Search Pilla

Search pages and blog articles, or ask Pilla.

Privacy Policy for Pilla Platform

Last updated: 14th September 2026 · Version 3.4

Comprehensive privacy policy for Pilla Platform explaining how we collect, use, store, and share your information.

1. Who We Are

Your Pilla Ltd ("Pilla," "we," "us," or "our") is a UK limited company registered with Companies House in the UK. We develop and operate the Pilla platform, including our web application and mobile app, to help employers manage and motivate their employees.

Company Details:

  • Company Name: Your Pilla Ltd
  • Registered Address: 86-90 Paul Street, London, EC2A 4NE
  • ICO Registration Number: ZC239279
  • Data Protection Officer: Liam Jones (liam@yourpilla.com)

2. This Privacy Policy

This Privacy Policy explains how we collect, use, store, and share information when you use the Pilla platform, including:

  • Our web application accessed through browsers
  • Our mobile application on iOS or Android devices
  • Related services and communications

This policy covers data collection through all Pilla services and does not apply to third-party websites or services linked from our platform.

Data Controller/Processor Relationship:

  • The employer who pays for the Pilla software is the Data Controller of employee personal data
  • Pilla is the Data Processor of employee personal data

3. Information We Collect

3.1 Data Types Collected

Our platform may collect the following categories of data:

Personal Identifiers

  • Name and email address
  • Employee ID number
  • Profile photos (if uploaded)
  • Device identifiers (IDFA/GAID when permitted - mobile app only)
  • Browser identifiers

Contact Information

  • Email addresses

Food Safety Pack Requests

  • When you request a food safety pack, we collect your email address and prepare a PDF containing your selected workflows and edits.
  • We keep a summary of your quiz answers, workflow count, request and delivery details, whether the download link was accessed, and your choice about the Pilla Newsletter. An access record may include an email security scanner opening the link.
  • We use a protected code derived from your IP address to limit repeated requests. Cloudflare Turnstile checks the request to help prevent abuse.
  • Loops sends the requested delivery email, including your private download link. Anyone you share the link with can download the PDF until it expires.
  • Requesting a pack does not create a Pilla account. We add you to the Pilla Newsletter only if you select the optional checkbox. It includes practical tips on helping your team follow through and updates on how Pilla can help. We also record that you signed up through the food safety pack. You can unsubscribe at any time.

Location Data

  • Web Application: None
  • Mobile App: Approximate location for timezone settings; precise location only when explicitly enabled

Device and Technical Information

Web Application:

  • Browser type, version, and language settings
  • Operating system and device type
  • Screen resolution and viewport size
  • Referring website URLs

Mobile App:

  • Device model and operating system version
  • App version and crash logs

Both Platforms:

  • IP address
  • Usage analytics and performance data
  • Session duration and frequency

Usage Data

Web Application:

  • Pages visited and time spent
  • Click patterns and navigation paths
  • Form interactions and search queries
  • Feature usage and preferences

Mobile App:

  • App interaction data and screen views
  • Feature usage patterns
  • Push notification interactions

Both Platforms:

  • Session duration and frequency
  • Content preferences and settings

Employee Data

  • Work schedules and availability
  • Performance metrics (as configured by employer)
  • Training records and certifications
  • Goal and task completion data

Communications Data

Web Application:

  • Contact form submissions
  • Live chat conversations
  • Email communications

Mobile App:

  • In-app messages and notifications
  • Push notification preferences

Both Platforms:

  • Support ticket communications
  • Feedback and survey responses

3.2 How We Collect Data

We collect information:

  • Directly from you: When you register, update your profile, or use platform features
  • Automatically: Through your use of our services via analytics and tracking technologies
  • From your employer: When they configure your account and input employee data
  • Through third-party integrations: From connected services your employer has authorized
  • Web-specific: Through cookies, web beacons, and similar tracking technologies
  • Mobile-specific: Through app analytics and device sensors (with permission)

3.3 Data We Don't Collect

We do not collect:

  • Health or medical information
  • Financial account information
  • Biometric data
  • Content of personal communications outside the platform

4. How We Use Your Information

We use collected data for the following purposes:

4.1 Platform Functionality

  • Web Application: Providing browser-based employee management features
  • Mobile App: Providing mobile app functionality and offline capabilities
  • Both Platforms:
    • Authenticating your account access
    • Syncing data across devices and platforms
    • Enabling communication between you and your employer

4.2 Analytics and Improvement

  • Web Application: Understanding website navigation and user behavior, including session replay (with inputs masked) to reproduce issues and improve usability
  • Mobile App: Identifying app crashes and performance issues
  • Both Platforms:
    • Analyzing feature usage and user engagement
    • Improving platform performance and user experience
    • Developing new features based on usage patterns

