🎉 Founder offer: 25% off your first 3 months on Pro and Agency with code FOUNDER25. Ends August 16.

Privacy Policy

Last updated: July 2026

HEXRATE LTD (company number 16665404), 38 Princess Park Manor, Royal Drive, London, United Kingdom, N11 3FL, is the data controller for Hexrate. This policy explains what we collect and why. Questions: [email protected].

What we collect from you

Data about people who are not Hexrate customers

The service analyses publicly available Instagram information about accounts our customers choose to track or look up, and maintains a directory of public creator profiles. This can include personal data (a public profile’s name, picture, follower statistics and public posts) of people who have no relationship with Hexrate. We process it on the basis of legitimate interest: providing analytics about publicly visible social-media activity, in the form its owners chose to make public. We do not collect private accounts’ content, and we do not enrich public data with non-public sources. If you are the owner of a public profile and want it removed from our directory, email [email protected] and we will remove it.

Why we process it

We do not sell personal data, and we do not send marketing email without your consent.

Who processes it for us

Service providers acting under contract: Stripe (payments), our hosting and infrastructure providers (servers, content delivery, file storage), Instagram data providers (public profile data), an AI text provider used to generate analytics summaries from the same public data, and Google Tag Manager for the analytics described under Cookies. Some providers process data outside the UK/EEA; those transfers rely on UK-approved safeguards (the UK IDTA or the International Data Transfer Addendum to the EU Standard Contractual Clauses). Email us for a copy of the relevant safeguard.

How we protect it

All traffic to Hexrate is encrypted in transit (HTTPS/TLS). Passwords are stored only as salted hashes, never in readable form. Card details are held by Stripe, a PCI DSS Level 1 certified payment processor, and never touch our servers. Access to production data is limited to the people who need it to operate the service, and our infrastructure runs on established providers with their own security certifications.

How long we keep it

Your rights

Under UK GDPR you can ask us for access to your data, its correction, deletion, restriction of processing, portability, or to object to processing based on legitimate interest; where processing is based on consent you can withdraw it at any time. Email [email protected] and we will respond within one month. You can also complain to the Information Commissioner’s Office (ico.org.uk).

Cookies

The dashboard uses cookies for your session and security, an affiliate-attribution cookie when you arrive through a partner link, and analytics cookies set through Google Tag Manager that help us understand signup and checkout performance. We are rolling out a cookie consent control for the analytics cookies; until then you can block them in your browser without affecting the service.

Changes

If this policy changes materially we will tell you by email before the change applies.