Privacy Notice
Last updated 21 August 2026.
1. Who we are
Globe Connected is operated by Globe Connected Limited (trading as Globe Connected), registered under number 166707. Our registered address and principal place of business is:
10 Fremont Perle, La Route Du Mont Mado, St John, JE3 4DN, Jersey
We are the controller for the personal data we collect about visitors to this site and users of our services. When you use this site you are contracting with us; purchases are sold through Link, LLC as merchant of record — see section 2.
For any privacy question, or to exercise your rights, email [email protected] or write to us at the address above.
2. Payments are handled by Link, a Stripe company
Paid services on this site are sold through Link, LLC, a Stripe company, acting as the merchant of record: Link charges you, issues your receipts and invoices, and handles refunds. Your card number is entered on the Link checkout and never touches our servers. Stripe and Link are the controller of the payment data collected at checkout, using it for purposes such as processing your payment, calculating and accounting for tax, fraud prevention and legal compliance — see Stripe's privacy policy, which covers Link. Stripe tells us the card brand and last four digits so we can show you which payment method is on file.
If you ask Stripe or Link to delete your data, Stripe cancels any subscription you bought through Link and deletes the related payment records, including the copies held in our Stripe account; we then keep only what our own legal obligations require, per section 6.
3. What we collect, why, and on what legal basis
| Data | Why we use it | Legal basis |
|---|---|---|
| Account data — name, username, email address, hashed password, account status, verification and join dates | Creating and running your account, authenticating you, verifying your email, sending service messages | Performance of a contract |
| Company content you submit — business name, postal address, telephone number, email address, website, description, images | Publishing your entry in the directory as you asked us to, and letting other users contact you about it. This content is public by design | Performance of a contract |
| Directory information compiled from public and third-party sources, which may include the contact details of a sole trader | Maintaining a useful business directory | Legitimate interests — running a directory of businesses and organisations that users expect to find listed |
| Moderation records — automated and human decisions on your submissions, reasons, and duplicate checks | Keeping the directory accurate, lawful and free of spam and fraud, and handling appeals | Legitimate interests — content moderation and platform integrity; legal obligation where content must be removed |
| Subscription and billing records — the Stripe customer, subscription and invoice identifiers Stripe sends us, plan, status, renewal dates, card brand and last four digits, slot entitlements | Giving you what you paid for, showing your billing state, applying refunds, chargebacks and adjustments | Performance of a contract; legal obligation for financial records |
| Technical and security data — IP address, browser user agent, request and error logs, rate-limiting and login-throttling records | Keeping the service secure and available, investigating abuse, diagnosing faults | Legitimate interests — security, abuse prevention and service reliability |
| Approximate country, derived from your IP address | Showing you prices and currency appropriate to your country | Legitimate interests — displaying locally relevant pricing and browse results |
| Correspondence — messages you send us and our replies | Answering you and keeping a record of what was agreed | Legitimate interests — customer support; performance of a contract where it concerns a paid service |
| Enquiries and conversation threads — the name and email address you give on a company's contact form, your message, and the replies you and the company exchange | Delivering your enquiry to the company's Owner, emailing you a confirmation and their replies, keeping the conversation available through your private thread link, and screening the opening message for spam | Legitimate interests — putting you in touch with a business at your request |
| Upsell campaign records — that we emailed you about Verified, when, which of two versions of the email you were sent, whether you followed the link in it, and whether you asked us to stop | Telling you once about the paid tier of a service you already use, learning which explanation of it people find useful, and making sure we don't email you about it again if you would rather we didn't | Legitimate interests — telling an existing account holder about a paid option on the service they already use. You can object at any time, and every one of these emails carries an unsubscribe link |
| Analytics data — pages viewed, referrers, approximate location, device and browser characteristics | Understanding how the site is used so we can improve it | Consent |
| Company interaction counts — which company pages were viewed and which contact links (website, phone, email, social, enquiry form) were used, counted per company per day. No identifier of any kind is stored with the count | Showing company Owners how their entry is performing, and understanding which parts of the directory are used | Legitimate interests — the count contains nothing about you and cannot be linked back to you |
Where we rely on legitimate interests we have considered the impact on you and use the least intrusive option that achieves the purpose. You can object — see section 7.
We do not sell personal data, and we do not use it for automated decisions that have a legal or similarly significant effect on you. Content moderation is automated in part, but a company decision you disagree with can always be reviewed by a person — just contact us.
When you send an enquiry, the confirmation email we send you contains a private link to your conversation. The link is unguessable, but anyone who has it can read the conversation and reply — treat it like a password and don't forward the email. The link does not expire; if you want a conversation removed, contact us and we will delete it.
If we email you about Verified, you get that email once — nobody is sent it twice — and it carries an unsubscribe link in the footer as well as the one-click unsubscribe your mail app offers. We don't use tracking pixels, so we don't know whether you opened it; we only record whether you followed the link, and only the first time. Unsubscribing stops emails about Verified and nothing else: you will still get the messages your account depends on, like password resets and enquiries from people who find your company.
4. Who we share it with
- The company Owner you contact — when you send an enquiry or reply in a thread, your name, email address and message are passed to the Owner of that company: by email, in their enquiry inbox, through their API access, and to any webhook endpoint URLs they have registered (which they control, and which may be hosted by providers of their choosing, anywhere in the world). The Owner receives that data as an independent controller and is responsible for their own use of it; our terms require them to use it only to deal with your enquiry.
