Privacy
Privacy policy
This policy covers everything that is true of TidyLabs as a whole: who is responsible for your personal data, why it is used, how long it is kept, and what you can make us do about it. Each product has its own shorter policy for what that product collects.
Last updated 4 August 2026.
Who is responsible
The data controller is Brett Jenkins, a sole trader trading as TidyLabs, of 52-56 Standard Road, London, NW10 6EU. Contact: [email protected]
TidyLabs is a trading name, not a company. A trading name cannot be responsible for anything, so the controller named above is the person behind it. That is the same person whichever TidyLabs product you use, which is why one policy can cover all of them.
How this policy fits with the product policies
This is the policy for the controller. It applies to every TidyLabs site and product. Each product then has its own policy covering only what that product collects and does, and links back here for everything on this page.
If a product policy and this one ever disagree about your rights, how to complain, or who the controller is, this one is right and the other needs fixing. Tell us and it will be.
What is used, why, and on what basis
UK GDPR requires a lawful basis for every use of personal data, and the basis changes what you can ask for. Where the basis is consent you can withdraw it. Where it is legitimate interests you can object. Both are covered under your rights.
Running a subscription or a purchase
What: your email address, billing details, payment history and the
record of what you bought, held by Stripe.
Why: to take payment, to give you access to what you paid for, to
issue receipts and invoices, and to handle cancellations and refunds.
Basis: performance of a contract with you (UK GDPR Article
6(1)(b)). Once the contract has ended, the tax and accounting records that come out
of it are kept under a legal obligation instead (Article 6(1)(c)).
Customer records and service email
What: your email address and whether you are a current customer,
held by Kit.
Why: so we can reach you about your own subscription — a billing
problem, a firmware issue affecting your sign, a change to the service or to these
terms.
Basis: performance of our contract with you (Article 6(1)(b)), and
our legitimate interest in being able to tell customers about things that affect
something they are paying for (Article 6(1)(f)). These are service messages rather
than marketing, so there is no opt-out from them, in the same way there is no
opt-out from a receipt. We keep them rare and we keep them relevant.
Marketing email
What: your email address, and whether you opened or clicked, held
by Kit.
Why: to send you the emails you asked for.
Basis: your consent (Article 6(1)(a)), together with the direct
marketing rules in PECR. This is separate from the record above: being a customer
does not put you on the marketing list. You are on it only if you ticked the box
and then confirmed by clicking a link in a separate email. Every email carries an
unsubscribe link, that link works immediately, and using it costs you nothing else
and changes nothing about your subscription. We do not sell or rent the list, and
we do not share it.
Support correspondence
What: your email address and whatever you write to us, held by
Help Scout.
Why: to answer you, and to be able to pick up the thread if you
write again.
Basis: performance of a contract where you are a customer asking
about something you bought (Article 6(1)(b)), and otherwise our legitimate interest
in answering people who contact us (Article 6(1)(f)).
Analytics
What: aggregated visit counts, referrers, rough location by
country and browser type, via Cloudflare Web Analytics.
Why: to know which pages get read and whether a change made things
better or worse.
Basis: our legitimate interest in understanding how our own sites
are used (Article 6(1)(f)). This is cookieless and does not follow you to other
sites or build a profile of you, which is what makes the interest a light one to
balance against your privacy. We get counts, not people.
Security, abuse prevention and keeping the sites up
What: request logs including IP addresses and user agents,
processed by Cloudflare.
Why: to serve pages, to block attacks and abuse, and to work out
what broke when something breaks.
Basis: our legitimate interest in keeping the service running and
secure (Article 6(1)(f)), which is a purpose UK GDPR itself recognises as
legitimate.
Who else handles your data
These processors act on our instructions across every TidyLabs product. They are not free to use your data for their own purposes. A product may use others of its own, in which case its own policy names them.
-
Cloudflare Hosting, CDN and site analytics
Serves every TidyLabs site and sits in front of it. Processes the technical detail of each request, including your IP address and browser user agent, to deliver pages and to block attacks. Also provides the cookieless visitor analytics described below.
-
Stripe Payments
Takes payment for anything TidyLabs sells and holds the card details, the billing email and the payment history. We never see or store a card number.
-
Kit Customer records and email
Holds our customer records and sends our email. Every customer is in it, so we can reach you about your own subscription. Marketing goes only to people who asked for it and confirmed, and every marketing email carries an unsubscribe link.
-
Help Scout Support correspondence
Receives and stores email sent to our support addresses, so a conversation is not lost between replies. It holds whatever you choose to put in an email to us.
-
Google Fonts Webfonts (not acting on our instructions)
Serves the typefaces our sites are set in. Your browser fetches them directly from Google, which means Google sees your IP address. Nothing about what you do on our sites is sent to them, and we receive nothing back.
We do not sell your personal data. We share it beyond these processors only where the law requires it, for example in response to a valid legal request.
Data leaving the UK
Every processor above is US based or runs a global network, so some of your data is processed outside the UK. That is allowed where there is a safeguard in place under Chapter V of UK GDPR.
