Privacy Policy
1. Introduction
Go Find Part Limited (“GoFindPart”, “we”, “us”, or “our”) is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data when you use our Platform.
Go Find Part Limited is the data controller for personal data processed through the Platform. We are registered in England and Wales.
This Privacy Policy applies to all users of the Platform, including Buyers, Sellers (Fulfilling Suppliers), and visitors.
We process personal data in accordance with the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.
Context on our role. GoFindPart operates as a managed-procurement platform and the merchant of record in every Transaction. We are the contracting seller to Buyers, and we source goods from a network of Fulfilling Suppliers under back-to-back terms (see our Buyer Terms and Seller Terms). This structure has specific implications for how we process the identity of Fulfilling Suppliers — see sections 3, 4, and 6.
2. Personal Data We Collect
2.1 Information you provide
When you register for an account and use the Platform, we collect the following categories of personal data:
- Account information — name, email address, phone number, business name, business registration details, and account type (Buyer, Seller, or Both).
- Organisation sign-in identifiers — if your organisation connects its Microsoft or Google directory, the identifier that directory assigns to you, the work email it asserted, and when you linked and last signed in. We never see or store your directory password.
- Seller-specific commercial information (for users registered as Sellers) — legal entity name, VAT registration status, VAT number (if VAT-registered), self-billing-agreement consent timestamp, and bank-account details required for Stripe Connect payouts.
- Seller tax identifiers (for users registered as Sellers) — the information we are required to collect and report as a UK digital platform operator under the Platform Operators (Due Diligence and Reporting Requirements) Regulations 2023 (SI 2023/817). Depending on your legal form this includes your National Insurance number, partnership Unique Taxpayer Reference, company registration number, date of birth and registered or home address. A National Insurance number is a national identification number, and we hold it only for this reporting purpose, only for sellers, and never disclose it to buyers or other users.
- Identity verification — information required for Stripe Connect onboarding (for Sellers), including identity documents and proof of business registration. This data is processed by Stripe and is subject to Stripe’s own privacy policy. Where we ask you to verify your identity — as a seller before you can quote, as a trade-account applicant, or before a high-value purchase — the check is run by Stripe in Stripe’s own interface: you photograph an identity document and take a short selfie, and Stripe compares the two. We never receive the images. We receive the result of the check and, from the document, your verified name and the month and year of your birth, which we keep encrypted for six years with the decisions they supported. Stripe processes the images and the comparison as an independent controller under its own privacy notice.
- Transaction data — details of Requests created, Offers submitted, accepted Transactions, pricing, delivery information, payment records, and self-billed VAT-invoice records.
- Parts you save — if you use My parts, the parts you choose to save, the name you give each one, your notes, where you keep it, the groups you put it in and which you pin. Only you see these: we never show them to sellers, to other users or to our staff, and we do not read them. Please do not put personal details about other people in your notes.
- Communication data — messages exchanged through the Platform, dispute evidence, product-claim correspondence, and support correspondence.
- Delivery information — delivery addresses, pickup locations, and geolocation data used for delivery cost calculation and fulfilment routing.
- Photographs and details of parts (sellers) — if you are a seller and photograph a part to identify it — its data plate and, where we ask, the part itself — to add it to your stock, or to suggest a part to a buyer in place of the one they asked for, we use the photographs, and any part number, link or details you give us, to identify the part. Photographs of parts are not meant to show people: please keep people, and labels with names or addresses, out of them. Photographs you take to add stock are seen by you and your team in your stock list, and by our staff; photographs you give us to suggest a part are seen only by our staff — never by the buyer or other sellers.
- Photographs of stock labels (trade organisations) — if your organisation keeps its stock list with us, you can photograph the label on a stock bin, or on a part, to find that part on your site’s list instead of typing what the label says. Before the photograph leaves our servers we remove its hidden details, such as where and when it was taken. We send it once to an automated service that reads what the label says — its codes, the part’s description and its maker — and we search your site’s list with those words. We do not keep the photograph, and we do not keep what the label said: we keep only a record that a label was read, by whom, when, and what it cost us. Please photograph only the label: keep people, and anything with a name or address on it, out of the picture.
2.2 Information we collect automatically
- Device and usage data — IP address, browser type, operating system, pages visited, and interaction patterns.
- Cookies and similar technologies — as described in our separate Cookies Policy.
- Analytics data — usage events collected through our analytics system, subject to your consent; linked to your account while you are signed in, and to an anonymous identifier otherwise.
- How you found us — when you register, the campaign details carried by the link that brought you to us (for example, which part of our website you came from), the name of the website that referred you (not the address of the page) and the first page of ours you opened. We record them once, with your new account, to learn which of our marketing brings people to GoFindPart. Nothing is stored on your device to do this.
