Privacy notice
What UCP Sandbox collects, why, and what you can do about it. The short version: an email address if you make an account, the test data you send to test stores, and page-view counts with no cookies.
Last updated: 2 October 2026
1. Who is responsible
UCP Sandbox is a trading name of Pactmode Ltd, registered in England & Wales (company no. 17295877). Registered office: 2-5 Trade Tower, Coral Row, London SW11 3UF. We are the controller of the personal data described here.
2. What we collect
| What | When | Why |
|---|---|---|
| Your email address, name, and how you sign in (for GitHub: your GitHub account id and avatar address) | When you sign in to the console | To give you an account and keep your stores yours |
| The store copies, changes and experiments you make | When you use the console | To run the service you asked for |
| A log of requests to the test stores, both the public reference stores and your store copies: the time, which agent (the host of the profile it sent, or its user agent), which door, which call, what it asked for (the search text, the product ids, the test instrument paid with) and the store's answer as a status and an error code. Not buyer details, and not the rest of a request or reply. | When anyone, or any agent, calls a test store | On your copies, so you can read your experiment's results. On the public reference stores, so we can see how the service is used and fix what breaks |
| What is sent to a test checkout or booking: names, email addresses, phone numbers, delivery addresses, and the test payment instrument chosen | When a person or agent checks out on a test store | So the store can answer as a shop would. These should be made-up details. |
| Page views on the public pages: the page, the referrer, and the browser, device type and country worked out from the request | When you load a public page | To see which pages are used. No cookie is set and no profile of you is kept. |
| Server logs: IP address, time, the address requested | On every request | Security and fixing faults |
Test stores take test payment instruments only. Do not enter real card details or real people's personal data.
3. Cookies
One essential cookie keeps you signed in to the console and one protects its forms from forgery. Test stores set a session cookie so a bag or booking stays yours while you browse. There are no advertising or tracking cookies.
4. Our lawful bases
Running your account and stores: performance of our agreement with you. Page-view counts, server logs and request logs on the test stores: our legitimate interest in running, securing and improving a testing service, which involves little personal data.
5. Who else handles the data
Companies that run parts of the service for us, under contract:
- DigitalOcean (servers, in the United States)
- Cloudflare (network and security in front of the site)
- Mailgun (sending sign-in emails, from the EU)
- Umami (page-view counts)
- GitHub, if you choose to sign in with it (it tells us who you are; we send it nothing about your use of the Service)
Where data leaves the UK, it is covered by the safeguards UK law requires. We do not sell personal data.
6. How long we keep it
- Your account, store copies and experiments: until you delete your account, which you can do from the Account page.
- Test orders and bookings on the public reference stores: cleared regularly, normally every night.
- Request logs on the test stores (reference stores and copies): 90 days, or longer while an experiment that reads them is running. Test orders on store copies: until the copy or the account is removed.
- A store copy that nothing uses or changes for 90 days is archived: it stops answering, and you can restore or delete it from the console.
- Server logs: a short period, for security.
7. Your rights
You can ask for a copy of your personal data, ask us to correct or delete it, object to or restrict how we use it, and ask for it in a portable form. Use the contact form or write to [email protected]. You can also complain to the UK Information Commissioner's Office (ico.org.uk).
8. Changes
If we change what we collect or why, we will update this notice and its date.
See also the terms of use.