Studio

Privacy & data (GDPR)

How Fern Dale Makers Studio handles your personal data under UK GDPR and the Data Protection Act 2018.

Who is the data controller?

Kathryn Barnes, trading as Fern Dale Handcrafted, operator of Fern Dale Makers Studio ("we", "us"), is the data controller for the personal data you provide when you create an account and use the app. You can contact us via the Contact & FAQs page.

What data we collect

Account data: email address, name (optional), business/brand name, authentication identifiers from Google or Apple sign-in if you choose to use them.

Maker records: the formulas, batch records, testing records, PIFs, ingredient library entries, stock items, suppliers, costings and notes you enter, and any marketing content you generate and save. This content belongs to you.

Maker products, market days and events: the general maker product records you create, the events or market days you set up, the quantities you take to an event and the takings, sales and reflections you record afterwards. These figures are your own bookkeeping notes — they are event-only records, are not connected to Stock Room stock levels, and are never shared with anyone else. The Studio is not a till, payment processor or accounting system, so no card or payment data from a market day passes through it.

Sales information you bring in from a selling platform: if you import an Etsy sales file, or in future connect your own online shop, we store the order reference, order date, the items, quantities, prices, currency, any discount, refund or cancellation shown, and the link you make between a listing and your own product record. We do not ask for or store your customers' names, email addresses, postal addresses or phone numbers from those sales, and no card or payment details pass through the Studio. This information is used only to show you your own sales and what you keep after costs, is private to your account, is never shared with other users and is never sent to any AI model. If you disconnect a shop or stop importing, the sales you have already brought in stay in your account until you delete them.

Your craft profile and plan: the product types and crafts you tick in your maker profile, so the workspace shows the areas relevant to you, and which subscription plan you hold, so the app knows which areas to open. Your craft choices are personalisation only and do not change what you have paid for.

Billing data: subscription status and customer reference held by our payment processor (Stripe on the web, or Apple/Google if you subscribe inside a store version of the app). We do not store full card details on our servers.

Planning and idea content: planner items and notes, concepts, Grow reflections, and anything you draw, write, pin or upload on The Drawing Board. These are private to your account, are never used to train AI models, and are not sent to any AI model — no AI feature reads your boards, planner or Grow notes.

Other people's details you enter: if you use Customers and Invoices, or record client product briefs, supplier and stockist contacts, uploaded supplier or client documents, or notes that mention identifiable people, you may enter third-party personal data. Client product briefs should record only non-sensitive product preferences and commercial requirements — you must not enter health information, skin conditions, allergy details linked to an identifiable person, or any other special-category personal data. For all of that content you are the data controller and we act as your processor — we store it so the relevant features work, and we do not use it for any other purpose or market to those people. No AI feature reads your customer, invoice, brief, contact, note, planner or Drawing Board records. The one exception is where you deliberately submit an uploaded supplier document for AI auto-fill: that file is sent in full on your instruction and may incidentally contain third-party personal data (see “AI features” below). You are responsible for having a lawful basis for holding it, and for telling us if you want it returned or deleted. Those terms are set out in full in our Data Processing Agreement, which applies automatically to every subscription.

Technical data: minimal logs needed to keep the service running and secure (e.g. error traces, sign-in events). We do not run advertising trackers or analytics products.

Email records: when we send you an account email (sign-in, password reset, verification, subscription confirmation or a feature announcement) we keep a short record of the address it went to, which email it was and whether it was delivered, so we can help you if something does not arrive. If a message bounces or you unsubscribe, we keep your address on a suppression list so we stop emailing it.

Support Desk requests: when you open a request in the in-app Support Desk we hold what you write, the type of request, the part of the Studio and the page address it relates to, any file you attach, the messages exchanged with us, and the status and reference of the request. This is used only to answer you and to keep a record of what was asked and answered — it is never sent to an AI model, and it is not used for marketing. We keep resolved requests while they are useful for support history and to meet our legal obligations, and they are deleted with your account. Where a request is a data-protection request, we may need to keep a short record of it, and of how we handled it, to show we complied.

Notifications on the Apple and Android app versions: if you allow notifications, your device's notification token is stored against your account so reminders you have set can reach that device. Nothing is collected on the website version, and the token is deleted with your account.

Uploads and file storage

You can upload files such as product labels, PIF evidence, and safety documents. These are stored in your private storage area and protected by the same row-level security as your maker records.

We do not use your uploads for advertising, training, or analytics, and we do not share them with other makers or third parties except as required to run the service (for example, our hosting/storage provider).

