Privacy
How this service uses information
Draft notice: the operator must add its legal identity and contact details before launch and complete the documented legitimate-interests assessment.
Information you submit
We do not request a name. When email check-ins are enabled, we collect a verified email address and keep it in a private contact record linked to the report. The address is never included in public results. Dates, broad region, value band, current status, dated status history and selected structured details may still relate to or identify a person—especially a sole trader—when combined. We therefore treat underlying submissions as personal data where applicable. The service does not accept free-text notes. Public statistics are shown at all sample sizes, so a result based on one or a few reports may reveal a contributor’s submitted values and must not be assumed to be anonymous. Only effectively anonymised information falls outside UK GDPR.
Purpose and lawful basis
We use report data to produce public aggregate statistics about waiting times, verify email ownership, let a verified contributor retrieve and update active reports linked to their address, send fortnightly service check-ins while a report is open, moderate data quality, prevent abuse and operate the service. Reminder emails are operational messages, not marketing, and each includes a way to stop them. Valid reports are included automatically, including in very small samples. Our proposed lawful basis is legitimate interests: providing a useful, current community evidence base while minimising collection and protecting contributors. This basis must be confirmed against the documented legitimate-interests assessment before launch. The acknowledgement on the form is not GDPR consent.
Technical information and fingerprints
The application uses a network address transiently to create a salted, non-reversible security fingerprint for rate limiting; it does not store the raw address in the application database. A separate salted fingerprint helps detect duplicate submissions. Cloudflare Turnstile processes technical information to distinguish legitimate users from automated abuse. Cloudflare, Vercel, Neon and other infrastructure providers may process network addresses, request details and device information in security and operational logs under their own retention controls.
Cookies and analytics
Google Analytics is optional and remains unloaded unless a visitor actively allows analytics. If allowed, it records standard page views without query strings. Enhanced Measurement, Google advertising signals and advertising personalisation are disabled. The choice is stored in local storage and can be changed from “Cookie settings” in the footer. See the cookie notice for cookie names and retention.
Sharing and international transfers
Vercel hosts the application, Neon hosts the database, Cloudflare provides DNS and bot protection, Resend delivers verification and reminder emails, and Google provides optional analytics. The operator remains the controller and must review processor terms, subprocessors, locations, safeguards and international-transfer arrangements before launch. Information may also be disclosed where law requires it.
Retention and deletion
Underlying reports are deleted after 24 months. A private verified email is retained only while reminder check-ins remain active. It is removed when the report is marked paid, the contributor stops reminders or the report is deleted. Expired verification records and security rate-limit records are cleared after their short operational windows. A private report token lets a contributor update status history or permanently remove a report earlier without an account. A fresh email verification code can retrieve active reports while their private contact record remains. Aggregate snapshots must be irreversibly anonymised or deleted when source reports expire.
Your rights
Depending on the circumstances, you may have rights to object, restrict processing, request erasure or complain to the ICO. Reminder messages provide a direct way to remove the private email address, while the private report token can update or delete the underlying report. The operator should provide a contact address here before launch.