Privacy policy

Version 2026-08-05 · effective 2026-08-05

Privacy Policy — GreaseDesk

This policy explains what personal data GreaseDesk handles, why, and what rights you have over it.


Contents

  1. Who we are
  2. The two roles we play
  3. What personal data we collect
  4. How we collect it
  5. Why we process your data, and our lawful basis
  6. Who we share your data with
  7. International transfers
  8. How long we keep your data
  9. Your rights
  10. Cookies
  11. How we protect your data
  12. Links to other websites
  13. Children
  14. Changes to this policy
  15. How to contact us

1. Who we are

This policy explains how GreaseDesk Ltd ("GreaseDesk", "we", "us", "our") handles personal data.

  • Company: GreaseDesk Ltd
  • Company number: 17312623
  • Registered office: Unit 7 Tinsley Street, Tipton, England, DY4 7LH
  • ICO registration number: ZC204726, registered 22 July 2026 (held under "Greasedesk Ltd")
  • Contact for privacy matters: dataprotection@greasedesk.com

If you have any questions about this policy or how we handle your data, contact us at the address above.


2. The two roles we play

GreaseDesk provides garage-management software to independent garages ("tenants"). Because of how the service works, we handle personal data in two distinct roles, and your rights and our obligations differ depending on which applies.

As a data controller, we decide how and why data is processed. We are the controller for:

  • Tenant users — the garage owners, managers and staff who hold accounts to use GreaseDesk.
  • Resellers — individuals who apply to, or act as, GreaseDesk resellers.
  • Website visitors and enquirers — people who contact us or interact with our marketing site.

As a data processor, we process data on a tenant's instructions and on their behalf, and the tenant garage is the controller. We are the processor for:

  • Garage customers' data — the names, contact details, vehicle registrations, mileage, job history and related information that a tenant garage enters into GreaseDesk about its own customers.
  • Garage employees' data — the employment and personal details a tenant garage records in GreaseDesk about its own staff.

For this processor data, the garage decides what is collected and why; we only process it to provide the service. If you are a customer or an employee of a garage that uses GreaseDesk and you wish to exercise your data-protection rights, your first point of contact is the garage, as controller. We will support the garage in responding to your request.

The relationship between GreaseDesk and each tenant for this processing is governed by a Data Processing Agreement, which forms part of our Terms of Service.


3. What personal data we collect

Tenant users (we are controller):

  • Name, email address, and the password (stored only as a secure hash) used to access GreaseDesk.
  • Role and site assignment within their garage.
  • Login and activity records necessary to operate and secure the account.

Garage customers (we are processor, on the tenant's behalf):

  • Names and contact details, vehicle registrations, mileage, VINs where entered, job and invoice history, and any notes the garage records. GreaseDesk does not decide what a garage enters about its customers.
  • Vehicle records obtained from official sources using a registration number entered by the garage: make, model, engine and fuel details, registration date, MOT test dates and results, MOT expiry, recorded odometer readings, and advisory and failure notes recorded by MOT testers.

Garage employees (we are processor, on the tenant's behalf):

  • Where a garage uses GreaseDesk to keep staff records, we process, on that garage's instruction: name; job role; pay (annual salary or hourly rate); date of birth; home address; personal email address; phone number; emergency contact name, relationship and phone number; gender; and pronouns.
  • Only name and pay are required for the record to exist. Every other field above is optional and may be left blank indefinitely. GreaseDesk does not decide what a garage records about its staff, and does not require any of this information for the service to work.
  • If you work for a garage that uses GreaseDesk and you wish to exercise your data-protection rights, your first point of contact is your employer, as controller. We will support them in responding to your request.

