Privacy Policy
Last updated: 18 August 2026
This Privacy Policy describes how Akrolimb Ltd (“Akrolimb”, “we”, “us” or “our”) collects, uses, stores and discloses your personal information when you visit or make a purchase from www.akrolimb.com (the “Site”), use our AkroScan iPhone application (the “App”), or otherwise communicate with us (collectively, the “Services”). For the purposes of this Privacy Policy, “you” and “your” means you as the user of the Services, whether you are a customer, a website visitor, or another individual whose information we have collected under this Privacy Policy.
Please read this Privacy Policy carefully. It explains what we collect, why we collect it, how long we keep it, and the rights you have over it. By using any of the Services, you acknowledge that we will handle your personal information as described in this Privacy Policy.
1. Who we are
Akrolimb Ltd operates the Site and the App and is the data controller of your personal information. Akrolimb Ltd is registered in England and Wales under company number 17066080. Our registered office address is recorded on the public register at Companies House under that company number and is available from us on request.
We are preparing to deliver to India. When we do, orders delivered to India will be sold by our group company, Akrolimb Private Limited (CIN U32506GJ2025PTC171426), registered in India, which will act as a joint controller of the order information for those orders.
For any question about this Privacy Policy, including access and deletion requests, you can contact us at support@akrolimb.com or through our support page.
2. Changes to this Privacy Policy
We may update this Privacy Policy from time to time, including to reflect changes to our practices or for operational, legal, or regulatory reasons. We will post the revised version on this page, update the “Last updated” date above, and take any further steps required by applicable law.
3. Personal information we collect
What we collect depends on how you use the Services.
When you scan with the App, we collect your email address, the 3D scans of the feet you choose to send, and, if you are scanning for someone else, the name you enter for them so that their insoles match their feet. Scanning requires no account and no payment details.
When you order insoles, we collect your name, email address, delivery address, phone number (used for delivery), shoe size and order history, together with anything you send us in reviews, scan feedback, or support and refund requests. Payment is handled entirely by our payment processor, Stripe. Your card details are sent directly to Stripe and never reach our servers; we see only that payment succeeded and the card digits Stripe shows us.
When you create an account, we collect your sign-in email address and password, which we store only as a salted hash, together with the scans and foot information you choose to save to the account.
When you book a call, request a demo, or message us, we collect your name, email address, and your message, so that we can hold your slot or reply to you. Video consultations are hosted on Microsoft Teams.
When you simply browse the Site, we collect almost nothing. We run no analytics and no advertising trackers. Our servers process your IP address transiently to protect the Services against abuse through rate limiting, and our security logs record sign-ins and other sensitive actions.
4. The App and your foot scans
The App uses Apple's TrueDepth camera (the Face ID sensor on the front of the phone) to capture a three-dimensional model of the shape of your feet. The camera runs only while you are scanning. It produces temporary depth data that is converted into a foot mesh on your phone; no facial data is captured or stored, and when you scan your own feet the App takes no photographs. When you press send, the mesh is transmitted to us over an encrypted connection together with the email address you entered and, if you are scanning for someone else, the name you entered for them. Nothing else is uploaded.
The App also has a clinic mode, used by clinicians during a supervised fitting. There, in addition to the 3D scan, the clinician may take reference photos of the patient's feet and record fitting details; those photos and details are uploaded to the patient's clinical record, are retained for up to 24 months and then deleted, and the patient can ask for earlier deletion at any time. The consent wording used for clinician-captured data is published in our Terms & Conditions.
We use your scans for one purpose: designing and making your insoles. A scan is a three-dimensional measurement of the shape of your feet, in the way a tailor measures for a garment: we use it to make a product that fits, we do not analyse it for information about your health, and we draw no conclusions about your health from it. We do not use scans to identify you, do not sell them, and do not use them for advertising, marketing, or data mining, and nor may anyone we share them with. The App links this Privacy Policy on the send screen, and by sending your scans you agree to our Terms & Conditions, which incorporate this Privacy Policy.
On your phone, the App reads the motion sensors during capture only, to detect the phone being bumped or moved mid-scan and to help you hold it steady and level, including when reference photos are taken in clinic mode; motion data never leaves your phone. The App keeps your latest scan of each foot in its own private storage on your phone, so that a crash or a closed app cannot lose them; each file is replaced when you rescan that foot, and all of them are removed when you delete the App.
The App stores in the iPhone's encrypted Keychain the email address you last sent scans with, your sign-in session if you sign in, and a small index of your latest scans. Signing out clears your session. You should be aware that Apple's Keychain can retain its entries even after the App itself is deleted.
The App contains no analytics, advertising, crash-reporting, or tracking libraries of any kind. On launch it asks the update service of Expo, the framework the App is built on, whether newer app code is available; this standard update check carries no scans and no personal details.
Once your scans reach us, what happens next depends on whether you order. If you do not order, unclaimed scans are deleted automatically 7 days after your latest scan, files included. While your scans remain unclaimed, you can also delete them sooner yourself, using the delete option on the App's confirmation screen, or by emailing support@akrolimb.com. If the email address you scanned with belongs to an Akrolimb account, your scans are saved to that account instead. If you order, or save scans to an account, your scan stays on file so that future pairs can be designed without re-scanning. You can ask us to delete your scans at any time: scans not yet used to design a pair can be deleted directly from your account's foot page once no order is being made from them, and scans already used to design a pair are deleted for you by our support team on request, so the record of what we made for you stays intact until you ask. We cannot design, make, or remake your insoles without a scan.
