Privacy Policy
1. Introduction
Go Find Part Limited (“GoFindPart”, “we”, “us”, or “our”) is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data when you use our Platform.
Go Find Part Limited is the data controller for personal data processed through the Platform. We are registered in England and Wales.
This Privacy Policy applies to all users of the Platform, including Buyers, Sellers (Fulfilling Suppliers), and visitors.
We process personal data in accordance with the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.
Context on our role. GoFindPart operates as a managed-procurement platform and the merchant of record in every Transaction. We are the contracting seller to Buyers, and we source goods from a network of Fulfilling Suppliers under back-to-back terms (see our Buyer Terms and Seller Terms). This structure has specific implications for how we process the identity of Fulfilling Suppliers — see sections 3, 4, and 6.
2. Personal Data We Collect
2.1 Information you provide
When you register for an account and use the Platform, we collect the following categories of personal data:
- Account information — name, email address, phone number, business name, business registration details, and account type (Buyer, Seller, or Both).
- Seller-specific commercial information (for users registered as Sellers) — legal entity name, VAT registration status, VAT number (if VAT-registered), self-billing-agreement consent timestamp, and bank-account details required for Stripe Connect payouts.
- Identity verification — information required for Stripe Connect onboarding (for Sellers), including identity documents and proof of business registration. This data is processed by Stripe and is subject to Stripe’s own privacy policy.
- Transaction data — details of Requests created, Offers submitted, accepted Transactions, pricing, delivery information, payment records, and self-billed VAT-invoice records.
- Communication data — messages exchanged through the Platform, dispute evidence, product-claim correspondence, and support correspondence.
- Delivery information — delivery addresses, pickup locations, and geolocation data used for delivery cost calculation and fulfilment routing.
2.2 Information we collect automatically
- Device and usage data — IP address, browser type, operating system, pages visited, and interaction patterns.
- Cookies and similar technologies — as described in our separate Cookies Policy.
- Analytics data — anonymised usage statistics collected through our analytics system (subject to your consent).
3. How We Use Your Personal Data
We use your personal data for the following purposes and on the following lawful bases:
| Purpose | Lawful Basis |
|---|---|
| Providing and operating the Platform | Performance of contract |
| Processing Transactions and payments (as seller of record to Buyers) | Performance of contract |
| Issuing self-billed VAT invoices on behalf of VAT-registered Sellers | Performance of contract + legal obligation (HMRC self-billing requirements) |
| Calculating delivery costs and routing fulfilment | Legitimate interests |
| Managing your account and communications | Performance of contract |
| Fraud prevention and security | Legitimate interests |
| Resolving disputes and product claims between Buyers and GoFindPart, and managing recovery against Fulfilling Suppliers | Performance of contract |
| Calculating Seller Tier and Priority Score | Legitimate interests |
| Calculating Buyer account standing (behavioural scoring for fraud and abuse prevention, based on adjudicated transaction outcomes such as cancellations, disputes, returns, and payment events) | Legitimate interests |
| Retaining the identity of the Fulfilling Supplier for any given Transaction so that we can disclose it on request under the Consumer Protection Act 1987 and discharge our obligations as the supplier of record | Legal obligation (CPA 1987 s.2(3) and related supplier obligations) + legitimate interests |
| Compliance with other legal obligations (e.g. anti-money laundering, tax, accounting) | Legal obligation |
| Analytics and Platform improvement (with consent) | Consent |
| Marketing communications (with consent) | Consent |
| Operating trade-organisation memberships, purchase-approval workflows, and spending controls on behalf of organisation customers | Legitimate interests (organisational governance and financial accountability) |
| Recording member actions in an organisation-visible activity log | Legitimate interests (accountability for spending decisions; see section 4.5) |
| Showing an organisation’s administrator the name and work email of accounts on its verified email domain (opt-out available) | Legitimate interests (workforce account governance), with prior notice |
| Processing site-contact details and working-hours schedules supplied by an organisation | Legitimate interests, with notice at first contact and confirmation before use |
| Retaining anonymised purchase-approval records after erasure requests | Legal obligation (HMRC record-keeping; Limitation Act 1980) |
4. Sharing Your Personal Data
We may share your personal data with the following recipients:
4.1 Other Platform users
Limited information is shared between users to facilitate fulfilment:
- The Buyer does not see the identity of the Fulfilling Supplier in the normal course of using the Platform. GoFindPart presents itself as the contracting seller; the Fulfilling Supplier’s identity is retained internally and disclosed only as set out in section 4.2 below.
- The Fulfilling Supplier sees the Buyer’s name and delivery address post-acceptance, to enable fulfilment. The Supplier may not use Buyer information for any purpose other than completing the Transaction.
