Privacy policy
Last updated: 9 September 2026
In August 2026 Grant Tracker became Shoots. This is a change of name only; nothing about how we handle your data changed.
This privacy policy explains how Shoots collects, uses, and protects your personal data. Shoots is operated by Paul Kilty as a sole trader, based in Brighton, United Kingdom.
If you have any questions about this policy or how we handle your data, please email hello@shootsfunding.co.uk.
Who we are
Shoots is a service that helps UK charities, community interest companies, social enterprises, co-operatives, and impact-focused organisations discover and manage funding opportunities.
For the purposes of UK data protection law, the data controller is:
Paul Kilty, sole trader, trading as Shoots (formerly Grant Tracker)
Email: hello@shootsfunding.co.uk
What data we collect
We collect the following categories of personal data:
Account data. When you create an account, we collect your first name, organisation name, email address, and an encrypted version of your password.
Profile data. When you complete your organisation profile, you may provide additional information including your organisation type, sectors and beneficiaries you serve, geographic focus, and information about your funding history. This data is used to match you with relevant funding opportunities.
Payment and subscription data. If you subscribe, our payment provider Stripe collects your card details directly. We never see or store your full card number. We store your plan, billing period, subscription status and dates, the Stripe customer and subscription identifiers, and a record of each payment.
Waitlist and enquiry data. If you join a waitlist, contact us, or send feedback through the service, we keep the details you provide, including your email address and message.
Application data. If you applied to join the founding cohort, we collected the responses you provided on the application form, including your contact details and the information you shared about your organisation and fundraising context.
Usage data. We collect aggregate, anonymised data about how the service is used, such as which pages are visited and which features are most useful. We use this to improve the service. We do not use this data to identify individual users.
Activity data. We record the actions you take in the service against your organisation's profile: the searches you run, the opportunities you view, save, or dismiss, changes to your funding pipeline, updates to your profile, and your use of application-building features. See “How your activity builds your organisation's profile” below for what this is used for and the promises that come with it.
Communications data. If you email us or respond to our messages, we keep a record of the correspondence.
We do not knowingly collect data from children, and the service is not directed at people under 18.
How we use your data
We use your personal data for the following purposes:
To provide the service. This includes creating and managing your account, matching you with funding opportunities based on your profile, storing the opportunities you save and the funding pipeline you build, and running the application tools you use.
To take payment and manage your subscription. This includes starting and ending your trial, processing payments through Stripe, sending receipts, and telling you about failed payments, renewals, and price changes.
To communicate with you. This includes responding to your questions, sending service emails about your account and subscription, and sending our regular funding newsletter and occasional product updates. Every newsletter and update carries an unsubscribe link, and service emails about your account and payments are sent whether or not you receive the newsletter. If you are a founding cohort member, we may also contact you for cohort check-ins.
To improve the service. We use anonymised usage data to understand which features are working and where the product needs to improve.
To comply with our legal obligations. This includes responding to lawful requests from regulators and authorities, and maintaining records where required by law.
How your activity builds your organisation's profile
Everything you do in Shoots builds a picture of your organisation and what it is looking for. We record activity such as the searches you run, the opportunities you view, save, or dismiss, the funding pipeline you build and update, and your use of application-building features. When you connect an AI agent through our MCP server, the queries it makes on your behalf are recorded in the same way.
We use this activity data for three things:
- To improve how we match your organisation with relevant funding.
- To personalise the service to your organisation over time.
- To produce aggregate, anonymised insights about the UK funding landscape, such as where demand outstrips available funding. These insights never identify your organisation, and we never share one organisation's specifics with another.
The lawful basis for this processing is legitimate interests: improving the product and personalising it for you. We have considered the impact on you and believe this is proportionate. You can object at any time by emailing us.
Retention. Activity data is kept while your account is active. If you close your account, it is deleted or anonymised within 30 days, in line with the rest of your data.
The promise that comes with it. The profile your activity builds is yours. It persists beyond beta, and you can export your organisation's data as JSON at any time from your account page. We never log your passwords or private correspondence in activity data, and free-text content is limited to what you typed as a search query.
Legal basis for processing
Under UK GDPR, we rely on the following legal bases:
Contract. Most of our processing is necessary to provide the service you have signed up for. This covers account management, profile data, the core matching and tracking functions, the AI-assisted features you choose to use, and taking payment for your subscription.
Legitimate interests. We rely on legitimate interests for activities such as improving the service, responding to your enquiries, and contacting cohort members for feedback. We have considered the impact on you and believe these uses are proportionate.
Consent. Where you have given consent, for example to receive marketing communications or to allow analytics cookies, we rely on that consent. You can withdraw consent at any time.
Legal obligation. Where we are required by law to retain or disclose data, we rely on that legal obligation.
Who we share your data with
We share your data only with the following categories of recipient, and only as necessary:
Service providers. We use trusted third-party providers to run the service. These are:
- Supabase stores your account data, profile data, and pipeline data. Supabase is a data processor acting on our instructions. Their privacy policy is at supabase.com/privacy.
- Vercel hosts the website and processes the technical requests needed to load pages. Vercel acts as a data processor. Their privacy policy is at vercel.com/legal/privacy-policy.
- Stripe processes payments and holds your card details. Stripe acts as an independent controller for the payment data it collects, under its own privacy policy at stripe.com/gb/privacy.
- Anthropic provides the AI models behind features such as matched search, the application tools, and the adviser. When you use one of these features, the text needed for that request, such as your organisation profile, your project description, or your draft, is sent to Anthropic's API to generate a response. Anthropic acts as a data processor and does not use API data to train its models. Their privacy policy is at anthropic.com/privacy.