- Stripe and Link, LLC, through which paid services are sold: Link, as merchant of record, takes payments, bills subscriptions, issues invoices and receipts, handles tax, and provides transaction-level buyer support.
- Service providers acting on our instructions — our hosting and infrastructure provider, our email delivery provider, our search provider (Meilisearch), our analytics providers (Google Analytics and Plausible), and our error-monitoring and logging tools. Each is bound by a written contract to process personal data only for us.
- OpenAI, which we use to screen submitted companies and enquiry messages for spam and prohibited content. Submitted company content, which may include contact details you have chosen to publish, is sent for that check; for enquiries, the name, email address and message you provide and the name of the company you are contacting are sent. None of it is used to train models.
- Professional advisers — our lawyers, accountants and auditors, where they need it to advise us.
- Authorities, courts and other third parties where we are required to disclose by law, or where disclosure is necessary to establish or defend legal claims or to protect the rights or safety of others.
- A buyer or successor, if the business is reorganised, sold or transferred, subject to this notice.
5. International transfers
Some of our providers, including Google Analytics, OpenAI and Stripe, process data outside Jersey, the United Kingdom and the EEA — including in the United States. Where that happens we rely on an adequacy decision covering the destination country, or on the UK International Data Transfer Agreement or the EU standard contractual clauses together with the relevant addendum, and we assess whether additional safeguards are needed. You can ask us for details of the safeguards applying to a particular transfer.
Webhook deliveries are different: they go to endpoint URLs chosen and controlled by the company Owner you contacted, and may be processed in any country. We make those deliveries on the Owner's instruction, and the Owner — as an independent controller — is responsible for the onward handling of the data they receive.
6. How long we keep it
- Account data — while your account is open, then up to 12 months after closure to handle disputes and prevent re-registration abuse.
- Published companies — while published; removed companies are retained for up to 12 months, then deleted.
- Moderation records — up to 24 months after the decision, so repeat problems and appeals can be handled.
- Billing and entitlement records — 7 years, to meet accounting and tax obligations.
- Security and request logs — up to 90 days, longer only where retained for a specific investigation.
- Correspondence — up to 24 months after the matter is closed.
- Enquiries and conversation threads — while the conversation may still be picked up, and no longer than 24 months after the last message in the thread, then deleted or anonymised.
- Webhook delivery records, including a copy of each payload sent — up to 90 days, kept to help Owners troubleshoot delivery, then deleted.
- Upsell campaign records — up to 12 months after the email was sent, then deleted.
- Unsubscribe records — kept indefinitely, because deleting the record that you asked us not to email you would leave us with no way of honouring it. Each one holds an email address, the reason, and the date, and nothing else.
When data is no longer needed for the purpose we collected it for we delete it, or irreversibly anonymise it so it can no longer be linked to you.
7. Your rights
You have the right to:
- access the personal data we hold about you, and get a copy;
- rectify data that is inaccurate or incomplete;
- erase your data where we no longer have grounds to keep it;
- restrict our processing while a dispute about accuracy or grounds is resolved;
- portability — receive the data you gave us in a machine-readable format, or have it sent to another provider;
- object to processing based on legitimate interests, and to direct marketing at any time; and
- withdraw consent at any time where we rely on it, without affecting processing already carried out.
Email [email protected] to exercise any of these. We reply within one month, and will tell you if we need the extension the law allows for a complex request. We may ask you to confirm your identity first. Exercising your rights is free; we only charge where a request is manifestly unfounded or excessive.
You can also complain to a data protection authority: in Jersey the Office of the Information Commissioner (jerseyoic.org), in the UK the Information Commissioner's Office (ico.org.uk), or your local supervisory authority in the EEA. We would rather you came to us first so we can put things right.
8. Security
We apply technical and organisational measures appropriate to the risk, including encryption of data in transit over HTTPS, one-way hashing of passwords, role-based access limited to staff who need it, rate limiting and login throttling, and logging of administrative actions. No system is completely secure, so we also keep breach-response procedures and will notify you and the relevant authority where the law requires it.
9. Cookies
We use a small number of cookies. Optional ones are only set after you accept them in our cookie banner — until then, Google Analytics is loaded with storage denied and stores nothing on your device.
Essential — no consent needed
- A session cookie and a CSRF token cookie, needed to log you in and to protect forms. If you choose to stay logged in, a “remember me” cookie.
- A
gc_cookie_consentcookie recording your cookie choice, kept for 12 months. Without it we would have to ask you on every page.
These cannot be switched off without breaking the site.
Optional — only with your consent
- Analytics — Google Analytics cookies, which tell us how the site is used in aggregate. We do not use them to identify you, and we do not use Google's advertising or cross-site tracking features.
We also use Plausible, a cookieless analytics tool, and count company interactions as described in section 3 — neither sets a cookie or stores anything on your device, so neither needs your consent.
To manage your preferences, and change your answer. You can also block or delete any cookie in your browser settings, browse in private mode, or opt out of Google Analytics everywhere using Google's opt-out browser add-on. Blocking essential cookies will stop you logging in.
10. Children
Globe Connected is for people aged 18 and over. We do not knowingly collect data from children; if you believe we have, contact us and we will delete it.
11. Changes to this notice
We may update this notice. The version on this page is the current one and the date at the top shows when it last changed. If a change materially affects how we use your data we will tell you directly.