ash makes things
The Lead SystemPricing
Sign up

Legal

Privacy Policy - ash makes things

Last updated: 30 August 2026 Applies to: ash-makes-things.com (the marketing site) and app.ash-makes-things.com plus every tenant subdomain (*.app.ash-makes-things.com - the LeadView product).

1. Who we are

"ash makes things" ("AMT", "we", "us", "our") is a sole trader business operated by Ashley Coombes, based in Cardiff, Wales, United Kingdom. We provide AI-powered business software (LeadView) and, historically, web development and marketing services to businesses.

We are the data controller for the personal data described in this policy, except where a section below says otherwise (see §5 - some LeadView data is processed on behalf of our clients, who are the controller for that data; that relationship is governed by our Data Processing Agreement, not this policy).

Contact us:

  • Email: info@ash-makes-things.com
  • Post: 61 Sycamore Road, Llanharry, CF72 9HP, United Kingdom
  • ICO registration: not yet registered

2. The short version

If you are...We hold...Because...For how long...
A visitor to ash-makes-things.comBasic analytics (pages viewed, device type), anything you submit via a contact formTo run and improve the site, and to reply to youSee Cookie Policy; form submissions per Data Retention Policy
A business we've contacted for marketing (cold email/call)Business name, a named contact's work name/email/phone, notes on why we reached outLegitimate-interest B2B marketing under PECR (we only contact limited companies/corporate bodies, never individuals or sole traders)12 months of inactivity, then deleted - see §7
A named user on an LeadView tenant accountYour name, work email, login/auth data, role, actions you take in the appTo provide you with the LeadView service you or your employer subscribed toFor as long as the account is active, plus a limited period after - see Data Retention Policy
An individual whose data appears inside a client's LeadView account (e.g. a named counterparty in a bank statement, a customer record)We may process this on the client's instructionsThe client is the controller of this data, not us - see §5Set by the client's agreement with us and their own instructions

3. Personal data we collect directly (we are the controller)

3.1 Website visitors

  • Standard server/analytics logs: IP address (may be truncated/anonymised), browser/device type, pages viewed, referrer, approximate location derived from IP.
  • Anything you submit through a contact form or booking link: name, email, phone (optional), and the content of your message.

3.2 Marketing/outreach contacts (B2B)

  • Business name, trading address, website.
  • A named contact's work name, role, business email or phone number.
  • How we identified you (public directory listing, referral, a form you submitted).
  • A record of contact we've had with you, so we can honour opt-outs and avoid duplicate contact.

We do not cold-contact individuals or sole traders - only limited companies and other corporate bodies, consistent with PECR. See §6 for the legal basis.

3.3 LeadView account holders

When you or your employer signs up for LeadView, we hold, about the individual users on that account:

  • Name, work email address, password (hashed, never stored in plain text) or SSO identifier.
  • Role/permissions within the tenant.
  • Login history, session data, and actions taken in the product (for security, audit, and support purposes).
  • Billing contact details (name, email; card/bank details are held by our payment processor, not us - see §8).
  • Any support correspondence you send us.

3.4 Connected third-party accounts

If you connect a Google or Meta (Facebook/Instagram) account to LeadView (for calendar, analytics, ad data, or Business Profile features), we receive and store the OAuth tokens and the specific data those connections are scoped to (e.g. calendar event metadata, ad account performance figures, Business Profile review counts). Tokens are encrypted at rest (AES-256-GCM) and used only to fetch the data your scopes permit, on your instruction. You can disconnect at any time in LeadView Settings, which revokes our access.

4. Cookies and similar technologies

Covered in full in the Cookie Policy. In short: strictly-necessary session/authentication cookies on both the website and LeadView, and (where enabled) privacy-conscious analytics. We do not currently run third-party advertising/tracking cookies on either property; if that changes, this policy and the Cookie Policy will be updated first.

