Legal
Privacy Policy
Effective date: 04 May 2026
Last reviewed: 04 May 2026
Website: buyabusinessltd.com
This Privacy Policy explains how BUYABUSINESS LTD collects, uses, stores and shares personal data when you use the Buy a Business Ltd website, marketplace, listings, account features, enquiry tools, subscriptions, support services, feedback forms and related pages.
It also explains your data protection rights and how to contact us.
Buy a Business Ltd is a marketplace, not a broker. Information, search results and recommendations on this site are for general guidance only and do not constitute legal, tax, financial, investment, valuation or regulated advice.
1. Who we are
This website is operated by BUYABUSINESS LTD, a company registered in England and Wales under company number 11440681.
Our registered office is:
For data protection purposes, BUYABUSINESS LTD is the data controller for personal data processed through this website and marketplace.
Our ICO registration number is .
You can contact us about privacy or data protection by using:
Email: gdpr@buyabusinessltd.com
Contact page: https://buyabusinessltd.com/contact
Post: BUYABUSINESS LTD,
2. What this policy covers
This policy applies when you:
- visit the website;
- create an account;
- browse listings;
- submit an enquiry;
- list a business for sale;
- use seller, broker or buyer features;
- subscribe to a paid plan;
- contact support;
- submit feedback through a webform;
- use search, recommendation or marketplace guidance features;
- interact with our cookie banner or preference settings;
- receive emails from us.
This policy should be read alongside our Terms and Conditions and Cookie Policy.
3. Personal data we collect
The personal data we collect depends on how you use the website.
3.1 Website visitors
When you visit the website, we may collect:
- IP address;
- device and browser information;
- pages viewed;
- approximate location based on browser or network data;
- referring website or search source;
- cookie preferences;
- basic security and fraud-prevention logs.
Where analytics cookies or similar technologies are used, they are controlled through our Cookie Policy and cookie preference tools.
3.2 Account users
When you register or use an account, we may collect:
- name;
- email address;
- account role, such as buyer, seller or broker;
- account login and authentication records;
- account preferences;
- saved listings or saved searches;
- subscription status;
- support history;
- records of account actions, such as listing submissions, enquiries or changes.
We do not store your password in plain text.
3.3 Buyers and enquirers
When you submit an enquiry about a business listing, we may collect:
- name;
- email address;
- enquiry message;
- phone number, if you choose to provide it;
- budget or buying preference information, if you choose to provide it;
- the listing you enquired about;
- related communication and support records.
When you submit an enquiry, the relevant enquiry information is shared with the seller or broker connected to that listing so they can respond.
3.4 Sellers and brokers
When you list or apply to list a business, we may collect:
- name;
- email address;
- business name;
- business sector;
- business location;
- asking price;
- listing description;
- seller or broker contact details;
- uploaded images, documents or listing content;
- records confirming authority to list the business;
- moderation, report and compliance records.
Financial figures and business information in listings are supplied by sellers or brokers. Buy a Business Ltd does not independently verify financial figures or business claims.
3.5 Payments and subscriptions
When you subscribe to a paid plan, we may process:
- subscription plan;
- payment status;
- billing history;
- receipts or invoice records;
- payment provider customer references;
- payment failure, refund or chargeback records.
We do not store full card numbers, bank account details or direct debit details. Payment processing is handled by a third-party payment provider.
3.6 Support, complaints, reports and feedback forms
Where you submit feedback, contact us through a webform, report a listing, request support, or send a general message, we may collect:
- your name;
- email address;
- message content;
- listing or account reference, where relevant;
- supporting information you choose to provide;
- records of our response;
- complaint, report or moderation outcome.
We use this information to respond to you, improve the platform, review marketplace safety, handle complaints, and keep appropriate compliance records.
We do not use webform feedback to provide legal, tax, financial, investment, valuation or regulated advice.
3.7 Data we do not intentionally collect
We do not intentionally collect special-category personal data, such as health data, political opinions, religious beliefs, biometric data, sexual orientation or trade union membership.
Please do not include special-category data in listings, enquiry messages, support messages or free-text fields.
If special-category data is accidentally provided, we may delete it or ignore it unless we are legally required to keep it.
We do not handle business sale deposits, escrow, completion funds, client money or sale proceeds.
4. How we use personal data
We use personal data for the following purposes:
- to operate the website and marketplace;
- to create and manage accounts;
- to allow buyers to browse, save and enquire about listings;
- to allow sellers and brokers to submit and manage listings;
- to route buyer enquiries to the relevant seller or broker;
- to manage subscriptions, payments, receipts and refunds;
- to provide support and respond to complaints;
- to receive and review feedback submitted through webforms;
- to moderate listings and detect misleading, fraudulent or prohibited content;
- to protect the website, users and marketplace from abuse, fraud and misuse;
- to provide limited automated or AI-assisted platform support;
- to send service emails, such as account, enquiry, billing, security and subscription messages;
- to send marketing emails where you have opted in;
- to manage cookie choices and analytics preferences;
- to understand how visitors use the website where analytics consent has been given;
- to comply with legal, tax, accounting and regulatory obligations;
- to establish, exercise or defend legal claims.
