PCHUB Privacy Policy
Last updated: 13 August 2026
PCHUB respects your privacy and is committed to protecting your personal information.
This Privacy Policy explains how we collect, use, store and share personal information when you:
- visit our website;
- contact us;
- request a repair quotation;
- book a repair or appointment;
- bring or send a device to us for repair;
- use our repair-tracking service;
- create a customer account;
- purchase products through our online shop;
- make a payment;
- request a refund;
- use our trade-in service;
- communicate with us by email, telephone, SMS or WhatsApp; or
- otherwise use our services.
This policy should be read together with our Cookie Policy and any specific terms that apply to repairs, ecommerce purchases or other PCHUB services.
1. Who we are
For the purposes of UK data protection law, the data controller is:
PCHUB
236 Archway Road
Highgate
London
N6 5AX
United Kingdom
Telephone: 020 8348 1377
Email: support@pchublondon.co.uk
Website: pchublondon.co.uk
Questions about privacy or requests concerning your personal information should be sent to:
2. Personal information we collect
The information we collect depends on the services you use.
Identity and contact information
This may include:
- name;
- billing or delivery address;
- email address;
- telephone number;
- account username;
- customer reference numbers; and
- preferred contact method.
Repair and device information
When you book or receive a repair service, we may collect:
- device category;
- manufacturer;
- model;
- serial number;
- IMEI number;
- device condition;
- accessories supplied with the device;
- reported fault;
- diagnostic information;
- repair history;
- photographs of the device;
- technician notes;
- customer-visible repair notes;
- repair status;
- parts used;
- warranty information;
- collection or delivery information; and
- other information required to diagnose or complete a repair.
Device access information
For some repairs we may need temporary access to the operating system or device in order to diagnose the fault, test the repair or verify functionality.
Where necessary, you may provide:
- PIN;
- password;
- temporary login details; or
- another access method.
We only request device-access information where reasonably necessary for the repair.
Access credentials are restricted to authorised staff who need them for the repair and should not be included in ordinary customer communications.
We normally delete or remove device-access credentials when they are no longer required for diagnosis, testing or completion of the repair.
You should remove or disable unnecessary accounts and back up important information before providing a device for repair where reasonably possible.
3. Information contained on devices
Computers, phones, tablets and storage devices can contain significant amounts of personal information.
During diagnostics, repair, testing or data recovery, our technicians may incidentally encounter files or information stored on your device.
We do not intentionally inspect personal files unless this is reasonably necessary to:
- diagnose a reported problem;
- verify that a repair has worked;
- recover data requested by you;
- test storage or operating-system functionality;
- investigate malware or corruption; or
- perform another service that you have authorised.
We do not use information found on your device for unrelated purposes.
You should tell us before the repair if the device contains particularly sensitive information that may affect how the repair should be handled.
PCHUB does not ask customers to provide special-category personal information unless it is genuinely necessary. If such information is encountered incidentally, access will be limited to what is necessary to provide the authorised service.
4. Contact forms and enquiries
When you submit a contact form or enquiry, we may collect:
- your name;
- email address;
- telephone number;
- enquiry type;
- device or product information;
- your message; and
- technical security information used to prevent spam or abuse.
Contact-form submissions are sent to the email address configured by PCHUB for customer enquiries.
We use this information to:
- respond to your enquiry;
- provide requested information;
- prepare quotations;
- arrange repairs or services;
- deal with product questions; and
- maintain appropriate records of communications.
Our lawful basis will normally be taking steps at your request before entering into a contract and/or our legitimate interests in responding to customers and operating our business.
5. Repair bookings, appointments and quotations
When you book a repair, appointment or request a quotation, we use your personal information to:
- identify you and your device;
- schedule appointments;
- assess the reported problem;
- prepare and send quotations;
- record acceptance or rejection of quotations;
- provide repair-status information;
- order or allocate parts;
- communicate with you about the repair;
- collect payment;
- provide invoices;
- administer warranties; and
- maintain repair records.
