How Advertise England collects, uses, stores, and protects your personal data — and how to exercise your rights.
The data controller for personal data processed through Advertiseengland.com is:
Advertise England Ltd
[Registered address — update before going live]
England & Wales
Email: data@advertiseengland.com
ICO Registration No: [Your ZA/ZB number — add before going live]
Companies House No: [Your company number]
If you have any questions about how we handle your data, contact us at data@advertiseengland.com. We aim to respond within 3 working days.
We collect personal data in the following circumstances:
| Data | Why collected |
|---|---|
| Email address | Account creation, login, transactional emails, security alerts |
| Mobile number | Account verification, urgent security notifications |
| Password (hashed) | Authentication — stored as a bcrypt hash, never in plain text |
| Data | Why collected |
|---|---|
| Business name | Directory listing display |
| Business address & postcode | Map display, local search, county filtering |
| Website URL | Directory listing display (optional) |
| Business description | Directory listing display & search indexing |
| Photos & logo | Directory listing display (optional) |
| Industry & speciality | Category search & filtering |
| Companies House number | Verified badge (optional — checked against Companies House API) |
| Data | Why collected |
|---|---|
| Payment card details | Processed entirely by Stripe — we never see, receive, or store card numbers, CVV codes, or sort codes. Card data never touches our servers. |
| Billing postcode | Passed to Stripe for VAT rate calculation and fraud prevention. We do not store this after it is passed to Stripe. |
| VAT receipts & purchase history | Generated and held by Stripe Tax on our behalf. We do not store VAT receipts. Customers can access their full purchase history (date, package, amount, VAT) directly from the Stripe billing portal at any time. |
| Transaction ID only | The only payment-related data we retain is a transaction reference ID linking the order to Stripe. Retained 7 years for HMRC Making Tax Digital compliance. Contains no financial or personal data beyond a reference number. |
| Data | Why collected |
|---|---|
| IP address | Security, fraud detection, approximate geolocation for weather widget |
| Browser & device type | Technical compatibility and analytics (with your consent) |
| Pages visited & time on site | Analytics to improve the directory (with your consent) |
| Referrer URL | Understanding how visitors find us (with your consent) |
Under UK GDPR Article 6, every processing activity must have a lawful basis. We rely on three:
Contract Processing necessary to fulfil your listing subscription — account creation, listing publication, and payment processing. VAT receipts are issued automatically by Stripe on our behalf.
Marketing emails, analytics cookies, and marketing cookies — you can withdraw consent at any time via your account settings or our cookie manager.
Legitimate Interests Security monitoring, fraud prevention, abuse detection, site performance improvement, and non-marketing communications (e.g. critical service updates). We have conducted a Legitimate Interests Assessment (LIA) for each activity; copies available on request.
We use your personal data only for the purposes stated at collection:
We do not sell, rent, or trade your personal data to any third party for their own marketing purposes.
Self-service: Most personal data we hold can be corrected or deleted by you directly from your account dashboard — see your data rights for the full list.
We share data only with processors who handle it on our behalf under a Data Processing Agreement (DPA). All processors are contractually bound to use data only for the specified purpose.
| Processor | Purpose | Data shared | Location |
|---|---|---|---|
| Stripe Inc. | Payment processing, VAT calculation (Stripe Tax), VAT receipt generation & delivery, fraud prevention, subscription management | Card details, billing postcode, email, purchase history, VAT receipts. We pass billing details to Stripe and do not retain them. Customers can access their full payment history via the Stripe billing portal. | USA (SCCs in place) |
| Cloudflare Inc. | CDN, DNS, DDoS protection, AI proxy | IP address, request headers | USA/EU (SCCs in place) |
| Google Analytics (if consent given) | Website analytics | Anonymised usage data, IP (truncated) | USA (SCCs in place) |
| Open-Meteo | Weather widget — IP-based weather lookup | IP address (used to determine approximate location, not stored) | Germany (EU) |
| Companies House API | Business verification | Company number (queried, not stored beyond verification) | UK |
| Email service provider [name before go-live] | Transactional & marketing emails | Email address, first name | [Confirm location] |
We will disclose data to law enforcement or regulatory bodies only where legally required and, where permitted, will notify you before doing so.
We keep personal data only as long as necessary for the purpose it was collected, or as required by law.
| Data type | Retention period | Reason |
|---|---|---|
| Account & login data | Duration of account + 2 years after closure | Fraud prevention, dispute resolution |
| Active listing content | Duration of subscription | Contractual obligation |
| Listing content after cancellation | 90 days | Recovery window for accidental cancellations |
| Transaction ID (reference only) | 7 years from transaction | HMRC Making Tax Digital requirement. This is a reference number only — no card, bank, or billing data is stored by us. Full records held by Stripe. |
| Marketing consent records | 3 years from last contact | ICO guidance on consent proof |
| Server access logs (IP) | 90 days | Security incident investigation |
| Analytics data | 26 months (aggregated, anonymised) | Trend analysis |
| Content moderation logs | 12 months | Abuse pattern detection |
At the end of each retention period, data is securely deleted or anonymised in line with our Data Deletion Standard Operating Procedure.
Under UK GDPR you have eight data subject rights. You can exercise any of them by emailing data@advertiseengland.com. We will respond within 30 days (extendable by a further 60 days for complex requests — we will notify you if this applies).
Request a copy of all personal data we hold about you (a Subject Access Request / SAR). We will provide it in a commonly used electronic format at no charge.
Ask us to correct inaccurate or incomplete data. Most listing data can be corrected directly in your dashboard.
Ask us to delete your personal data ("right to be forgotten"). This right applies where there is no overriding legal obligation to retain the data.
Ask us to pause processing while accuracy or legitimacy is disputed, without deleting the data.
Receive your data in a structured, machine-readable format (JSON or CSV) so you can transfer it to another service.
Object to processing based on legitimate interests or for direct marketing. Objection to direct marketing is absolute — we must stop immediately.
We do not use fully automated decision-making (including profiling) that produces legal or similarly significant effects on you.
Withdraw marketing or cookie consent at any time via your account settings or our cookie manager. Withdrawal does not affect processing already carried out.
We use cookies and similar technologies to operate the site, measure performance, and (with your consent) deliver relevant promotions. A full list of cookies is available in our Cookie Policy.
| Category | Examples | Consent required? |
|---|---|---|
| Strictly necessary | Session ID, CSRF token, cookie-consent choice | No — required to operate the site |
| Analytics | Google Analytics (_ga, _gid) | Yes — opt-in via cookie banner |
| Marketing | Ad pixels, remarketing tags | Yes — opt-in via cookie banner |
You can change your cookie preferences at any time using the or the "Manage cookies" button in the footer.
Advertiseengland.com is a B2B directory intended for use by businesses and people aged 18 or over. We do not knowingly collect personal data from anyone under 18.
If you believe a child under 18 has provided us with personal data, please contact data@advertiseengland.com and we will delete the data promptly.
We take the security of your personal data seriously and implement technical and organisational measures including:
If you discover a security vulnerability, please report it responsibly to security@advertiseengland.com.
We may update this Privacy Policy from time to time. When we make material changes we will:
Continued use of the directory after the effective date constitutes acceptance of the updated policy.
Previous versions of this policy are available on request by emailing data@advertiseengland.com.
For any questions, requests, or concerns about this policy or our data practices:
Data queries & subject access requests:
data@advertiseengland.com
Security vulnerabilities:
security@advertiseengland.com
Postal address:
Data Protection Officer
Advertise England Ltd
[Registered address — update before going live]
We aim to acknowledge all data-related emails within 3 working days and to fully resolve requests within 30 days.