5. How we use your personal information
We use your personal information to make and deliver your order: designing from your scan, printing, shipping, and sending the emails that keep you informed about your order's progress. The lawful basis for this processing is the performance of our contract with you. We process the foot scans you send from the App on the same basis: they are necessary to design and make the insoles you are asking us for, and, where you scan before ordering, they are the steps you ask us to take ahead of entering into that contract. We rely on our legitimate interests to keep the Services secure (rate limiting and security logging), to answer your messages, and to improve our design and manufacturing from order outcomes. We keep order and payment records to comply with our legal obligations under tax and accounting law.
We do not run marketing email lists, and we never sell, rent, or share your personal information with anyone for their own marketing. The emails you receive from us concern your scans, your order, or your account. The email sent after you first send scans simply confirms that they arrived and explains how ordering works. Two kinds of email carry an offer, and both are sent only on request: if you ask for a first-order discount code on the Site, we send that code (or a note that the offer is for first orders only) to the address you enter; and, if you use our refer-a-friend feature, we send a one-off invitation to the friend's address you give us, naming you as the referrer. We only send a discount code to an address that asked for one, we only ever email a friend at an address you enter yourself, and deleting your scans stops any further scan emails.
6. How long we keep your information
Unclaimed scans, where you scanned but did not order, are deleted automatically once the 7-day window after your latest scan has passed. Scans connected to an order or saved to an account are kept so that future pairs fit without re-scanning, until you delete them or ask us to. Security and audit logs are kept for 12 months and then deleted automatically. Order and payment records are kept for as long as tax and accounting law requires, typically six years, and then deleted.
7. Who we share your information with
We share personal information only with the service providers that make the Services work, each under a data processing agreement, and each receiving only what it needs:
- Stripe, our payment processor. Your card details go directly to Stripe and never to us.
- Microsoft Azure, which provides our hosting, our database, and encrypted private file storage for your scans and any photos you add to a review.
- Microsoft Azure Communication Services, which sends our transactional emails, such as order confirmations and scan-received notices. Resend, the provider we previously sent from, remains configured as a fallback sender while we complete the move.
- Upstash, which operates the rate limiter protecting our public endpoints from abuse and briefly processes request identifiers such as your email address or IP address.
- Microsoft Teams, if you book a video consultation, to create and host your meeting link.
Beyond these providers, we disclose personal information only to public authorities where the law genuinely requires it. We never share your personal information with anyone for advertising.
8. International transfers
We are a UK company. Your scans and order records are stored with Microsoft Azure, and our transactional emails are sent through Microsoft Azure Communication Services, in the United Kingdom. Some of our providers, such as Stripe, Upstash, and Resend (our fallback email sender), may process data outside the UK. Where they do, we rely on safeguards recognised under UK law, such as adequacy decisions or the UK International Data Transfer Addendum to the standard contractual clauses. Once we begin delivering to India, order information for Indian deliveries will be shared with Akrolimb Private Limited in India to fulfil your order, under the same safeguards.
9. Cookies
The Site has no cookie banner because we use no analytics, advertising, or tracking cookies. We set only two kinds of cookie. Sign-in and security cookies keep you signed in to your account or dashboard and protect our forms against cross-site request forgery; they are set by our authentication system and are essential to how the Site works. A single preference cookie, akro_audience, remembers which version of the Site you chose so that return visits open the right one; it is set only when you make that choice, lasts 180 days, and contains that one choice and nothing else. Your light or dark theme preference is stored in your browser's local storage and is never sent to us.
10. Security
All data travels over encrypted connections (TLS), and files are held in private, access-controlled storage that is never public. Access within Akrolimb is role-based, so staff see only what their role requires, and sensitive administrative actions are recorded in an audit log. Passwords are stored only as salted hashes, and payment details never touch our systems. Our public endpoints are rate limited, and location and device metadata is stripped from photos on upload.
11. Your rights
Under the UK GDPR and the Data Protection Act 2018, you have the right to:
- access a copy of the personal information we hold about you;
- correct anything that is inaccurate or incomplete;
- have your personal information deleted, subject only to records the law requires us to keep;
- restrict or object to our processing of your personal information;
- receive your personal information in a portable format;
- withdraw any consent at any time, without affecting processing that happened before.
To exercise any of these rights, email support@akrolimb.com. We will respond within one month. Deletion works as described in Sections 4 and 6: unclaimed scans can be deleted from the App's confirmation screen (and delete themselves after 7 days in any case), account scans can be deleted from your account's foot page or by asking support as Section 4 describes, and one email covers everything else.
If you are unhappy with how we handle your personal information, we would appreciate the chance to put it right first; our support page explains how complaints are handled. You also have the right to complain at any time to the UK Information Commissioner's Office at ico.org.uk. If you are in India, you also keep any rights your local data protection law gives you.
12. Children
The Site, the App, and our products are intended for adults. If insoles are for someone under 18, a parent or guardian should place the order and manage the scans.
13. How to contact us
Questions about this Privacy Policy or about your personal information can be sent to support@akrolimb.com, or through our support page. Akrolimb Ltd is registered in England and Wales under company number 17066080.