Privacy Policy
Last updated May 2026
1. Who we are
Supply & Fit ("we", "us") provides software that helps trade businesses run their day-to-day operations. This policy explains what personal data we collect, why we collect it, and the choices you have. We act as a data controller for your account information and as a data processor for the customer data you upload to your workspace.
2. Data we collect
- Account data — name, work email, business name, phone, role and password hash.
- Workspace content — leads, jobs, products, quotes, invoices, files and messages you create.
- Usage data — log-in events, device and browser type, IP address, and feature usage to keep the Service secure and improve it.
- Payment data — handled by our payment processor; we store only the billing contact and the last four digits of your card.
3. How we use your data
- To provide, secure and maintain the Service.
- To process payments and send transactional emails.
- To respond to support requests and notify you of important changes.
- To analyse aggregated usage and improve features. We never sell your data.
4. Sharing and processors
We share data only with sub-processors we need to run the Service — hosting, email delivery, error monitoring and payments. All processors are bound by data protection agreements and equivalent security standards.
5. Storage and security
Workspace data is encrypted in transit (TLS) and at rest. Access is restricted to authorised personnel and logged. We host data in the UK and EU.
6. Retention
We keep your data while your workspace is active. After cancellation, your data is retained for 30 days to allow export and then permanently deleted, unless we are required to retain it by law (e.g. invoices for tax purposes).
7. Your rights
Under UK GDPR you have the right to access, correct, export or delete your personal data, and to object to processing. To exercise a right, email supplyfitco@gmail.com You can also complain to the ICO.
8. Cookies
We use a small number of essential cookies to keep you signed in and remember preferences, plus privacy-friendly analytics. No third-party advertising cookies are set.
9. Changes to this policy
We may update this policy from time to time. Material changes will be notified by email or in-product at least 14 days before they take effect.