2.3 Company officers and persons with significant control
If you apply for a trade account or for credit on behalf of a company, we use information from the Companies House public register — the names, roles, appointment and cessation dates and month and year of birth of the company’s officers, the names and natures of control of its persons with significant control, and, for each current officer, how many of their other companies have been dissolved — to check that the person applying is entitled to act for the company, to screen the company and the people who control it against the UK Sanctions List (which we are required to do by law), and to check whether a connected company already has an overdue balance with us before we extend credit. We obtain this information from the public register, not from the individuals concerned, and we do not run personal credit-reference searches on directors. Our lawful basis is our legitimate interest (UK GDPR Article 6(1)(f)) in checking that the person applying is entitled to act for the company and in identifying connected companies before we extend credit; for sanctions screening we rely on the same legitimate interest, supported by the prohibitions in the Sanctions and Anti-Money Laundering Act 2018 regimes, which we are required to observe. A match against the Sanctions List is always reviewed by a member of staff before any decision is made. Records of these checks are kept for seven years as evidence of the decision. There are no recipients of this information beyond our staff and the processors named in this policy. If you are unhappy with how we handle it, section 12 explains how to complain to us and to the Information Commissioner. If you are an officer of a company that uses GoFindPart and would like to know more, or to object, contact [email protected].
2.4 Designated payers
A trade customer may nominate a named person — for example a director or bookkeeper who is not a GoFindPart user — to pay for approved orders by card on the customer’s behalf. If you are nominated, we receive your name and email address from the customer’s finance contact, send you an email explaining the arrangement and asking you to confirm it, and, once you have confirmed, send you payment requests for specific orders with a secure link. When you pay, your card details go directly to our payment provider, Stripe; we never see or store your full card number. We record that you confirmed the nomination and made each payment (including the time and a hashed form of your internet address) as evidence of the transaction. You are paying on the customer’s behalf — the customer, not you, is our buyer, and any refund goes back to the card you paid with. Our lawful basis is our legitimate interest, and the customer’s, in settling approved orders. You can decline the nomination by not confirming it, or end it at any time by telling the customer’s finance contact or emailing [email protected]. We keep your details for as long as the nomination stands and for the period set out in section 6 afterwards.
2.5 Supplier contacts provided by sellers
Sellers may store the business contact details of their suppliers and their suppliers’ staff — a name, a telephone number, a mobile number for texts, an e-mail address and a business address — to arrange collections. If you are one of those contacts, the seller gave us your details; we did not collect them from you.
We use them only to arrange and support the collection of an order. We show them to the seller’s own team and to our staff when handling that order, and we give the courier collecting the order the collection address and your name and telephone number, so the driver can reach you.
When the seller asks us to, we also send you messages about a collection, by e-mail, by text message or both: that the order is confirmed and the part should be kept aside, when the collection is booked, when the driver is on the way, and if it is cancelled — at most four messages for one collection, and never marketing. Each message links to a page showing the part and how the collection is going. The messages and the page never show you the buyer or the price. From the page you can tell the seller the part is ready or that there is a problem.
Where a seller lets buyers collect from your premises, the buyer is given your address (never your business name) and a collection note the seller writes. When they collect, you scan the code they show and photograph the part, from the page; the collection is complete only when the buyer confirms they have the part. We keep the photograph and the time of the handover with the order as evidence of it.
Our lawful basis is our legitimate interest, and the seller’s, in getting the order collected. We keep your contact details for 90 days after the seller removes you from their list or the order is finished, and the business name and address with the order record.
To stop us messaging you, use Stop these messages in any e-mail or on the page, or reply STOP to a text where the text says you can. We then stop messaging you about any seller’s collections, and keep a record that you asked us to stop — a coded form of your address or number, not the address or number itself — so that we keep to it. Stopping our messages does not stop a courier’s driver telephoning you about a collection; to object to that, contact us. You have the rights described in section 7, and may complain as section 12 explains. Questions, or to know what we hold about you: [email protected].
2.6 People a customer hands an order over to
A buyer who will not be there when an order arrives, or a seller who will not be there when it is collected, may hand it over to up to three people on the Platform. If you are one of them, the buyer or seller gave us your name, e-mail address and, if they chose, your mobile number; we did not collect them from you.
We use them only for that order. We send you a link, by e-mail and by text if we have your mobile, to a page that shows the part, how the order is going, when it is expected and the delivery postcode — never the address’s first line and never a price — and we send you a small number of messages about it: that it has been handed over to you, when it is on its way, that it is out for delivery today, if it is running late, when it is arriving, if the carrier could not deliver it, when it has been delivered, and if the hand-over is stopped (and, if the buyer lets you choose a quote, when quotes arrive and before the request closes; and, if you paid, that your order was placed, or that the hold on your card was released or your payment refunded). Never marketing. If you are the contact for the delivery or collection, we give your name and mobile number to the courier so the driver can reach you.
If the buyer lets you collect, we text a code to your mobile before we show you a collection code of your own. When you collect, the seller (or the business handing the part over) sees your first name. We keep the time of the collection with the order, with a reference to your hand-over, as evidence of it; your name and contact details are removed as described below. Where the buyer must confirm a handover at a counter and you collected it with your own code, you may confirm it for them from the phone that received our code; we keep the time of your confirmation with the order.
