Privacy Policy

This notice explains what Step Social does with personal data. It covers the personal data we hold about our clients, the people who enquire about our services, visitors to our website, and people who apply to work with us. It also explains the personal data we handle on behalf of our clients when we deliver their services.
We have written it in plain English rather than legal language. If anything is unclear, email us and we will explain it.
We handle personal data in line with the UK GDPR (the UK General Data Protection Regulation) and the Data Protection Act 2018.
Last updated: 17 August 2026

1. Who we are

Step Social is a trading name of Step Digital Media Limited, a company registered in England and Wales.
Company number: 13148731
Registered office: Unit A, 82 James Carter Road, Mildenhall, England, IP28 7DE
Website: stepsocial.com
Email: support@stepsocial.com
ICO registration number: ZB292622
We are the data controller for the personal data described in section 2.1 below. We are registered with the Information Commissioner’s Office (ICO), the UK’s data protection regulator. We have not appointed a Data Protection Officer, as we are not required to, but you can raise any privacy question by emailing us at the address above.

2. When we are the controller, and when we are the processor

This matters, because it changes who is responsible for what. “Controller” and “processor” are the terms used in the UK GDPR.
2.1 We are the controller for personal data about our own clients, prospective clients, website visitors, contacts and job applicants. This notice explains how we handle that data. Being the controller means we decide why and how it is used.
2.2 We are the processor for personal data that belongs to our clients and that we handle only in order to deliver their services. This includes the contact details of people who respond to a client’s Meta Lead Ads, the content and messages on a client’s social media accounts, and the analytics we connect for a client’s Reports Hub. In those cases our client is the controller and decides what happens to the data. We only act on their instructions.
If you have submitted your details to an advert or a social media account run by one of our clients, that client is the controller, and you should contact them about your data. We will pass any request we receive straight to them.
The terms on which we act as a processor are set out in section 17 of our Terms of Service.

3. The personal data we collect

If you are a client or a prospective client: your name, business name, email address, phone number, billing address, the content of your messages to us, your onboarding answers, brand assets you upload, the social media accounts you connect, your order and payment history, and notes from calls and meetings.
If you visit our website: your IP address, browser and device type, the pages you view, how you arrived, and how you interact with the page. Some of this is collected through cookies and similar technologies (see section 6).
If you book a demo or a call: your name, email address, business, availability, and anything you tell us in the booking form. If a call is recorded we will tell you at the start and you can ask us not to.
If you apply for a job: your CV, contact details, work history and anything else you send us.
Payment details. We do not see or store your full card number. Payments are handled by our payment providers, who hold the card details and give us only a reference, the last four digits, and whether the payment succeeded.
Special category data. We do not ask for and do not want special category data (for example health, race, religion, or political opinions). Please do not send it to us.

4. Where we get it from

Most of the personal data we hold comes directly from you, when you fill in a form, place an order, email us, book a call, or use our website.
We also collect it from: our client portal and content scheduling tools when you use them; our payment providers when you pay us; publicly available business sources such as a company website or LinkedIn profile, where we are researching a business we think we can help; and referrals, where an existing contact passes on your details.

5. Why we use it, and our lawful basis

Under the UK GDPR we must have a lawful basis for using personal data. Ours are set out below.
To deliver the services you have ordered, including creating and scheduling content, running campaigns, giving you access to the client portal, and providing support. Lawful basis: performance of a contract.
To take payment, invoice you, and manage renewals, refunds and cancellations. Lawful basis: performance of a contract.
To answer enquiries, provide quotes and run demo calls before you become a client. Lawful basis: steps taken at your request before entering a contract, and our legitimate interests in responding to enquiries.
To keep accounting and tax records. Lawful basis: legal obligation.
To run and improve our website, understand which pages work, fix problems and keep the site secure. Lawful basis: our legitimate interests in running a working, secure website. Where this involves non-essential cookies, we also rely on your consent (see section 6).
To market our services to businesses we think would benefit, and to send existing clients news and offers about services similar to those they already buy. Lawful basis: our legitimate interests in growing our business, and consent where the law requires it (see section 7).
To use testimonials, case studies and client logos in our marketing, as set out in our Terms of Service. Lawful basis: our legitimate interests in demonstrating our work. You can opt out in writing at any time.
To protect our business, prevent fraud and abuse, recover unpaid amounts, and establish or defend legal claims. Lawful basis: our legitimate interests, and legal obligation where one applies.
To consider job applications. Lawful basis: steps taken at your request before entering a contract, and our legitimate interests in recruiting.
Where we rely on legitimate interests, we have considered whether our interests are outweighed by your rights. You can object at any time (see section 13).

