Legal
Privacy Policy - ash makes things
Last updated: 30 August 2026 Applies to: ash-makes-things.com (the marketing site) and app.ash-makes-things.com plus every tenant subdomain (*.app.ash-makes-things.com - the LeadView product).
1. Who we are
"ash makes things" ("AMT", "we", "us", "our") is a sole trader business operated by Ashley Coombes, based in Cardiff, Wales, United Kingdom. We provide AI-powered business software (LeadView) and, historically, web development and marketing services to businesses.
We are the data controller for the personal data described in this policy, except where a section below says otherwise (see §5 - some LeadView data is processed on behalf of our clients, who are the controller for that data; that relationship is governed by our Data Processing Agreement, not this policy).
Contact us:
- Email: info@ash-makes-things.com
- Post: 61 Sycamore Road, Llanharry, CF72 9HP, United Kingdom
- ICO registration: not yet registered
2. The short version
| If you are... | We hold... | Because... | For how long... |
|---|---|---|---|
A visitor to ash-makes-things.com | Basic analytics (pages viewed, device type), anything you submit via a contact form | To run and improve the site, and to reply to you | See Cookie Policy; form submissions per Data Retention Policy |
| A business we've contacted for marketing (cold email/call) | Business name, a named contact's work name/email/phone, notes on why we reached out | Legitimate-interest B2B marketing under PECR (we only contact limited companies/corporate bodies, never individuals or sole traders) | 12 months of inactivity, then deleted - see §7 |
| A named user on an LeadView tenant account | Your name, work email, login/auth data, role, actions you take in the app | To provide you with the LeadView service you or your employer subscribed to | For as long as the account is active, plus a limited period after - see Data Retention Policy |
| An individual whose data appears inside a client's LeadView account (e.g. a named counterparty in a bank statement, a customer record) | We may process this on the client's instructions | The client is the controller of this data, not us - see §5 | Set by the client's agreement with us and their own instructions |
3. Personal data we collect directly (we are the controller)
3.1 Website visitors
- Standard server/analytics logs: IP address (may be truncated/anonymised), browser/device type, pages viewed, referrer, approximate location derived from IP.
- Anything you submit through a contact form or booking link: name, email, phone (optional), and the content of your message.
3.2 Marketing/outreach contacts (B2B)
- Business name, trading address, website.
- A named contact's work name, role, business email or phone number.
- How we identified you (public directory listing, referral, a form you submitted).
- A record of contact we've had with you, so we can honour opt-outs and avoid duplicate contact.
We do not cold-contact individuals or sole traders - only limited companies and other corporate bodies, consistent with PECR. See §6 for the legal basis.
3.3 LeadView account holders
When you or your employer signs up for LeadView, we hold, about the individual users on that account:
- Name, work email address, password (hashed, never stored in plain text) or SSO identifier.
- Role/permissions within the tenant.
- Login history, session data, and actions taken in the product (for security, audit, and support purposes).
- Billing contact details (name, email; card/bank details are held by our payment processor, not us - see §8).
- Any support correspondence you send us.
3.4 Connected third-party accounts
If you connect a Google or Meta (Facebook/Instagram) account to LeadView (for calendar, analytics, ad data, or Business Profile features), we receive and store the OAuth tokens and the specific data those connections are scoped to (e.g. calendar event metadata, ad account performance figures, Business Profile review counts). Tokens are encrypted at rest (AES-256-GCM) and used only to fetch the data your scopes permit, on your instruction. You can disconnect at any time in LeadView Settings, which revokes our access.
4. Cookies and similar technologies
Covered in full in the Cookie Policy. In short: strictly-necessary session/authentication cookies on both the website and LeadView, and (where enabled) privacy-conscious analytics. We do not currently run third-party advertising/tracking cookies on either property; if that changes, this policy and the Cookie Policy will be updated first.