If a seller asks you to hand a part over at their collection point, you check the buyer’s collection code on your page, photograph the part and confirm the handover, and the buyer then confirms they have it. You see the buyer’s reference on the Platform, never their name or contact details. We keep with the order the time of the handover, how the code was checked and your photograph of the part, as evidence that the goods changed hands; you can ask us to delete the photograph.
If the buyer lets you choose and pay for a quote, you see the quotes, with their prices, once we have checked your phone, and you pay with your own card, on the buyer’s behalf: the buyer, not you, is our customer, and any refund goes back to the card you paid with. Your card details go directly to our payment provider, Stripe. We record your typed name and your agreement, with the time and a coded form of your internet address, as evidence of the payment.
If the order is a trade organisation’s, the organisation’s administrators and the approvers at the site it is for can also see that you are following it — your first name, your e-mail address partly hidden, whether we have your mobile number, and what you can do and when — and can stop your link, because the organisation answers for its orders and needs to know who outside it is following them.
Our lawful basis is our legitimate interest, and the buyer’s or seller’s, in getting the order delivered, collected or paid for as they asked. We remove your contact details 90 days after your link stops working — it stops when the order is done, when the person who handed it over takes it back or the order is cancelled, and at the latest when it expires — or later only while a dispute about the order is open, or where the law requires us to keep them. We keep the record of a collection or a handover with the order record, and the record of a payment for six years from the payment.
To stop us messaging you, use Stop these messages in any e-mail or on the page, or reply STOP to a text where the text says you can. We then stop messaging you about anyone’s orders, and keep a record that you asked us to stop — a coded form of your address or number, not the address or number itself — so that we keep to it. Stopping our messages does not stop a courier’s driver telephoning you about a delivery you are the contact for; to object to that, contact us. You have the rights described in section 7, and may complain as section 12 explains. Questions, or to know what we hold about you: [email protected].
2.7 People who request our security report
Our Security page offers a security report produced by Aikido Security (Aikido Security BV, Belgium), the service we use to scan our source code, the configuration of our cloud accounts and our public websites for security weaknesses. To ask for it, you give your full name, your company’s name and your email address on a request form on Aikido’s website. Aikido passes your request to us, and if we approve it, Aikido emails the report to the address you gave.
We use your details only to decide on your request and to send you the report. Our lawful basis is our legitimate interest in answering a request you made to us. Aikido holds your details for us as our processor (section 4.3), and the GoFindPart staff who decide on requests see them. Aikido is based in the European Union; some of its own providers may process data in the United States, under the safeguards described in section 5. When you visit Aikido’s website, Aikido’s own privacy policy also applies to what that website records, such as your internet address.
We keep your details for as long as we use Aikido, unless you ask us to delete them sooner. You have the rights described in section 7, and may complain as section 12 explains. Questions, or to have your request deleted: [email protected].
3. How We Use Your Personal Data
We use your personal data for the following purposes and on the following lawful bases:
| Purpose | Lawful Basis |
|---|---|
| Providing and operating the Platform | Performance of contract |
| Processing Transactions and payments (as seller of record to Buyers) | Performance of contract |
| Issuing self-billed VAT invoices on behalf of VAT-registered Sellers | Performance of contract + legal obligation (HMRC self-billing requirements) |
| Calculating delivery costs and routing fulfilment | Legitimate interests |
| Managing your account and communications | Performance of contract |
| Fraud prevention and security | Legitimate interests |
| Resolving disputes and product claims between Buyers and GoFindPart, and managing recovery against Fulfilling Suppliers | Performance of contract |
| Calculating Seller Tier and Priority Score | Legitimate interests |
| Calculating Buyer account standing (behavioural scoring for fraud and abuse prevention, based on adjudicated transaction outcomes such as cancellations, disputes, returns, and payment events) | Legitimate interests |
| Retaining the identity of the Fulfilling Supplier for any given Transaction so that we can disclose it on request under the Consumer Protection Act 1987 and discharge our obligations as the supplier of record | Legal obligation (CPA 1987 s.2(3) and related supplier obligations) + legitimate interests |
| Compliance with other legal obligations (e.g. anti-money laundering, tax, accounting) | Legal obligation |
| Analytics and Platform improvement (with consent) | Consent |
| Recording how you found us when you register — the campaign details on the link you followed, the referring website and the first page you opened (section 2.2) — to learn which of our marketing brings people to the Platform | Legitimate interests |
| Marketing communications (with consent) | Consent |
| Verifying your identity through Stripe Identity (document and selfie) before you quote as a seller, before a high-value purchase, or as a trade-account applicant | Legitimate interests (fraud prevention; our obligations as seller of record) |
| Checking that a person applying for a trade account or credit is entitled to act for the company, screening the company and its officers and controllers against the UK Sanctions List, and checking connected companies for overdue balances before extending credit (section 2.3) | Legitimate interests (supported, for the screening limb, by the Sanctions and Anti-Money Laundering Act 2018 regimes) |