6. Cookies and similar technologies

Cookies are small files placed on your device. We use them, and similar technologies such as pixels and tags, for the purposes below.
Strictly necessary. Needed for the website to work, for example remembering form entries and keeping the site secure. These do not require your consent.
Analytics. Help us understand how people use the site so we can improve it. We use Google Analytics and Google Tag Manager, and Microsoft Clarity, which records anonymised session activity such as scrolling and clicks so we can see where pages are confusing.
Advertising. Let us measure and target our own advertising. We use the Meta Pixel, the TikTok Pixel, the LinkedIn Insight Tag and Google Ads tags. These may be used to show you our adverts on those platforms, and to build audiences of people who look similar to our existing visitors.
Functional. Support features such as review widgets, web push notifications and live chat.
How to control cookies. You can block or delete cookies in your browser settings, though some parts of the site may then not work properly. You can also control advertising on each platform directly, through your Meta, TikTok, LinkedIn and Google ad settings, and you can opt out of Google Analytics using Google’s browser add-on.
We do not use cookies to identify you personally, and we do not sell your personal data to anyone.

7. Marketing

If you are an existing client, or you have enquired about our services, we may email you about services similar to those you have bought or asked about. You can opt out at any time and every marketing email has an unsubscribe link.
If you are a business contact at a company we think we can help, we may contact you about our services. The UK’s electronic marketing rules (the Privacy and Electronic Communications Regulations, or PECR) allow this for corporate subscribers, and we will always tell you who we are and give you a way to stop hearing from us.
We will not add you to a marketing list simply because you booked a demo or downloaded something, unless you asked us to or the rules above apply.
The SMS alerts available as an add-on to our Meta Lead Ads service are service messages sent to our client about their own leads. They are not marketing.
To stop all marketing from us, click unsubscribe in any email or reply to support@stepsocial.com asking to be removed. We will action it promptly.

8. Who we share it with

We do not sell personal data. We share it only with the providers we need in order to run the business, and only as far as necessary.
Payments and billing: Stripe and PayPal.
Client portal, orders and support: our client management platform.
Content scheduling and publishing: our social media scheduling platform.
Email, files and internal working: Google Workspace.
Email marketing and notifications: Brevo and Mailchimp.
Website, hosting and analytics: our hosting provider, WordPress and Automattic, Google Analytics, Google Tag Manager and Microsoft Clarity.
Advertising platforms: Meta, TikTok, LinkedIn and Google.
Reviews and website widgets: Elfsight, Trustindex, WonderPush and ProveSrc.
Calls and scheduling: Calendly and Zoom.
We also share personal data with our accountants and professional advisers, and with the authorities where the law requires it. If our business is ever sold or merged, personal data may transfer as part of that, and we would tell you first.
We review this list from time to time and update it when providers change.

9. Sending data outside the UK

Some of the providers listed above are based outside the United Kingdom, or store data outside it, mainly in the European Economic Area and the United States. Members of our own team also work from outside the UK.
Where personal data leaves the UK, we make sure one of the following applies: the country is covered by UK adequacy regulations; or the provider has signed the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses; or the provider is certified under the UK Extension to the EU-US Data Privacy Framework.
You can ask us for more detail about a specific provider by emailing us.

