Demo mode — payments run on test credentials. Stripe card 4242 4242 4242 4242 or Razorpay test UPI.

Privacy Policy

Last updated October 3, 2026

This Privacy Policy describes how Basilico Simply Italian Limited (“we”, “us”), trading as BEA, collects, uses, and safeguards your personal data when you use BEA Type at https://beatype.co.uk. We process personal data in line with the UK GDPR and the Data Protection Act 2018.

Who we are (data controller)

The data controller is Basilico Simply Italian Limited, trading as BEA, registered in England & Wales. Our registered office is 41 Trinity Street, Dorchester, England, DT1 1TT. For any privacy question, or to exercise your rights, email privacy@beatype.co.uk.

Information we collect

You can use BEA Type anonymously: taking a typing test needs no account, and a guest result is stored without any identifier that ties it to you. We only collect personal data once you create an account or make a purchase.

We collect the minimum information needed to operate the service:

  • Account data — name, email address, and (for credentials login) a bcrypt-hashed password. We never store plaintext passwords.
  • Typing-test results — the text you typed, your WPM/accuracy score, test duration, and timestamp.
  • Certificate data — recipient name, WPM/accuracy, and issue date. This information appears on the public verification page so employers can confirm authenticity.
  • Payment metadata — gateway name, transaction ID, amount, currency, and status. Full card numbers and banking credentials are handled by our payment processors (Stripe, Razorpay) and never reach our servers.
  • Operational logs — IP address, user agent, and request path, retained for a short period for abuse detection and security monitoring.

How we use information, and our lawful basis

Under the UK GDPR we must have a lawful basis for each use of your data:

  • To run tests, issue and verify certificates, take payment, and send transactional emails (welcome, receipt, certificate ready, subscription notices) — performance of our contract with you.
  • To detect abuse, fraud and cheating, keep the service secure, and improve it — our legitimate interests in running a trustworthy service, balanced against your rights.
  • To keep payment and tax records — compliance with a legal obligation.
  • To send marketing emails, and to set non-essential (analytics / advertising) cookies — your consent, which you can withdraw at any time. For our own product updates and offers to existing customers we may also rely on our legitimate interests under the “soft opt-in”, always with a one-click opt-out.

Marketing emails

Separately from transactional emails (receipts, certificate notices), we may send marketing in three categories, each controlled in Settings → Emails:

  • Product updates and our own offers — first-party emails about BEA Type. You can opt in or out when you sign up and at any time afterwards.
  • Partner (third-party) offers — sent only if you explicitly opt in. This is off by default and we never add you to it without your clear consent.

Every marketing email carries an unsubscribe link, and turning a category off in your settings stops it. We do not sell your personal data.

Public verification

When a certificate is issued, its certificate number, recipient name, WPM, accuracy, duration, and issue date are made publicly accessible at https://beatype.co.uk/verify/{certificateNo}. This is the whole point of the product — so employers can independently verify the certificate is real. If you do not want this, do not purchase a certificate.

Third-party processors

We share data with the following processors only to the extent needed to provide the service. Each handles your data under its own contract and privacy terms:

  • Stripe, Razorpay — payment processing (PCI-DSS compliant).
  • Google — optional “Sign in with Google”, and AdSense advertising on free-tier pages (subject to Google’s own privacy terms).
  • Resend — transactional and (if you opt in) tips email delivery.
  • Cloudflare — DNS, CDN, DDoS protection, and object storage for certificate PDFs.
  • Sentry — error tracking (no request bodies are forwarded; only stack traces and request metadata).

Google user data (sign-in)

If you choose “Sign in with Google”, we receive basic profile information — your name and email address — to create or access your account. BEA Type’s use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

International transfers

Some of these processors are based outside the UK, so your data may be transferred abroad. Where it is, we rely on an appropriate safeguard — UK “adequacy” regulations where they apply, or the UK International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses) — so your data keeps an equivalent level of protection. You can ask us for details of the safeguard used for a specific transfer.

Cookies

We use a small number of strictly necessary cookies for sign-in, CSRF protection and remembering your consent choice. Analytics and advertising cookies are off until you opt in. Full details, and the controls to change your choice at any time, are in our Cookie Policy.

Data retention

  • Account data — retained while your account is active.
  • Typing-test results & certificates — retained while needed for public verification (certificates are a lasting credential).
  • Payment records — retained for at least 6 years to meet UK tax and accounting rules.
  • Server logs — rotated after 30 days.

Your rights

Under the UK GDPR you have the right to access your data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, to data portability, and to withdraw consent at any time (without affecting processing already carried out). To exercise any of these, email privacy@beatype.co.uk. We respond within one month.

Erasure has one limit: an issued or revoked certificate record cannot be deleted, because it is a public integrity record employers rely on — but the account behind it can be anonymised so it no longer identifies you.

If you are unhappy with how we handle your data you can complain to the Information Commissioner’s Office (ICO) at ico.org.uk, though we’d appreciate the chance to put things right first.

Children

Anyone can take a typing test as a guest, at any age — a guest result carries no personal data. Creating an account, however, requires you to be 13 or older: BEA Type is not directed at children under 13 and we do not knowingly collect their personal data. If you are under 18, please get a parent or guardian’s permission before creating an account.

Changes to this policy

We will update the “Last updated” date at the top of this page whenever this policy changes materially. For significant changes we will also email account holders.

Contact

Questions? Email privacy@beatype.co.uk.