Privacy Policy

Last updated: October 2026

1. Who We Are

ForgeDash Ltd (Company Number: 17032281) is the data controller for your personal information. We are registered in England and Wales and registered with the Information Commissioner's Office (ICO) under registration number ZC095670.

Registered Office: 14 Willow Way, Wisbech, PE13 2SY, UK
ICO Registration No: ZC095670
Contact: [email protected]

2. What Data We Collect

We collect the following categories of personal data:

  • Account information — name, email address, trade type
  • Financial data you enter — income, expenses, invoices, receipts, customer records
  • Usage data — how you interact with the platform, pages visited, features used
  • Device and browser information — IP address, browser type, operating system, for security purposes
  • Payment information — processed securely by Stripe; we do not store full card details on our servers
  • Garage Admin Leak Audit answers — how your business works (for example jobs a week, the tools you use), how you reached the page (campaign tags and the referring website's name), stored without your name or email. See section 3a
  • Audit contact details — only if you ask for the full audit report: your email, and optionally your first name and business name, plus whether you agreed to marketing emails

3. How and Why We Use Your Data

Under UK GDPR, we must have a lawful basis for each processing activity:

PurposeLawful Basis
Providing ForgeDash services and calculating your tax obligationsContract — necessary to deliver the service you signed up for
Processing payments via StripeContract — to fulfil your subscription
Sending important service updates and security notificationsLegitimate interest — to keep your account secure and informed
Preventing fraud and ensuring platform securityLegitimate interest — to protect users and the service
Analytics on the marketing website (if you consent)Consent — via cookie preferences
Sending the Garage Admin Leak Audit report you ask for, and letting you reopen itLegitimate interest — to provide the report you requested
Studying anonymous audit answers to understand how garages work and improve ForgeDashLegitimate interest — the answers are stored without your name or contact details
Occasional ForgeDash tips, product updates and offers by emailConsent — only if you tick the box; you can withdraw at any time
Complying with legal obligations (e.g. tax records, law enforcement requests)Legal obligation

3a. The Garage Admin Leak Audit

The audit at forgedash.uk/tools/garage-admin-audit shows your result without asking for any contact details. Your answers are saved as you go, without your name or email, so we can see which admin problems garages report most. Your progress is also kept in your own browser so a refresh does not lose it.

If you ask for the full breakdown we store your email (and your first name and business name if you give them) separately from your answers, linked only by an audit reference, and send you one email with your report and a private link to reopen it. Anyone you forward that link to can see your results.

Marketing emails are a separate choice. We only send them if you tick the box, which is never ticked for you, and we record when you ticked it and the wording you agreed to. Asking for the report on its own does not sign you up to anything. To withdraw consent or have your audit details deleted, email [email protected].

If you accepted analytics cookies, we also record which steps of the audit you reached, to see where people stop. We do not do this without your consent.

4. Who We Share Your Data With

We only share your data with trusted third-party providers necessary to deliver our services:

  • netcup GmbH — the dedicated server ForgeDash runs on: database, sign-in, file storage and the application (Germany)
  • Amazon Web Services (S3) — encrypted backup storage (Stockholm, Sweden)
  • Stripe — payment processing (PCI DSS Level 1 certified)
  • Resend — transactional email delivery (invoices, receipts, reminders)
  • Google (Gemini) — reads the contents of receipts you upload, to log expenses automatically
  • Cloudflare — DNS, CDN, DDoS protection, and web application firewall (WAF)
  • Sentry — error monitoring, so we can find and fix faults; personal data is scrubbed from error reports
  • DVLA and DVSA — when you enter a registration, we look up the vehicle's details and MOT history. Only the registration is sent

ForgeDash itself — its database, sign-in, file storage and our receipt-scanning workflow (Windmill) — runs on one dedicated server in Germany that we operate ourselves, rented from netcup. It is not a shared hosting platform. The full list of sub-processors, with what each receives and where, is in our Data Processing Agreement.