5. Data we process on our clients' behalf (we are the processor, not the controller)

LeadView's core value is turning a client's own business data into insight. That means LeadView holds data about a client's business that the client - not AMT - controls and is responsible for under data protection law:

  • Financial data: bank statement transactions uploaded or connected for the Financials module (dates, amounts, descriptions, counterparty names - which may include names of individuals, e.g. a sole-trader supplier or a named customer).
  • Marketing/analytics data: Google Analytics, Meta Ads, and Google Business Profile data connected by the client, which may include reviewer names or ad audience insights.
  • Calendar data: event titles, attendees, and times from a connected Google Calendar.

For all of the above, the client is the data controller and AMT is the data processor, acting only on the client's documented instructions, under the terms of our Data Processing Agreement. If you are an individual whose personal data appears inside someone else's LeadView account (e.g. you're a named counterparty on your customer's bank statement), your rights request should go to that business, not to AMT directly - though we will assist them in responding, and will forward you to them if you contact us directly.

The current list of infrastructure providers (sub-processors) who may incidentally handle this data is published on our Security & Sub-processors page and forms part of the DPA.

6. Our legal basis for processing

PurposeLegal basis (UK GDPR Art. 6)
Running the website, responding to enquiriesLegitimate interests (operating our business) / contract (if you've asked us to take steps towards one)
B2B marketing to corporate bodiesLegitimate interests, subject to PECR's B2B carve-out and a working opt-out on every message
Providing the LeadView service to a signed-up accountPerformance of a contract with you or your employer
Security, fraud prevention, audit logsLegitimate interests
Complying with law (e.g. tax records)Legal obligation

We never rely on consent as the sole basis for direct marketing to individuals - we don't do that kind of marketing (see §3.2).

7. How long we keep it

Full schedule in the Data Retention Policy. Headlines:

  • Marketing/outreach contact records with no engagement: deleted after 12 months of inactivity.
  • LeadView account data: retained while your subscription is active, plus a limited window after cancellation to allow data export/recovery, then deleted or anonymised - exact periods in the Data Retention Policy.
  • Financial/business data processed on a client's behalf: retained per the client's instructions and our DPA; deleted or returned within a defined window of contract termination.
  • Records we must keep by law (e.g. invoices, for UK tax purposes): 6 years.

8. Who we share data with

We don't sell personal data, and we don't share it with third parties for their own marketing. We use infrastructure and service providers to run AMT and LeadView - full current list on our Security & Sub-processors page - under their own data processing terms, each bound (directly or via our DPA with clients) to process data only for the purposes we specify. This currently includes, at a high level: cloud hosting and database providers, our payment processor, our email provider, and - where a client has connected them - Google and Meta APIs.

We may disclose data where required by law, to protect our rights, or in connection with a sale or restructuring of the business (in which case you'd be notified).

9. International transfers

Several of our infrastructure providers are US-headquartered - including Supabase and Vercel, which host LeadView itself, both in US regions. Where personal data is transferred outside the UK, we rely on that provider's UK International Data Transfer Agreement (IDTA) or the UK's Addendum to the EU Standard Contractual Clauses, as applicable, and we don't use a provider without one in place.

10. Your rights

Under UK GDPR, you can ask us to:

  • Access what we hold about you (a subject access request).
  • Correct anything inaccurate.
  • Delete what we hold about you, subject to legal retention requirements.
  • Restrict or object to certain processing.
  • Port your data to another provider, where technically feasible.
  • Withdraw any consent you've given, at any time.
  • Opt out of marketing at any time - every email includes a one-click unsubscribe.

Contact info@ash-makes-things.com for any of the above; we aim to respond within 30 days. If you're not satisfied with our response, you can complain to the UK Information Commissioner's Office (ico.org.uk).

11. Children

Our services are aimed at businesses and are not directed at children. We don't knowingly collect personal data from anyone under 18.

12. Changes to this policy

We'll post updates here with a new "Last updated" date, and for material changes affecting LeadView account holders, we'll email the account's admin contact.

Privacy PolicyTerms of ServiceCookie PolicyData RetentionSecurity & Sub-processors
Cardiff, South Walesinfo@ash-makes-things.comLeadViewClient sign in
PrivacyTermsCookiesData retentionSecurity© 2026 ash makes things