| Settling approved orders paid by a designated payer on a trade customer’s behalf (section 2.4) | Legitimate interests (ours and the customer’s) |
| Arranging a collection a seller has asked us to arrange at its supplier: messaging the supplier’s contact by e-mail or text, the supplier’s collection page, and giving the courier the contact’s name and telephone number (section 2.5) | Legitimate interests (ours and the seller’s) |
| Recording a handover at a supplier’s premises — the supplier’s scan of your collection code, their photograph of the part and your confirmation that you received it — as evidence that the goods changed hands | Performance of contract (for you as the buyer) and legitimate interests (establishing and defending claims) |
| Sharing an order with the people a buyer or seller hands it over to, as they ask: messaging them, their page, giving the courier the name and mobile number of the person who is the contact, and recording a collection or a handover by one of them (section 2.6) | Performance of contract (for the buyer or seller who asked) and legitimate interests (for the person the order is handed over to) |
| Taking payment from a person a buyer has let pay for their order with the person’s own card (section 2.6) | Legitimate interests (ours and the buyer’s) |
| Answering a request for our security report made on Aikido’s request form: deciding on it and sending the report (section 2.7) | Legitimate interests |
| Operating trade-organisation memberships, purchase-approval workflows, and spending controls on behalf of organisation customers | Legitimate interests (organisational governance and financial accountability) |
| Recording member actions in an organisation-visible activity log | Legitimate interests (accountability for spending decisions; see section 4.5) |
| Showing an organisation’s administrator the name and work email of accounts on its verified email domain (opt-out available) | Legitimate interests (workforce account governance), with prior notice |
| Processing site-contact details and working-hours schedules supplied by an organisation | Legitimate interests, with notice at first contact and confirmation before use |
| Keeping a site’s stock list on a trade organisation’s behalf — recording who added, changed, removed or shared a part, who uploaded a file and who accepted a quote — and checking each line of a file the organisation uploads with an automated service (section 4.4) | Legitimate interests (organisational governance) and performance of contract (the import the organisation asks for) |
| Reading the label you photograph on a stock bin to find the part on your site’s stock list, and recording that a label was read | Legitimate interests (helping your organisation’s team find a part on its own list, and controlling what each read costs us); the photograph is yours to take — typing what the label says does the same |
| Retaining anonymised purchase-approval records after erasure requests | Legal obligation (HMRC record-keeping; Limitation Act 1980) |
| Identifying a part from the photographs, a link or the details a seller gives us — to add it to the seller’s stock, or to check a part a seller suggests in place of the one a buyer asked for | Performance of contract (for the seller) and legitimate interests (checking a suggested part before a buyer relies on it) |
4. Sharing Your Personal Data
We may share your personal data with the following recipients:
4.1 Other Platform users
Limited information is shared between users to facilitate fulfilment:
- The Buyer does not see the identity of the Fulfilling Supplier in the normal course of using the Platform. GoFindPart presents itself as the contracting seller; the Fulfilling Supplier’s identity is retained internally and disclosed only as set out in section 4.2 below.
- The Fulfilling Supplier sees the Buyer’s name and delivery address post-acceptance, to enable fulfilment. The Supplier may not use Buyer information for any purpose other than completing the Transaction.
- Collecting from a supplier’s premises. Where a seller lets buyers collect from its own supplier and you choose to, the supplier’s staff at the counter see you when you collect and scan the collection code you show them. We do not give them your name, your company or your delivery address, and the page they use shows only the part and the collection reference. A seller’s supplier never sees your name or address through the Platform.
- Parts a seller suggests. When a seller suggests a part in place of the one a buyer asked for and the buyer approves it, other sellers can quote that part on the request. They see the part — its maker, part number and details — never which seller suggested it, the seller’s photographs, a link the seller gave, or the seller’s own words.
- People you hand an order over to. If you hand a request or an order over to someone (section 2.6), they see your first name, the part, how the order is going, when it is expected and the postcode of the delivery address — and, if you let them choose and pay, the request and the quotes as you see them, once we have checked their phone. They never see your account, your other requests, your payment details or your own collection code.
- A person collecting for the buyer. When someone collects an order for a buyer, the seller (or the business handing the part over) sees that person’s first name. A person collecting for a buyer, like the buyer, sees the collection point and the name the order shows.
- A person handing over for a seller. When a seller asks someone to hand a part over at their collection point, that person sees the buyer’s reference on the Platform, the part and the collection — never the buyer’s name or contact details — and the buyer is told that the seller handed it over.
4.2 Disclosure of the Fulfilling Supplier’s identity
In the following circumstances, GoFindPart may disclose the identity of the Fulfilling Supplier (business name, registered address, contact details, VAT number) to a third party:
- (a) CPA 1987 requests. Where a Buyer makes a request under section 2(3) of the Consumer Protection Act 1987 to identify the producer of defective goods, GoFindPart will disclose the Fulfilling Supplier’s identity to the Buyer (or to the Buyer’s legal representative) within a reasonable time.
- (b) Regulator requests. Where a regulator with lawful jurisdiction over the goods requests the Supplier’s identity.