We never sell, rent, or share your personal or financial data with third-party lenders, brokers, advertisers, or data brokers.

5. International Data Transfers

Your financial data is stored on our dedicated server in Germany, with encrypted backups in Stockholm, Sweden (both in the EU). Some of our service providers (Stripe, Resend, Google, Cloudflare and Sentry) may process data in the United States. Where data is transferred outside the UK, we ensure appropriate safeguards are in place, including:

  • UK International Data Transfer Agreements (UK IDTAs)
  • Standard Contractual Clauses (SCCs)
  • UK adequacy decisions where applicable

6. How Long We Keep Your Data

Data TypeRetention Period
Account informationUntil you delete your account, plus 30 days
Financial records (income, expenses, invoices)6 years after the tax year they relate to (HMRC requirement)
Payment transaction records6 years (legal obligation)
Usage and analytics data26 months
Garage Admin Leak Audit contact details and marketing consent24 months after you last asked for a report, or until you ask us to delete them
Unfinished audits90 days
Finished audit answers (no name or contact details)Kept for research; deleting your contact details leaves nothing that identifies you
Cookie consent records5 years (PECR requirement)

7. Data Storage & Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Encryption at rest and in transit (AES-256, TLS 1.2+)
  • Cloudflare DDoS protection and Web Application Firewall (WAF)
  • Row-level security on all database tables
  • Regular security audits and vulnerability assessments
  • Secure authentication with password hashing and session management
  • Access controls based on the principle of least privilege

8. Your Rights Under UK GDPR

You have the following rights regarding your personal data:

  • Right to be informed — this privacy policy fulfils this right
  • Right of access — request a copy of the personal data we hold about you
  • Right to rectification — request correction of inaccurate or incomplete data
  • Right to erasure — request deletion of your personal data ("right to be forgotten")
  • Right to restrict processing — request that we limit how we use your data
  • Right to data portability — receive your data in a structured, machine-readable format
  • Right to object — object to processing based on legitimate interests
  • Rights related to automated decision-making — ForgeDash does not make solely automated decisions with legal or significant effects

How to Exercise Your Rights

To exercise any of these rights, contact us at [email protected]. We will respond to your request within one month. You can also export your data directly from the ForgeDash dashboard at any time.

Right to Complain

For a complaint about how we handle your personal data, email [email protected] with the details and your preferred contact address. We acknowledge privacy complaints within 30 days, investigate, and communicate the outcome and any action taken. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).

ICO Contact: 0303 123 1113 · ico.org.uk

9. Our Role: Controller vs Processor

As a data controller: We determine how and why your personal data is processed when you use ForgeDash. This includes your account information, usage data, and marketing website data.

As a data processor: When you enter your customers' information into ForgeDash (e.g. customer names and contact details on invoices), you are the data controller for that customer data, and we process it on your behalf to deliver our services.

That processor relationship is governed by our Data Processing Agreement, which contains the binding terms UK GDPR Article 28 requires — our processing instructions, confidentiality and security obligations, the full sub-processor list, how we assist with data subject requests, breach notification timescales, and what happens to the data when you leave. It applies automatically to every ForgeDash account.

10. Cookies

We use essential cookies to make ForgeDash work and optional analytics cookies (with your consent) to improve our marketing website. For full details, see our Cookie Policy.

11. Children's Privacy

ForgeDash is designed for self-employed adults and sole traders. We do not knowingly collect data from individuals under 18. If we become aware that we have collected data from a minor, we will delete it promptly.

12. Changes to This Policy

We may update this privacy policy from time to time. If we make significant changes, we will notify you by email or through a notification on the ForgeDash platform. The "Last updated" date at the top of this page will always reflect the most recent version.

13. Contact Us

For any privacy-related questions or requests, contact us at:

ForgeDash Ltd

14 Willow Way, Wisbech, PE13 2SY, UK

Email: [email protected]

Company Number: 17032281 · ICO Registration No: ZC095670 · Registered in England and Wales