Privacy notice
What we collect, why we collect it, how long we keep it, and how to have it removed.
The short version is at the top, because most people only need that. We never enter areas behind a login, so we never encounter your customers' data — and if you would rather we stopped entirely, one request ends it permanently.
Last updated 14 August 2026
The short version
We check publicly accessible business websites. We record the website address, the pages we visited, what those pages returned and when. We do not enter areas behind a login, so we never see your customers' data. If you ask us to stop, we stop and we keep a note of your domain solely so that we remember to.
What we collect, and why
1. Publicly available business information
Website addresses and the business details published alongside them in public listings — trading name, sector, town or city, and a publicly listed contact route where one exists. This is what allows us to identify which business a website belongs to and how to reach them about a finding.
2. Technical observations from public pages
- the URLs we requested
- the HTTP status codes and response headers returned
- page timings and, where relevant, browser console errors
- the date and time of each observation and re-check
- the finding itself, with its severity and confidence scores
These are the evidence behind a report. Without them a finding could not be verified, disputed or withdrawn.
3. Information you send us
If you contact us, request a check, or ask to opt out, we keep your message and the details you included — typically your name, email address and the website concerned — so that we can reply and act on it.
4. Payment information
If you buy a repair pack, payment is processed by a third-party payment provider. Card details never pass through FaultFound and we do not store them. We retain the record of the transaction that we need for accounting purposes.
What we do not collect
- Your customers' personal data. We never enter authenticated areas, so we never encounter it.
- Login credentials of any kind. We do not ask for them and cannot use them.
- The contents of your database, order records or customer messages.
- Anything obtained by bypassing an access control — we do not do that.
Our lawful basis
Where we check publicly accessible business websites and contact a business about a fault affecting its own customers, we rely on legitimate interests: our interest in offering a relevant service, balanced against the business's interest in not being contacted unnecessarily. We consider that balance carefully, which is why we only make contact when a fault has been confirmed and re-verified, and why a single opt-out request ends contact permanently.
Where you contact us or request a check, we rely on your consent and on the steps necessary to respond to your request. Where we take payment, we rely on performance of a contract and on our legal obligations for financial records.
How long we keep things
- Findings and evidence: retained while the finding is live and for a reasonable period afterwards, so it can be re-checked or disputed. Deleted on request.
- Correspondence: kept while we deal with your enquiry and for a reasonable period afterwards.
- Suppression records: kept indefinitely. This is the record that stops us contacting you again — deleting it would defeat its purpose.
- Transaction records: kept as long as UK accounting requirements demand.
Who we share it with
We do not sell data and we do not share findings about your website with anyone else. Information is shared only with the service providers needed to run the business — hosting, email delivery and payment processing — and only to the extent they need it to provide that service.
Your rights
Under UK data protection law you have the right to:
- ask what we hold about you and get a copy
- have inaccurate information corrected
- ask us to delete information we no longer need
- object to our processing, including to being contacted at all
- ask us to restrict how we use it while a query is resolved
- complain to the Information Commissioner's Office
To exercise any of these, email support@faultfound.co.uk. If you simply want us to stop, the opt-out page is the fastest route and requires no explanation from you.
This website
This site uses no advertising cookies, no tracking pixels and no third-party analytics scripts. There is no cookie banner because there is nothing to consent to. Fonts, styles and scripts are served from this domain only, so loading a page does not report your visit to anyone else.
Private report pages are unlisted, excluded from search engines, and reachable only via the link we sent. Anyone you forward that link to will be able to open it, which is deliberate — most people want to send it to their developer.
Changes to this notice
When this notice changes materially we update the date at the top. The outstanding sections marked above will be completed before public marketing begins.
Contact
support@faultfound.co.uk — or use the contact page. We aim to reply within one working day, and to any formal data request within the statutory timeframe.