A note on gender and pronouns. Both fields are optional and both start unstated — GreaseDesk never infers either, including from a person's name. Gender identity is not one of the categories listed in Article 9(1) of the UK GDPR, which covers racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used to identify someone, health, sex life and sexual orientation. It can nevertheless become special category data in context — for example where it reveals, or supports an inference about, a person's health. Because that line depends on how the information is used rather than on the field itself, we apply the protections we would apply to special category data: the two fields are recorded and shown back to the garage, and nothing is derived, inferred or decided from them.

Resellers (we are controller):

  • Name, business or brand, area covered, email, phone number, and any information provided in a reseller application.
  • Where a reseller is active: attribution and commission records relating to the garages they introduce.

Website visitors and enquirers (we are controller):

  • Information you provide when you contact us or submit a form (name, email, phone, message).
  • Referral information: if you arrive via a reseller's referral link, a first-party referral identifier, only where you have consented to functional cookies (see our Cookie Policy).
  • Limited technical data necessary to serve and secure the website.

Payment data:

  • Card and payment processing is handled by Stripe. GreaseDesk does not store full card numbers. We hold only Stripe customer and subscription identifiers and payment status; full card details never reach our systems.

4. How we collect it

  • Directly from you — when you create an account, apply as a reseller, contact us, or use the product.
  • From tenants — garage-customer and garage-employee data reaches us because a tenant enters it into the service.
  • From official vehicle records — when a garage enters a vehicle registration, we retrieve that vehicle's details and MOT history from the Driver and Vehicle Standards Agency (DVSA). This means we may hold information about a vehicle that its owner did not give us directly. The same information is publicly available to anyone with the registration number.
  • Automatically — a limited set of strictly-necessary cookies (to run and secure the service) and, only with your consent, functional or analytics cookies. See our Cookie Policy.

5. Why we process your data, and our lawful basis

PurposeWhose dataLawful basis
Providing and operating the GreaseDesk service to a tenantTenant usersPerformance of a contract
Processing garage-customer data to deliver the serviceGarage customersWe process on the tenant's instructions; the tenant relies on its own lawful basis as controller
Retrieving vehicle and MOT records to support servicing and inspection workGarage customersWe process on the tenant's instructions; the tenant relies on its own lawful basis as controller
Processing garage-employee data to deliver the serviceGarage employeesWe process on the tenant's instructions; the tenant relies on its own lawful basis as controller — ordinarily performance of a contract, or legitimate interests, for employment administration
Managing reseller applications, attribution and commissionResellersPerformance of a contract / legitimate interests
Sharing tenant contact details and account status with the introducing resellerTenant usersLegitimate interests (operating our reseller programme and paying commission accurately)
Responding to enquiries and providing supportEnquirers, tenantsLegitimate interests
Taking payment and managing subscriptionsTenantsPerformance of a contract
Securing our systems and preventing misuseAllLegitimate interests
Analytics and marketing cookiesVisitorsConsent
Sending service and account communicationsTenants, resellersPerformance of a contract / legitimate interests
Marketing communicationsWe do not currently send marketing emailn/a

Where we rely on legitimate interests, we have considered your rights and interests and are satisfied our processing does not override them. You can ask us about this balancing at any time.

Where a garage records customer or staff details in GreaseDesk, the garage is the controller and chooses its own lawful basis for doing so. We process those records only to provide the service, on the garage's instructions. GreaseDesk does not decide what a garage records about its customers or its employees, does not require any of the optional fields, and does not use that data for any purpose of its own.


6. Who we share your data with

We do not sell your personal data. We share it only with the service providers ("sub-processors") that we use to run GreaseDesk, and only as needed to provide the service:

ProviderPurposeLocation
VercelApplication hosting and deliveryLondon, UK (lhr1)
NeonDatabase hostingLondon, UK (AWS eu-west-2)
StripePayment processingUS / global
ResendTransactional email deliveryIreland (eu-west-1)
Cloudflare R2File and image storageGlobal (Cloudflare network)
GoogleWebsite analyticsUS — only where analytics is enabled and only with your consent

We also send vehicle registration numbers to the Driver and Vehicle Standards Agency (DVSA) in the United Kingdom in order to retrieve vehicle and MOT records. DVSA is a UK government agency and acts as controller of the records it holds.

