← Back to home

Privacy Policy

Orkazoo LTD · Last updated 13 August 2026

This Privacy Policy explains how Orkazoo LTD ("we", "us", "our") collects and uses personal data when you use PetitionMinder, our petition-tracking app and website at petitionminder.com. Orkazoo LTD is the data controller for the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. What we collect

Account data

When you create a PetitionMinder account with an email address and password, we store your email address and a hashed password. Passwords are hashed using scrypt with a per-user salt. We never store, log or transmit your password in plain text, and we cannot recover it.

If you sign in with Google or Apple, we receive your email address and a stable identifier from that provider, which we use to recognise your account on return visits. We never receive, see or store your Google or Apple password.

Your petition record

PetitionMinder stores the petitions you choose to log: the petition title, platform, URL and the date you logged it. This record is saved locally on your device and, if you are signed in to an account, is also synced to our servers so it is available across your devices. If you use the app as a guest, your record stays on your device only and is never sent to us.

Optional Gmail scanning

PetitionMinder offers an optional feature that reads petition confirmation emails to auto-capture petitions you have signed. If you enable it, we request the gmail.readonly scope from Google. This access is:

  • Explicitly requested by you — scanning only runs when you actively ask for it. There is no background or scheduled scanning.
  • Used in-flight only — messages are processed in memory to extract the petition name, platform and URL, and are discarded immediately afterwards.
  • Never stored — we do not store, copy, log, index or retain the content, subject lines, attachments or metadata of your emails.
  • Never shared — email content is never sold, transferred or disclosed to any third party, and is never used for advertising or to train machine-learning models.
  • Credential-free — we do not store your Google credentials. You can revoke access at any time in your Google Account settings.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Technical data

Our servers process standard request data such as IP address and timestamps for security, abuse prevention and to keep the service running. We do not use advertising trackers or third-party analytics profiling.

2. Why we use your data (lawful bases)

  • Contract — to create and operate your account and to sync your petition record across devices.
  • Consent — for optional Gmail scanning. You may withdraw consent at any time.
  • Legitimate interests — to secure the service, prevent abuse and fix faults.

3. Petition data from UK Parliament

Public petition information shown in PetitionMinder is retrieved from petition.parliament.uk under the Open Parliament Licence v3.0. This is public data and contains no personal information about you. PetitionMinder does not sign petitions on your behalf and never submits your personal details to any petition platform.

4. Sharing your data

We do not sell your personal data. We share it only with infrastructure providers who host and operate the service on our behalf under written data-processing terms, and where we are required to do so by law.

5. Your UK GDPR rights

You have the right to:

  • Access — obtain a copy of the personal data we hold about you.
  • Rectification — have inaccurate or incomplete data corrected.
  • Erasure — have your account and data deleted ("right to be forgotten").
  • Portability — receive your data in a structured, machine-readable format.
  • Restriction — ask us to limit how we process your data.
  • Objection — object to processing based on our legitimate interests.

To exercise any of these rights, email privacy@petitionminder.com. You can delete your account instantly in the app under My Record → Delete account, or follow the steps on our Account Deletion page. You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk).

6. Data retention

We retain your account data and synced petition record until you delete your account. When you delete your account, your account record and all associated petition data are removed from our servers. Email content is never retained at any point. Minimal security logs may persist for a short period before routine rotation.

7. Children

PetitionMinder has a minimum age of 13. We do not knowingly collect personal data from anyone under 13. If you believe a child under 13 has created an account, contact privacy@petitionminder.com and we will delete it. See also our Child Safety Standards.

8. Security

Data is transmitted over TLS. Passwords are hashed with scrypt. Access to production systems is restricted to authorised personnel. No system is perfectly secure, but we take reasonable and proportionate technical and organisational measures to protect your data.

9. International transfers

Where data is processed outside the UK, we rely on appropriate safeguards such as UK adequacy regulations or the International Data Transfer Addendum to the EU Standard Contractual Clauses.

10. Changes to this policy

If we make material changes to this policy we will update the date at the top of this page and, where appropriate, notify you in the app.

11. Contact us

Email: privacy@petitionminder.com
Post: Orkazoo LTD, London, United Kingdom