4.2 Disclosure of the Fulfilling Supplier’s identity
In the following circumstances, GoFindPart may disclose the identity of the Fulfilling Supplier (business name, registered address, contact details, VAT number) to a third party:
- (a) CPA 1987 requests. Where a Buyer makes a request under section 2(3) of the Consumer Protection Act 1987 to identify the producer of defective goods, GoFindPart will disclose the Fulfilling Supplier’s identity to the Buyer (or to the Buyer’s legal representative) within a reasonable time.
- (b) Regulator requests. Where a regulator with lawful jurisdiction over the goods requests the Supplier’s identity.
- (c) Legal proceedings. Where required by a court, tribunal, or other legal authority in connection with legal proceedings.
- (d) Third parties with a valid legal basis — including holders of intellectual property rights making credible infringement complaints relating to goods supplied.
- (e) Professional advisers. Our legal, accounting, and audit advisers, bound by duties of confidentiality.
Every disclosure under this section 4.2 is recorded in an internal audit log (requester, reason, timestamp).
The Fulfilling Supplier’s consent to these disclosures is captured through the Seller Terms and Conditions as a condition of using the Platform.
4.3 Service providers and processors
- Stripe — payment processing, Stripe Connect onboarding / identity verification for Sellers, and self-billed-invoice payment routing. Stripe acts as an independent data controller.
- Crisp (Crisp IM SAS, France) — in-Platform support chat. Crisp runs server-side only: when you message support, our backend relays the conversation (your email, display name, and the message content) to Crisp so our team can respond. Crisp does not load any software or set any cookies in your browser. Crisp processes this data as our data processor under their data processing terms, within the European Union.
- Delivery providers — where a courier service is engaged, we share necessary details (addresses, parcel dimensions, contact information) with our courier partners (which may include Gophr, Stuart, CitySprint, DPD, Yodel).
- Cloud service providers — hosting (Fly.io, London (lhr) region, United Kingdom), database (Neon), caching (Upstash), email (AWS SES), and storage (AWS S3) providers who process data on our behalf under data-processing agreements.
- Professional advisers — legal, accounting, audit, and insurance advisers where necessary.
- Law enforcement and regulatory bodies — where required by law or in response to valid legal process.
We do not sell your personal data to third parties. We do not use advertising cookies or share cookie data with advertising networks.
A structured, itemised register of our sub-processors is published at https://gofindpart.com/legal/subprocessors (register v1.1.0, effective 2026-07-24). The register is maintained for transparency; if the register and this Privacy Policy ever disagree, this Privacy Policy prevails.
4.4 Where we store your data
Your core account and marketplace data is hosted and stored in the United Kingdom. Our database of record (Neon PostgreSQL), file storage (AWS S3), and application servers (Fly.io) all run in the London region.
A small number of specialist sub-processors operate outside the UK — for example payment processing (Stripe), error monitoring (Sentry), AI-assisted request parsing and matching (OpenAI, Anthropic), automated first-line replies in our support chat (Anthropic — when you message support, the conversation text may be processed to generate an automated reply, always labelled as automated, with a human handover available at any time), and email delivery (AWS SES). Where personal data is transferred outside the UK it is protected by the safeguards described in section 5 (International Transfers); the full list of sub-processors is in section 4.3.
4.5 Trade organisations and team accounts
If you use GoFindPart as a member of a trade organisation (for example, your employer’s account), the following applies in addition to the rest of this policy:
- Your organisation sees your activity within it. Actions you take in the organisation — submitting purchase requests, approving or declining purchases, changes to team membership and sites — are recorded in the organisation’s activity log and are visible to its approvers and administrators. This log records what you did and when; it never includes your IP address, device details, or location.
- Colleagues at your site may see your open part requests. To stop the same site buying the same part twice, if a colleague at your site asks for a part you already have an open request for, they may be shown your name, when you raised the request, its quantity, and whether it is still open or already ordered — never prices or suppliers — so the two of you can combine orders. You are reminded of this on the request form whenever it applies, every such disclosure is recorded in the organisation’s activity log, and you can object to this processing at any time (see section 7).
- Seats, not accounts. Your organisation’s administrators manage your membership (your seat, role, site assignment, and spending limits). They do not control your GoFindPart account. If your organisation removes you, your seat is deactivated and its personal details are anonymised after 90 days; your own account and its rights under section 7 are unaffected.
- Approval records are kept. Records of purchase requests and approvals are financial records of the organisation. If you ask us to erase your data, we anonymise your identity in these records but the financial record itself is retained (up to 7 years) to meet legal record-keeping obligations.
- Work email domains. Where an organisation has verified ownership of its email domain, its administrator may see the name and work email of platform accounts registered on that domain, so they can invite colleagues. You will be notified before this applies to you, and you can opt out at any time in your account settings.
- Site contact details. If your employer adds you as a site contact (for example, for deliveries), we will email you first to explain what we hold and let you confirm — we do not send operational messages until you accept, and you can opt out of categories of messages at any time. Your working-hours schedule is deleted immediately when you stop being a contact.