- (c) Legal proceedings. Where required by a court, tribunal, or other legal authority in connection with legal proceedings.
- (d) Third parties with a valid legal basis — including holders of intellectual property rights making credible infringement complaints relating to goods supplied.
- (e) Professional advisers. Our legal, accounting, and audit advisers, bound by duties of confidentiality.
Every disclosure under this section 4.2 is recorded in an internal audit log (requester, reason, timestamp).
The Fulfilling Supplier’s consent to these disclosures is captured through the Seller Terms and Conditions as a condition of using the Platform.
4.3 Service providers and processors
- Stripe — payment processing, Stripe Connect onboarding / identity verification for Sellers, and self-billed-invoice payment routing. Stripe acts as an independent data controller.
- Crisp (Crisp IM SAS, France) — in-Platform support chat. Crisp runs server-side only: when you message support, our backend relays the conversation (your email, display name, and the message content) to Crisp so our team can respond. Crisp does not load any software or set any cookies in your browser. Crisp processes this data as our data processor under their data processing terms, within the European Union.
- Delivery providers — where a courier service is engaged, we share the details needed to fulfil the delivery (names, addresses and contact telephone numbers — including, where goods are collected from a seller’s supplier, the name and telephone number of the supplier’s contact, and, where a buyer or seller has handed an order over to someone, that person’s name and mobile number, so the driver can reach them — the parcel’s dimensions and weight, a short description of the goods and their declared value) with our courier partners: our same-day couriers (Gophr, Stuart) directly and, for parcel collections and deliveries, our carrier broker Interparcel Limited, which passes them to the carrier selected for the parcel (for example DPD, Evri, Parcelforce, UPS or CitySprint; the full list is on our sub-processor register). None of them is our processor: Interparcel’s privacy policy names it as the controller of the details it receives, and it says it keeps order details for up to six years; each carrier’s own privacy notice says how it uses the details and where it processes them, and some say they may transfer them to other countries under the safeguards the law requires. We do not pass them your e-mail address or ask them to contact you; a carrier may still send delivery updates to the telephone number on the parcel under its own privacy notice.
- Cloud service providers — hosting (Fly.io, London (lhr) region, United Kingdom), database (Neon), caching (Upstash), email and text-message delivery (AWS), and storage (AWS S3) providers who process data on our behalf under data-processing agreements.
- Cloudflare, Inc. (United States) — protects our sign-up and contact forms from automated abuse (Cloudflare Turnstile), and delivers and secures the websites themselves. To tell a person from a bot, Turnstile receives your IP address. As the service that answers every request to our sites, Cloudflare also handles the connection itself.
- Google LLC (United States) — checks and standardises delivery addresses, converts them to map coordinates, and calculates distances between a collection point and a delivery point. Google receives the address you enter and the coordinates derived from it. We use this to work out what a delivery will cost and how far a seller is from you.
- Ideal Postcodes (IDDQD Limited, United Kingdom) — when you type a full UK postcode into an address field, suggests the addresses at that postcode from Royal Mail’s Postcode Address File so you can choose yours. Ideal Postcodes receives only the postcode you typed — not your name, your account or any other detail — and processes it in the United Kingdom and the European Union. Anything else you type into an address field is looked up by Google (above).
- Plausible Insights OÜ (European Union, Estonia) — privacy-focused analytics on our public marketing site only, never inside the signed-in Platform. Plausible sets no cookies and builds no profile; it receives your IP address and browser type so it can tell which country and kind of device a visit came from and count one person once, and discards them after that. It is not loaded when your browser sends the Global Privacy Control signal or you have turned analytics off for your device (see the Cookies Policy).
- Sentry (Functional Software, Inc., United States) — error monitoring for our public website and the Platform. When something breaks in your browser or on our servers, Sentry receives the error message and the place in our code it came from, the address of the page you were on, and your browser type and version, so we can reproduce and fix the fault. No session recordings are made, no form contents are sent, and your IP address is not stored with the report. Reports are deleted after 90 days. The transfer to the United States is covered by Sentry’s data-processing agreement, which incorporates the safeguards described in section 5. On the public website the same signal and control that turn analytics off turn error reporting off.
- Aikido Security (Aikido Security BV, Belgium) — scans our source code, the configuration of our cloud accounts and our public websites for security weaknesses; protects our servers against attempts to break into the Platform; and runs the form on which you can ask for our security report (section 2.7). Aikido’s software runs inside our servers and checks each request for known kinds of attack. When a request looks like one, Aikido receives a report of it: the address requested, the IP address it came from, your browser type, and the part of the request that looked like an attack. It also receives counts of requests and the names of the outside services our servers contact; it does not receive your name, email address or account. Aikido receives the full name, company name and email address you enter on the report form, holds them for us as our data processor under its data-processing terms, and emails you the report if we approve your request. Aikido does not read our database: its software checks a database instruction before it runs and sends one to Aikido only when it looks like an attack. Aikido does not publish a fixed period for keeping these reports: it keeps them while we use its service, and its customer agreement requires our data to be purged from its systems within 200 days after that agreement ends. Some of its own providers may process data in the United States, under the safeguards described in section 5.