4.3 Communications

  • Web Application: Sending email notifications and updates
  • Mobile App: Sending push notifications and in-app messages
  • Both Platforms:
    • Providing customer support
    • Sending important security notifications
    • Product updates and announcements (with consent)

4.4 Security and Fraud Prevention

  • Protecting against unauthorized access
  • Detecting and preventing fraudulent activity
  • Ensuring data security and integrity

4.5 Legal Compliance

  • Complying with applicable laws and regulations
  • Responding to legal requests and court orders
  • Protecting our legal rights and interests

5. Data Sharing and Third Parties

5.1 We Share Data With:

Service Providers

We work with trusted third-party service providers who process data on our behalf:

  • Cloud infrastructure and database hosting: Secure storage, authentication, and serverless computing
  • Web hosting and content delivery: Application hosting and performance optimisation
  • Email services: Transactional and marketing email delivery
  • Payment processing: Subscription billing and secure payment handling
  • Push notification services: Mobile notification delivery for iOS and Android
  • Video hosting: Video upload, processing, and playback
  • AI services: AI-powered assistant features
  • Product analytics and session replay: Understanding product usage and improving the experience
  • Security services: Rate limiting and abuse prevention

All service providers are contractually required to:

  • Process data only as instructed by us
  • Implement appropriate security measures
  • Not use data for their own purposes
  • Delete data when our relationship ends

Advertising Platforms

If you enable Advertising cookies, we share Insight Tag data with LinkedIn to measure our campaigns and create anonymous retargeting audiences. For LinkedIn Marketing Solutions products, including the Insight Tag, website retargeting, and conversion tracking, LinkedIn acts as an independent controller under its Independent Controller Addendum. LinkedIn and its affiliates may use audience data to improve their services and for reporting and performance purposes, subject to LinkedIn's terms and member controls. See LinkedIn's Privacy Policy and Independent Controller Addendum.

Your Employer

As the Data Controller, your employer has access to:

  • Data they have configured in the system
  • Employee performance and usage metrics
  • Work-related communications and activities

Legal Requirements

We may share data when required by law:

  • Court orders or government requests
  • Legal compliance in jurisdictions where we operate
  • Protection of our legal rights or safety of users

5.2 We Don't Share Data For:

  • Advertising unrelated third-party products or services
  • Sale to data brokers
  • Purposes unrelated to providing our service

5.3 Third-Party Technologies

Web Application:

CategoryPurposeData Collected
Cloud infrastructureDatabase, authentication, file storageAccount data, application data
Web hostingApplication hosting and deliveryIP address, request logs
Payment processingSubscription billingBilling and payment data
CookiesSession management, preferencesUser preferences, session data
Product analytics & session replayUsage analytics, heatmaps, and session replay to improve the productPages viewed, clicks, device/browser, approximate location (from IP), session recordings with input values masked
Advertising measurementLinkedIn campaign measurement and retargeting, only after advertising consentPage URL, referrer, IP address, device/browser characteristics, timestamp, button and form-submission metadata

Mobile App:

CategoryPurposeData Collected
App framework and push notificationsMobile functionality and alertsDevice info, push tokens
Cloud infrastructureDatabase and authenticationAccount data, application data

Shared Services:

CategoryPurposeData Collected
AI servicesAI-powered assistantConversation content, context data
Email servicesTransactional emailEmail address, name
Video hostingVideo upload and playbackVideo content, playback data
Security servicesRate limitingIP address, request metadata

Each third-party service operates under its own privacy policy and data practices. Product analytics and session replay are provided by PostHog, with data stored in the EU. Advertising measurement and website retargeting are provided by LinkedIn through the Insight Tag, which loads only after advertising consent and only on explicitly approved public marketing pages. It never loads on authentication, signup, authenticated product, public playground, community, profile, consultant, legal, or other unreviewed pages. LinkedIn gives us aggregate reports and anonymous matched audiences, not the identities of individual website visitors. A full list of specific providers is available on request by contacting hello@yourpilla.com.

6. Data Security

We implement industry-standard security measures:

  • Encryption: Data is encrypted in transit (TLS 1.2+) and at rest (AES-256)
  • Access Controls: Role-based access with multi-factor authentication
  • Regular Audits: Security assessments and vulnerability testing
  • Secure Development: Code reviews and security-focused development practices
  • Incident Response: Procedures for detecting and responding to security breaches

7. Data Retention

We retain personal data only as long as necessary:

  • Active Account Data: While your employer's account is active and you are employed
  • Support Communications: 3 years after resolution
  • Food Safety Packs: Download links expire after 7 days. Expired PDFs are removed by daily cleanup. Request records, including your email address, quiz summary and delivery details, are scheduled for deletion after 90 days, once the PDF has been removed. Marketing subscriptions and unsubscribe preferences are managed separately.
  • Analytics Data: 26 months (anonymized after 14 months)
  • Session Recordings: Retained for 30 days, then automatically deleted
  • LinkedIn Insight Tag Data: LinkedIn removes direct identifiers within 7 days and deletes the remaining pseudonymised data within 180 days
  • Legal Compliance: As required by applicable laws (typically 7 years for employment records)

When data is no longer needed, it is securely deleted or anonymized.