We keep this list current. Where we add a new provider that processes personal data, we will update this policy.

Resellers. GreaseDesk is introduced and supported by independent resellers. If you signed up through a reseller, we share your business contact details and your account status with that reseller so they can support you and so we can calculate the commission we owe them. Resellers act as independent controllers of that information and are contractually required to keep it confidential and to comply with data protection law in their own right.

Resellers have no access to your GreaseDesk account and cannot see your customers' data. They cannot log in to your account, and we do not disclose your customer records to them. If you choose to show a reseller something in your account, that is your decision as controller of that data.

We may also disclose data where required by law, to establish or defend legal claims, or in connection with a sale or reorganisation of the business — in which case any recipient would be bound to protect it.


7. International transfers

The application, the database and transactional email are hosted in the UK and Ireland. Your GreaseDesk data — including your customer and staff records — is stored in the United Kingdom.

Some of our sub-processors operate outside the UK, including in the United States: Stripe for payment processing, Google for website analytics where you have consented to it, and Cloudflare, whose storage network is global. Where personal data is transferred outside the UK, we rely on the data-processing terms we have accepted with each of those providers, which incorporate one of the transfer mechanisms recognised under UK law — the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or the provider's certification under the UK Extension to the EU–US Data Privacy Framework.

You can ask us for more information about these transfers and the safeguards that apply to them.


8. How long we keep your data

  • Tenant account data — for as long as the account is active, and then 90 days after closure, unless we must keep it longer for legal reasons.
  • Garage-customer data — retained while the tenant's account is active and subject to the tenant's own retention decisions as controller. On account closure the garage may extract its data; it is then deleted after 90 days.
  • Garage-employee data — retained while the tenant's account is active, and deleted with the tenant's other data 90 days after account closure. How long an individual employment record is kept during the life of the account is the garage's decision as controller. Employment records are conventionally kept for six years after employment ends, because a contractual claim can be brought within the six-year limitation period, and National Minimum Wage records must by law be kept for six years. GreaseDesk does not currently provide any way to delete an individual employee's record from within the product — marking someone as having left keeps their record, because past pay and hours are what historic cost and capacity figures are built from. A garage that needs a specific employee record erased should contact us at dataprotection@greasedesk.com and we will action it directly.
  • Invoice and financial records — kept for 6 years to meet legal and accounting obligations.
  • Audit and security records — records of privileged actions, account changes and changes to financial records are kept as a permanent, unalterable log for 6 years, so that changes to financial and account data can be accounted for. These records identify the user who performed each action.
  • Reseller data — for the duration of the reseller relationship and 6 years afterwards, in line with financial-record requirements.
  • Enquiry data12 months after the enquiry is resolved.
  • Consent records — kept as evidence of consent for as long as we rely on that consent and a reasonable period after.

When data is no longer needed, we delete or anonymise it.


9. Your rights

Under UK data-protection law you have a number of rights over your personal data. Most apply in particular circumstances rather than absolutely, so we have explained when each one is available.

Access — you can ask for a copy of the personal data we hold about you, and to check we are processing it lawfully. This is often called a "data subject access request".

Rectification — you can ask us to correct data that is inaccurate, or to complete data that is incomplete. We may need to verify the accuracy of anything new you give us.

Erasure — you can ask us to delete your data where there is no good reason for us to keep processing it, where you have successfully objected to processing, or where we are legally required to erase it. We cannot always comply — for example, where we must keep records for tax or legal reasons — and we will tell you if that applies.

Restriction — you can ask us to pause processing while we check the accuracy of data, where our use is unlawful but you would rather we did not erase it, where you need us to keep it to establish or defend a legal claim, or while we consider an objection you have raised.