- Professional advisers — legal, accounting, audit, and insurance advisers where necessary.
- Law enforcement and regulatory bodies — where required by law or in response to valid legal process.
We do not sell your personal data to third parties. We do not use advertising cookies or share cookie data with advertising networks.
A structured, itemised register of our sub-processors is published at https://gofindpart.com/legal/subprocessors (register v1.15.0, effective 2026-10-03). The register is maintained for transparency and carries its own version number, which we cite here as the version this Policy was last reviewed against; if the register and this Privacy Policy ever disagree, this Privacy Policy prevails.
4.4 Where we store your data
Your core account and marketplace data is hosted and stored in the United Kingdom. Our database of record (Neon PostgreSQL), file storage (AWS S3), and application servers (Fly.io) all run in the London region.
A small number of specialist sub-processors operate outside the UK — for example payment processing (Stripe), error monitoring (Sentry), AI-assisted request parsing and matching, identifying a part from a seller’s photographs of it, a link to its page or its details (to add it to stock, or when a seller suggests a part in place of the one a buyer asked for), the checking of each line of a stock list a trade organisation uploads or asks us to run — the line’s description, its category, part number, maker and any standard designation, never the supplier, the site or the stock levels — the reading of a stock label a member of a trade organisation photographs to find a part on its list (the photograph, with its hidden details removed, sent once and not kept by us; it may show the organisation’s own codes for the part) — and the mapping of the columns and category names of a stock file a seller uploads (OpenAI, Anthropic), automated first-line replies in our support chat (Anthropic — when you message support, the conversation text may be processed to generate an automated reply, always labelled as automated, with a human handover available at any time), email and text-message delivery (AWS), and security scanning, the protection of our servers against attacks and the security report request form (Aikido). Where personal data is transferred outside the UK it is protected by the safeguards described in section 5 (International Transfers); the full list of sub-processors is in section 4.3.
4.5 Trade organisations and team accounts
If you use GoFindPart as a member of a trade organisation (for example, your employer’s account), the following applies in addition to the rest of this policy:
- Your organisation sees your activity within it. Actions you take in the organisation — submitting purchase requests, approving or declining purchases, changes to team membership and sites, and changes to your site’s stock list (which part, and which of its details — never the values you typed) — are recorded in the organisation’s activity log and are visible to its approvers and administrators. This log records what you did and when; it never includes your IP address, device details, or location.
- People you hand an order over to. On a trade request, if you hand an order over to someone, your organisation’s administrators and the approvers at your site can see who you handed it to and can stop their link (section 2.6).
- Colleagues at your site may see your open part requests. To stop the same site buying the same part twice, if a colleague at your site asks for a part you already have an open request for, they may be shown your name, when you raised the request, its quantity, and whether it is still open or already ordered — never prices or suppliers — so the two of you can combine orders. You are reminded of this on the request form whenever it applies, every such disclosure is recorded in the organisation’s activity log, and you can object to this processing at any time (see section 7).
- Your site’s stock list. Your organisation’s approvers and administrators keep a list of the parts each site holds, and your site’s list shows you where a part is kept. Words you type into that list — a name for a part, where it is kept, a note — belong to the list and stay in it if you leave, so please do not put personal details about other people in them. If you share a part from My parts with your site, the site’s master approver or your organisation’s administrator sees that you shared it, together with the name and location you chose to share (your notes only if you choose to include them), and decides whether to add it. The list itself never shows who shared a part. You can suggest a change to an entry you shared, which the same people decide, and you can object to this processing at any time (see section 7).
- Seats, not accounts. Your organisation’s administrators manage your membership (your seat, role, site assignment, and spending limits). They do not control your GoFindPart account. If your organisation removes you, your seat is deactivated and its personal details are anonymised after 90 days; your own account and its rights under section 7 are unaffected.
- Approval records are kept. Records of purchase requests and approvals are financial records of the organisation. If you ask us to erase your data, we anonymise your identity in these records but the financial record itself is retained (up to 7 years) to meet legal record-keeping obligations.
- Work email domains. Where an organisation has verified ownership of its email domain, its administrator may see the name and work email of platform accounts registered on that domain, so they can invite colleagues. You will be notified before this applies to you, and you can opt out at any time in your account settings.
- Site contact details. If your employer adds you as a site contact (for example, for deliveries), we will email you first to explain what we hold and let you confirm — we do not send operational messages until you accept, and you can opt out of categories of messages at any time. Your working-hours schedule is deleted immediately when you stop being a contact.
- Who is responsible. For the data processed inside your organisation’s account, GoFindPart and your organisation each act as described in our terms with the organisation. Requests about your seat (role, limits, membership) are best directed to your organisation; requests about your account and your legal rights come to us as set out in section 7.
5. International Transfers
Your personal data may be transferred to and processed in countries outside the United Kingdom where our service providers are located. Where this occurs, we ensure appropriate safeguards are in place, including UK International Data Transfer Agreements (“UK IDTAs”), the UK Addendum to the EU Standard Contractual Clauses, or reliance on adequacy decisions made by the UK government.
