LEGAL
Privacy Policy
Last updated: April 2026
1. Data controller
The data controller for Breadboard.it is Arcneon Limited, a company registered in England and Wales (company number 07227927).
Registered address: Unit A, 82 James Carter Road, Mildenhall, England, IP28 7DE
For privacy queries, contact us at privacy@breadboard.it.
2. What data we collect
We collect the minimum data needed to operate the store:
- Account data — email address and password (managed by AWS Cognito). If you sign in via a third-party provider such as Google, we receive your email address only.
- Order data — what you ordered, order status, and payment reference. We do not store your payment card details or shipping address in our database.
- Chip requests — if you request a component, we store the part number and any notes you provide, linked to your account.
- Quote requests — custom board specifications you submit.
3. What data we do NOT collect
- Shipping addresses — collected and processed by Stripe on our behalf during checkout. We do not store them in our own database.
- Payment card details — handled entirely by Stripe. We only receive a payment reference and status.
- Tracking cookies — we use Grafana Cloud Faro for error monitoring and performance, which is cookie-free and does not track individual users across sites.
4. Legal basis for processing
We process your personal data under the following lawful bases (UK GDPR Article 6):
- Contract — to fulfil your orders, process payments, send dispatch notifications, and provide our services.
- Legal obligation — to comply with accounting, tax, and record-keeping requirements (e.g. HMRC).
- Legitimate interests — to operate, secure, and improve our website, including error monitoring and performance measurement, provided these interests are not overridden by your rights and freedoms.
5. How we use your data
- To process and fulfil your orders
- To send order confirmation and dispatch emails
- To respond to custom board quotes
- To track which components have been requested
- To monitor errors and improve site reliability
We do not sell, rent, or share your personal data with third parties for marketing purposes. We do not use your data for automated decision-making or profiling.
6. Third-party services
We use the following third-party services that may process your data:
- Stripe — payment processing and shipping address collection. See Stripe's privacy policy at https://stripe.com/privacy.
- AWS (Amazon Web Services) — hosting, authentication, email delivery, and database. Data is stored in the EU (eu-west-1, Ireland).
- Grafana Cloud — frontend error monitoring, performance metrics, and web vitals. No cookies, no cross-site tracking. We may process your IP address to estimate your approximate location for error monitoring, performance optimisation, and fraud prevention, under our legitimate interests.
7. International transfers
Our primary infrastructure is hosted in the EU (AWS eu-west-1, Ireland). Some of our service providers (such as Stripe and Grafana Labs) may process data outside the UK/EEA. Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or equivalent measures.
8. Data security
We use appropriate technical and organisational measures to protect your data, including encryption in transit (TLS), access controls, and secure cloud infrastructure. Payment data is handled entirely by Stripe, a PCI DSS Level 1 certified provider.
9. Data retention
Account and order data is retained for as long as your account is active and for a reasonable period afterwards for legal and accounting purposes (typically 6 years per HMRC requirements).
You may request deletion of your account and associated data at any time by contacting us. We may retain certain data where required to comply with legal obligations (for example, financial records).
10. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data
- Object to processing of your data
- Data portability — receive your data in a structured format
To exercise any of these rights, contact privacy@breadboard.it.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at https://ico.org.uk.
11. Cookies
We use essential cookies only — authentication session tokens required for the site to function. We do not use advertising or tracking cookies. Our monitoring provider (Grafana Cloud Faro) is cookie-free.
Because we only use essential cookies, a cookie consent banner is not required under current UK regulations.
12. Children
We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it.
13. Changes to this policy
We may update this policy from time to time. Changes will be posted on this page with an updated date. We will not reduce your rights under this policy without your consent.
See also: Terms & Conditions · Returns & Shipping