Objection — you can object where we rely on legitimate interests and something about your situation means that processing affects your rights. We may continue if we can show compelling grounds that override your interests.

Portability — you can ask us to provide certain data in a structured, commonly used, machine-readable format, or to transfer it to another provider where technically feasible. This applies to data you gave us and that we process by automated means under consent or contract.

Withdrawing consent — where we rely on consent, you can withdraw it at any time. This does not affect anything we did lawfully before you withdrew it.

Making a request

Contact us at dataprotection@greasedesk.com.

No fee is usually payable. You will not have to pay to exercise any of these rights. If a request is clearly unfounded, repetitive or excessive we may charge a reasonable fee, or refuse it — and we will explain why if that happens.

We may need to verify your identity. Before releasing personal data we may ask for information confirming who you are. This protects you: it stops us disclosing your data to someone impersonating you. We may also ask you to clarify a request so we can respond faster.

We aim to respond within one month. If a request is particularly complex, or you have made several, it may take longer — up to a further two months. We will tell you within the first month if that is the case and keep you updated.

If you are a customer or an employee of a garage

If your request concerns data a garage holds about you, please contact the garage — they are the controller of that data. We will help them respond.

Complaints

You have the right to complain to the Information Commissioner's Office (ico.org.uk, helpline 0303 123 1113) if you are unhappy with how we have handled your data. We would ask that you raise it with us first at dataprotection@greasedesk.com so we have the chance to put it right.


10. Cookies

We use a limited set of cookies. Strictly-necessary cookies keep the service running and secure and do not require consent. Functional, analytics and marketing cookies are used only with your consent. Full details, and the controls to change your choices, are in our Cookie Policy.


11. How we protect your data

We take appropriate technical and organisational measures to protect personal data, including:

  • Encrypted connections (HTTPS) across the service.
  • Passwords stored only as secure hashes, never in plain text.
  • Separate, isolated administrative access. Our platform-administration system runs on a separate origin with its own authentication; administrative sessions cannot cross into the main application, and vice versa.
  • Multi-factor authentication on administrative accounts.
  • Role-based access control, enforced server-side, limiting what each user can see and do — including region-scoped restrictions for administrative staff.
  • Audit logging of privileged actions, including changes to accounts, permissions and financial records.
  • Secret scanning in our development pipeline, to prevent credentials being exposed.
  • Automated database backups with point-in-time recovery.

If something goes wrong. We assess any suspected personal-data breach without delay. Where a breach is likely to result in a risk to people's rights and freedoms, we report it to the Information Commissioner's Office within 72 hours of becoming aware of it. Where it is likely to result in a high risk, we tell the people affected without undue delay. Where the breach involves data we process on a tenant's behalf, we tell that tenant promptly so they can meet their own obligations as controller.

No system is perfectly secure, but we work to protect your data and to respond quickly if something goes wrong.


12. Links to other websites

Our website and service contain links to other sites — for example, to Stripe when you enter payment details. If you follow a link away from GreaseDesk, that site's own privacy policy applies. We do not control those sites and are not responsible for how they handle your data. We encourage you to read the privacy policy of any site you visit.


13. Children

GreaseDesk is a business service and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us at dataprotection@greasedesk.com and we will delete it.


14. Changes to this policy

We may update this policy from time to time. The version and effective date shown at the top of this page record when it was last changed, and previous versions are retained. Where changes are significant, we will take reasonable steps to bring them to your attention.


15. How to contact us

  • Privacy matters and data requests: dataprotection@greasedesk.com
  • Post: GreaseDesk Ltd, Unit 7 Tinsley Street, Tipton, England, DY4 7LH
  • Regulator: Information Commissioner's Office — ico.org.uk — 0303 123 1113

We use strictly-necessary cookies to keep the site working. With your consent we’d also use a referral cookie. We run no analytics or advertising cookies today. You can accept all, reject all, or choose per category. Cookie policy.