ashdub. Auctions

Privacy Policy

Last updated: 17 March 2026

1. Introduction

This privacy policy explains how ashdub. Auctions collects, uses, and protects your data when you access and use the Auctions platform and related services (the "Service").

This policy is provided in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It supplements the ashdub. Group Privacy Policy with information specific to the Auctions service.

2. Who We Are

The data controller for personal data collected through ashdub. Auctions is:

ashdub. Ltd

Registered in England & Wales

ICO Registration: [Pending]

Email: privacy@ashdub.com

Website: auto.ashdub.com

3. Data We Collect

3.1 Personal Information

  • Full name, email address, and telephone number
  • Business name and address
  • Account credentials (password stored in hashed form)

3.2 Auctions-Specific Data

  • Bidder registration details
  • Bid history and auction activity
  • Payment information for winning bids
  • Vehicle interest and watchlist data
  • Seller listing and inventory data

3.3 Usage Data

  • IP address, browser type, and device information
  • Pages visited, features used, and session duration
  • Referral source and navigation paths

3.4 Payment Data

  • Billing name and address. Payment card details are processed directly by Stripe and are never stored on our servers.

4. How We Use Your Data

We use your personal data to:

  • Provide, maintain, and improve the Auctions service
  • Create and manage your account
  • Process payments and send billing notifications
  • Provide customer support and respond to enquiries
  • Send service-related communications (updates, security alerts)
  • Send marketing communications where you have opted in
  • Analyse usage patterns to improve functionality and user experience
  • Detect, prevent, and address technical issues and security threats
  • Comply with legal obligations

6. Data Sharing

We do not sell your personal data. We may share your data with the following third-party service providers who act as data processors on our behalf:

  • Stripe — Payment processing
  • Twilio — SMS and messaging services
  • Resend — Transactional email delivery
  • Supabase — Database hosting and authentication
  • Vercel — Application hosting and CDN
  • Sentry — Error monitoring and performance tracking
  • Pusher real-time bid updates

We may also share data with professional advisers (lawyers, accountants, insurers) where reasonably necessary, and with law enforcement where required by law.

7. Data Retention

We retain your personal data only for as long as necessary for the purposes set out in this policy:

  • Account Data: Retained for the duration of your subscription, plus 30 days after termination to allow for data export.
  • Service Data: Retained for the duration of your subscription. You may request earlier deletion at any time.
  • Billing Records: Retained for 7 years in accordance with HMRC requirements.
  • Usage Data: Retained in anonymised or aggregated form for up to 24 months.

You have the right to request deletion of your personal data at any time by contacting us at privacy@ashdub.com.

8. Your Rights (GDPR Articles 15–22)

Under UK GDPR, you have the following rights in relation to your personal data:

  • Right of Access (Art. 15): Request a copy of the personal data we hold about you.
  • Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal data.
  • Right to Erasure (Art. 17): Request deletion of your personal data, subject to legal obligations.
  • Right to Restrict Processing (Art. 18): Request restriction of processing in certain circumstances.
  • Right to Data Portability (Art. 20): Request your data in a structured, commonly used, machine-readable format.
  • Right to Object (Art. 21): Object to processing based on legitimate interests or for direct marketing.
  • Rights Related to Automated Decision-Making (Art. 22): Right not to be subject to decisions based solely on automated processing that produce legal or significant effects.

To exercise any of these rights, contact us at privacy@ashdub.com. We will respond within one month.

9. International Transfers

Some of our data processors may process data outside the United Kingdom:

  • Supabase: Primary database hosted in the EU (Frankfurt). Authentication services may involve US infrastructure.
  • Vercel: Global CDN with edge locations worldwide. Application data processed in accordance with their Data Processing Addendum.

Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (International Data Transfer Agreement) approved by the ICO, or transfers to countries deemed to provide adequate protection.

10. Cookies

We use cookies and similar technologies to enhance your experience, analyse usage, and remember your preferences. For full details on the cookies we use on ashdub. Auctions, please see our Cookie Policy.

11. Children's Privacy

ashdub. Auctions is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal data, we will take steps to delete such data promptly.

12. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any material changes by email or by posting a prominent notice within the Auctions service at least 30 days before the changes take effect. The updated policy will be effective from the date stated at the top of this page.

13. Contact & Complaints

If you have any questions about this privacy policy or wish to exercise your data protection rights, please contact us:

ashdub. — Data Protection

Email: privacy@ashdub.com

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your data protection rights have been violated:

Information Commissioner's Office

Website: ico.org.uk/make-a-complaint

Telephone: 0303 123 1113

14. Data Processing Agreement for Business Customers

If you use ashdub. Auctions in a business capacity and process personal data of your own customers through our platform, a Data Processing Agreement (DPA) governs our relationship as processor and controller. You can review our standard DPA at:

auto.ashdub.com/dpa