Legal
Privacy Policy
Last updated 11 April 2026
Data Controller
The data controller for your personal data is Iron Stable Ltd, a company registered in England and Wales (Company No. 17061294), with registered office at Suite A, 82 James Carter Road, Mildenhall, England, IP28 7DE.
Order fulfilment, dispatch, and returns are handled by our fulfilment partner, SK Motorcycles Limited (trading as Iron City Motorcycles), an authorised Harley-Davidson dealer (Company No. 11359053), based at Wellington Road Industrial Estate, Wellington Road, Leeds, LS12 2UA. SK Motorcycles processes your name, delivery address, and order details solely for the purpose of fulfilling your order.
For any data protection queries, please contact us at support@ironstable.app.
What Data We Collect
Account Data
When you create an account, we collect your email address and password (which is securely hashed and stored by our authentication provider). During onboarding, we collect your first name, surname, display name, and gender.
Profile Data
You may optionally provide a profile photo (avatar), cover photo, mobile phone number, and social media links (Facebook, Instagram, TikTok).
Order & Transaction Data
When you place an order through the Iron Stable shop, we collect your delivery name and address, email address, order details (items, quantities, prices), and transaction amounts. Payment card details are entered directly into Stripe's secure payment form and are never stored on our servers — we only receive a transaction reference and the last four digits of your card for order identification.
Bike Data
When you register a motorcycle, we collect the Vehicle Identification Number (VIN), model code, year, colour, mileage, and nickname. You may add service records, parts fitted, modifications, and photographs. This data is attached to the motorcycle's VIN and forms its provenance record.
HOG Membership Data
If you join a HOG chapter, we collect your HOG membership number, chapter affiliation, preferred dealer, and any officer roles assigned to you. Insurance documents may be uploaded for ride-out RSVP validation.
Social Data
Content you post on the Platform including feed posts, comments, likes, and uploaded media (photos, images).
Technical Data
We automatically collect your IP address, browser type, device information, and pages visited when you use the Platform. This data is collected by our hosting and authentication infrastructure.
Lawful Basis for Processing
We process your personal data under the following lawful bases (UK GDPR and the Data (Use and Access) Act 2025, Article 6):
- Contract (Article 6(1)(b)): Processing necessary to provide you with the Platform services you signed up for — account management, bike records, chapter features, social functionality.
- Legitimate Interests (Article 6(1)(f)): Platform security, fraud prevention, service improvement, and ensuring the safety of our community. Under the Data (Use and Access) Act 2025, these are recognised legitimate interests. We have conducted a balancing test and are satisfied that these interests do not override your rights and freedoms.
- Legal Obligation (Article 6(1)(c)): Where we are required to retain or disclose data to comply with UK law.
- Consent (Article 6(1)(a)): For any optional processing such as marketing communications. You may withdraw consent at any time.
How We Use Your Data
- To create and manage your account
- To display your profile and content to other Platform users
- To maintain motorcycle provenance and service history records
- To facilitate HOG chapter membership, ride-outs, and community features
- To process and fulfil orders placed through the Iron Stable shop
- To arrange delivery of purchased items
- To handle returns, refunds, and customer service enquiries
- To prevent fraudulent transactions and protect against payment fraud
- To communicate with you about your account, orders, and Platform changes
- To ensure Platform security and prevent abuse
- To analyse website usage and improve the site (via Google Analytics 4, with your consent)
- To improve the Platform and fix issues
- To send you service emails related to your account activity, including onboarding guidance, membership status updates, and approval notifications. You can opt out of non-essential service emails at any time via the unsubscribe link in each email or through your account Settings.
Data Sharing
5.1 Infrastructure Providers
We share your data with the following third-party service providers who process data on our behalf to operate the Platform:
- Supabase (authentication, database, file storage) — hosted on AWS in the EU West (London) region. Processes account data, profile data, bike data, and uploaded media.
- DigitalOcean (server hosting) — EU-based infrastructure. Processes technical data and serves the Platform.
- Cloudflare (CDN, security, and static site hosting) — processes technical data (IP address, request headers) to serve web pages and protect against attacks. Data may be processed at edge locations worldwide.
- Stripe (payment processing) — processes payment card details, delivery address, and transaction data when you place an order. Stripe also provides Link, Klarna, and Amazon Pay as checkout options. Your card details are entered directly into Stripe's secure form and never touch our servers. Data processed under Stripe's Data Processing Agreement.
- SendGrid (Twilio Inc.) (transactional email delivery) — processes your email address and first name for the purpose of sending service communications such as onboarding guidance, membership status updates, order confirmations, and approval notifications. Data processed in the US under Standard Contractual Clauses.
- Google Analytics (website analytics) — with your consent, collects anonymised browsing data (pages visited, device information, time on site) via cookies. We do not send any personally identifiable information to Google Analytics. Data processed in the US under Standard Contractual Clauses.