5. Data we process on our clients' behalf (we are the processor, not the controller)
LeadView's core value is turning a client's own business data into insight. That means LeadView holds data about a client's business that the client - not AMT - controls and is responsible for under data protection law:
- Financial data: bank statement transactions uploaded or connected for the Financials module (dates, amounts, descriptions, counterparty names - which may include names of individuals, e.g. a sole-trader supplier or a named customer).
- Marketing/analytics data: Google Analytics, Meta Ads, and Google Business Profile data connected by the client, which may include reviewer names or ad audience insights.
- Calendar data: event titles, attendees, and times from a connected Google Calendar.
For all of the above, the client is the data controller and AMT is the data processor, acting only on the client's documented instructions, under the terms of our Data Processing Agreement. If you are an individual whose personal data appears inside someone else's LeadView account (e.g. you're a named counterparty on your customer's bank statement), your rights request should go to that business, not to AMT directly - though we will assist them in responding, and will forward you to them if you contact us directly.
The current list of infrastructure providers (sub-processors) who may incidentally handle this data is published on our Security & Sub-processors page and forms part of the DPA.
6. Our legal basis for processing
| Purpose | Legal basis (UK GDPR Art. 6) |
|---|---|
| Running the website, responding to enquiries | Legitimate interests (operating our business) / contract (if you've asked us to take steps towards one) |
| B2B marketing to corporate bodies | Legitimate interests, subject to PECR's B2B carve-out and a working opt-out on every message |
| Providing the LeadView service to a signed-up account | Performance of a contract with you or your employer |
| Security, fraud prevention, audit logs | Legitimate interests |
| Complying with law (e.g. tax records) | Legal obligation |
We never rely on consent as the sole basis for direct marketing to individuals - we don't do that kind of marketing (see §3.2).
7. How long we keep it
Full schedule in the Data Retention Policy. Headlines:
- Marketing/outreach contact records with no engagement: deleted after 12 months of inactivity.
- LeadView account data: retained while your subscription is active, plus a limited window after cancellation to allow data export/recovery, then deleted or anonymised - exact periods in the Data Retention Policy.
- Financial/business data processed on a client's behalf: retained per the client's instructions and our DPA; deleted or returned within a defined window of contract termination.
- Records we must keep by law (e.g. invoices, for UK tax purposes): 6 years.
8. Who we share data with
We don't sell personal data, and we don't share it with third parties for their own marketing. We use infrastructure and service providers to run AMT and LeadView - full current list on our Security & Sub-processors page - under their own data processing terms, each bound (directly or via our DPA with clients) to process data only for the purposes we specify. This currently includes, at a high level: cloud hosting and database providers, our payment processor, our email provider, and - where a client has connected them - Google and Meta APIs.
We may disclose data where required by law, to protect our rights, or in connection with a sale or restructuring of the business (in which case you'd be notified).
9. International transfers
Several of our infrastructure providers are US-headquartered - including Supabase and Vercel, which host LeadView itself, both in US regions. Where personal data is transferred outside the UK, we rely on that provider's UK International Data Transfer Agreement (IDTA) or the UK's Addendum to the EU Standard Contractual Clauses, as applicable, and we don't use a provider without one in place.
10. Your rights
Under UK GDPR, you can ask us to:
- Access what we hold about you (a subject access request).
- Correct anything inaccurate.
- Delete what we hold about you, subject to legal retention requirements.
- Restrict or object to certain processing.
- Port your data to another provider, where technically feasible.
- Withdraw any consent you've given, at any time.
- Opt out of marketing at any time - every email includes a one-click unsubscribe.
Contact info@ash-makes-things.com for any of the above; we aim to respond within 30 days. If you're not satisfied with our response, you can complain to the UK Information Commissioner's Office (ico.org.uk).
11. Children
Our services are aimed at businesses and are not directed at children. We don't knowingly collect personal data from anyone under 18.
12. Changes to this policy
We'll post updates here with a new "Last updated" date, and for material changes affecting LeadView account holders, we'll email the account's admin contact.