Breakthrough

Privacy & terms

What we collect, why, and what you’re agreeing to.

Breakthrough is built on real ink and real parcels. This page covers our privacy policy and our service terms together, in plain English, so you can read the whole thing in a few minutes rather than skim past it.

Last updated 19 August 2026

Who we are

Breakthrough is operated by Charlie Hollinrake, trading as Breakthrough and based in the United Kingdom. For anything to do with this policy — a question, a request, a complaint — email hello@charliehollinrake.co.uk. We’re small enough that a real person reads every email and replies personally.

What we collect

We only collect what we need to run a campaign or answer an enquiry. Three sources:

Enquiry & VIP form

Your name, email address, company, budget and whatever you write in the message field — nothing else. Used only to reply to you.

Orders, via Stripe

When you check out, card details go straight to Stripe — they never touch our servers, and we never see or store your full card number. We keep the order record itself: the product, the price paid, and the billing email Stripe passes back to us.

Prospect CSVs you upload

After ordering, you upload a list of the people you want us to post to — typically their names, job titles, and company (business) addresses. This is data about your prospects, not about you, and we only ever use it to fulfil your campaign. See “Your prospects’ data” below.

QR scans on parcels

Every parcel carries a printed QR code unique to the person it was posted to. If they scan it, we record which parcel it was and the time — and nothing else. See “The code on the parcel” below.

Why we’re allowed to use it

Under UK GDPR, we rely on two lawful bases, depending on what you’ve done:

  • Legitimate interest — for enquiry-form messages, so we can reply to someone who has asked us a question.
  • Contract — for orders and the prospect data you send us, so we can actually deliver the campaign you’ve paid for.

Where it’s stored

Everything we hold — enquiries, orders, uploaded lists — lives in Supabase, hosted in a UK/EU data centre (London). Payment is handled by Stripe, which stores card data on our behalf under its own PCI-DSS compliant systems — we never hold it ourselves. We don’t use any storage provider outside the UK/EU for your data.

Selling & marketing lists

We do not sell, rent or trade your data, or anyone’s prospect data, to any third party — ever. We don’t build a marketing list from enquiries or orders, and we don’t add you or your prospects to any newsletter or mailing list unless you explicitly ask us to. The only outside processors involved are the ones needed to run the service: Supabase (database), Stripe (payment) and Royal Mail / a courier (physical delivery of your order).

Your prospects’ data

When you upload a CSV of people you want us to post to, you are the data controller for that list and we act as your data processor. In practice that means:

  • You’re responsible for having a lawful basis to hold and share that data with us — for B2B outreach to named individuals at their work address, that’s usually legitimate interest, but it’s your call to make, not ours.
  • We only ever use the list to produce and post the campaign you ordered — never for our own marketing, and never shared with anyone else’s campaign.
  • Ask and we’ll delete an uploaded list — email hello@charliehollinrake.co.uk and we’ll confirm once it’s gone.

How long we keep it

  • Enquiry-form messages: kept while we’re in conversation, deleted on request or after a period of no contact.
  • Order records: kept for as long as UK tax law requires us to keep financial records (currently six years), because we have to.
  • Uploaded prospect lists: kept only for as long as it takes to fulfil your campaign, then deleted — sooner if you ask.
  • QR scan records: kept alongside the campaign they belong to, and deleted with it. Deleting a recipient deletes their scans in the same breath.

Your rights

Under UK GDPR you can ask us what we hold about you, ask us to correct it, or ask us to delete it. There’s no form or portal for this — just email hello@charliehollinrake.co.uk and we’ll deal with it directly, normally within a few days. If you’re ever unhappy with how we’ve handled your data, you can also complain to the Information Commissioner’s Office (ICO).

Postal campaigns

Everything we send is addressed to a named individual at a business address, as part of B2B sales outreach — not unsolicited consumer marketing to a home address. If a recipient asks not to be contacted again, tell us and we’ll make sure they’re removed from any future send.

The code on the parcel

Every parcel we post carries a printed QR code that is unique to the person it was addressed to. It is on the card, in plain sight, and scanning it is entirely the recipient’s choice. It opens a page that greets them by first name and says who sent the parcel and why.

When it is scanned, we record two things: which parcel the code belonged to, and the date and time. That lets the sender follow up like a human — ringing the people who actually opened the box, while it is still on the desk — instead of calling a whole list blind.

What we do not record: no cookies, no tracking pixels, no third-party analytics, no advertising tags, no IP address, no device or browser fingerprint, no location. There is no hidden mechanism anywhere in this — we do not track whether a letter was opened, and there is nothing to scan by accident. If the recipient never points a phone at the code, we learn nothing at all.

A scan is personal data, because it is tied to a named person. Our lawful basis is legitimate interests — confirming that a parcel somebody paid to have delivered actually arrived and was opened, which is the least intrusive way we can think of to find that out. Any recipient can email hello@charliehollinrake.co.uk and ask us what we hold, ask us to delete it, or object to it entirely, and we will do it.

Service terms

The short version of what you’re agreeing to when you order:

  • Prices are exactly as shown on the site — no hidden fees added at checkout.
  • No VAT is added — Breakthrough is not currently VAT registered, so the price you see is the price you pay.
  • Free resend on any item that fails to be delivered — we’ll send a replacement at no extra cost.
  • Dispatch SLA — we post within 5 working days of receiving both your list and your copy/message. The clock starts when we have everything we need, not when you check out.
  • Cancelling a shop order — email us any time before we start making it and you get a full refund, no questions. Nothing is sourced, handwritten or printed until your list is in, so in practice that is any point before you upload it. Once an order has been made and posted it can’t be refunded, but the free-resend guarantee above still applies to anything that fails to arrive.
  • Data processing agreement — for your prospect data we act as your processor and you remain the controller (see “Prospect data” above). If your legal or procurement team needs a signed DPA before you order, email us and we’ll send one over — there is no charge and it is not conditional on order size.
  • VIP cancellation — the VIP plan runs on a 30-day rolling basis. Cancel any time and it ends at the close of the current 30-day period, with nothing further billed.
  • No guaranteed replies or meetings — we guarantee the object is made properly and posted on time. Whether a recipient replies or books a meeting depends on your offer, your list and your follow-up, none of which we control, so we can’t promise a result.

Get in touch

Questions about any of this — privacy, an order, a cancellation — go to one place:

hello@charliehollinrake.co.uk

Prefer to browse first? See how it works or head to the shop.

free resend on failed delivery

dispatch SLA: posted within 5 working days of receiving your list & copy

tracked postage included