The main lawful basis for this processing is that it is necessary to take steps at your request or perform our contract with you.
We may also process information where necessary for legitimate interests such as protecting our business, preventing fraud, maintaining accurate repair histories and resolving disputes.
6. Repair tracking
Our repair-tracking system may allow you to check the progress of a repair using information such as:
- repair reference;
- email address; or
- telephone number.
We only display customer-appropriate information through the public tracking interface.
Internal technician notes, cost prices, passwords, access credentials and other restricted information are not intended to be displayed through public repair tracking.
7. Customer accounts
If you create an account, we may store:
- contact details;
- login credentials in protected form;
- addresses;
- order history;
- repair history;
- quotations;
- appointments;
- invoices;
- saved devices;
- trade-in records; and
- account preferences.
Passwords are handled by WordPress/WooCommerce authentication systems and are not stored by us in readable plain-text form.
You are responsible for keeping your account password secure.
8. WooCommerce and online shopping
Our ecommerce store may use WooCommerce.
When you place an order, we may process:
- name;
- billing address;
- delivery address;
- email;
- telephone number;
- account information;
- products ordered;
- prices;
- discounts;
- shipping method;
- order status;
- payment status;
- refund information; and
- transaction references.
We use this information to:
- process your order;
- take payment;
- deliver or make goods available for collection;
- provide order updates;
- handle refunds and returns;
- provide invoices;
- comply with accounting and tax requirements; and
- prevent fraud.
WooCommerce provides settings allowing website operators to manage personal-data retention for orders and accounts.
9. Payments
Payments may be processed through third-party payment providers such as Stripe, PayPal or another payment provider configured on our website.
PCHUB does not intentionally store your complete payment-card number, card security code or full card credentials on its own website database.
Payment providers may receive information necessary to:
- process the transaction;
- authenticate payment;
- prevent fraud;
- deal with disputes; and
- process refunds.
We may retain transaction references, payment status, payment method, amount paid and refund information for accounting and customer-service purposes.
The lawful bases for payment processing are performance of our contract and compliance with legal/accounting obligations.
10. Invoices and accounting records
We maintain records relating to:
- sales;
- repairs;
- invoices;
- payments;
- refunds;
- VAT where applicable;
- supplier transactions; and
- other financial transactions.
Where records must be retained for accounting or tax purposes, we retain them for the period required by law.
UK VAT records generally need to be retained for at least six years, subject to applicable exceptions.
11. WhatsApp, SMS and telephone communications
Where enabled, PCHUB may communicate with you by:
- telephone;
- SMS;
- WhatsApp;
- email; or
- another communication channel selected by you.
Transactional communications may include:
- appointment confirmations;
- repair-status updates;
- quotation notifications;
- payment confirmations;
- invoice notifications;
- collection notifications;
- dispatch information; and
- other messages necessary to provide your requested service.
To send SMS or WhatsApp communications we may use third-party providers such as WhatsApp Business, Meta, Twilio or another configured communications provider.
These providers may process:
- telephone number;
- message content;
- message status;
- delivery information; and
- associated technical metadata.
Transactional messages are different from marketing messages.
We will only send electronic direct marketing where permitted by applicable UK privacy and electronic-communications rules, and you may unsubscribe from marketing at any time. Where PECR requires consent for electronic marketing, consent must meet the UK GDPR standard.
12. Email and SMTP services
We use email to provide customer support and transactional notifications.
Email may be delivered through an SMTP or email-delivery provider.
Such providers may process:
- sender and recipient email addresses;
- subject lines;
- email content;
- delivery status;
- timestamps; and
- technical delivery information.
We use these services for reliable and secure delivery of communications.
Our current customer-facing sender may appear as:
PCHUB London Website
support@pchublondon.co.uk
13. Google services
We may use Google services including, depending on our current configuration:
- Google Analytics;
- Google Search Console;
- Google Maps;
- Google Business Profile; and
- other Google services.