6. Data Retention
We retain personal data for the following periods:
| Data Type | Retention Period | Reason |
|---|---|---|
| Account data | Until deletion requested (subject to legal-obligation exceptions) | Service provision |
| Parts you save in My parts, with your name, notes, location and groups for each | Until you delete the part or erase your account. If your account is under a legal hold when you delete a part, it leaves your list at once and is deleted when the hold ends. If we withdraw My parts, twelve months after it is switched off | Providing the service |
| Transaction records | 7 years from Transaction completion | UK tax and accounting law |
| Self-billed VAT invoices | 6 years from issue (or longer where HMRC requires) | HMRC self-billing record-keeping requirements |
| Audit logs | 7 years | Security, compliance, and disclosure-trail requirements |
| Dispute evidence | 2 years from resolution (or longer where related to an unresolved product claim) | Legal-claims limitation |
| Fulfilling Supplier identity records (linked to each Transaction) | 10 years from the date of supply | Consumer Protection Act 1987 limitation period for product-liability claims; supports our obligation to identify the producer on request |
| Certifications of conformance given when goods are dispatched or handed over — the part, any batch or lot stated, and the name of the person who gave the certification (the seller or a member of the seller’s team) | 10 years from the date of supply | Evidence for warranty and product-liability claims (Consumer Protection Act 1987 limitation period); kept after an erasure request where needed to defend legal claims |
| Seller tax identifiers (National Insurance number, partnership UTR, company number, date of birth, registered address) | 6 years from the end of the reportable period in which they were last used | Legal obligation — UK digital-platform reporting, Platform Operators (Due Diligence and Reporting Requirements) Regulations 2023 (SI 2023/817). Retained through an erasure request on the Art 17(3)(b) basis and disclosed to you as retained when you erase your account |
| Operational logs | 90 days | Debugging and security |
| Error reports sent to Sentry (section 4.3) | 90 days, then deleted by Sentry | Diagnosing faults in our website and the Platform |
| Reports of requests that looked like an attack, sent to Aikido (section 4.3) | While we use Aikido; Aikido publishes no fixed period, and its customer agreement requires our data to be purged from its systems within 200 days after that agreement ends | Protecting the Platform against attacks |
| Analytics events | 26 months, then deleted; deleted earlier if you erase your account | Platform improvement |
| How you found us (recorded when you register, section 2.2) | With your account; removed when you erase your account | Learning which of our marketing works |
| Identity-verification outputs (verified name, month and year of birth — encrypted) | 6 years after our relationship ends, with the decisions they supported | Evidence that the person was who they said when money moved (fraud defence; Limitation Act 1980) |
| Company-officer, authority and sanctions-screening check records (section 2.3) | 7 years | Evidence of the decision; Sanctions and Anti-Money Laundering Act 2018 compliance |
| Designated-payer details and payment-request records (section 2.4) | For as long as the nomination stands, then 6 years from the last payment request; a nomination that is revoked before any request is anonymised after 90 days | Transaction evidence |
| Trade-organisation records | Purchase approvals: 7 years (identity anonymised on erasure requests). Organisation activity logs: up to 7 years for governance events, 2 years for operational events. Deactivated team-seat and site-contact details: anonymised after 90 days | Legal record-keeping obligations and organisational governance (see section 4.5) |
| A part you share with your site, or a change you suggest to one | 90 days after it is declined or withdrawn; an accepted share for as long as the entry it created stays in the list, then 30 days | Deciding what enters the site’s list; letting you suggest a change to an entry you shared |
| Records of who changed a site’s stock list | With the organisation’s activity log (Trade-organisation records, above); the record of accepting a quote, 7 years | Organisational governance |
| Quotes, charges and VAT invoices for a stock-list import, with the name of the person who accepted the quote | 7 years | Financial records |
| Supplier contact details a seller stores, and the copy we keep of the contact a collection message was sent to | 90 days after the seller removes the supplier from their list or the order is finished; the supplier’s business name and address kept with the order record | Arranging collections |
| A supplier contact’s request that we stop messaging them | Kept for as long as we message suppliers — a coded form of the address or number, not the address or number itself | So that we keep to the request |
| The record of a handover at a supplier’s premises — the time, the photograph of the part and the buyer’s confirmation | With the order record | Evidence that the goods changed hands |
| Photographs of a part a seller gives us to add it to stock | 30 days after the scan is finished (added, discarded or failed); if the part is added, kept with the stock item until it is deleted | Identifying the part |
| Photographs a seller gives us to suggest a part in place of the one a buyer asked for | Deleted when the seller’s quote for the part closes without being bought, or 30 days after the order’s dispute and return windows close; a suggestion never quoted, after 30 days. Kept longer only while a dispute about the part is open, or where the law requires | Identifying the part; evidence if the identification is disputed |
| Photographs of stock labels (section 2.1), and what the label said | Not kept: the photograph is discarded as soon as the label has been read, and what it said is shown to you only. The record that a label was read (by whom, when, the cost) is kept with our records of automated part reading (below) | Finding the part; controlling the cost of each read |
| Records of each time we use an automated service to read or identify a part — whose account it was for, when, the outcome, what it cost us and the part it identified | 26 months, then deleted; deleted earlier if you erase your account | Measuring what these services cost and how well they work |
| The contact details of a person a buyer or seller hands an order over to | 90 days after their link stops working; longer only while a dispute about the order is open, or where the law requires | Telling them about the order |
| The record of a collection or a handover by a person a buyer or seller named — the time, how the code was checked, a photograph of the part at a counter, and a reference to the hand-over (never their name or contact details) | With the order record | Evidence that the goods changed hands |
| The record of a payment by a person a buyer let pay for their order — their typed name, their agreement, the time and a coded internet address | 6 years from the payment | Transaction evidence |
| A request for our security report — the full name, company name and email address given on Aikido’s request form (section 2.7) | For as long as we use Aikido, unless you ask us to delete it sooner | Answering the request |
After the applicable retention period, personal data is securely deleted or anonymised.