The four processors rely on the same one. Cloudflare, Stripe, Kit and Help Scout are each certified under the UK Extension to the EU-US Data Privacy Framework, and that is the safeguard relied on for every transfer described here. Each also carries standard contractual clauses as a contractual fallback, so a transfer does not become unlawful if a certification or an adequacy decision lapses: Cloudflare and Help Scout through the EU standard contractual clauses, Stripe through the UK International Data Transfer Agreement in its data transfers addendum, and Kit through both the clauses and that agreement in its data processing addendum.
Google is different. It is not acting on our instructions, so the safeguard above is not ours to rely on for it. Your browser contacts Google directly to fetch the fonts our sites are set in, and Google receives your IP address as a result of that request. Google is itself certified under the UK Extension to the EU-US Data Privacy Framework, and what it does with what it receives is governed by its own privacy policy rather than by any instruction from us.
You can ask for a copy of the safeguard relied on for any transfer by emailing [email protected].
How long things are kept
Nothing is kept because it might be useful one day. Each category has a reason for its period, and when the reason runs out the data goes.
- Payment, invoice and subscription records. Kept for the life of the subscription and then retained as business records. A sole trader must keep records for at least five years after the 31 January submission deadline of the relevant tax year, so in practice this is around six years. We cannot delete these on request while that obligation runs.
- Your record at Kit. Once your email address is in Kit it stays there until we remove it. Nothing takes it out automatically: unsubscribing stops us emailing you but does not delete the record, and neither does ending a subscription. Kit keeps the profile of someone who has unsubscribed, and keeping it is also what stops you being added back by mistake.
- Getting it removed. Ask us and we will delete it. We would rather offer you a route to erasure than imply one happens by itself, because it does not.
- Support correspondence. Kept while it is still useful for supporting you or for resolving anything arising from it, and deleted on request. UK GDPR allows a retention rule to be stated as the criteria that decide it rather than as a fixed number of days, and that is what this is.
- Support bundles. A diagnostic bundle sent from a sign is deleted automatically 30 days after it is uploaded. That is an expiry rule on the storage bucket itself rather than a habit, so it happens whether or not anybody remembers, and it cannot be extended by leaving a support thread open.
- Analytics. Aggregated counts only, with no record identifying a visitor, held by Cloudflare for 30 days and then dropped. Cloudflare Web Analytics also samples roughly one page load in ten rather than recording every visit.
- Request and security logs. None are kept. Cloudflare does not retain HTTP request logs unless a customer switches retention on, and we have not, so there is no request log of your visit held on our behalf to ask for, export or delete. Cloudflare keeps a short window of security events for its own protection of the network, measured in days rather than months.
Your rights
Under UK GDPR you have the right to:
- Access. Ask whether we hold personal data about you, and get a copy of it along with an explanation of what it is used for.
- Rectification. Have anything inaccurate corrected, and anything incomplete completed.
- Erasure. Have your data deleted where we no longer need it, where you withdraw the consent it rests on, or where you successfully object. This is not absolute: records we must keep by law, such as the tax records above, stay until that obligation ends.
- Restriction. Have us pause using your data, for instance while a dispute about its accuracy is sorted out.
- Objection. Object to anything done on the basis of legitimate interests, which here means analytics and security logging. Where the objection is to direct marketing it is absolute, and it stops immediately with no balancing test.
- Portability. Get the data you gave us, in a structured, commonly used, machine-readable format, or have it sent straight to someone else. This applies to data processed by consent or under a contract, and processed automatically.
- Withdrawing consent. Where the basis is consent, withdraw it at any time. That does not undo anything done lawfully before you withdrew it.
How to exercise them
Email [email protected] and say what you want. There is no form to fill in and no fee. Say which product you used if you know, as it makes finding your data faster, but it is our job to look and not yours to know where.
We will reply within one month of receiving the request. If a request is complex, or you have made several, we may extend that by up to two further months, and we will tell you inside the first month if that happens and why. We may ask you for enough information to confirm who you are, because handing your data to somebody else who claims to be you would be worse than being slow.
Complaining to the ICO
If you think your data has been handled badly, please tell us first, because most problems are quicker to fix directly. You do not have to, and complaining to us is not a condition of anything below.
You have the right to complain to the Information Commissioner's Office, the UK's data protection regulator. Complaining to them costs nothing and does not affect any other route open to you, including a claim in court.
Information Commissioner's Office
Wycliffe HouseWater Lane
Wilmslow
Cheshire
SK9 5AF
Helpline: 0303 123 1113
Cookies
This site sets no cookies for analytics, advertising or tracking. Cloudflare Web Analytics is cookieless, which is why there is no consent banner here to click through: PECR requires consent for storing or reading information on your device, and we do not. A product site that does set cookies says so in its own policy.
Changes to this policy
When this policy changes in substance, the date at the top changes with it. If a change materially affects how your data is used, and we hold a way to reach you, you will be told rather than left to notice.
Contact
Anything on this page, including a request under your rights, goes to [email protected]. The postal address is on the contact page and in the footer of every page.