Studio

Privacy & data (GDPR)

How Fern Dale Makers Studio handles your personal data under UK GDPR and the Data Protection Act 2018.

Who is the data controller?

Fern Dale Makers Studio ("we", "us") is the data controller for the personal data you provide when you create an account and use the app. You can contact us via the Contact & FAQs page.

What data we collect

Account data: email address, name (optional), business/brand name, authentication identifiers from Google sign-in if you choose to use it.

Maker records: the formulas, batch records, burn tests, PIFs, stock items, suppliers and notes you enter. This content belongs to you.

Billing data: subscription status and customer reference held by our payment processor (Stripe). We do not store full card details on our servers.

Technical data: minimal logs needed to keep the service running and secure (e.g. error traces, auth events). We do not run advertising trackers.

Uploads and file storage

You can upload files such as product labels, PIF evidence, and safety documents. These are stored in your private storage area and protected by the same row-level security as your maker records.

We do not use your uploads for advertising, training, or analytics, and we do not share them with other makers or third parties except as required to run the service (for example, our hosting/storage provider).

Who can see your information

Your account information, records, and uploads are only visible to you while you are signed in. They are not publicly accessible and cannot be viewed by other users of the app.

We only look at your information when you ask us to (for example, to resolve a support problem), or where we are legally required to do so. We do not sell or share your personal data for marketing.

Lawful bases under UK GDPR

Contract — to provide the account, store your records, and operate your subscription.

Legitimate interests — to keep the service secure, prevent abuse, and improve features.

Legal obligation — to retain financial records (e.g. invoices) for the period required by HMRC.

Consent — for any optional marketing emails (you can withdraw at any time).

Your rights

Under UK GDPR you have the right to:

  • Access a copy of the personal data we hold about you.
  • Rectify inaccurate data.
  • Erase your account and associated records ("right to be forgotten").
  • Restrict or object to certain processing.
  • Port your data — most maker records can be exported as PDF from within the app.
  • Complain to the Information Commissioner's Office (ICO) at ico.org.uk.

To exercise any right, contact us via the Contact & FAQs page. We will respond within one calendar month.

Sub-processors

We use the following providers to deliver the service:

  • Supabase — managed database, authentication and storage (EU/UK regions where available).
  • Stripe — subscription billing and payment processing.
  • Google — only if you choose Google sign-in.
  • Cloudflare — content delivery and DDoS protection.

Each provider acts as a data processor on our behalf under appropriate data-processing terms.

International transfers
Where personal data is transferred outside the UK/EEA (for example to US-based infrastructure providers), we rely on UK International Data Transfer Agreements or the EU Standard Contractual Clauses, together with the providers' additional safeguards.
Retention
We keep your account and records for as long as your account is active. If you cancel and delete your account, we remove your personal content within 30 days, except for limited financial records we are required to retain for tax purposes.
Security
The app uses HTTPS everywhere, row-level security on the database (so makers only see their own records), hashed credentials, and least-privilege access for administrators. No system is perfectly secure — please use a strong, unique password.
Cookies
We use only the cookies and local storage strictly necessary to keep you signed in and to remember your preferences. We do not set advertising or cross-site tracking cookies.