Privacy Shield
Last Updated: August 23, 2026 · Protocol V3.0 · UK GDPR Compliant
Privacy questions? Email office@partshift.co.uk.
1. Who We Are (Data Controller)
PartShift ("we", "us") is a B2B automotive parts marketplace operated from the United Kingdom. For UK GDPR purposes, PartShift is the data controller for personal data processed through the Platform.
Contact for all privacy matters: office@partshift.co.uk.
2. What Data We Collect
Account data: your name/business name, email address, hashed password, and shop association.
Business data: shop details you provide or that appear in our public registry of UK bodyshops and breakers (sourced from public records such as Companies House, OpenStreetMap, and Google Places), including address, postcode, and coordinates.
Transaction data: reservations made, wanted requests posted, payment confirmations from our payment processor (we never see or store full card numbers), dispute records, and reputation events.
Technical data: IP addresses, request timestamps, and security logs used for rate-limiting and abuse prevention.
Communications data: emails and notifications we send you, and messages you send us.
3. Why We Process It — Lawful Bases
Providing the marketplace (accounts, listings, reservations, reveals): performance of a contract with you.
Security, anti-fraud, rate-limiting, tarpitting: legitimate interests in protecting the Platform and its Members.
Service emails (receipts, reservation alerts, syndication notices): performance of contract; transactional messages are not marketing.
Legal obligations (record-keeping, tax): legal obligation.
We do not use your data for third-party marketing, and we do not sell personal data to anyone.
4. Need-to-Know Data Policy
PartShift operates on a "Zero-Knowledge" bias for sensitive PII. Shop addresses, phone numbers, and direct contact emails are locked until a verified £5 service fee is paid — and are then revealed only to the paying Member for the purpose of arranging collection.
Revealed contact details may be used only to complete the specific part transaction. Systematic harvesting or redistribution of revealed details is a breach of our Terms and will result in permanent exclusion.
5. Payment Processing
Payments are processed by Stripe Payments Europe Ltd. We receive confirmation of payment status (authorised, captured, refunded) but never receive or store your card number. Stripe acts as an independent controller for its own fraud-prevention processing under its own privacy policy.
6. Service Providers (Processors)
We share personal data only with the providers needed to run the Platform:
• Supabase (database & authentication) — account and marketplace data; hosted in the EU/UK region.
• Stripe — payment authorisation, capture and refunds.
• Resend — transactional email delivery.
• Cloudflare — hosting, CDN, object storage for syndication files, and DDoS protection.
• Google Gemini API — AI-assisted extraction of OEM numbers from photos you upload (listing content only).
Each provider processes data under a contract with us and only per our instructions.
7. International Transfers
Some providers may process data outside the UK/EEA. Where that happens, transfers are protected by the UK International Data Transfer Addendum or equivalent safeguards (such as the EU Standard Contractual Clauses adopted for UK use).
8. How Long We Keep Data
Account data: for as long as your account is active, plus up to 24 months after closure for security and dispute-resolution purposes.
Transaction and ledger records: up to 7 years, as required for financial record-keeping.
Security logs and rate-limit entries: typically 30–90 days.
Wanted requests: expired automatically after 14 days; records retained for a further 12 months for matching quality analysis.
9. Your Rights
Under UK GDPR you have the right to: access your personal data; correct inaccurate data; erase data (where retention rules allow); restrict or object to processing; data portability; and withdraw consent where processing is based on consent.
To exercise any right, email office@partshift.co.uk. We respond within one month. You also have the right to complain to the Information Commissioner's Office (ico.org.uk) — though we would appreciate the chance to fix any issue first.
10. Cookies & Anti-Bot Protection
We use strictly necessary cookies for session management and security. No advertising or analytics tracking cookies are used.
Our "Adaptive Tarpit" defence tracks IP addresses and request patterns purely to prevent automated scraping and denial-of-service attacks. This is legitimate-interest processing under UK GDPR.
11. Security
Data is encrypted in transit (TLS) and at rest. Passwords are stored as salted hashes by our authentication provider. Sensitive seller contact details are cryptographically sealed until a verified transaction occurs. Access to production data is restricted and audited.
12. Personal Data Breaches
In the event of a personal data breach likely to affect your rights, we will notify the ICO within 72 hours where required, and inform affected Members without undue delay.
13. Changes to This Policy
We may update this policy; material changes will be announced on the Platform. The "Last Updated" date above always reflects the current version.
Your data is secured by HMAC-SHA256 signatures and linear tarpitting.
Protocol enforced by the Ironclad Mandate.