TRUST & TRANSPARENCY

Privacy & disclosures

How CHIRPCheck handles searches, corrections and evidence—and how to interpret the results.

Version 1.1 · Last updated 2 August 2026

How to read CHIRPCheck results

CHIRPCheck is a consumer-information and research tool. It helps identify merchants, organise public evidence and highlight possible payment, subscription, marketplace and digital-monetisation concerns.

Risk signals are indicators—not findings of guilt. A Red or Amber signal does not establish fraud, unlawfulness, dishonesty, prevalence or individual entitlement to a refund.

Results may be automated scans, provisional research profiles or practitioner-reviewed Deep Dives. These are different levels of research and are labelled separately.

Summary translates signals into everyday language. Full analysis shows the formal mechanism names, confidence, evidence links, limitations and coverage behind the same result.

  • Automated scan: a current, limited search of public material. It may be incomplete or contain an incorrect identity match.
  • Provisional research profile: preliminary structured research that has not completed the full practitioner-led Deep Dive process.
  • Practitioner-reviewed Deep Dive: a more extensive evidence review that has passed the applicable publication controls. It can still become outdated or require correction.

Checked, fetched and linked sources

CHIRPCheck may use merchant websites, company registers, app stores, public bodies, consumer organisations, news reporting, review platforms, forums and other publicly accessible material. Sources controlled by a merchant describe its own position; complaint and review sources describe reported experiences and do not establish how common an issue is.

A page that was fetched and analysed provides stronger source-local support than a search reference that was merely located. Evidence links are provided so you can inspect the material yourself. External pages can change, disappear or differ by country, account, device or date.

Prices, renewal terms, in-app purchases, cancellation routes and corporate relationships can change quickly. Check the live merchant journey before making a decision.

Important limitations

  • CHIRPCheck does not provide legal, financial, regulatory, investment or dispute advice.
  • It does not guarantee that a merchant is safe, unsafe, lawful or unlawful.
  • It does not verify every review, complaint, app mechanic, product or regional variation.
  • Complaint themes are qualitative signals and must not be read as prevalence estimates.
  • An absence of a signal may reflect missing evidence rather than an absence of risk.
  • You should do your own research and seek qualified advice where the decision or loss is significant.

Corrections and challenges

Users, merchants and other interested people can submit a correction from a result. Corrections are treated as reviewable claims, not automatic truth. They may be accepted, partly accepted or rejected after checking. A correction may improve future identity matching or evidence records once verified.

Do not submit card numbers, bank-account details, passwords, order references, private correspondence or information about another identifiable person.


Privacy notice

Who is responsible for the data?

CHIRPCheck is the controller for personal information collected directly through this service. Privacy enquiries, corrections and rights requests can be sent through the contact form below.

Contact CHIRPCheck

This form sends a private email to the project operator. Your name, email address and message are not shown publicly or added to the merchant research queue.

Maximum 500 words. Do not send card, bank-account, password or order details.0 / 500 words

Information we process

Merchant searches work without user accounts, names or email addresses. If you choose to use the private contact form, we also process the contact details and message you provide. Depending on how you use the service, we may process:

  • the merchant, app, game, website or statement descriptor you search;
  • a privacy-minimised search record, including the normalised query, matched entity, result status, broad search categories, source metadata and detected signal keys;
  • correction information you choose to submit, such as a suggested name, domain, evidence link and explanation;
  • an anonymous research-queue request, including the merchant and aggregate request count;
  • contact-form information you choose to provide, including your name, email address and message;
  • technical security and connection logs generated by hosting and infrastructure providers, which may include IP address, browser/device information, timestamps and request details.

The service attempts to remove email addresses and payment-card-length number strings from search and correction text, but automated redaction cannot be guaranteed. Please do not provide personal financial information.

Why we use it

  • to provide and cache merchant searches and research profiles;
  • to resolve aliases, domains, products and statement descriptors;
  • to review corrections and improve future matching;
  • to operate the human research queue and publish an aggregate merchant-request list without requester details;
  • to reply to private contact-form enquiries;
  • to protect the service, investigate failures and prevent misuse;
  • to maintain evidence, corrections and auditability where publication may be challenged.

Lawful basis

We rely primarily on legitimate interests in operating, securing and improving a public-interest consumer-information service, maintaining accurate evidence and responding to corrections. We balance those interests against privacy by avoiding accounts, minimising data, redacting common sensitive patterns and applying retention limits. We may also process information where necessary to comply with a legal obligation or establish, exercise or defend legal claims.

Automated processing

Automated systems may help classify a query, rank possible merchants, extract structured information and group evidence. They do not make decisions that have legal or similarly significant effects on you. Public results remain advisory and contestable.

Service providers and sharing

To operate the service, limited query or technical data may be processed by providers including Netlify (website hosting), Render and its database services (API hosting and storage), Brave Search (including public-web searches for indexed review and complaint pages), OpenAI (constrained classification or extraction where enabled), Companies House and other public-data sources. CHIRPCheck does not require Trustpilot Data Solutions. We may also disclose information where required by law, to protect rights and security, or to professional advisers under appropriate duties.

We do not sell personal information and do not use CHIRPCheck search records for behavioural advertising.

International processing

Some service providers operate internationally and may process information outside the UK. Where UK data-protection law requires it, transfers are handled using an applicable adequacy decision or contractual and organisational safeguards. Provider practices are also governed by their own privacy terms.

Retention

  • temporary scan cache: normally up to 30 days;
  • privacy-minimised search events: normally up to 180 days;
  • raw correction submissions: normally up to 365 days;
  • anonymous aggregate research requests: retained while needed to manage and explain the practitioner queue;
  • contact-form messages: delivered to the project mailbox and retained according to the mailbox and email-provider settings, or longer where needed for a rights request, correction, dispute or legal obligation;
  • verified aliases, entity relationships and published evidence records: retained while needed for accuracy, audit, correction history and public-interest research, then reviewed or superseded.

Infrastructure providers may keep security logs and backups for their own documented periods. Records may be kept longer where reasonably necessary for security, a dispute, legal compliance or the establishment, exercise or defence of legal claims.

Cookies and tracking

The current CHIRPCheck frontend does not set advertising or analytics cookies. Essential network, security or caching technologies may be used by hosting providers. If analytics or optional cookies are introduced, this notice and any required consent controls will be updated first.

Security

CHIRPCheck uses data minimisation, restricted database access, input redaction, bounded correction submissions, encrypted HTTPS connections and separation between public results and internal review records. No internet service can guarantee absolute security.

Your rights

Depending on the circumstances, you may have rights to access, rectify or erase personal information, restrict processing, object to processing, and complain about how your information is used. Because searches are designed to be anonymous, we may need a search-event, correction or queue reference to locate a record, and we may be unable to identify anonymous data as yours.

Your right to object: you can object to processing based on legitimate interests by using the private contact form above. We will consider the circumstances and any overriding legitimate or legal grounds.

You can also complain to the UK Information Commissioner’s Office. Details are available at ico.org.uk.

Changes to this notice

This notice may change as CHIRPCheck develops, providers change or legal requirements are updated. The version and date at the top show the current published notice.

Return to CHIRPCheck