Moving Manes — Privacy Policy
Last updated: 10 September 2026
Who we are. Moving Manes is a trading name of Data Forage Limited (“we”, “us”, “our”), a company registered in England and Wales (company no. 12944938). This Privacy Policy explains how we collect and use your personal data when you use movingmanes.com and related services (the “Services”). It is incorporated into and forms part of our Terms and Conditions.
We collect account details you provide (e.g., name and email), listing contact details you choose to publish (e.g., phone and postcode), limited payment information via Stripe, and usage data via cookies (Google Analytics, Microsoft Clarity, and Meta Pixel), plus limited technical error diagnostics through Sentry. We use this to run the platform, publish your listings, operate our in-platform messaging (including storing messages and checking for fraud and abuse), prevent fraud, diagnose faults, improve the Service (including AI-powered features), and - if you opt in - send you marketing. You can contact us any time at [email protected] to exercise your UK GDPR rights.
1. Data controller & contact
Data controller: Data Forage Limited (operator of Moving Manes). For any privacy query or request, email [email protected].
2. The personal data we collect
2.1 Account registration
When you register, we collect: first name, last name, email, password (authentication via Supabase), and your reason for registering (whether you are looking to buy, looking to sell, or just browsing). We also collect the following optional fields: telephone, postcode, business name, and your marketing preference. We may store some account information (not your password) in our own database.
2.2 Listings (public adverts)
When you create a listing, we collect first name, last name, telephone (optional) and postcode to display on the listing page so buyers can contact you and gauge location. By supplying a telephone number, you consent to its publication on a public page that may be indexed by search engines. You remain responsible for any personal data you include in listing text or images.
2.3 Messaging
We operate an in-platform messaging service that lets users send and receive enquiries about listings. We collect and store the content of messages (including any text, images, files and links you send) and related data such as the sender and recipient, the listing concerned, timestamps, delivery/read status and technical metadata. We use this to deliver and display messages to the participants, to send you notifications (by email and/or in the app) that you have a new message, and to detect and investigate spam, scams, fraud, abuse and prohibited or illegal content. The other participant in a conversation will see the messages you send and your display name; depending on the listing this may include your name or business name. Please do not send special category (sensitive) personal data, payment card details or bank credentials through messaging.
2.4 Payments
Payments are processed by Stripe. We do not store full card details. We keep payment confirmations and transaction references for accounting and fraud prevention.
2.5 Usage data, cookies & similar tech
We use cookies and similar technologies to operate and improve the Service. Third-party tools include Google Analytics (site analytics), Microsoft Clarity (UX analytics), and the Meta Pixel (advertising measurement). See the separate Cookies Policy for details and choices.
2.6 Error monitoring
We use Sentry to diagnose unexpected technical errors in the Service. An error report may contain the sanitised error type and message, relevant application code locations, timestamp, application release and environment, the operation that failed and, if you are signed in, your pseudonymous account identifier. We do not intentionally include your account name or email address, cookies, HTTP headers, request or response bodies, URL query parameters, message content or listing content in error reports. The integration is configured to exclude those request fields and to redact or discard errors that match sensitive-data patterns. Browser error reports are sent directly to Sentry, so Sentry may also receive network information such as your IP address when the connection is made.
2.7 Vehicle history (public data, non-personal)
To show MOT status/history for vehicles, we retrieve public information from the UK Government’s Driver and Vehicle Standards Agency (DVSA) MOT database via its API. This information does not contain personal data and is reused under the Open Government Licence v3.0 (see our Terms & Conditions for attribution and disclaimers).
2.8 Reports, moderation and abuse-prevention data
If you report a listing, message or user, or if we review content or accounts, we process the information in the report (including any screenshots you provide), the content under review, and records of the action we take. We use automated systems (including filtering and risk-scoring, which may be AI-assisted) and human review to help keep the Service safe, and we keep records of moderation decisions and enforcement action to operate a consistent and proportionate process and to meet our legal obligations.
3. Purposes & lawful bases
| Purpose | Examples | Lawful basis |
|---|---|---|
| Provide and operate the Service | Account creation/login; publishing listings; operating in-platform messaging (delivering, storing and notifying); showing approximate location from postcode | Contract (to provide requested services) |
| Process payments | Charge listing fees; confirmations; fraud checks via Stripe | Contract; Legal obligation (tax/accounting) |
| Security & fraud prevention | Abuse/spam filtering; rate-limiting; investigating suspicious activity | Legitimate interests (secure, reliable service) |
| Messaging, safety and content moderation | Storing and delivering messages; sending message notifications; scanning and risk-scoring messages and content for spam, scams, fraud and prohibited or illegal content; human review; enforcing our Terms; handling reports and complaints | Contract (to deliver messages you choose to send); Legitimate interests (a safe, secure and lawful service; fraud and abuse prevention); Legal obligation where applicable, including responding to lawful requests and complying with online safety, regulatory and record-keeping obligations |
| Comply with online-safety and other legal duties | Assessing and responding to legal, regulatory, safety, illegal-content, law-enforcement and record-keeping obligations where they apply | Legal obligation; Legitimate interests |
| Analytics & product improvement | Google Analytics; Microsoft Clarity; A/B testing; UX metrics | Legitimate interests (improve service) and/or Consent (for non-essential cookies) |
| Reliability and error monitoring | Diagnosing unexpected application errors and identifying the affected release or operation through Sentry | Legitimate interests (maintain a secure, reliable service and correct faults) |
| Advertising measurement | Meta Pixel for reach and conversion measurement | Consent (marketing cookies) |
| Marketing communications | Newsletters, offers from Moving Manes | Consent (opt-in; withdraw any time) |
| AI/ML features | Develop, train, and operate models for search, categorisation, fraud prevention, auto-populate and translation | Legitimate interests (service improvement). Where personal data is involved, rights (e.g., object) apply. |
| Legal & compliance | Tax records; responding to lawful requests; enforcing Terms | Legal obligation; Legitimate interests |
4. Automated processing and decisions
We use automated systems to help keep the platform safe, including filtering, risk-scoring and other automated or AI-assisted checks of messages, listings and accounts, to detect spam, scams, fraud, abuse and prohibited or illegal content. Some protective measures (such as spam filtering, rate-limiting and temporary blocks) may be applied automatically. We do not normally take decisions that produce legal or similarly significant effects about you based solely on automated processing without human involvement. Where such a measure is taken solely by automated means and significantly affects you, you have the right to request human review, to express your point of view and to contest the decision: email [email protected]. These systems support, and do not replace, your own judgement, and we do not guarantee that they will detect or prevent any particular message, scam or harm. We do not use private message content to train general-purpose AI models. Message content may be processed by automated or AI-assisted systems for safety, fraud prevention, moderation, security and operation of the Messaging Service.