Who can see your information

Your account information, records and uploads are private to your account: they are not publicly accessible and cannot be viewed by other users of the app. They are not, however, technically invisible to everyone — a small number of authorised people can reach them under tightly controlled conditions, namely our support access when you ask us to look at a problem, security investigation where we suspect abuse or a breach, and the administrative access held by our hosting, backend and storage providers to operate and back up the platform. That access is limited to what is needed, logged, and covered by confidentiality and written data-protection terms.

We access your information only where it is reasonably necessary to provide support you have asked for, to operate or secure the service, to investigate abuse or a suspected personal data breach, or to comply with a legal obligation. Any such access is limited to the least amount of data needed for that purpose, is subject to confidentiality obligations, and is never used to sell or share your personal data for marketing.

AI features — what leaves the Studio and what stays in it

Two parts of the app use AI models operated by third parties: document auto-fill in the Ingredient Library, and the optional Marketing Suite. Nothing is sent to an AI model unless you take an action that asks for it — there is no background processing of your records.

Supplier-document auto-fill (Ingredient Library)

When you deliberately choose auto-fill on a supplier document you have uploaded (SDS, TDS, IFRA certificate, allergen declaration, specification sheet), the uploaded PDF or image file itself is sent to the AI service so that its contents can be read and proposed back to you as structured ingredient data. It is the file that is transmitted, not a filtered extract of it.

This means the process may read anything contained in that supplier document, including supplier percentages or usage levels, allergen declarations, IFRA limits, CLP/UFI information, base composition and supplier batch or lot information where those appear on the document.

It also means the file may incidentally contain third-party personal data — for example a named supplier account contact, a direct email address, a telephone number or a signature. That content is sent to the AI service on your own documented instruction, and for that limited action the Lovable AI Gateway and the model provider used are treated and disclosed as sub-processors. Please remove or redact personal data you do not need read before you submit a supplier document for auto-fill.

Outside that deliberate action, no AI feature reaches your records: AI does not independently access your customer records, invoices, client briefs, supplier-contact records, notes, planner content or Drawing Board content, and none of those records are used to train AI models.

These are supplier and raw-material records provided to you by your supplier — they are not your own finished-product formulation. This process is separate from the Marketing Suite and from how the Marketing Suite treats your own formulations. Extracted values are always shown to you as suggestions before anything is saved, and auto-fill only runs on the document you select.

Marketing Suite

Your formulation records stay in Makers Studio. The Marketing Suite does not read formulation percentages, weights, ratios, base levels, manufacturing methods, batch data, supplier costs or internal formulation notes into its AI requests. Instead, it builds a restricted product brief from approved product and ingredient information.

Text that you deliberately type or paste into AI-enabled fields — such as product descriptions, additional instructions, brand-voice examples, your own custom detail rows and measurements on a product record, or copy supplied for repurposing — is sent as written so the AI can respond to it. You should therefore not enter confidential recipe information into those fields. We do not scan or redact your free text.

The restricted product brief can include:

  • product name, type, category and intended use;
  • your own maker-written product description and marketing notes;
  • ingredient names and trade names, ingredient types, functions and characteristics recorded in your Ingredient Library;
  • maker-approved consumer information, and recorded supplier/manufacturer information clearly labelled as information about the raw material rather than an approved finished-product claim;
  • structured sensory details (appearance, texture, scent), packaging, finished size, directions for use and retail price;
  • your brand voice examples and any substantiated claims you have recorded;
  • photographs you attach to a marketing post, where you ask for graphics to be produced from them — the photograph is placed into your own branded template in your browser and is not sent to an AI model.

The restricted product brief excludes:

  • formulation percentages, ingredient weights or ratios;
  • pre-made base constituent levels;
  • complete recipes, manufacturing/GMP method or method steps;
  • internal formulation, batch or test notes;
  • batch quantities, batch or lot numbers;
  • supplier names, supplier costs, cost calculations or margins;
  • your uploaded files, PIFs, batch records or PDFs.

These confidential fields are excluded at source: they are not assembled into the request in the first place, rather than sent and then removed. You can also exclude an individual ingredient from the Marketing Suite entirely from its Function & use tab; it then stays fully available in your formulas, records, labels and compliance calculations, but it is left out of Marketing Suite requests.

How the AI providers handle it

Requests are routed through the Lovable AI Gateway to OpenAI and Google models. Under the service terms we rely on, content sent through these AI services is not used to train the underlying models. This is a contractual commitment from those providers rather than something our app can technically enforce.

Makers Studio itself does not store the prompts it sends — in your account we keep only the ingredient values or generated content you choose to save. Any logging or temporary retention carried out by the AI gateway or the model providers for abuse prevention and service operation is governed by their own terms and is not under our direct control.