- Resend delivers the emails we send you, including receipts, account emails, and the newsletter. Resend acts as a data processor. Their privacy policy is at resend.com/legal/privacy-policy.
- Upstash provides the rate-limit counters used by our MCP server (see “MCP, OAuth, and API access” below). Upstash stores short-lived per-IP and per-key request counts; no profile or pipeline data is sent to Upstash. Their privacy policy is at upstash.com/privacy.
We do not sell your personal data to anyone. We do not share your organisation's data with funders, other organisations, or third parties without your explicit permission.
Legal disclosures. We may disclose your data if required by law, court order, or to protect our legal rights, but only to the extent necessary.
MCP, OAuth, and API access
Shoots operates a Model Context Protocol (MCP) server at www.shootsfunding.co.uk/api/mcp/v1/mcp. The MCP lets AI agents, including Claude, ChatGPT, Gemini, and any other MCP-compatible client, use Shoots on your behalf, so that an agent you already work with can answer your funding questions. Connecting an AI agent is opt-in.
All connected accounts can read from our funding catalogue through the MCP. On the Apply plan and above, a connected agent can also make changes on your behalf, limited to your own organisation's data: adding opportunities to your pipeline, updating their stage, and setting your funding goal and what it is for. On the Match plan the connection reads only. An agent can never read or change another organisation's data, and it can only do what your plan allows.
You connect by completing the OAuth 2.0 consent flow that an MCP-compatible client initiates when it adds Shoots as a connector. The client registers itself with us automatically using standard MCP registration mechanisms. If you do not yet have a Shoots account, you can create one during the connection flow; the account data we collect is the same as described in “What data we collect” above.
What we store when you connect. When you complete the OAuth flow, we store the registration record for the AI client, the access and refresh tokens issued to that client, the user identifier the client is acting on behalf of, and a record of your consent. We do not store your AI-client conversation history or anything else from inside the agent.
What we log when the MCP is used. When an AI agent makes a request to the MCP on your behalf, we may log the tool that was called, the parameters passed (for example, search filters or opportunity IDs), the authentication identifier on the request (the OAuth client and user ID), the source IP address, the response status, and the response time. We use these logs to operate rate limiting, to debug issues, and to measure service quality. They are not shared with the AI client and are not used to identify individuals beyond the authentication identifier already on the request.
Third-party AI clients. The AI client you use to connect to Shoots (for example, Claude operated by Anthropic) is a separate company with its own privacy policy and its own handling of your conversation history. When the client calls Shoots via MCP, the responses we return are passed back into that client's context. We have no control over how the client stores, retains, or further processes that data; that relationship is between you and the client. Before connecting, you should be comfortable with the AI client's privacy practices for the content of your queries and our responses.
Revoking access. To revoke a connection, disconnect Shoots from inside the AI client you connected through; revocation is enforced on the next request. After revocation, retention follows the rules in “How long we keep your data” below.
Where your data is stored
Our service providers operate data centres in the United Kingdom, the European Union, and the United States. Where data is transferred outside the UK, the providers we use rely on appropriate safeguards such as Standard Contractual Clauses or UK Adequacy Decisions to ensure your data remains protected to UK GDPR standards.
How long we keep your data
We keep your account and profile data for as long as your account is active. If you close your account, we will delete or anonymise your personal data within 30 days, except where we are required by law to keep it for longer.
If your subscription or trial ends without a new subscription, we keep your account, profile, saved opportunities and pipeline so that you can return. If an account stays without a subscription for 12 months, we may close it after notice by email, and the 30-day deletion rule above then applies.
Payment records are kept for six years after the payment, as UK tax law requires.
Waitlist entries are deleted within 30 days of you asking to be removed. Application data from people who applied to the founding cohort but were not accepted is kept for up to 12 months and then deleted.
Email correspondence is kept for up to 24 months unless there is a specific reason to retain it longer.
OAuth client and token records are kept for as long as the connection is active. After you disconnect an OAuth client, we keep the record for a further 12 months for fraud-prevention and rate-limit-consistency purposes, and then delete it. MCP request logs are kept for up to 12 months and then deleted or anonymised.
Cookies and analytics
We use a small number of essential cookies that are necessary for the service to work, such as remembering that you are signed in.
We use Umami, a privacy-respecting analytics tool, to understand how the service is used in aggregate. Umami does not set cookies and does not identify individual visitors, which is why we do not show a cookie banner. If we ever add a tool that sets non-essential cookies, we will ask for your consent first.
We do not use advertising cookies, third-party trackers, or session recording tools.
Your rights
Under UK GDPR, you have the following rights in relation to your personal data:
The right to be informed about how we use your data, which is the purpose of this policy.
The right of access. You can ask us for a copy of the personal data we hold about you.
The right to rectification. You can ask us to correct inaccurate or incomplete data.
The right to erasure. You can ask us to delete your data, subject to certain exceptions.
The right to restrict processing. You can ask us to limit how we use your data.
The right to data portability. You can ask us to provide your data in a portable format.
The right to object. You can object to processing based on legitimate interests.
The right to withdraw consent at any time, where we are relying on consent.
To exercise any of these rights, please email hello@shootsfunding.co.uk. We will respond within one month.
If you are not satisfied with how we have handled your data, you have the right to complain to the Information Commissioner's Office (ICO), the UK data protection regulator. You can contact them at ico.org.uk or on 0303 123 1113.
Changes to this policy
We may update this policy from time to time. If we make significant changes, we will let you know by email or through a notice on the service. The “last updated” date at the top of this page will always show when the policy was last changed.
Contact us
If you have any questions about this privacy policy or how we handle your data, please email hello@shootsfunding.co.uk.