Legal
Privacy Policy
Version 2026-09-04. Last updated 3 September 2026.
1. Who is responsible for your data
It's Broken. Help! is the controller for personal information processed to operate this network platform.
You can automatically request an email-verified export of records from public-facing services. Privacy questions, broader rights requests and requests requiring identity checks can be submitted through our secure platform contact form. You may alternatively email notifications@itsbroken.help.
2. Repair groups and the platform
Community Repair Groups use the platform to organise their own activities and respond to public enquiries. A group may be an independent controller for information it decides to collect and use, including repair case notes, volunteer administration, event attendance and local financial records. Contact the group directly about that local processing. We remain responsible for platform accounts, security, central support, network administration and donations made to support the network.
3. Information we collect
- Account, profile and membership details, including contact details, skills, availability and group roles.
- Public repair enquiries and platform support cases, including replies, triage notes and contact preferences.
- Messages, discussions, documents, event participation and administrative audit records.
- Donation records including donor name, email, amount, recipient, payment provider, refunds, payouts, disputes, recovery status and provider transaction references. We do not store full payment-card or PayPal login details.
- Paid-promotion records including campaign copy, the submitting group administrator, review decisions, invoices, Stripe transaction references, and aggregate impression and visit counts.
- Private group-application and verification records, including organisation details, eligibility declarations, second-organiser and venue-representative contact details, venue and organiser evidence, official registration numbers where applicable, reviewer checks and decisions.
- Photos, captions and alternative text that authorised group administrators choose to publish in a group's public gallery. A photo may contain personal information about identifiable people.
- Verified visitor reviews, including the public reviewer's name, rating, comments and optional visit date; an encrypted email address used for verification; group responses; and private flag and moderation records.
- Public booking requests, including contact details, the item and fault description, access needs, selected repair skill and time, email-verification status, reminders and cancellations.
- Optional public event reminders, including the session, name, encrypted email address, verification status, delivery time and cancellation status.
- Security and technical data such as session activity, IP-derived security records, browser information, access logs and MFA status.
- Information you choose to make public, such as a public volunteer profile.
Group-verification evidence is restricted to authorised group coordinators and core platform administrators. It is not published with the group's verified badge.
4. Why we use it and our lawful bases
- Contract: to provide accounts, membership tools, communications, donation checkout, paid group promotion, receipts, invoices and requested platform services.
- Legitimate interests: to run and improve a safe repair network, route enquiries, prevent abuse, support groups, maintain records and protect the service. We balance these interests against your rights.
- Legal obligation: to keep financial, tax, fraud-prevention and compliance records and respond to lawful requests.
- Consent: where you choose optional communications, public-profile visibility or another feature that specifically asks for consent. You may withdraw consent at any time without affecting earlier lawful processing.
- Vital interests: in a genuine emergency where emergency-contact information is needed to protect someone.
5. Who receives information
We share information only where needed with the Community Repair Group concerned; members explicitly authorised to handle an enquiry or administration; and suppliers providing hosting, email, monitoring, file storage, mapping, anti-abuse and payment processing. A published review's name, rating and content are visible to anyone; the verification email is not shown to the group or public. Stripe or PayPal processes payment, seller-onboarding and identity-verification information under its own privacy terms when selected. When enabled, Cloudflare Turnstile receives limited browser and network information to distinguish legitimate visitors from automated abuse. Paid placements are delivered directly by this platform without a third-party advertising network or behavioural targeting. We may also disclose information where required by law or to establish, exercise or defend legal claims.
6. International transfers
Some suppliers may process information outside the UK. Where this happens, we require an approved transfer mechanism such as UK adequacy regulations, the UK International Data Transfer Agreement or an approved UK Addendum, together with appropriate safeguards. Supplier details are available on request.
7. How long we keep information
- Account and active membership information is normally kept while the account is active, then deleted or anonymised under the account-closure process, subject to records we must retain.
- Unverified repair enquiries are removed after 7 days. Verified repair enquiries are normally removed 24 months after their latest activity. A group may preserve an important enquiry where it has a documented safety, safeguarding, dispute or legal reason.
- Unactivated repair-group reports are removed after 48 hours. Other unverified platform support cases are removed after 30 days. Resolved support records are normally retained for up to two years.
- Unverified public data requests expire after 48 hours and completed export downloads after 7 days.
- Review submissions that are not email-verified are removed after 48 hours. Published reviews, official responses and moderation records remain while the group is listed or until removal is justified by a rights request, moderation decision or legal requirement.
- Booking requests that are not email-verified are removed after 48 hours. Confirmed, unavailable and cancelled booking records are normally retained for up to two years so groups can manage attendance, safety concerns and service history.
- Event reminder requests that are not email-verified are removed after 48 hours. Verified reminder records are removed 30 days after the session ends.
- Cases held in spam quarantine are normally removed after 90 days.
- Messages and discussions are retained according to the applicable group policy, normally up to three years after the last activity unless moderation, safeguarding or legal needs require longer.
- Donation, refund, payout, acceptance and accounting records are retained for at least six years after the end of the relevant financial year, or longer where tax, dispute or legal requirements apply.
- Paid-promotion, invoice, refund and related accounting records are retained for at least six years after the end of the relevant financial year. Campaign content and aggregate performance are retained with that record.
- Public gallery photos are kept until an authorised group administrator removes them or the group closes, unless they must be retained temporarily for a complaint, safeguarding concern or legal claim.
- Security and audit logs are normally retained for up to 12 months, with material security records kept longer where necessary.
- Backups expire on a rolling basis and are access-restricted while retained.
8. Security
We use access controls, group-scoped permissions, MFA for privileged functions, encryption in transit, private file storage, audit logging, session controls, backups and supplier controls. No internet service can guarantee absolute security. Please report suspected misuse promptly.
9. Advertising measurement
Homepage promotions are contextual and relate only to participating repair groups. We count a view when a promotion is rendered and a visit when its platform link is followed. These counters are aggregate: the advertising record does not store a visitor identifier, advertising cookie, browsing profile or IP address. We do not use these measurements to personalise which promotion a visitor sees.
10. Cookies and saved preferences
Essential cookies support security, sessions, authentication and fraud prevention and cannot be disabled through our preference control. If you choose “Accept cookies”, we also store an encrypted preference cookie containing your repair-group directory search, such as town or group text, postcode, distance, item type and whether you asked to see groups accepting enquiries. This saves you entering the same search again. It expires after one year and does not contain geocoded coordinates.
You can change your choice at any time using “Cookie settings” in the footer. Choosing “Essential only” removes the saved directory preference cookie. We do not use advertising cookies or cross-site behavioural tracking.
11. Your rights
Depending on the circumstances, you may ask for access, correction, deletion, restriction, portability or objection, and may withdraw consent. You also have the right not to be subject to a solely automated decision producing legal or similarly significant effects. The platform does not currently make such decisions.
We may need to verify your identity. We normally respond within one month. You may complain to the Information Commissioner's Office if you are dissatisfied, but we would appreciate the opportunity to address the issue first.
12. Source of information
Most information comes from you. We may also receive information from a group coordinator, another member involved in an enquiry or event, Stripe, PayPal, security providers, or publicly available sources where needed to operate and protect the service.
13. Changes
We may update this policy when the service, suppliers or law changes. Material changes will be highlighted in the platform and the version date will be updated.