AI output is drafting assistance and can be wrong. The AI is instructed not to invent ingredients, claims, sizes, prices or test results, but generated content is a draft and you remain responsible for reviewing and verifying any wording, claim or extracted technical value before you rely on it.

AI addendum to this privacy notice

This addendum supplements the rest of this notice and explains how Kathryn Barnes, trading as Fern Dale Handcrafted, operator of Fern Dale Makers Studio, processes personal data when AI tools are used, under the UK GDPR and the Data Protection Act 2018. Where it overlaps with the “AI features” section above, that section gives the detail of what is and is not sent.

AI tools in use

AI here means technologies designed to emulate human reasoning to carry out tasks. Inside the app, AI is used for supplier-document auto-fill in the Ingredient Library and for drafting content in the Marketing Suite, and only when you deliberately trigger it. Behind the scenes we also use AI tools in running the business: drafting and summarising support replies, general business admin and content writing, and assistance with software development and maintenance of the app.

What data may be processed

  • Contact details, such as a name, email address or telephone number appearing in correspondence or in a document you upload.
  • Professional information, such as a job title or supplier/employer details on a supplier document.
  • Financial information appearing in a document or message, such as supplier billing or payment references.
  • Other content you provide: free text you type into AI-enabled fields, and files or documents you choose to submit for auto-fill.
  • Your maker product information as described in the “AI features” section, which excludes formulation percentages, recipes, batch data, supplier names and costs at source.

How that data reaches the AI tools

  • Files and documents you upload and choose to auto-fill.
  • Text you type or paste into AI-enabled fields in the app.
  • Email correspondence with us, including support requests.

Why we use it

  • To save you re-typing information that is already on a supplier document.
  • To help you draft marketing wording more quickly.
  • To answer support questions and run our own business admin more efficiently.
  • To build, fix and maintain the app.

Lawful basis

For AI used to run and improve the service our lawful basis is legitimate interests — improving service delivery and business efficiency — and contract where the AI feature is part of the service you have subscribed to. We do not seek to process special category data through AI tools; if that ever became necessary we would do so only on a compliant basis, which may include your explicit consent.

How we protect it

  • Data in transit is encrypted with HTTPS/TLS, and your stored records are protected by row-level security so only your account can reach them.
  • AI requests are routed through our hosting provider's AI gateway under written data-processing terms; the AI providers act as sub-processors through that provider and are not permitted to use your content to train their models.
  • We review these AI features for accuracy and fairness, and AI output is always presented to you as a draft to check.
  • We do not make solely automated decisions about you that have legal or similarly significant effects.

Third parties involved

The AI models used are OpenAI and Google models, reached through the Lovable AI Gateway. Their handling of data is described in their own privacy documentation: Lovable, OpenAI and Google.

Changes and contact

We may update this addendum from time to time; please check this page periodically. For any query about it, contact Kathryn Barnes, trading as Fern Dale Handcrafted, 288 Ferndale Road, Swindon, SN2 1HL — telephone 07889 667490, email contact@ferndale-handcrafted.co.uk.

Lawful bases under UK GDPR

Contract — to provide the account, store your records, and operate your subscription.

Legitimate interests — to improve features and run our own business admin. Where we use your data to keep the service secure, detect or prevent crime and fraudulent use, or respond to an emergency, we rely on the recognised legitimate interests set out in UK data protection law, so no separate balancing exercise is required for those purposes.

Legal obligation — to retain our own subscription billing and accounting records for the period required by HMRC. This does not include the invoices or customer records you create inside the app.

Consent — for any optional marketing emails (you can withdraw at any time).

Your rights

Under UK data protection law you have the right to:

  • Access a copy of the personal data we hold about you.
  • Rectify inaccurate data.
  • Erase your account and associated records ("right to be forgotten").
  • Restrict or object to certain processing.
  • Port your data — most maker records can be exported as PDF from within the app.
  • Complain to us, and then to the data protection regulator (see below).

To exercise any right, contact us via the Contact & FAQs page or email contact@ferndale-handcrafted.co.uk. We will respond within one calendar month.

How we handle an access request. If we genuinely need more information to identify you or to understand what you are asking for, we will ask you promptly — and the one-month period does not start, or is paused, until you reply. Our search for your data will be reasonable and proportionate: we look where the information would sensibly be held rather than through every backup copy. If your request is complex, or you have made several, we may extend the period by up to two further months and will tell you why within the first month.