10. How long we keep it

We keep personal data only as long as we need it. In practice that means:
Client records, contracts and correspondence: for the duration of the relationship and 7 years afterwards, so we can meet our accounting and tax obligations and defend any claim.
Invoices and payment records: 7 years, as required for tax.
Completed content and campaign assets: at least one month from delivery, as set out in our Terms of Service. Please download and keep your own copies.
Enquiries that do not become clients: 24 months from the last contact.
Marketing contacts: until you unsubscribe or ask us to stop, and we review the list at least every 24 months.
Website analytics: up to 14 months.
Support messages and tickets: 24 months after the ticket is closed.
Job applications: 6 months after the role is filled, unless you agree to us keeping them longer.
Data we hold as a processor for a client: for as long as their subscription runs, then deleted or returned as set out in our Terms of Service, unless we have to keep it by law.

11. How we keep it secure

We take security seriously, particularly because we hold access to our clients’ social media and advertising accounts.
Our measures include: access on a need-to-know basis; multi-factor authentication on our key systems; connecting client accounts through secure platform permissions rather than sharing passwords; encrypted connections for our website and tools; reputable providers for hosting, payments and storage; and confidentiality obligations on everyone who works with us.
No system can be guaranteed completely secure, but we work to protect your data and we review our practices regularly.

12. If something goes wrong

If a personal data breach happens and it is likely to result in a risk to people’s rights, we will report it to the ICO within 72 hours of becoming aware of it, as the UK GDPR requires. If the risk is high, we will tell the people affected as well, without undue delay.
Where a breach affects data we hold on behalf of a client, we will tell that client without undue delay so they can meet their own obligations.

13. Your rights under the UK GDPR

The UK GDPR gives you the following rights over your personal data:
Access. Ask for a copy of the personal data we hold about you.
Rectification. Ask us to correct anything inaccurate or incomplete.
Erasure. Ask us to delete your personal data, where there is no good reason for us to keep it.
Restriction. Ask us to pause how we use your data while a concern is looked into.
Portability. Ask for the data you gave us in a machine-readable format, or ask us to send it to someone else.
Objection. Object to us using your data where we rely on legitimate interests. You can always object to direct marketing, and we will stop.
Withdraw consent. Where we rely on consent, you can take it back at any time. That does not affect anything we did before you withdrew it.
Complain. Raise a concern with the ICO (see section 18).
How to use these rights. Email support@stepsocial.com. It is free, and we will respond within one calendar month. If your request is complicated we may need up to two further months, and we will tell you if so. We may ask you to confirm your identity first, so that we do not give your data to the wrong person.
If your request relates to data we hold for one of our clients (see section 2.2), we will pass it to that client, because they decide what happens to it.

14. Automated decision-making

We do not make decisions about you using only automated means where those decisions have a legal or similarly significant effect on you.
We do use advertising platforms that profile people for targeting, for example to show our adverts to people whose interests suggest they may want our services. This affects which adverts you see and nothing more. You can control it in your settings on each platform.

15. Children

Our services are sold to businesses and our website is not directed at children. We do not knowingly collect personal data from anyone under 13. If you believe a child has given us their details, email us and we will delete them.

16. Other websites

Our website links to other sites, including social media platforms and our client portal. This notice does not cover those sites, and we are not responsible for how they handle your data. Please read their own privacy notices.

17. Changes to this notice

We review this notice regularly and update it when our services, tools or the law change. The date at the top shows when it was last updated. If we make a significant change we will say so on this page and, where appropriate, tell you by email.

18. How to contact us, and how to complain

If you have any question about this notice or about how we handle your personal data, email support@stepsocial.com or write to us at Step Digital Media Limited, Unit A, 82 James Carter Road, Mildenhall, England, IP28 7DE.
We would rather hear from you first so we can put things right. But you also have the right to complain to the Information Commissioner’s Office at any time:
Website: ico.org.uk/make-a-complaint
Helpline: 0303 123 1113
Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF