Privacy Policy
This Privacy Policy explains how Wardenfox Ltd (company number pending), a company registered in England and Wales whose registered office is to be updated before public launch (“we”, “us”, “our”), collects, uses and protects personal data when you use the WardenFox inventory and point-of-sale software and website (the “Service”). We are committed to handling your data in line with the UK GDPR and the Data Protection Act 2018.
1. Who we are
The data controller for personal data about you (the account holder and your staff) is:
- Business: Wardenfox Ltd, a company registered in England and Wales (company number pending)
- Registered office: to be updated before public launch
- Contact: [email protected]
- ICO data protection fee / registration reference: not yet registered; to be added if applicable before launch
- Data Protection Officer: we are not legally required to appoint one and have not done so. You can raise any data-protection question with us at [email protected].
Important — data about your own customers. When you, as a shop owner, enter information about your customers (names, contact details, purchase history) into WardenFox, you are the data controller of that information and we are your data processor. We only process it on your instructions to provide the Service. You are responsible for having a lawful basis to collect it and for your own privacy notice to your customers. Our processing of that data on your behalf is set out in our Data Processing Agreement, which forms part of our Terms of Service.
2. What data we collect
- Account & profile: name, email, password (stored only as a secure hash), shop name, role, and till PINs (hashed).
- Billing: your plan and subscription status. Card payments are handled by Stripe; we do not store your full card details.
- Your shop data: the inventory, sales, stock counts, suppliers, purchase orders, waste and customer records you create in the Service.
- Usage & analytics (with consent): if you click “Accept all” on our cookie banner, we use PostHog to see how you use the Service (pages visited, features used). When enabled, this is linked to your account (your email, role and plan) so we can understand how shops of different sizes use WardenFox. It does not capture your shop data (stock, sales or customer records) and does not record your screen. With the same consent, we may load Sentry in your browser to collect error reports that help us fix bugs; we configure it not to capture your IP address or cookies. See “Cookies” below.
- Technical & security: IP address and browser type (recorded in our server logs and, where enabled, by Cloudflare), and error diagnostics needed to run, secure and debug the Service on our servers (including server-side error monitoring via Sentry, if enabled). To protect your account we also keep a record of sign-ins to it — the IP address, browser/device and time — so we can recognise the devices you normally use and email you a security alert when your account is signed in to from a new device. That alert shows the IP address the sign-in came from so you can judge whether it was you.
- Support access: if you contact us, authorised support staff may access your account and store data to investigate and resolve your request. In limited cases, after verifying your request, we may use a single-use secure link to view your store exactly as you see it; such access is time-limited, recorded in your store’s audit log (including who accessed and why), and used only for support — we do not routinely browse customer stores.
3. How we use your data and our legal bases
| Purpose | Legal basis (UK GDPR) |
|---|---|
| Provide the Service, your account and support | Performance of our contract with you |
| Take payment and manage subscriptions | Performance of contract; legal obligation (tax/accounting) |
| Keep the Service secure, prevent fraud/abuse, fix bugs | Our legitimate interests |
| Recognise your devices and alert you to sign-ins from a new device (the alert shows the originating IP address) | Our legitimate interests (keeping your account secure) |
| Product analytics to understand and improve the Service | Your consent (you can withdraw it any time) |
| Browser error diagnostics (Sentry in your browser, if enabled) | Your consent (you can withdraw it any time) |
| Send service emails (password resets, receipts, important notices) | Performance of contract / legitimate interests |
| Comply with the law and respond to lawful requests | Legal obligation |
More about our legitimate interests. Where the table above relies on “legitimate interests”, those interests are: keeping the Service and your account secure, preventing fraud and abuse, diagnosing and fixing problems, and running and protecting our business. We have weighed these against your rights and freedoms and only process what is necessary.
Do you have to provide this data? The account details and shop data needed to operate the Service are required under our contract with you — without them we cannot create your account or provide the Service. PostHog and browser Sentry are entirely optional: they run only if you consent, and declining them does not affect your use of the Service.
No automated decision-making. We do not use your personal data to make solely automated decisions, or to carry out profiling, that produce legal or similarly significant effects on you.
4. Cookies & analytics
We use a small number of cookies/local storage:
- Essential — needed to log you in, keep you signed in, and remember settings (e.g. theme, your cookie choice). These don’t need consent.
- Analytics (optional) — PostHog (product analytics) and, if enabled on our side, Sentry in your browser (error diagnostics). Both are used only if you click “Accept all” on our cookie banner.
You choose when you first visit, and can change your mind at any time using Cookie settings in our footer (which re-opens the banner), or by clearing your browser’s site data for WardenFox. Choosing “Reject all” means no analytics cookies are set and neither PostHog nor the browser Sentry SDK is loaded.
