Skip to content
FaultcodeCheck

Privacy policy

We store the least we can. No full postcodes, no readable contact details, and nothing non-essential — including advertising cookies — before you agree to it.

Last updated

The short version

Fault Code Check (faultcodecheck.co.uk) explains appliance and heating fault codes for people in the United Kingdom, and is operated from the Isle of Man. We collect as little as we can, we do not sell your data, and nothing non-essential — including Google advertising and analytics cookies — runs before you agree to it.

This notice is written for Isle of Man data protection law, for UK GDPR and for the Privacy and Electronic Communications Regulations (PECR). The cookie policy lists each cookie and similar technology by name.

Who is responsible

The data controller is OmegaIT Limited (company no. 135506C), trading as Fault Code Check.

  • Email: hello@faultcodecheck.co.uk
  • Post: OmegaIT Limited (company no. 135506C), Unit 12, Tower House, Castle Street, Douglas, Isle of Man IM1 2EZ

OmegaIT Limited is established in the Isle of Man. The Isle of Man is not part of the United Kingdom and has its own data protection law — the Data Protection Act 2018, the Data Protection (Application of the GDPR) Order 2018, which applies the GDPR in Manx law, and the GDPR and LED Implementing Regulations 2018 — supervised by the Isle of Man Information Commissioner (inforights.im). That is the law we are established under. Because this site is offered to people in the United Kingdom, UK GDPR also applies to the processing of their personal data, and a reader in the UK can complain to the UK Information Commissioner's Office as well as to the Isle of Man Information Commissioner.

We are the organisation that decides why personal data on this site is processed and how. If you write to us, that is who will answer.

What we collect, and why

When you ask us to find an engineer

Only these: the first half of your postcode, the appliance category, how urgent it is, a one-way hash of the contact detail you gave us, the time you consented, and which page you were on.

We never store your full postcode. We never store your email address or phone number in a readable form. The contact detail you enter is passed directly to the repair partner over an authenticated connection and is not retained by us beyond that transfer.

Lawful basis: your consent, given on the form (UK GDPR Article 6(1)(a)). The partner is a separate controller for what they then do with the details you sent them.

When you share your experience or report a correction

The text you write, an optional display name and model, and a one-way hash of your IP address used solely for rate limiting and abuse handling. Do not put contact details in the text — our filter rejects submissions containing them, and anything approved is public.

Lawful basis: legitimate interests in hosting moderated reports and correcting the pages (Article 6(1)(f)), and consent where a contribution is published under a name you chose.

When you just read the site

Your browser asks our server for a page. The web server writes a standard access log line — time, path, status, bytes, user-agent, and the network address the request came from. We do not use that log to build a profile of you.

For a count of distinct people we keep a one-way hash of the UTC day, the address and the user-agent, under a server-side salt. The hash changes at midnight by construction, so it cannot become a long-lived identifier. Crawler addresses are never hashed. Those hash rows are deleted after 35 days; the daily count they produced is kept, and it cannot be turned back into a person. Nothing is stored on your device for this, so it is not a cookie and it does not need a PECR consent prompt.

Lawful basis: legitimate interests in measuring audience size, keeping the site reliable, and blocking abuse (Article 6(1)(f)). The hash is still personal data while it exists, which is why it is in this notice.

When you sign in to the admin area

If you are the site operator and you log in, we set one HttpOnly cookie named fc_admin on the /admin path, lasting twelve hours. Visitors never receive it.

Lawful basis: legitimate interests in securing the admin area (Article 6(1)(f)).

Cookies and similar storage

Your cookie choice is stored in your browser's local storage under the key fc-consent, so we can remember it on the next visit. That storage is essential: without it we would have to ask you on every page.

Google AdSense advertising cookies, and any analytics cookies (Google Analytics 4 or Plausible), are not set unless you accept that category. Ads are not currently shown on the site. The AdSense account is registered so Google can verify ownership; the advertising library itself does not load until you accept advertising cookies *and* we switch ads on. The cookie policy is the list.

Lawful basis for non-essential cookies: consent (Article 6(1)(a) and PECR regulation 6). You can reject them and the pages work the same.

Advertising and Google AdSense

We use, or are preparing to use, Google AdSense to show display adverts. Google is a separate controller for the personal data it collects to serve and measure those adverts.

When advertising cookies are accepted, Google may set cookies and use advertising identifiers to:

  • serve adverts on this site
  • measure whether they were shown and clicked
  • personalise adverts if you have also allowed that in your Google account settings

Google describes that processing in Google's privacy policy and you can change advert personalisation at Google's ad settings.

We do not send Google a name, email address, or phone number from this site. The AdSense script is not loaded at all until advertising consent is given, so an unconsented visit does not receive those cookies.

Analytics

Two client-side tools exist in the code and are off until we choose to turn them on, and even then only after you accept analytics cookies:

  • Plausible — a page-view counter that does not use cookies to track you across sites. If enabled, it still waits for analytics consent, because the banner treats it as non-essential.
  • Google Analytics 4 — only if we need it to reconcile AdSense reports. If enabled, it sets _ga cookies after analytics consent, with IP anonymisation on.

Neither is enabled on the live site today. Server-side counting, described above, is what we actually use.

Who else receives data

  • Google, if you accept advertising or analytics cookies, as described above. Google may process data in the United States and other countries. Google relies on its own transfer mechanisms (including the UK-US data bridge where it applies) for that.
  • Repair partners, only when you submit the engineer form and tick consent. They receive the contact detail you typed, the outward postcode, the category and the urgency.
  • Hosting and infrastructure (the server that serves the pages, email for hello@faultcodecheck.co.uk). They process data on our instructions as processors.

We do not sell personal data. We do not use it for credit scoring. We do not run a remarketing list of our own.

How long we keep it

  • Engineer-lead hashes and the metadata of a request: no longer than we need to handle a follow-up or a dispute about that request, and not as a marketing list.
  • Published contributions: for as long as the page they sit on is live, or until you ask us to take yours down.
  • Visitor-day hashes: 35 days, then deleted.
  • Web-server logs: typically a fortnight of uncompressed files, then rotated off.
  • Cookie choice in local storage: until you clear it or change it.
  • Admin session cookie: 12 hours.

Your rights

Under UK GDPR, and under the GDPR as applied in the Isle of Man, you can ask us to:

  • tell you what we hold about you (access)
  • correct it
  • delete it
  • restrict how we use it
  • give you a copy in a portable form, where the basis is consent or contract and the processing is automated
  • stop processing that relies on legitimate interests, including the hashed visitor count

You can also withdraw consent for advertising or analytics cookies at any time — use Change cookie preferences on the cookie policy, or the banner the first time you visit. Withdrawal does not affect processing that already happened.

Email hello@faultcodecheck.co.uk and we will respond within one month. Because we store hashes rather than raw contact details, please include the detail you originally submitted so we can find the record.

If you are unhappy with how we handle this, you can complain to the Isle of Man Information Commissioner at inforights.im, which supervises us, or, if you are in the UK, to the UK Information Commissioner's Office at ico.org.uk. We would rather you wrote to us first so we can put it right.

Children

The site is written for adults dealing with household appliances. We do not knowingly collect personal data from anyone under 13, and we do not target children with adverts.

Changes

If we change what we collect or who we share it with, we update this page and the date at the top. A change that needs new consent — turning on a new advertising or analytics cookie, for example — will be asked for in the banner, not buried here.