7. Your Rights
Under the UK GDPR, you have the following rights:
- Right of access — you may request a copy of the personal data we hold about you. You can generate a data export through the Platform at any time.
- Right to rectification — you may request correction of inaccurate or incomplete data through your account settings or by contacting us.
- Right to erasure — you may request deletion of your personal
data, subject to our legal-retention obligations. In particular:
- Transaction records, audit logs, and Fulfilling Supplier identity records are retained for the periods set out in section 6 on the basis of legal obligation (UK tax law, CPA 1987, HMRC self-billing rules). These records will not be erased on request before the applicable retention period has expired.
- Right to data portability — you may request your data in a structured, machine-readable format (JSON).
- Right to restrict processing — you may request that we restrict processing of your data in certain circumstances.
- Right to object — you may object to processing based on our legitimate interests; we will consider any such objection on a case-by-case basis.
- Rights relating to automated decision-making — our Seller Tier system and our Buyer account-standing system involve automated scoring. You have the right to request human review of decisions that significantly affect you (for example, a seller tier downgrade or a PAUSED classification, or a buyer account restriction). Where a buyer account is blocked automatically on the basis of sustained, adjudicated misconduct signals, the appeal facility offered at sign-in is the guaranteed route to human review: one appeal per account, reviewed and decided by a member of our staff (UK GDPR Articles 22A–22D, as inserted by the Data (Use and Access) Act 2025).
To exercise any of these rights, please contact us at [email protected]. We will respond within one month of receiving your request.
8. Consent Management
Where we rely on consent as the lawful basis for processing (e.g. analytics, marketing), you may withdraw your consent at any time through the consent-management controls on the Platform. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
Our consent-management system operates three tiers:
- Necessary — essential cookies and processing required for the Platform to function. These cannot be disabled.
- Functional — cookies and processing for user preferences (theme, locale, last role). Requires your opt-in consent.
- Analytics — usage analytics, linked to your account while you are signed in. Requires your opt-in consent.
On our public website (the pages you can read without signing in) analytics and error reporting are cookieless and run without a consent banner, under the exemption for statistics-purpose measurement. You can still object: we honour the Global Privacy Control signal from your browser, and the “Analytics on this device” control on the Cookies Policy and Privacy Policy pages turns both off for that browser.
See the separate Cookies Policy for the cookie-level detail and the full list of what the public website loads and stores.
9. Security
We implement appropriate technical and organisational measures to protect your personal data, including encryption in transit (TLS), secure password hashing, session management, rate limiting, and regular security assessments. Card-payment data is processed by Stripe and never touches our servers (PCI DSS compliance via Stripe).
10. Children
The Platform is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified to you by email and / or a prominent notice on the Platform. The “Effective Date” at the top of this Policy indicates when it was last revised.
12. Complaints
If you are unhappy with how we handle your personal data, you can complain to us and we will deal with it under section 164A of the Data Protection Act 2018:
- In the app: Support → Your data & privacy → Complain about how we use your data. You will get a reference straight away and an email acknowledging your complaint.
- By email: [email protected] — quote your account email.
We acknowledge every complaint — immediately if you use the app, and in any event within the 30 days the law allows if you email us. We look into it and reply without undue delay — normally within 30 days — telling you the outcome and what we have done. We keep a record of complaints and how they were resolved for three years, and will report complaint numbers to the Information Commissioner if the law requires it.
You also have the right to lodge a complaint with the Information Commissioner’s Office (“ICO”) at any time, before or after complaining to us:
- Website: ico.org.uk
- Telephone: 0303 123 1113
- Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
13. Contact
For any questions about this Privacy Policy or how we process your personal data, please contact:
Data Protection Contact Go Find Part Limited Email: [email protected]
Analytics on this device
This public site uses cookieless page analytics (Plausible) and error reporting (Sentry). Neither stores anything on your device. You can turn both off for this browser here; your choice is kept in this browser's local storage until you clear it or switch it back on.
Checking this browser's setting…