Privacy Policy
How we handle your data and your rights under UK law.
Effective Date: 19 May 2025
1. Who We Are
StashForge is operated by Chris Baines as a sole trader in the United Kingdom.
If you have any questions about this policy, please use our contact form.
2. What Information We Collect
- Account details: name, email, password
- Subscription and payment data via Stripe
- IP address, device info, session and security cookies
- Stash and usage activity (e.g. paints you own, comments)
3. How We Use Your Data
- To provide your account and membership features
- To process payments securely via Stripe
- To communicate service updates and support
- To improve security and performance
4. Legal Basis
We process your data under:
- Contract: To provide our service
- Legal obligation: For tax/compliance
- Legitimate interests: Security and service improvement
- Consent: For any optional communications
5. Sharing Your Information
We don’t sell your data. We share it only with trusted processors like:
- Stripe: Payments
- Laravel Hosting / Cloud Services: Infrastructure
6. Cookies
We use essential cookies for login, sessions, and payment processing. We currently do not use tracking or analytics cookies.
A cookie notice is shown to inform users and obtain consent where necessary.
7. Data Retention
We retain data while your account is active. After closure, we may keep necessary records for up to 6 years for tax/legal reasons.
8. Your Rights
You have the right to:
- Access your personal data
- Request correction or deletion
- Withdraw consent at any time
- File a complaint with the ICO (Information Commissioner’s Office)
9. Children’s Privacy
StashForge is not designed for children under 16. We do not knowingly collect data from minors.
10. Changes
This policy may be updated from time to time. Major changes will be communicated via email or on our website.