Privacy
How this service uses information
Draft notice: the operator must add its legal identity and contact details before launch and complete the documented legitimate-interests assessment.
Information you submit
Reports are submitted without names or contact details, but dates, broad region, value band and status may still relate to or identify a person—especially a sole trader—when combined. We therefore treat underlying submissions as personal data where applicable. Public results are aggregate statistics subject to minimum-sample suppression; only effectively anonymised information falls outside UK GDPR.
Purpose and lawful basis
We use report data to produce privacy-protecting aggregate statistics about waiting times, moderate data quality, prevent abuse and operate the service. Our proposed lawful basis is legitimate interests: providing a useful community evidence base while minimising collection and protecting contributors. This basis must be confirmed against the documented legitimate-interests assessment before launch. The acknowledgement on the form is not GDPR consent.
Technical information and fingerprints
The application uses a network address transiently to create a salted, non-reversible security fingerprint for rate limiting; it does not store the raw address in the application database. A separate salted fingerprint helps detect duplicate submissions. Cloudflare Turnstile processes technical information to distinguish legitimate users from automated abuse. Cloudflare, Vercel, Neon and other infrastructure providers may process network addresses, request details and device information in security and operational logs under their own retention controls.
Cookies and analytics
Google Analytics is optional and remains unloaded unless a visitor actively allows analytics. If allowed, it records standard page views without query strings. Enhanced Measurement, Google advertising signals and advertising personalisation are disabled. The choice is stored in local storage and can be changed from “Cookie settings” in the footer. See the cookie notice for cookie names and retention.
Sharing and international transfers
Vercel hosts the application, Neon hosts the database, Cloudflare provides DNS and bot protection, and Google provides optional analytics. The operator remains the controller and must review processor terms, subprocessors, locations, safeguards and international-transfer arrangements before launch. Information may also be disclosed where law requires it.
Retention and deletion
Underlying reports are deleted after 24 months. Security rate-limit records should be routinely cleared after their configured short window. A private deletion token lets a contributor permanently remove a report earlier without an account. Aggregate snapshots must be irreversibly anonymised or deleted when source reports expire.
Your rights
Depending on the circumstances, you may have rights to object, restrict processing, request erasure or complain to the ICO. Because the service deliberately does not collect contact details, the private deletion token is the practical way to identify and delete a report. The operator should provide a contact address here before launch.