Privacy Policy
How OCEBASE LTD collects, uses, shares, retains and protects personal data.
- Version
- 2026-09-03
- Effective
- 3 September 2026
- Last updated
- 3 September 2026
1. Controller and contact
OCEBASE LTD (company number 17221259), Office 15301, Initial Business Centre, Unit 7 Wilson Business Park, Manchester, M40 8WN, United Kingdom is the controller of personal data processed for SubPlaza. Privacy requests: privacy@subplaza.com. General support: support@subplaza.com. This Policy covers visitors, account holders, purchasers, support contacts and affiliate participants.
2. Data we collect and sources
- Account, contact, authentication, language, country and preference data supplied by you or an OAuth provider.
- Orders, delivery destinations, product access, coupons, Credits, refunds, disputes and support evidence.
- Payment status, wallet address, asset, network and transaction identifiers from payment and blockchain providers; we normally do not receive full card details.
- IP address, approximate location, browser, device, cookie choices, security logs, referral and interaction events collected from your device.
- Fraud, chargeback, sanctions and wallet-risk signals from payment, security, compliance and public blockchain sources.
3. Purposes and lawful bases
- Contract: create and secure accounts, accept payment, deliver orders, provide warranty support, refunds and requested communications.
- Legal obligation: tax, accounting, consumer, sanctions, anti-fraud, court and regulatory records.
- Legitimate interests: service security, abuse prevention, troubleshooting, product improvement, defence of claims and limited existing-customer communications, balanced against your rights.
- Consent: non-essential analytics or advertising cookies and marketing where consent is required. You may withdraw consent without affecting earlier processing.
4. Required information
Account, payment, delivery and verification information marked as required is necessary to form or perform a contract, secure the service or comply with law. If it is not provided, we may be unable to create an account, accept or deliver an order, issue an external refund or complete verification.
5. Cookies, attribution and advertising
Strictly necessary cookies and local storage support authentication, security, checkout, language, currency, consent records and first-party affiliate referral attribution. The referral cookie records which affiliate introduced a customer for the disclosed referral period; it is not used for cross-site advertising profiles and cannot be disabled in Cookie settings. First- and last-touch advertising campaign parameters may be retained for up to 90 days only when the relevant optional consent permits.
With consent where required, Google Tag Manager loads enabled Google and Meta measurement tags. These providers may receive page and conversion events, advertising click identifiers, device or network data, and hashed account identifiers. Browser tags remain disabled when advertising consent is rejected or withdrawn. Consent records may be retained for up to three years.
Marketing email preferences are separate from advertising-cookie consent. Withdrawal stops future optional processing but does not affect transactional, security, order or legal notices.
6. Recipients and processors
We share only necessary data with Cloudflare for delivery, security, Turnstile, Workers, storage or email routing; hosting, database, backup and logging providers; enabled authentication providers; payment, wallet and blockchain-risk providers shown during checkout; email and customer-support providers; and Meta and Google when advertising measurement is enabled with the required consent. Professional advisers, authorities or a business successor may also receive data where lawful. Each independent provider may process data under its own notice. We do not sell personal data for cash.
7. International transfers
Providers may process data in the United Kingdom, EEA, United States, Singapore or other locations stated in their notices. For restricted transfers we rely, as applicable, on UK adequacy regulations, the UK International Data Transfer Agreement or Addendum, approved contractual safeguards, and transfer-risk assessments. Contact privacy@subplaza.com for information about applicable safeguards.
8. Retention
- Account profile: while active and normally up to 24 months after closure, unless a longer period is needed for another category.
- Orders, payments, refunds, invoices and tax records: normally 6 years after the relevant financial year or longer where legally required.
- Warranty and support records: the warranty or dispute period plus up to 6 years for legal claims.
- Security, fraud, sanctions, wallet-risk and chargeback records: normally up to 6 years after the last relevant event, subject to necessity and legal requirements.
- Marketing consent records: until withdrawal plus up to 3 years as evidence of compliance.
- Routine technical logs: normally 30–365 days; backups expire on their configured rotation. Data is then deleted or anonymised unless preservation is legally required.
9. Fraud screening and automated decisions
Automated rules may score payment, device, location, sanctions and public-wallet risk and may delay an order or request verification. We do not intend to make a solely automated decision with legal or similarly significant effect without a lawful basis and required safeguards. Ask support@subplaza.com for human review, to express your view and contest a decision.
10. Your rights and complaints
Depending on applicable law, you may request access, correction, deletion, restriction, portability, objection, consent withdrawal and review of automated decisions. We may verify identity and retain data required for legal obligations or claims. You may complain to the UK Information Commissioner’s Office at ico.org.uk or to the competent authority where you live or work.
11. Children and security
SubPlaza is not directed to anyone under 18 and we do not knowingly permit minors to create accounts. We use access controls, least-privilege practices, encryption in transit, provider security controls, logging, backups and incident response. No system is risk-free. Where legally required, we will notify affected people and regulators of a personal-data breach.
12. Changes and language
We identify this Policy by version and retain prior versions. Material changes will be communicated through the website, account or email where required. A translated version is provided for convenience; if it conflicts with English, English prevails to the extent permitted by law, without limiting mandatory rights under applicable local law.