5. Who we share your data with (sub-processors)
We do not sell your data. Depending on the features you use and how the Service is configured, we share data only with providers that help us run the Service, under contract and only as needed:
| Provider / category | Purpose |
|---|---|
| Stripe (if billing is enabled) | Payment processing, subscriptions and billing history |
| Cloudflare (if enabled) | DNS, content delivery, bot protection (Turnstile), edge security such as DDoS/WAF, and — where configured — object storage (Cloudflare R2) for uploaded item images, stored in the European Union |
| PostHog (only with your consent, and only if enabled) | Product analytics |
| Sentry (server-side if enabled; browser SDK only with your consent) | Error monitoring and diagnostics |
| Email delivery provider (if configured) | Sending service emails such as verification, password reset and billing messages |
| Hosting / infrastructure providers we use from time to time | Application, database, cache and backup hosting. Uploaded item images are stored in the EU (Cloudflare R2) when object storage is enabled. |
| jsDelivr | Delivery of Bootstrap CSS and icon assets on certain public pages |
These providers are separate companies. Each provider listed above is an independent legal entity, separately owned and operated — none is owned by, controlled by, or affiliated with WardenFox, and their names and logos are their own trademarks. Each handles data under its own privacy policy and terms, which we encourage you to read. Most act as our data processors, handling personal data only on our instructions and under a data-processing agreement; some — for example Stripe for payments — act as independent data controllers in their own right (for instance for their own fraud prevention and regulatory record-keeping), in which case their own privacy policy governs that processing. We choose our providers carefully and put the required contracts in place, but we are not responsible for the independent practices of these separate third parties.
Styling files served from a CDN. Some of our public pages (such as sign-in, password reset and these legal pages) load standard styling and icon files (Bootstrap) from the jsDelivr content delivery network — a separate third party that is not owned or controlled by WardenFox. To deliver those files your browser connects to jsDelivr directly, so jsDelivr receives your IP address and basic technical request data as part of loading the page. We use this only to display the page correctly and do not track or profile you with it. How jsDelivr itself handles that data is governed by its own terms and privacy policy, which apply independently and are not limited or overridden by anything in this policy; we encourage you to review them.
Legal and law-enforcement requests. We may disclose personal data to the police, courts, regulators or other authorities where we are required to by law, or where it is necessary to comply with a valid legal request, to establish, exercise or defend legal claims, or to prevent, detect or report a crime, fraud or harm (for example, reporting unlawful content uploaded to the Service). We disclose only what is necessary and lawful, and we will tell you about a request where we are legally permitted to do so.
6. International transfers
Some of our providers are based outside the UK or may process data through global infrastructure. In our default configuration this may include Stripe (payment processing), Cloudflare (security, delivery and, where configured, item-image storage in the European Union), PostHog (analytics, if enabled with consent), Sentry (server-side error monitoring if enabled; browser SDK only with consent), and jsDelivr (public-page asset delivery). Where personal data is transferred internationally we rely on appropriate safeguards such as adequacy regulations, the UK International Data Transfer Agreement, or Standard Contractual Clauses with the UK Addendum, and we minimise what is transferred. Uploaded item images are stored in the EU when object storage is enabled. You can request a copy of the safeguards we rely on for international transfers by emailing [email protected].
7. How long we keep it
We keep your account and shop data for as long as your account is active. Cancelling a paid subscription does not by itself delete your account or shop data; if you stay on the Service, your data remains available to you. If you use the in-app Delete account & everything in it feature, the live account/store data is deleted from the primary database promptly, except where we must keep certain records longer to meet legal obligations (for example invoices and accounting records). Residual copies may remain in routine backups until those backups expire under our backup-rotation schedule. Our default backup retention is currently 7 days, but that operational setting may change over time. The sign-in and device-recognition records described in section 2 (IP address, browser/device and time) are kept while your account is active and are deleted when your account is deleted; we also keep limited server and security logs for a short period for security and troubleshooting.
8. How we protect your data
We use encryption in transit (HTTPS/TLS), encrypted database connections, strict per-shop data isolation, hashed passwords and PINs, optional two-factor authentication, access controls, and regular backups. No system is perfectly secure, but we work hard to protect your information.
Data breaches. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the ICO within 72 hours where we are required to. Where a breach is likely to result in a high risk to you, we will also tell you without undue delay.
9. Your rights
Under UK data protection law you have the right to: access your data; correct it; erase it; restrict or object to processing; data portability; and withdraw consent (for anything based on consent) at any time. To exercise any of these, email [email protected]. You can also export your inventory as a CSV at any time from Settings → Export & Data, and request a copy of your other personal data by emailing us. We’d appreciate the chance to put things right first, so please contact us before going further. If you’re still unhappy with how we handle your data you can complain to the UK Information Commissioner’s Office (ICO): ico.org.uk, helpline 0303 123 1113, or Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
10. Children
The Service is for businesses and is not directed at children. We do not knowingly collect data from anyone under 18.
11. Changes to this policy
We may update this policy from time to time. We’ll post the new version here and, for significant changes, let you know by email or in the app.
12. Contact
Questions about your privacy? Email [email protected] or write to Wardenfox Ltd at to be updated before public launch.