- Who is responsible. For the data processed inside your organisation’s account, GoFindPart and your organisation each act as described in our terms with the organisation. Requests about your seat (role, limits, membership) are best directed to your organisation; requests about your account and your legal rights come to us as set out in section 7.
5. International Transfers
Your personal data may be transferred to and processed in countries outside the United Kingdom where our service providers are located. Where this occurs, we ensure appropriate safeguards are in place, including UK International Data Transfer Agreements (“UK IDTAs”), the UK Addendum to the EU Standard Contractual Clauses, or reliance on adequacy decisions made by the UK government.
6. Data Retention
We retain personal data for the following periods:
| Data Type | Retention Period | Reason |
|---|---|---|
| Account data | Until deletion requested (subject to legal-obligation exceptions) | Service provision |
| Transaction records | 7 years from Transaction completion | UK tax and accounting law |
| Self-billed VAT invoices | 6 years from issue (or longer where HMRC requires) | HMRC self-billing record-keeping requirements |
| Audit logs | 7 years | Security, compliance, and disclosure-trail requirements |
| Dispute evidence | 2 years from resolution (or longer where related to an unresolved product claim) | Legal-claims limitation |
| Fulfilling Supplier identity records (linked to each Transaction) | 10 years from the date of supply | Consumer Protection Act 1987 limitation period for product-liability claims; supports our obligation to identify the producer on request |
| Operational logs | 90 days | Debugging and security |
| Analytics data (anonymised) | 26 months | Platform improvement |
| Trade-organisation records | Purchase approvals: 7 years (identity anonymised on erasure requests). Organisation activity logs: up to 7 years for governance events, 2 years for operational events. Deactivated team-seat and site-contact details: anonymised after 90 days | Legal record-keeping obligations and organisational governance (see section 4.5) |
After the applicable retention period, personal data is securely deleted or anonymised.
7. Your Rights
Under the UK GDPR, you have the following rights:
- Right of access — you may request a copy of the personal data we hold about you. You can generate a data export through the Platform at any time.
- Right to rectification — you may request correction of inaccurate or incomplete data through your account settings or by contacting us.
- Right to erasure — you may request deletion of your personal
data, subject to our legal-retention obligations. In particular:
- Transaction records, audit logs, and Fulfilling Supplier identity records are retained for the periods set out in section 6 on the basis of legal obligation (UK tax law, CPA 1987, HMRC self-billing rules). These records will not be erased on request before the applicable retention period has expired.
- Right to data portability — you may request your data in a structured, machine-readable format (JSON).
- Right to restrict processing — you may request that we restrict processing of your data in certain circumstances.
- Right to object — you may object to processing based on our legitimate interests; we will consider any such objection on a case-by-case basis.
- Rights relating to automated decision-making — our Seller Tier system and our Buyer account-standing system involve automated scoring. You have the right to request human review of decisions that significantly affect you (for example, a seller tier downgrade or a PAUSED classification, or a buyer account restriction). Where a buyer account is blocked automatically on the basis of sustained, adjudicated misconduct signals, the appeal facility offered at sign-in is the guaranteed route to human review: one appeal per account, reviewed and decided by a member of our staff (UK GDPR Articles 22A–22D, as inserted by the Data (Use and Access) Act 2025).
To exercise any of these rights, please contact us at privacy@gofindpart.com. We will respond within one month of receiving your request.
8. Consent Management
Where we rely on consent as the lawful basis for processing (e.g. analytics, marketing), you may withdraw your consent at any time through the consent-management controls on the Platform. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
Our consent-management system operates three tiers:
- Necessary — essential cookies and processing required for the Platform to function. These cannot be disabled.
- Functional — cookies and processing for user preferences (theme, locale, last role). Requires your opt-in consent.
- Analytics — anonymised usage analytics. Requires your opt-in consent.
See the separate Cookies Policy for the cookie-level detail.
9. Security
We implement appropriate technical and organisational measures to protect your personal data, including encryption in transit (TLS), secure password hashing, session management, rate limiting, and regular security assessments. Card-payment data is processed by Stripe and never touches our servers (PCI DSS compliance via Stripe).
10. Children
The Platform is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified to you by email and / or a prominent notice on the Platform. The “Effective Date” at the top of this Policy indicates when it was last revised.
12. Complaints
If you are dissatisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office (“ICO”):
- Website: ico.org.uk
- Telephone: 0303 123 1113
- Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
We would, however, appreciate the chance to address your concerns before you approach the ICO — please contact us first at privacy@gofindpart.com.
13. Contact
For any questions about this Privacy Policy or how we process your personal data, please contact:
Data Protection Contact Go Find Part Limited Email: privacy@gofindpart.com