Peregrine TermsFAQ Start a site

Privacy

Last updated 20 August 2026 · TGF Digital Ltd, United Kingdom

This describes exactly what Peregrine collects, why, and who else sees it. It is written to be read rather than to be defensible, so where something is a genuine limitation it says so.

The short version. We store enquiry details so we can reply, account details so you can sign in, and conversion statistics so the console can show you numbers. Images you upload to the demo are deleted before the response is sent. Card details never reach us at all — Stripe handles those.

Who we are

Peregrine is operated by TGF Digital Ltd, a company registered in England and Wales. Company number: registration in progress — this page is updated the day it is issued. Registered office: registration in progress — this page is updated the day it is issued. Not VAT registered, so no VAT is added to these prices. For anything on this page, including a request to see or delete your data, email tgf@xpose.online.

Controller or processor, depending on whose data it is

This distinction matters if you are an agency, because your client will ask about it.

  • For your details — the enquiry you sent, your account, your billing — we are the controller, and everything below describes what we do with them.
  • For what passes through the service on behalf of a site you look after — the image files, and on Dive the page requests and visitor IP addresses in the CDN logs — you are the controller and we are your processor. What we may do with those is set by you, and the Article 28 terms governing it are in the terms of service rather than a separate document to chase.

What we collect, and why

WhenWhatWhyKept
You send an enquiry Name, email, company, number of sites, the site you named, your message, your IP address, browser user agent and referring page To reply, and to work out what to quote. IP and user agent are kept because the form is public and they are what let us recognise abuse. Until you ask us to delete it
You measure a site The address you typed, and the sizes of the images on it To produce the report. The result is cached for 30 minutes so a shared link does not hammer the site being measured. 30 minutes, then gone
You upload an image to the demo The image itself To optimise it and show you the result Deleted before the response is written — it is never stored
You have an account Name, email, a hashed password, session cookie, and the sites on your account To let you sign in and see your own portfolio and nobody else’s While the account exists
You subscribe Stripe customer and subscription identifiers, plan, number of sites, amount To know what you are paying for. Card numbers never reach our servers — they go directly to Stripe. Six years, for UK accounting requirements
Your site serves images Counts and byte sizes of converted files, per day To show usage in the console and to bill correctly While the site is on the service

What we do not do

  • No advertising or tracking cookies. The only cookie we set is the session cookie in the console, and only once you sign in.
  • No analytics script on the marketing site.
  • We do not sell or share your details with anyone for marketing.
  • We do not read the content of the sites we deliver, beyond the image files themselves.

Who else processes it

These are the only third parties involved, and each one only receives what it needs. This table is the live sub-processor list: we give account holders 30 days’ notice by email before adding to it, so it is the page to check rather than a document to request.

WhoWhat they getWhere
Bunny.netThe image files we deliver on your behalf, and standard CDN request logsEU (storage in Germany or the UK, delivered worldwide)
StripeYour payment details, name and billing address, directly — not via usEU / US
MailgunThe contents of enquiry notifications sent to usEU
Google reCAPTCHA EnterpriseSignals from the forms on this site, to tell a person from a botEU / US
NetcupHosting for our serversGermany

Legal basis

  • Legitimate interests — replying to an enquiry you sent us, keeping the public tools from being abused, and running the service securely.
  • Contract — everything needed to provide the service you are paying for.
  • Legal obligation — keeping billing records for the required period.

Your rights

Under UK GDPR you can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Email tgf@xpose.online and we will do it within 30 days — usually the same week, because there is not very much of it. If you are unhappy with how we have handled that, you can complain to the Information Commissioner’s Office.

Security

Passwords are stored hashed, never in plain text. API keys are stored as hashes too, so a database dump does not hand anyone working keys for the sites we deliver. Credentials for third parties live in root-owned files on the servers, not in the applications that face the web — the console cannot reach the CDN account key even if it were compromised. Everything is served over HTTPS.

Changes

If this changes materially we will email account holders rather than quietly updating the date at the top.

This notice describes our actual practice accurately, but it has not been reviewed by a solicitor. If you need a warranty to that effect before signing something, say so and we will get it reviewed.

Peregrine · peregrinecdn.com · Terms · tgf@xpose.online

TGF Digital Ltd, a company registered in England and Wales. Company number: registration in progress — this page is updated the day it is issued. Registered office: registration in progress — this page is updated the day it is issued. Not VAT registered, so no VAT is added to these prices.