Privacy Policy
Last updated: 28 May 2026
MDStack is built privacy-first. We run no telemetry, no analytics, and no third-party tracking. This policy explains the limited data we do handle — essentially, only what you choose to send us — and your rights under UK data protection law.
1. Who we are (data controller)
The data controller is David Robertson, a sole trader trading as “MDStack”, of Collingwood Buildings, 38 Collingwood Street, Newcastle, NE1 1JF, United Kingdom.
Data protection / DSAR contact: hello@mdstack.co.uk.
ICO registration number: ZC160375.
2. Our privacy promise
We do not track you. MDStack sets no analytics, advertising, or third-party tracking cookies, embeds no tracking SDKs, and operates no telemetry or “phone-home” mechanisms. We do not build profiles of visitors and we never sell or rent personal data.
3. What data we collect
The only personal data we collect is what you voluntarily enter into our contact / enquiry form when you ask us about a product or request an invoice. That is:
- Your name
- Your email address
- The product or plan you are enquiring about (and any plan/duration you selected)
- The content of your message
We do not operate user accounts, store passwords, or process card or bank details on this site. (Automated checkout and payment are a planned future addition — see section 5.)
4. Why we process it, and our lawful basis
- To respond to your enquiry and prepare and issue any invoice for the service you request — lawful basis: Article 6(1)(b) UK GDPR (steps taken at your request prior to, and performance of, a contract).
- To keep proper business records and to protect our systems and customers against fraud and misuse — lawful basis: Article 6(1)(f) UK GDPR (our legitimate interests in security and the prevention of crime), and applicable legal obligations.
5. How your enquiry is handled (processors)
Your enquiry is submitted to our own server-side handler. We use Resend (operating in the EU region) solely as an email-delivery processor to forward your message to our inbox. Resend acts on our instructions as a data processor; it is not analytics and does not track you.
Automated checkout (via the payment provider Mollie) and automated invoicing (via Invoice Ninja) are planned future additions and are not yet active. When they go live, this policy will be updated beforehand to name them as processors and to describe the billing data involved.
6. Cookies and local storage
We use no tracking, analytics, or advertising cookies. Because we set no non-essential cookies, we do not show a cookie consent banner — there is nothing to consent to.
We use a small amount of strictly-necessary browser storage (sessionStorage) purely to remember interface preferences during your visit (for example, the pricing duration you last viewed). This data stays on your device, is not transmitted to us, and is not used to identify you.
7. How long we keep your data
We keep enquiry data only for as long as needed to respond to you and, where a transaction results, to meet our legal and accounting obligations (UK tax law generally requires financial records to be kept for up to 6 years). After that, we delete it.
8. International transfers
We aim to keep personal data within the UK and EEA. Our email processor operates in the EU region. Where any transfer outside the UK is necessary, we rely on an adequacy decision or appropriate safeguards as required by UK GDPR.
9. Your rights
Under the UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025, you have the right to:
- Access the personal data we hold about you (a “DSAR”)
- Have inaccurate data corrected
- Have your data erased
- Restrict or object to our processing
- Data portability
- Withdraw any consent you have given, at any time
To exercise any of these, email hello@mdstack.co.uk. We will respond within one month.
10. Complaints
If you are unhappy with how we have handled your data, you can contact us first so we can try to resolve it. You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk.
11. Changes to this policy
We may update this policy as our service evolves (for example, when automated checkout launches). The “last updated” date above always reflects the current version.