Complaints

If you are unhappy with how we have handled your personal data, please tell us first — it is usually the quickest way to put something right. Email contact@ferndale-handcrafted.co.uk with the words "data protection complaint" in the subject line, or write to Kathryn Barnes, trading as Fern Dale Handcrafted, 288 Ferndale Road, Swindon, SN2 1HL.

We will acknowledge your complaint within 30 days of receiving it, take appropriate steps to look into it, and tell you the outcome without undue delay. If we need longer to finish looking into something, we will explain why and keep you updated.

You can complain to the UK data protection regulator — currently the Information Commissioner's Office — at any time, whether or not you have raised it with us first: ico.org.uk/make-a-complaint.

Sub-processors

We use the following providers to deliver the service:

  • Lovable — application hosting and content delivery, the managed backend (database, authentication, file storage) provided through it, transactional email delivery infrastructure, connector/payment gateway traffic, and the AI Gateway that routes AI requests. Diagnostic and error logs are processed here.
  • Supabase — the managed database, authentication and storage platform behind the Lovable backend, holding your account and maker records.
  • OpenAI and Google — AI models used for supplier-document auto-fill and the Marketing Suite (see “AI features” above). They have no general access to your workspace: they only receive the content of a single request you have deliberately triggered. Where that request is a supplier-document auto-fill, the file you selected may incidentally contain third-party personal data, and for that limited action the Lovable AI Gateway and the model provider used are sub-processors of that data. Content is processed to return your result and, under the service terms we rely on, is not used to train the underlying models.
  • Stripe — subscription billing and payment processing on the web.
  • Apple — only if you choose Sign in with Apple, and for billing if you subscribe inside an App Store version of the app.
  • Google — only if you choose Google sign-in, and for billing if you subscribe inside a Google Play version of the app.

Not every provider has the same legal role, and we do not claim they are all our processors:

  • Processors acting on our instructions: Lovable, for application hosting, the managed backend, email delivery infrastructure and AI-request routing. Supabase and the AI model providers listed above are engaged as sub-processors through Lovable rather than directly by us, under Lovable's own written data-processing terms.
  • Independent controllers for parts of what they do: Apple and Google act as independent controllers for store account, billing, tax, receipt and fraud-prevention purposes when you subscribe or sign in through them — that processing is governed by their own privacy notices, not ours. Stripe acts as our processor for the subscription data we ask it to handle, but as an independent controller for payment-network, fraud-prevention, anti-money-laundering and regulatory reporting purposes.

Where a provider acts as our processor we have written data-processing terms in place, including a signed data processing agreement with our hosting and backend provider. We do not sell your data and no provider is permitted to use it for advertising.

Where you store other people's details in the app, the providers acting as our processors also act as your sub-processors — see our Data Processing Agreement, which sets out the advance notice you get before we add or replace one. The Lovable AI Gateway and the AI model provider used for a request are sub-processors only for the limited processing action described above, where you deliberately submit a supplier document for auto-fill. They are not given access to your customer records, invoices, client briefs, supplier-contact records, notes, planner content or Drawing Board content.

Emails we send you

We always send the emails needed to run your account — email verification, sign-in and password reset, and subscription confirmations. Those are part of providing the service, so they are not something you can opt out of while your account is open.

News, new features and offers are separate and only sent if you tick the box when you sign up, when you subscribe, or later on your account page. We record that you ticked it and when. You can untick it at any time on your account page, or use the unsubscribe link in the email — we do not sell, rent or share your email address with anyone.

Marketing emails are governed by the UK's electronic marketing rules as well as data protection law, and penalties for breaking those rules now match the higher data protection level. We treat that consent record, the unsubscribe link in every marketing email and our suppression list as part of how the service is run, not optional extras.

Maker Community

The Maker Community is a place where a maker can choose to share a product or idea, a guide or tip, a supplier find or a full recipe, and where makers can ask each other questions. It is being built, and nothing in your Studio is shared anywhere until you deliberately choose to share it.

When you do share something, or post a question, comment or reply, what becomes public is the wording and any photographs you chose to include, the maker or business name shown on your profile, and the dates. Public Community pages can be read by anyone and can be found by search engines. Nothing else travels with it: your formulas, quantities, method, costs, margins, supplier prices and ordering notes, customers, sales, private notes, compliance documents, certificates and stock figures are never published, and there is no route by which a Community page can reach them. A full recipe becomes public only where you separately and deliberately choose to publish it.

The lawful basis for publishing what you have chosen to share is performance of our contract with you. Anyone can ask us to remove their own contributions at any time. Where another maker has already copied something you shared, their copy is their own record and is not deleted from their Studio, but we remove yours from public view and no new copies can be made.