8. Your Privacy Rights

Under applicable data protection laws (including UK GDPR), you have the following rights:

8.1 Right to Access Request a copy of personal data we hold about you.

8.2 Right to Rectification Request correction of inaccurate or incomplete data.

8.3 Right to Erasure Request deletion of your personal data (subject to legal requirements).

8.4 Right to Restrict Processing Request limitation of how we process your data.

8.5 Right to Data Portability Request transfer of your data in a machine-readable format.

8.6 Right to Object Object to processing based on legitimate interests.

8.7 Right to Withdraw Consent Withdraw consent for processing that requires it (this won't affect previous lawful processing).

To Exercise Your Rights: Contact your employer (as Data Controller) or our DPO at liam@yourpilla.com. We will respond within 30 days.

9. Platform-Specific Privacy Features

9.1 Web Application Privacy Features

  • Cookie Controls: Accept all, reject all optional cookies, or choose analytics and advertising separately. Reopen the controls at any time through Cookie settings in the website footer
  • Do Not Track: We respect browser Do Not Track signals
  • Data Downloads: Export your data through account settings
  • Browser Privacy: Compatible with private/incognito browsing modes

9.2 Mobile App Privacy Features

iOS Privacy Features

  • App Tracking Transparency: We request permission before tracking your activity across other apps
  • Privacy Labels: View our data practices in the App Store before downloading
  • Permission Requests: Clear explanations when requesting access to device features

Android Privacy Features

  • Data Safety: View our data practices in Google Play Store before downloading
  • Permission Controls: Granular control over what device features the app can access
  • Data Deletion: Request deletion of your data through in-app settings

9.3 Device Permissions (Mobile App Only)

Our mobile app may request the following device permissions:

PermissionPurposeRequired/Optional
CameraProfile photo uploadOptional
PhotosProfile photo selectionOptional
NotificationsApp alerts and updatesOptional
Location (Approximate)Timezone and regional settingsOptional
Location (Precise)Location-based featuresOptional

You can manage these permissions in your device settings at any time.

10. Children's Privacy

Our platform is not intended for children under 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16, we will take steps to delete such information promptly.

11. International Data Transfers

Your data may be processed outside the UK by our service providers. When data is transferred internationally, we ensure appropriate safeguards through:

  • Adequacy decisions by the UK government
  • Standard Contractual Clauses approved by UK authorities
  • Other legally approved transfer mechanisms

LinkedIn states that Insight Tag processing takes place on its servers in the United States. Its Data Processing Agreement and Independent Controller Addendum set out the applicable roles and international-transfer terms.

12. Cookies and Tracking Technologies

12.1 Web Application Cookies, Analytics and Advertising

How we use cookies and similar storage depends on which part of our site you're using:

  • Marketing website (approved public pages): By default we run cookieless analytics and heatmaps (provided by PostHog). Nothing is stored on your device and you are not identified. On your first visit we show controls for two optional categories. Analytics lets PostHog set first-party cookies so we can recognise repeat visits and measure how people move through the site. Advertising loads LinkedIn's Insight Tag on an explicit list of public marketing pages so we can measure campaigns and build anonymous audiences of LinkedIn member accounts that visited those pages. LinkedIn may then show our ads to those audiences. The Insight Tag collects the page URL, referrer, IP address, device and browser characteristics, timestamp, and limited website-action metadata such as button clicks and form submissions. We do not enable LinkedIn enhanced matching or deliberately send form-field values. Authentication, signup, authenticated product, public playground, community, profile, consultant, legal, and other unreviewed pages are excluded. If you reject a category or make no choice, its optional storage and tracking remain off. We remember your choices.
  • Product application (after you log in): We use cookies and session replay (a recording of on-screen interactions, with anything you type masked) to understand usage, reproduce issues, and improve the product. This forms part of providing the authenticated service; your employer (as Data Controller) is informed of this processing.
  • Interactive playground (public demo): Analytics cookies and session replay (with anything you type masked) run only if you accept Analytics. LinkedIn's Insight Tag never loads in the playground.
  • Community: LinkedIn's Insight Tag never loads on community pages.

