This notice explains how FadeFoundry handles personal information when someone visits fadefoundry.co.uk, sends an enquiry, buys a service, works with us on a website or receives relevant business-to-business marketing from us.
1. Controller and contact details
The controller is Connor Morgan, trading as FadeFoundry, of 37 Deri Avenue, Pencoed, CF35 6TT. Contact: admin@fadefoundry.co.uk.
2. Information we collect
- Enquiry and identity details: name, business or shop name, role, email, phone number and the content of messages.
- Project information: services, prices, opening hours, location, booking links, social profiles, photographs, branding, feedback and approvals.
- Contract and payment information: order, subscription, invoices, payment status and limited transaction details. Stripe processes card and bank details; we do not receive or store full card numbers.
- Technical information: internet address, browser, device, timestamps, requested pages, security events and ordinary server logs collected by our hosting and form providers.
- Public business and prospect information: a business name, company status, business contact details, location, website status and information visible on a website, social profile, booking page, Companies House record or public business listing where relevant to an enquiry, project or carefully targeted business outreach.
3. How we obtain it
We receive information from the person who contacts or buys from us, their colleagues, the website contact form, email, Stripe checkout, project conversations, and relevant public sources such as a business website, booking page, social profile, Companies House or a public business directory. Our technical suppliers generate ordinary security and access records when the site or checkout is used.
4. What we use it for and our lawful bases
- To answer enquiries, assess fit, prepare a concept or quote, form and perform a contract, take payment, build and maintain a website — necessary for a contract or steps requested before one.
- To run, secure, troubleshoot and improve the service, prevent misuse, keep business records and communicate with business contacts — our legitimate interests in operating a safe and effective small business.
- To keep tax, accounting, complaint and legal records and respond to lawful requests — compliance with legal obligations and, where relevant, our legitimate interests.
- To send relevant, proportionate business-to-business marketing to corporate bodies where permitted by the Privacy and Electronic Communications Regulations, relying on our legitimate interests in introducing our barber-website service to suitable businesses. We do not send unsolicited electronic marketing to sole traders or individual subscribers unless we have consent or another applicable permission.
- To manage opt-outs and maintain a minimal suppression record so that we do not contact someone again after they object — compliance with electronic-marketing rules and our legitimate interests in respecting preferences.
- To establish, exercise or defend legal claims where necessary — our legitimate interests and applicable legal provisions.
5. Who receives information
We share only what is reasonably needed with suppliers that help deliver the service, including:
- Netlify for public website hosting and form submissions;
- Google Workspace for business email and files;
- Stripe for checkout, subscriptions, payment records, fraud prevention and receipts;
- domain, hosting, booking, map, analytics or technical providers selected for an agreed customer project;
- professional advisers, insurers, accountants and authorities where reasonably necessary or legally required; and
- a purchaser or successor if the business is reorganised or sold, subject to appropriate confidentiality.
Stripe acts as an independent controller for parts of its payment and fraud-prevention processing. Its own privacy notice applies on Stripe-hosted checkout.
6. International transfers
Some suppliers may process information outside the UK. Where UK data protection law requires a safeguard, we rely on an adequacy regulation, the UK International Data Transfer Agreement or Addendum, or another lawful mechanism used by the supplier. Contact us for more information about the safeguard relevant to a particular transfer.
7. Retention
- Unsuccessful enquiries are normally kept for up to 12 months after the last meaningful contact.
- Business prospect records are normally reviewed or deleted within 12 months. If someone opts out, we keep only the minimum contact detail needed on a suppression list for as long as reasonably necessary to honour that choice.
- Customer, contract, invoice and payment records are normally kept for six years after the end of the relevant financial year or contract, as appropriate for tax, accounting and legal purposes.
- Project files and website content are kept during the service and normally deleted or anonymised within 90 days after hosting and any reasonable handover period end, unless needed for legal records or the Customer asks us to retain them.
- Security and server logs are retained for the shorter periods set by our providers unless an incident requires longer investigation.
We may keep information longer where a dispute, legal duty, fraud concern or active claim reasonably requires it.
8. Security
We use reasonable organisational and technical measures appropriate to a small website service, including controlled account access, multifactor authentication where available, HTTPS, trusted payment processing and limited supplier access. No internet service can promise absolute security. Customers should not email passwords or full payment-card details.
9. Your rights
Depending on the circumstances, UK data protection law may give you rights to access, correct, erase or restrict personal information; object to processing based on legitimate interests; receive certain information in a portable format; and withdraw consent without affecting earlier lawful processing.
You have an absolute right to object to direct marketing. Every marketing email we send provides a simple opt-out, and you can also email us with “no thanks” or “unsubscribe”. We will stop the marketing and add the minimum detail to our suppression list.
To exercise a right, email admin@fadefoundry.co.uk. We may need enough information to verify identity and understand the request. You also have the right to complain to the Information Commissioner's Office, although we would appreciate the opportunity to address the concern first.
10. Cookies and external links
The FadeFoundry marketing site does not currently use advertising or behavioural tracking cookies. Essential hosting and security technology may process technical information. Stripe and other external services use their own cookies when a visitor follows a link to them. See our Cookie Notice for details.
11. Children
This is a business service and is not directed to children. Do not submit information about a child unless it is genuinely necessary and we have agreed an appropriate lawful process.
12. Changes
We may update this notice when the service, suppliers or law changes. The date above identifies the current version. Material changes will be highlighted where practical.