If you report content, we record what you reported, the reason you chose, anything you added, the time and the outcome. That report is visible only to you and to the studio owner. We never tell the person you reported who reported them. Where content is removed we keep a private record of what was reported and why, so we can understand our own decisions and answer any later dispute.

Where we believe content or behaviour may involve a criminal offence, a risk of serious harm, or a risk to a child or vulnerable person, we may report it to the police or another statutory or regulatory authority and share the information needed to do so. Where the law requires it, or a court, the police or a regulator makes a lawful request, we may disclose information about a post and the account behind it. The lawful basis for that is our legal obligation, or our legitimate interest in keeping the Community safe.

Partner Programme data

If you apply to our Partner Programme, we hold what you give us in the application — your name, any trading or market name, contact email, website or social page, where you would promote the Studio, roughly how many makers you reach and any note you add — together with the payment details you choose to give us for rewards (UK account name, sort code and account number, or a PayPal email). The lawful basis is performance of the partner arrangement with you, and for records of rewards paid, our legal obligation to keep accurate business records.

We also record how many people arrived through a partner link and how many of them subscribed. A partner sees only those counts and their own rewards. We never tell a partner who signed up through their link, and we do not pass a member’s details to a partner.

Payment details are visible only to the studio owner, for the purpose of making the payment. Application and reward records are kept for as long as the partnership lasts and then for six years, because they are financial records.

Where the service is offered

Fern Dale Makers Studio is written for and offered to makers in the United Kingdom only, and its compliance guidance and calculators follow UK rules. We do not market, price or offer the service to individuals in the European Union or European Economic Area, and app store availability is limited to UK territories.

Because our processing is not directed at individuals in the EU/EEA, we are not currently required to appoint an EU representative under Article 27 of the EU GDPR. If we later open the service to EU or EEA users we will appoint an EU representative and publish their name and contact details here before doing so. We are established in the UK, so no separate UK representative is required.

Our processing is governed by the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025, and our supervisory authority is the UK data protection regulator — currently the Information Commissioner's Office (ICO). If the regulator is renamed or restructured, references here should be read as referring to its successor.

International transfers
Where personal data is transferred outside the UK/EEA (for example to US-based infrastructure providers), we rely on UK International Data Transfer Agreements or the EU Standard Contractual Clauses, together with the providers' additional safeguards.
Retention

We keep your account and records for as long as your account is active.

If you delete your account, the deletion runs straight away, not over the following weeks. Your login, every record you own (formulas, batches, tests, PIFs, labels, ingredient library, stock, planner, Drawing Board, marketing content, customers, events and workshops), your uploaded files and images, your notification tokens, and our record of emails sent to your address — including any unsubscribe and suppression entries — are deleted at that point, and any live subscription is cancelled at the same time. Backup copies are put beyond ordinary use at the same time and are deleted as they age out of our backend provider's documented backup-retention cycle; while they persist they remain encrypted and are not accessed for any other purpose.

The only exception is limited financial records we are required to keep for tax and accounting purposes. Those are our own billing records for your subscription — who paid us, for which plan, when and how much. The invoices, customer records, client briefs and other content you create inside the app are not retained as our accounting records.

If the business is sold or transferred

If Fern Dale Makers Studio is ever sold, merged, restructured or transferred to another owner — in whole or in part — account and subscription information may pass to the buyer or new owner so the service can keep running for you. That includes your account details and email address, your subscription and consent records, and the records you have created in the app.

Any buyer would be bound by this notice as it stands at the time of the transfer. They could not use your data for a new or different purpose, and could not send you news, offers or their own marketing unless you had ticked the box for it or you agreed separately. Your email address would not be sold, rented or passed on as a standalone marketing list.

During a genuine sale process we may need to share limited information with a prospective buyer and their advisers — normally aggregate figures such as subscriber and revenue totals, under confidentiality. Where any personal data has to be shared at that stage it is kept to the minimum needed.

We will tell you in the app or by email before any transfer of your data takes effect, and you can delete your account at any point beforehand.

Security
The app uses HTTPS everywhere, row-level security on the database (so makers only see their own records), hashed credentials, and least-privilege access for administrators. No system is perfectly secure — please use a strong, unique password.
Cookies and automated decisions

We use only the cookies and local storage strictly necessary to keep you signed in and to remember your preferences. We do not set advertising or cross-site tracking cookies, and we do not rely on the newer exemptions that allow certain low-risk statistical or appearance cookies without consent — so no cookie banner is needed.

We do not make solely automated decisions about you that have legal or similarly significant effects. Nothing in the app decides your subscription, access or standing without a person involved, so the safeguards for automated decision-making do not arise. AI features only ever produce drafts for you to review.