Privacy policy
Last updated: 10 July 2026
1. Who we are
Nintech Ltd (Company No. 11946229), Suite 2a Blackthorn House, St Pauls Square, Birmingham B3 1RL, United Kingdom, is the data controller for personal data collected through this website, the store, and the client portal.
2. What we collect
Account details you give us: name, email, and company. Order details: your delivery address, the contents of your orders, and any notes you add for our engineers. Support tickets and contact-form messages. A record of the transactional emails we send you. Payment records: card payments are processed by Stripe and your card details never touch our servers; for bank transfer and USDT payments we keep the payment reference or transaction hash needed to match your payment to your invoice. We also keep the technical records needed to run the platform safely — session identifiers and login attempts.
3. Why we process it
To run your account, take and fulfil your orders, dispatch goods, provision hosting, and answer your tickets — processing necessary for our contract with you (UK GDPR Article 6(1)(b)). To keep the platform secure — login rate-limiting, session management, and abuse prevention — under our legitimate interests (Article 6(1)(f)). To keep VAT and accounting records — a legal obligation (Article 6(1)(c)).
4. Who we share it with
We do not sell personal data. We use three processors: Stripe for card payments, Resend for transactional email, and DigitalOcean for the infrastructure the platform and customer hosting run on, in the regions listed on their site. Each receives only what it needs to do its job under a data-processing agreement. Beyond that, personal data leaves us only where the law requires it.
5. How long we keep it
Invoices, payment records, and other accounting data are kept for six years from the end of the financial year they relate to, as UK tax law requires. Account, order, and ticket data are kept while your account is active and deleted when you ask us to delete them — apart from the accounting records above, which we must retain.
6. Your rights
You can ask for a copy of your personal data, have it corrected or erased, receive it in a portable format, restrict how we use it, and object to processing based on legitimate interests. We respond within one month. If you are unhappy with how we handle your data, you can complain to the Information Commissioner's Office at ico.org.uk.
7. Cookies
The site sets one essential cookie (nt_session) to keep you signed in. It is httpOnly, expires after 30 days, and is never used for tracking. We run no analytics or advertising cookies — which is why there is no cookie banner: there is nothing to consent to.
8. Privacy requests
To exercise any of these rights, or to ask anything about this policy, reach us through the contact page — a real engineer reads it and replies within one business day.