Last updated 7 September 2026
I'm Martin, a sole trader trading as ThermoLet, and I run this site and the ThermoLet service. For data protection law I'm the data controller for the personal data described here — meaning I decide what is collected and why, and I'm responsible for looking after it.
You can reach me about anything on this page at [email protected]. I answer these myself. My full name and a postal address for formal correspondence are available on request — email and ask, and I'll send them straight back.
This policy covers this website and the signup form in full, and summarises what the ThermoLet service processes once I've set you up. The service isn't generally available yet — I'm onboarding the first hosts personally — so the service section describes how it works today and I'll expand this policy as it grows.
This site sets no cookies and makes no third-party requests. There is no advertising pixel, no analytics script and no tracking of any kind. Fonts are served from this domain rather than Google's, specifically so that visiting the page doesn't tell anyone else you were here.
The only personal data I collect is what you deliberately type into the signup form, and I only collect it because you ticked the box.
The signup form asks for the following. Only the first two are required; leave any of the rest blank and nothing is stored for them.
| What | Why I ask |
|---|---|
| First name | So I can write to you like a person |
| Email address | To arrange your setup — this is the only way I contact you |
| Heating type | To know whether ThermoLet suits your property before we spend time on a call |
| Thermostat make | To check I support it — right now that means Hive |
| Number of properties | To plan how long your setup will take |
| Booking platform | To check I can read your calendar feed |
| Town | To gauge where hosts are and which timezone you're in |
| Best time to call | So I don't ring at a useless hour |
The form also has a hidden field that people never see. If it's filled in, the submission came from a bot and is discarded without being stored. It's a spam trap, not a tracker.
Consent. The tick box on the form is not pre-ticked and the form won't submit without it, so nothing is stored unless you actively opted in. You can withdraw that consent at any time and I'll delete your details — see your rights below.
I email you to arrange a setup call, and I use the answers to prepare for it. That's all. I don't sell your details, share them for marketing, or add you to anything you didn't ask for.
Two companies handle your signup data on my behalf. Both are processors, which means they act on my instructions and can't use your data for their own purposes. The service you'd use as a host runs somewhere else again — covered below.
Your signup goes to Brevo (Sendinblue SAS, 17 rue Salneuve, 75017 Paris, France), which stores the contact list and sends the emails. Brevo is a French company operating under the GDPR and states that contact data is held in European data centres, so your details aren't transferred outside Europe.
This site is hosted on Cloudflare Pages. Like any web host, Cloudflare processes your IP address and basic request information in order to serve the page and to block attacks. I haven't enabled any Cloudflare analytics product, and I don't have access to a log of who visited.
This site sets no cookies. There is no consent banner because there is nothing to consent to. If that ever changes — if I add analytics or an advertising pixel — I'll ask you first, properly, and refusing will be as easy as accepting.
Under UK data protection law you can ask me to:
Email [email protected] and I'll action it. There's no charge, and I'll respond within one month. I'm a one-person business, so it'll usually be a lot faster than that.
If you think I've handled your data badly, please tell me first and I'll try to put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk, without going through me at all.
This section applies once you're a host and I've set your property up. It's here so you know what you'd be agreeing to before you get on a call with me.
To link your bookings to your heating, ThermoLet reads:
I don't store anything about your guests. ThermoLet takes three things from a calendar feed: the booking's reference, when it starts, and when it ends. Never a name, and never payment information — no feed carries those.
Airbnb's feed does put two extra details in each booking: a link to the reservation, and the last four digits of the guest's phone number. ThermoLet ignores both. They are not read, not saved, and there is nowhere in the database they could go. I have no way to identify who is staying in your property, and I don't want it.
Connecting your thermostat uses OAuth, which means you authorise ThermoLet through your thermostat provider's own login. I never see or store your thermostat account password — only a token, which is encrypted in the database rather than held in plain text, and which you can revoke from your provider's app at any time. Revoking it immediately stops ThermoLet controlling anything.
Your thermostat provider (currently Hive, via SmartThings) is a separate company with its own privacy policy governing the account you already have with them. I send commands to it and read the state back; I don't change your relationship with them.
Every command sent to your thermostat is written to a log: what was sent, when, why, and whether the thermostat accepted it. It's what lets me answer "why was the heating off on Tuesday?" — for you, and for me when something misbehaves. It records your property's heating, not any person.
The ThermoLet service and its database run on Railway (Railway Corporation, 548 Market St PMB 68956, San Francisco, California 94104), in its EU West region — your data is stored in Amsterdam, in the Netherlands. The UK treats the EU as offering equivalent protection, so your data being there changes nothing about the rights you have over it.
Railway itself is a US company, so its staff can in principle reach the infrastructure from outside Europe while running and supporting it. My contract with Railway covers that using the standard clauses UK law provides for exactly this, including the UK addendum.
This is separate from the marketing site above, which is on Cloudflare Pages. Nothing about your property or your bookings goes anywhere near Brevo — that holds signup enquiries only.
If I change anything meaningful I'll update the date at the top, and if it affects how I use data you've already given me, I'll email you rather than quietly editing the page.
← Back to the main page