Google Analytics
Where Google Analytics is enabled, it may collect information about how visitors use the website, such as:
- pages viewed;
- approximate location;
- device/browser information;
- traffic source;
- interactions; and
- technical identifiers.
Non-essential analytics technology will only be enabled where the required cookie/storage consent has been obtained.
Google Search Console
Search Console is primarily used by PCHUB administrators to understand how the website performs in Google Search.
Google Maps
Our Contact page may provide a Google Maps feature.
The map is designed to load only after you choose to load it, rather than automatically sending information to Google when you first open the Contact page.
When you choose to load Google Maps, Google may process information such as your IP address, browser/device details and interaction with the map.
14. Rank Math SEO
We use Rank Math SEO to manage website search-engine optimisation, including:
- page titles;
- meta descriptions;
- structured data;
- XML sitemaps;
- redirects;
- search-performance integrations; and
- other SEO functions.
Rank Math primarily operates within our WordPress administration system.
Where Rank Math is connected to external services such as Google Analytics or Google Search Console, information may be exchanged with those services in accordance with the configuration selected by PCHUB.
If administrative AI/Content AI functionality is used, website content entered into that service may be processed by the relevant service provider.
We do not intentionally submit customer repair data, device passwords, recovered files or private device contents to SEO or AI-content services.
15. Cookies and similar technologies
Our website uses cookies and similar storage/access technologies.
Strictly necessary technologies may be used where required for functions such as:
- website security;
- customer login;
- shopping cart;
- checkout;
- session management;
- cookie preferences; and
- fraud prevention.
Analytics, advertising and other non-essential technologies are only used where the required consent has been obtained.
Further information is provided in our Cookie Policy.
ICO guidance requires users to be given meaningful control over non-essential cookies and similar technologies, with consent based on a clear positive action rather than simply continuing to browse.
16. Information we receive automatically
When you use our website, our hosting, security and web systems may automatically record technical information such as:
- IP address;
- browser type;
- operating system;
- requested URLs;
- date and time;
- HTTP status;
- security events;
- referrer information; and
- server logs.
We use this information where necessary to:
- provide the website;
- maintain security;
- investigate attacks or abuse;
- diagnose technical problems;
- prevent fraud; and
- protect our services.
Our lawful basis is normally our legitimate interests in operating and securing the website.
17. Who we share information with
We do not sell customer personal information.
We may disclose information to service providers where reasonably necessary to operate PCHUB, including:
Website and infrastructure providers
Such as:
- website hosting;
- server providers;
- CDN providers;
- caching providers;
- backup providers;
- cybersecurity providers; and
- Cloudflare or equivalent services.
Ecommerce and payment providers
Such as:
- WooCommerce;
- Stripe;
- PayPal;
- card processors;
- payment gateways; and
- fraud-prevention services.
Communications providers
Such as:
- SMTP/email providers;
- SMS providers;
- Twilio;
- WhatsApp/Meta; and
- telephone providers.
Google and analytics services
Where enabled and permitted by your consent choices.
Shipping and delivery providers
Where required to deliver an order or device.
Suppliers
Where it is necessary to identify or obtain a product or repair part. We minimise customer information shared with suppliers.
Professional advisers
Including accountants, insurers, legal advisers and professional consultants where necessary.
Government or regulatory authorities
Where disclosure is required by law or necessary to establish, exercise or defend legal claims.
Service providers processing personal data on our behalf should be subject to appropriate contractual and security obligations. UK GDPR places requirements on controller-processor relationships.
18. International transfers
Some technology providers used by PCHUB may process personal information outside the United Kingdom.
Where a restricted international transfer occurs, we take reasonable steps to ensure that an appropriate UK data-transfer mechanism is available, such as:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to approved standard contractual clauses; or
- another lawful safeguard or exception.
The ICO recognises adequacy and Article 46 safeguards such as the IDTA as mechanisms for restricted transfers.
19. How long we keep information
We do not intend to keep personal information for longer than reasonably necessary.