5.2 Dealership and Partner Data Sharing
When you join a chapter on Iron Stable and accept the Platform Data Sharing Agreement, you consent to the following additional sharing:
- Your registered dealership may receive your bike details (make, model, year, mileage, modification history) to provide service reminders, safety recall notifications, and relevant offers.
- Approved Iron Stable partners may use your bike and riding data to provide personalised product suggestions and member-exclusive discounts through the Platform.
- Your anonymised riding data may contribute to chapter and manufacturer mileage programmes.
- Your vehicle compliance dates (MOT due date, insurance expiry) may be used to send timely reminders, including from approved partner services.
What is never shared: Your personal contact details (email address, phone number, home address) are never shared with dealerships or partners. They receive your bike data, not your identity, unless you choose to contact them directly through the Platform.
5.3 Your Control
- You can withdraw your data sharing consent at any time from Settings within the Platform.
- You can request deletion of your account and all associated data at any time from Settings.
- Withdrawing consent may limit certain features of the Platform, such as personalised service reminders and partner offers.
5.4 Legal Disclosure
We may disclose your data if required by law, court order, or to protect the safety of our users.
We do not sell, rent, or trade your personal contact details to any third party.
Data Retention
- Account and profile data: Retained while your account is active. Deleted or anonymised within 30 days of account deletion.
- Bike Data (service history, provenance): Retained indefinitely as it is attached to the motorcycle's VIN, not your personal account. This is a core feature of the Platform — provenance records persist to support future owners and buyers.
- Insurance documents: Retained while relevant to active chapter membership. Deleted on request or when expired.
- Technical/server logs: Retained for up to 90 days for security and diagnostic purposes.
Your Rights Under UK GDPR
You have the following rights regarding your personal data:
- Right of access — request a copy of the personal data we hold about you
- Right to rectification — request correction of inaccurate data
- Right to erasure — request deletion of your personal data. Please note that Bike Data attached to a VIN cannot be erased as it forms part of the motorcycle's permanent provenance record (see Section 6).
- Right to restrict processing — request that we limit how we use your data
- Right to data portability — receive your data in a structured, machine-readable format
- Right to object — object to processing based on legitimate interests
- Right to withdraw consent — where we rely on your consent, you may withdraw it at any time
To exercise any of these rights, please email us at marketing@opusmotorgroup.co.uk. We will respond within one month of receiving your request, in accordance with UK GDPR requirements.
Under the Data (Use and Access) Act 2025, response deadlines may be paused where we reasonably need to verify your identity or clarify the scope of your request. Any search for your personal data will be conducted on a reasonable and proportionate basis.
Complaints About Data Processing
Under the Data (Use and Access) Act 2025, you have the right to complain to us about how your personal data is processed.
If you are a registered user of the Platform, you can submit a data protection complaint through the Settings page within your account.
Alternatively, you may submit a complaint by post to:
SK Motorcycles Limited
Kia Lockheed Close, Preston Farm Industrial Estate
Stockton-On-Tees, England, TS18 3BP
Or by email to: marketing@opusmotorgroup.co.uk
We will acknowledge your complaint within 30 days of receipt, take appropriate steps to address it, and inform you of the outcome.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).
International Data Transfers
Your data is primarily stored within the EU/UK region (AWS eu-west-2, London). Where data is processed outside the UK, we ensure appropriate safeguards are in place, including Standard Contractual Clauses or reliance on UK adequacy decisions.
Security
We take the security of your data seriously and implement appropriate technical and organisational measures, including:
- Row-level security (RLS) on all database tables ensuring users can only access authorised data
- Encrypted connections (HTTPS/TLS) for all data transmission
- Passwords are securely hashed — we never store plaintext passwords
- Restricted storage bucket access with role-based permissions
- Regular security reviews of our infrastructure and access controls
Children
The Platform is intended for users aged 18 and over. We do not knowingly collect personal data from anyone under 18 years of age. If we become aware that we have collected data from a person under 18, we will take steps to delete that data promptly.
Cookies
We use analytics cookies (Google Analytics 4) to understand how visitors use the site. These cookies are only set with your consent — when you first visit, a cookie banner asks for your preference. If you decline, no analytics cookies are set and Google Analytics does not load.
We also use strictly necessary cookies for authentication and session management, which do not require consent.
For full details, see our Cookie Policy.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via the Platform or by email. The "Last updated" date at the top of this page indicates when the policy was last revised.
Contact and Complaints
If you have any questions or concerns about how we handle your personal data, please contact:
Iron Stable Ltd
Suite A, 82 James Carter Road
Mildenhall, England, IP28 7DE
Email: support@ironstable.app
Tel: 0113 245 2499
You have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your data protection rights have been violated:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Website: ico.org.uk
Telephone: 0303 123 1113