Privacy Policy

This Privacy Policy explains how Wardenfox Ltd (company number pending), a company registered in England and Wales whose registered office is to be updated before public launch (“we”, “us”, “our”), collects, uses and protects personal data when you use the WardenFox inventory and point-of-sale software and website (the “Service”). We are committed to handling your data in line with the UK GDPR and the Data Protection Act 2018.

1. Who we are

The data controller for personal data about you (the account holder and your staff) is:

Important — data about your own customers. When you, as a shop owner, enter information about your customers (names, contact details, purchase history) into WardenFox, you are the data controller of that information and we are your data processor. We only process it on your instructions to provide the Service. You are responsible for having a lawful basis to collect it and for your own privacy notice to your customers. Our processing of that data on your behalf is set out in our Data Processing Agreement, which forms part of our Terms of Service.

2. What data we collect

3. How we use your data and our legal bases

More about our legitimate interests. Where the table above relies on “legitimate interests”, those interests are: keeping the Service and your account secure, preventing fraud and abuse, diagnosing and fixing problems, and running and protecting our business. We have weighed these against your rights and freedoms and only process what is necessary.

Do you have to provide this data? The account details and shop data needed to operate the Service are required under our contract with you — without them we cannot create your account or provide the Service. PostHog and browser Sentry are entirely optional: they run only if you consent, and declining them does not affect your use of the Service.

No automated decision-making. We do not use your personal data to make solely automated decisions, or to carry out profiling, that produce legal or similarly significant effects on you.

4. Cookies & analytics

We use a small number of cookies/local storage:

You choose when you first visit, and can change your mind at any time using Cookie settings in our footer (which re-opens the banner), or by clearing your browser’s site data for WardenFox. Choosing “Reject all” means no analytics cookies are set and neither PostHog nor the browser Sentry SDK is loaded.

5. Who we share your data with (sub-processors)

We do not sell your data. Depending on the features you use and how the Service is configured, we share data only with providers that help us run the Service, under contract and only as needed:

These providers are separate companies. Each provider listed above is an independent legal entity, separately owned and operated — none is owned by, controlled by, or affiliated with WardenFox, and their names and logos are their own trademarks. Each handles data under its own privacy policy and terms, which we encourage you to read. Most act as our data processors, handling personal data only on our instructions and under a data-processing agreement; some — for example Stripe for payments — act as independent data controllers in their own right (for instance for their own fraud prevention and regulatory record-keeping), in which case their own privacy policy governs that processing. We choose our providers carefully and put the required contracts in place, but we are not responsible for the independent practices of these separate third parties.

Styling files served from a CDN. Some of our public pages (such as sign-in, password reset and these legal pages) load standard styling and icon files (Bootstrap) from the jsDelivr content delivery network — a separate third party that is not owned or controlled by WardenFox. To deliver those files your browser connects to jsDelivr directly, so jsDelivr receives your IP address and basic technical request data as part of loading the page. We use this only to display the page correctly and do not track or profile you with it. How jsDelivr itself handles that data is governed by its own terms and privacy policy, which apply independently and are not limited or overridden by anything in this policy; we encourage you to review them.

Legal and law-enforcement requests. We may disclose personal data to the police, courts, regulators or other authorities where we are required to by law, or where it is necessary to comply with a valid legal request, to establish, exercise or defend legal claims, or to prevent, detect or report a crime, fraud or harm (for example, reporting unlawful content uploaded to the Service). We disclose only what is necessary and lawful, and we will tell you about a request where we are legally permitted to do so.

6. International transfers

Some of our providers are based outside the UK or may process data through global infrastructure. In our default configuration this may include Stripe (payment processing), Cloudflare (security, delivery and, where configured, item-image storage in the European Union), PostHog (analytics, if enabled with consent), Sentry (server-side error monitoring if enabled; browser SDK only with consent), and jsDelivr (public-page asset delivery). Where personal data is transferred internationally we rely on appropriate safeguards such as adequacy regulations, the UK International Data Transfer Agreement, or Standard Contractual Clauses with the UK Addendum, and we minimise what is transferred. Uploaded item images are stored in the EU when object storage is enabled. You can request a copy of the safeguards we rely on for international transfers by emailing [email protected].

7. How long we keep it

We keep your account and shop data for as long as your account is active. Cancelling a paid subscription does not by itself delete your account or shop data; if you stay on the Service, your data remains available to you. If you use the in-app Delete account & everything in it feature, the live account/store data is deleted from the primary database promptly, except where we must keep certain records longer to meet legal obligations (for example invoices and accounting records). Residual copies may remain in routine backups until those backups expire under our backup-rotation schedule. Our default backup retention is currently 7 days, but that operational setting may change over time. The sign-in and device-recognition records described in section 2 (IP address, browser/device and time) are kept while your account is active and are deleted when your account is deleted; we also keep limited server and security logs for a short period for security and troubleshooting.

8. How we protect your data

We use encryption in transit (HTTPS/TLS), encrypted database connections, strict per-shop data isolation, hashed passwords and PINs, optional two-factor authentication, access controls, and regular backups. No system is perfectly secure, but we work hard to protect your information.

Data breaches. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the ICO within 72 hours where we are required to. Where a breach is likely to result in a high risk to you, we will also tell you without undue delay.

9. Your rights

Under UK data protection law you have the right to: access your data; correct it; erase it; restrict or object to processing; data portability; and withdraw consent (for anything based on consent) at any time. To exercise any of these, email [email protected]. You can also export your inventory as a CSV at any time from Settings → Export & Data, and request a copy of your other personal data by emailing us. We’d appreciate the chance to put things right first, so please contact us before going further. If you’re still unhappy with how we handle your data you can complain to the UK Information Commissioner’s Office (ICO): ico.org.uk, helpline 0303 123 1113, or Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.

10. Children

The Service is for businesses and is not directed at children. We do not knowingly collect data from anyone under 18.

11. Changes to this policy

We may update this policy from time to time. We’ll post the new version here and, for significant changes, let you know by email or in the app.

12. Contact

Questions about your privacy? Email [email protected] or write to Wardenfox Ltd at to be updated before public launch.