Typical retention periods are:
General contact enquiries
Normally up to 12 months after the last meaningful communication, unless the enquiry develops into a customer relationship or there is another reason to retain it.
Quotations that do not become repairs
Normally up to 12 months after the quotation expires or the enquiry closes.
Repair records
Normally retained for up to 6 years after completion, where reasonably necessary for transaction records, warranty history, dispute handling, legal claims, accounting or business records.
Device passwords or access credentials
Only for as long as reasonably necessary to diagnose, repair and test the device, and normally removed when no longer required.
Orders, invoices, payments and accounting records
Normally retained for at least six years where required for accounting or tax purposes.
Customer accounts
Normally while the account remains active, subject to applicable legal and transactional retention requirements.
Security/server logs
Normally retained for a shorter operational period unless required to investigate security incidents, fraud or abuse.
Email, SMS and WhatsApp communications
Retained only for as long as reasonably necessary for customer service, transaction records, dispute handling and legitimate business requirements.
Backups
Information may remain within protected backup copies for a limited additional period until those backups are overwritten under our backup-retention cycle.
Retention may be extended where:
- required by law;
- a dispute or claim exists;
- fraud or misuse is being investigated;
- regulatory requirements apply; or
- the information is necessary to establish, exercise or defend legal rights.
20. Security
We take reasonable technical and organisational measures to protect personal information.
Measures may include:
- access controls;
- staff permissions;
- strong authentication;
- administrator two-factor authentication;
- secure hosting;
- encrypted HTTPS connections;
- security monitoring;
- firewall protection;
- software updates;
- malware protection;
- restricted database access;
- backups;
- activity logging; and
- limiting staff access to information needed for their role.
No internet or storage system can be guaranteed to be completely secure.
21. Your data-protection rights
Depending on the circumstances and the lawful basis being used, you may have rights including:
- the right to be informed;
- the right of access;
- the right to rectification;
- the right to erasure in certain circumstances;
- the right to restrict processing;
- the right to data portability where applicable;
- the right to object to certain processing; and
- the right to withdraw consent where processing is based on consent.
These rights are not all absolute and their availability can depend on the lawful basis and circumstances of the processing.
Your right to object
You have the right to object to processing based on legitimate interests in certain circumstances and you have an absolute right to object to the use of your personal information for direct marketing.
To exercise a privacy right, contact:
We may need to verify your identity before responding to a request.
22. Marketing preferences
Marketing consent is separate from transactional communications required to manage a repair, order, payment, appointment or other requested service.
Where you receive marketing from us, you can normally unsubscribe using the link or instructions included in the communication or by contacting:
Withdrawing marketing consent does not prevent us from sending service-related communications necessary to fulfil an existing order or repair.
23. Automated decision-making
PCHUB does not currently intend to make decisions about customers solely by automated processing where those decisions would produce legal effects or similarly significant effects.
Automated systems may assist with functions such as:
- spam detection;
- fraud indicators;
- inventory recommendations;
- website security; or
- administrative automation.
A member of staff remains responsible for relevant repair, quotation and customer-service decisions.
24. Third-party websites
Our website may contain links to websites operated by other organisations.
Their privacy practices are controlled by their own privacy policies.
PCHUB is not responsible for the content or privacy practices of independent third-party websites.
25. Children
Our website and repair/ecommerce services are intended primarily for adults.
If a person under 18 uses our services, a parent or guardian may need to assist with contracts, payments or repair authorisation where appropriate.
We do not knowingly use children’s personal information for targeted marketing.
26. Changes to this Privacy Policy
We may update this Privacy Policy when:
- our services change;
- new technology or providers are introduced;
- the law or regulatory guidance changes; or
- our privacy practices change.
The latest version will be published on this website with an updated revision date.
27. Complaints
If you have concerns about how PCHUB handles your personal information, please contact us first so that we can investigate.
Email: support@pchublondon.co.uk
Telephone: 020 8348 1377
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s data-protection regulator.