Strictly Necessary Cookies (always used)

  • Authentication: Secure login and session management
  • Security: CSRF protection and security measures
  • Functionality: User preferences and settings

Strictly necessary cookies don't require consent. Analytics and advertising cookies are used only after you enable the relevant category. You can change or withdraw your choices at any time through Cookie settings in the website footer, and changes sync across open tabs. Withdrawing Advertising reloads the page so the LinkedIn tag stops immediately. Moving from an approved marketing page to an excluded page also opens a clean page so the LinkedIn tag does not carry across. We also honour browser "Do Not Track" signals for PostHog analytics.

12.2 Mobile App Technologies

Our mobile app uses minimal tracking technologies:

Essential Technologies

  • Authentication tokens for secure login
  • Session management for app functionality
  • Preference storage for user settings

Analytics Technologies

  • App analytics for usage insights (can be opted out)
  • Crash reporting for app stability (essential for security)

12.3 Your Tracking Choices

Web Application:

  • Reopen Cookie settings in the website footer to change or withdraw analytics and advertising consent
  • Disable cookies in browser settings
  • Use private/incognito browsing mode
  • Install ad blockers or privacy extensions

Mobile App:

  • Disable analytics in app settings
  • Control advertising tracking through device settings:
    • iOS: Settings > Privacy & Security > Tracking
    • Android: Settings > Privacy > Ads

12.4 Affiliate Referral Tracking

When you sign up for a paid Pilla subscription using a referral promo code at checkout, we record which code was used so we can pay commission to the affiliate who referred you and apply the corresponding discount to your subscription. We do not use cookies, tracking pixels, or any other tracking technology for affiliate attribution. The promo code you enter at checkout is the only signal we use. Our lawful basis for this processing is our legitimate interest in operating the affiliate program and paying affiliates accurately (UK GDPR Article 6(1)(f)). The affiliate receives commission statements that may include the date and amount of each charge to your subscription but do not include your name, email address, address, or other directly identifying information. Where an affiliate has only one referred customer, the affiliate may be able to infer your identity from the statement; we mitigate this by aggregating where possible. We retain the promo-code-to-affiliate mapping for as long as you remain a paying customer and for 7 years afterwards for tax and audit purposes.

13. Communications and Notifications

13.1 Web Application Communications

  • Email Notifications: Account updates, security alerts, and system notifications
  • In-Browser Notifications: Real-time updates while using the web application
  • Marketing Emails: Product updates and feature announcements (with consent)

13.2 Mobile App Notifications We send push notifications for:

  • Important work-related updates
  • App security notifications
  • Feature updates and announcements

13.3 Managing Communications

Web Application:

  • Update email preferences in account settings
  • Unsubscribe links in all marketing emails
  • Browser notification controls in browser settings

Mobile App:

  • Control notification types in app settings
  • Device notification settings:
    • iOS: Settings > Notifications > Pilla
    • Android: Settings > Apps > Pilla > Notifications

14. Data Deletion

You can request deletion of your data through:

14.1 Web Application

  1. Account settings page (self-service deletion options)
  2. Contact form on our website
  3. Emailing our DPO at liam@yourpilla.com

14.2 Mobile App

  1. In-app data deletion tools (if available)
  2. App settings menu
  3. Contacting support through in-app chat

14.3 General Deletion Process

  1. Contact your employer (primary data controller)
  2. Email our DPO directly at liam@yourpilla.com
  3. Submit a formal data subject access request

Note: Some data may be retained for legal compliance or legitimate business purposes as outlined in our retention policy.

15. Updates to This Privacy Policy

We may update this Privacy Policy to reflect:

  • Changes in our data practices
  • Legal or regulatory requirements
  • New platform features

When we make material changes:

  • We'll update the "Last Updated" date
  • Notify you through email, web notifications, or mobile app alerts
  • Request consent for significant changes affecting your rights
  • Post updates on our website and in app stores

16. Contact Information

For Privacy Questions:

  • Data Protection Officer: Liam Jones
  • Email: liam@yourpilla.com
  • Address: 86-90 Paul Street, London, EC2A 4NE

For Platform Support:

For Complaints: If you're not satisfied with our response to your privacy concerns, you can file a complaint with:

  • Information Commissioner's Office (ICO)
  • Phone: 0303 123 1113
  • Website: ico.org.uk

We process personal data under the following legal bases:

  • Contract Performance: To provide services requested by your employer
  • Legitimate Interests: For analytics, security, and service improvement
  • Legal Compliance: To meet employment and business legal requirements
  • Consent: For analytics cookies, LinkedIn advertising measurement and retargeting, marketing communications, and other optional features (where required)

This Privacy Policy is compliant with:

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018
  • Apple App Store Privacy Requirements
  • Google Play Store Privacy Requirements
  • ePrivacy Directive (Cookie Law)
  • California Consumer Privacy Act (CCPA) - if applicable

For questions about this Privacy Policy, please contact liam@yourpilla.com.