Provide the service — create, store and show the pages you set up.
- Send the one-time sign-in code to your email.
- Send client-update emails when you ask us to.
- Generate a draft page from a pasted email when you use the Email Assistant.
- Keep the service secure, rate-limit abuse, and diagnose faults.
- Understand how the site is used so we can improve it.
Lawful bases
We rely on the following, depending on the activity:
- Contract — creating your account, running your pages, sending the sign-in code, and sending the client emails you request.
- Legitimate interests — keeping the service secure, preventing abuse, and understanding usage so we can run and improve SharedStatus. We do not treat analytics as “consent for everything”.
- Consent — only where it actually applies (for example if you choose to send us optional feedback details). There is no cookie-consent banner on the site today.
How long we keep it
We keep account and page data while you use the service. Sign-in codes expire after 15 minutes. Sign-in sessions last about 30 days.
Anonymous or free pages may expire. If a page expires or you delete it, it is no longer shown on the public link.
If you want your account and related data deleted, email support@sharedstatus.com and we will delete it. You can also delete individual status pages from your dashboard.
Who we share data with
We do not sell personal data.
We use service providers to host the site, send email, run the Email Assistant, and measure usage. From the product itself, those include:
- MailerSend — sending sign-in codes and the client emails you request.
- OpenAI — generating a draft status page when you use the Email Assistant.
- Google — Google Analytics 4.
- Microsoft — Microsoft Clarity.
We also store data in a database and on the servers that run SharedStatus. We have not named a hosting region here because it is not published in the product.
International transfers
Some of the providers above are based outside the UK (including in the United States). If they process personal data, that may involve an international transfer. We have not listed specific transfer mechanisms or hosting regions beyond what we can see in how the product is built.
Your rights
Under UK GDPR you can ask us to:
- access the personal data we hold about you
- correct inaccurate data
- erase your data
- restrict how we use it
- object to processing based on legitimate interests
To do that, email support@sharedstatus.com. You can also complain to the Information Commissioner’s Office (ICO) if you are unhappy with how we handle your data. The ICO is the UK supervisory authority: ico.org.uk.
Children
SharedStatus is a business tool. It is not directed at children, and we do not knowingly collect data from children.
Changes
If we change this notice we will update this page and the date at the top.
