Back to Spike

Privacy Policy

Last updated: July 2026

1. Who is responsible

This Privacy Policy explains how ITALIK STUDIO LTD (“we”, “us”, “our”) processes personal data when you use Spike (the “Service”). We are the data controller for personal data we process to operate the Service.

Controller: ITALIK STUDIO LTD, company number 16135088, registered office: 167-169 Great Portland Street, London W1W5PF, United Kingdom. Contact: hello@spike.zip.

If you upload or share Content that contains other people's personal data, you may be an independent controller of that data. You are responsible for ensuring you have a lawful basis and any required notices or consents. When you sell Content, you (not us) are typically responsible for buyer relationship data you collect outside our checkout flow.

2. Information we collect

Depending on how you use the Service, we may process:

  • Account and profile data — such as email address, display name, avatar, authentication identifiers, and account settings.
  • Content and metadata — files and folders you upload, names, sizes, structure, previews, share settings, passwords you set (stored in protected form), licences, and similar metadata. Content may itself contain personal data if you include it.
  • Transaction data — purchase records, subscription status, plan, invoices/receipts metadata, payout status, and related identifiers. Card details are handled by our payment provider; we do not store full payment card numbers.
  • Usage and technical data — approximate location derived from network signals (such as country), device/browser type, timestamps, referrers, pages or share links viewed, download events, and security/diagnostic logs. Where we retain IP-related signals for abuse prevention or analytics, we may store them in hashed or truncated form.
  • Communications — messages you send via contact forms or email, and our replies.
  • Cookie and similar data — as described in our Cookie Policy.

We do not intentionally collect special-category data. Please do not upload sensitive data unless necessary and lawful.

3. How we use personal data

We use personal data to:

  • provide, operate, maintain, and improve the Service;
  • authenticate users and secure accounts;
  • store, deliver, share, and (where enabled) sell access to Content as you direct;
  • process payments, subscriptions, payouts, refunds, and fraud checks;
  • provide support and respond to requests;
  • monitor abuse, enforce our Terms, and protect rights, safety, and integrity of the Service;
  • comply with law, respond to lawful requests, and establish or defend legal claims;
  • produce aggregate or de-identified metrics to understand Service usage;
  • send service/transactional messages (for example sign-in links, receipts, security notices).

We do not sell personal data for money. We do not use your Content to train public generative AI models.

4. Legal bases (UK GDPR)

Where UK GDPR applies, we rely on one or more of:

  • Contract — to provide the Service you request (account, storage, sharing, paid plans).
  • Legitimate interests — security, fraud/abuse prevention, service improvement, enforcing Terms, and keeping the platform reliable, balanced against your rights.
  • Legal obligation — where law requires retention, disclosure, or other processing.
  • Consent — for optional cookies/analytics where required, and where we otherwise ask for consent. You may withdraw consent at any time without affecting prior lawful processing.

5. Sharing and disclosures

We may share personal data with:

  • Service providers (processors) — categories such as cloud hosting, object storage, content delivery, authentication/database, email delivery, error/uptime monitoring, and payment processing. They may process data only on our instructions and under appropriate contracts, except where they act as independent controllers (for example a payment provider for its own regulated purposes).
  • Other users — when you share or sell Content, recipients see what you make available (including profile or storefront details you choose to show).
  • Professional advisers and corporate transactions — lawyers, accountants, insurers, or parties to a merger, acquisition, or asset sale, under confidentiality where appropriate.
  • Authorities and rights holders — where required or permitted by law, or to protect rights, safety, and security (including child-safety and serious-crime reports).

For security and competitive reasons, we do not publish a full map of our infrastructure, vendors, or internal systems beyond what this Policy and applicable law require. You may request more information about processors relevant to your data by contacting us.

6. Storage, security, and no absolute guarantee

We use technical and organisational measures designed to protect personal data (such as encryption in transit, access controls, and provider-side protections). No method of transmission or storage is 100% secure. You use the Service at your own risk regarding residual security risk.

We will not publicly disclose detailed security architecture, penetration-test results, or internal controls except as required by law or under a suitable confidentiality arrangement.

7. Cookies and similar technologies

We use cookies and similar technologies (including local storage) for essential operation and, with consent where required, optional analytics. Details and controls are in our Cookie Policy. You can change non-essential choices via "Cookie settings" in the site footer.

8. Public sharing and your responsibility

If you set Content to public, share a link, or share a password, others may access and further copy that Content. We are not responsible for recipients' use or redistribution. Choose sharing settings carefully.

9. Retention

We retain personal data only as long as needed for the purposes above, including to provide the Service, resolve disputes, enforce agreements, maintain security, and meet legal/accounting obligations. Typical patterns:

  • Account and Content — while the account is active and for a short period after deletion from active systems (backups/caches may persist longer).
  • Billing and purchase records — for statutory retention periods.
  • Security, abuse, and enforcement logs — for as long as reasonably needed for safety and compliance.
  • Contact messages — for as long as needed to handle your request and follow up.

10. International transfers

Personal data may be processed in the UK, European Economic Area, United States, or other countries where our providers operate. Where required, we use appropriate safeguards (such as the UK International Data Transfer Agreement / Addendum, Standard Contractual Clauses, or an adequacy decision).

11. Your rights

Depending on applicable law, you may have rights to access, rectify, erase, restrict, or object to certain processing; to data portability; and to withdraw consent where processing is consent-based. To exercise rights, email hello@spike.zip. We may need to verify your identity and may refuse requests that are manifestly unfounded, excessive, or where an exemption applies.

UK users may complain to the Information Commissioner's Office (ICO) at ico.org.uk. We encourage you to contact us first so we can try to resolve concerns.

12. Children

The Service is not directed to children under 16. We do not knowingly collect personal data from children under 16. If you believe we have, contact us and we will take appropriate steps to delete it.

13. Automated decision-making

We do not use solely automated decision-making that produces legal or similarly significant effects about you without human involvement, other than routine fraud/security and eligibility checks that are necessary to provide the Service.

14. Changes

We may update this Privacy Policy from time to time. The “Last updated” date will change when we do. Material changes may be notified in-product or by email where appropriate. Continued use after the effective date means you acknowledge the updated Policy.

15. Contact

Privacy questions and data-subject requests: hello@spike.zip. Data controller: ITALIK STUDIO LTD, 167-169 Great Portland Street, London W1W5PF, United Kingdom, company number 16135088.

Privacy PolicyCookie PolicyTerms of ServiceContact