5. Sharing your data
- Service providers (processors): e.g., Supabase (auth/database), Stripe (payments), Sentry (technical error monitoring), analytics (Google, Microsoft), and advertising measurement (Meta Pixel). This also includes cloud hosting and storage for the platform, messages and attachments, email delivery for notifications, and any moderation or safety tooling we use. We share only what’s necessary under contracts with appropriate safeguards.
- Other users (messaging): When you send a message, its content and your display name (and, where relevant, your name or business name) are shared with the recipient. Messages are not public, but the recipient can read, copy, save or screenshot them.
- Public listings: Your listing contact details (name, phone if provided, postcode) are public on the listing page and may be copied or indexed.
- Safety and law enforcement: We may disclose messages, content and account data to the police, regulators (including Ofcom) or other authorities where we are required to, or where we consider it appropriate to prevent, detect or investigate crime, fraud, abuse or harm, or to protect the rights, safety or property of any person.
- Third-party data for auto-populate (optional): If you use the auto-populate feature (e.g., by providing a vehicle registration mark), we may share that identifier with trusted data providers to pre-fill fields. You must review and confirm any pre-filled data before publishing.
- Legal/compliance: We may disclose data where required by law or to protect rights, safety, and security.
- Business transfers: If we undergo a merger or sale, personal data may transfer subject to equivalent protections.
6. International transfers
Where data is transferred outside the UK/EEA (for example, to service providers in the USA), we implement appropriate safeguards such as UK-approved Standard Contractual Clauses or other lawful transfer mechanisms. We aim to store user data in the UK/EEA where feasible.
7. Data retention
- Account data: Held while your account is active, then deleted or anonymised. Limited data may be retained for a period to comply with legal, accounting or fraud-prevention obligations (typically up to 6 years for financial/tax records).
- Listings: Public while live; removed from public view when expired/removed. We may retain copies internally for a short period (e.g., a few months) for re-listing support, dispute handling, or fraud checks, then delete or anonymise.
- Error reports: Retained for the period configured in Sentry and no longer than needed to investigate faults, protect the Service and confirm that fixes are effective.
- Payments: Transaction records kept as required by law (usually up to 6 years). We do not store full card details.
- Messaging: We keep messages while your account is active so your conversations remain available to you, and no longer than necessary for the purposes described in this Policy. When you delete a message from your inbox within the platform's messaging service (this does not affect any separate email notification you may have received, which is held in your own email account), it is removed from your view and then permanently deleted from our active systems within a limited period, after which routine backups cycle out. Where a message, attachment or account is the subject of a report, or is flagged for or relevant to suspected spam, scams, fraud, abuse, illegal content or a dispute, we keep the relevant content and records for longer as needed for investigation, enforcement, safety and legal purposes (and, for serious matters, for as long as required to comply with our legal obligations or to establish, exercise or defend legal claims).
- Analytics: Stored per provider settings; we primarily use aggregated/anonymised data for trend analysis.
8. Your rights (UK GDPR)
You have rights to access, correct, delete, and restrict or object to processing of your personal data, and to data portability. You also have the right to withdraw consent (e.g., for marketing or cookies) at any time. To exercise your rights or raise a concern, email [email protected]. You can also complain to the UK Information Commissioner’s Office (ICO). We would appreciate the chance to address your concerns first.
9. Children
Our Services are for users aged 18+. We do not knowingly collect personal data from children. If you believe a child has provided us data, please contact us and we will delete it.
10. Security
We use appropriate technical and organisational measures (e.g., HTTPS/TLS, access controls, hashing passwords; Stripe for payments) to protect your data. No system is 100% secure; please keep your password confidential and contact us promptly if you suspect unauthorised access. Access to message content and personal data is restricted to authorised staff on a need-to-know basis, subject to access controls and logging, and is used only for the purposes described in this Policy (such as operating the Service, support, safety and complying with the law).
11. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated Policy with a new “last updated” date and, where appropriate, notify you. Continued use of the Services after changes take effect constitutes acceptance.
12. Contact us
Email: [email protected]