Any automated or AI-assisted output is for general guidance only. It does not constitute legal, tax, financial, investment, valuation, commercial or regulated advice.
Users remain responsible for checking information independently before relying on it.
5. Lawful bases for processing
Under UK data protection law, we must have a lawful basis for using personal data.
We rely on the following lawful bases:
Creating and managing your account
Contract
Providing marketplace features
Contract and legitimate interests
Publishing and managing listings
Contract and legitimate interests
Routing buyer enquiries to sellers or brokers
Contract and legitimate interests
Managing subscriptions and payments
Contract and legal obligation
Sending service emails
Contract and legitimate interests
Sending marketing emails
Consent
Managing cookie preferences
Legal obligation and legitimate interests
Google Analytics and non-essential cookies
Consent
Fraud prevention, moderation and platform security
Legitimate interests
Handling feedback forms, support messages and reports
Legitimate interests and contract
Limited automated or AI-assisted platform support
Legitimate interests
Keeping financial and accounting records
Legal obligation
Handling legal disputes or regulatory requests
Legal obligation and legitimate interests
Where we rely on legitimate interests, we consider whether our interests are overridden by your rights and freedoms.
6. Buyer enquiry sharing
When a buyer submits an enquiry about a listing, we share the enquiry with the relevant seller or broker.
This may include:
- buyer name;
- buyer email address;
- enquiry message;
- phone number, if provided;
- any other information the buyer chooses to include.
Sellers and brokers must only use buyer enquiry data to respond to the specific enquiry.
They must not use buyer enquiry data for unrelated marketing, spam, resale, data harvesting or unrelated commercial purposes unless they have obtained separate lawful permission from the buyer.
7. Sellers, brokers and independent responsibility
Sellers and brokers are responsible for the personal data they choose to include in listings and communications.
Where a seller or broker receives buyer enquiry data, they may become an independent controller of that data for their own response and follow-up activity.
Sellers and brokers must handle buyer enquiry data lawfully and securely.
8. Marketing
We only send marketing emails where you have opted in or where we are otherwise legally permitted to do so.
Marketing emails will include an unsubscribe option.
You can withdraw marketing consent at any time by clicking unsubscribe or contacting us.
Withdrawing marketing consent does not stop essential service emails, such as account, security, billing, subscription or enquiry-related messages.
9. Cookies and similar technologies
We use cookies and similar technologies to operate the website, remember preferences, protect accounts, support payments, measure website use and improve the marketplace.
Essential cookies are needed for the website to work.
We use Google Analytics to understand how visitors use the website and to improve the platform. Google Analytics should only run where legally valid cookie consent has been given.
We do not currently use Meta Pixel, Google Ads remarketing, TikTok Pixel, LinkedIn Insight Tag or other retargeting pixels.
Non-essential cookies, including analytics cookies, will only be used where legally valid consent has been obtained.
You can manage cookie choices using the cookie banner or the Cookie Preferences link on the website.
More information is available in our Cookie Policy.
10. Search, recommendations and automated support
The website may include search results, listing suggestions, automated support features or general marketplace guidance.
These features are for general guidance only.
They are not based on a personalised assessment of your financial circumstances, investment objectives, risk appetite, tax position, legal position or business suitability.
Search results and recommendations must not be treated as a recommendation to buy, sell, invest in, value, finance or proceed with any business.
We do not keep AI/chatbot conversation logs as a standard feature.
Where users submit feedback, support requests or webform messages, those messages may be retained in accordance with the retention periods set out in this Privacy Policy.
11. Who we share personal data with
We may share personal data where necessary with:
- sellers or brokers, where you submit a buyer enquiry;
- buyers, sellers or brokers, where marketplace communication requires it;
- payment processors;
- email and communication service providers;
- website hosting, storage and infrastructure providers;
- authentication and account service providers;
- Google Analytics, where analytics consent has been given;
- cookie consent providers;
- limited automated or AI-assisted service providers, where used for platform operation or content support;
- professional advisers, such as accountants, solicitors, insurers or auditors;
- regulators, law enforcement, courts, HMRC, the ICO or other public authorities where required;
- fraud prevention, security or abuse-prevention services;
- a buyer or successor if our business or assets are sold, reorganised or transferred.
We only share personal data where we have a lawful basis to do so and where the sharing is reasonably necessary.
We do not sell personal data.
Current named processors and infrastructure providers used to maintain the service may include Vercel for hosting, Supabase for database and account infrastructure, Stripe for payments and billing, Resend for transactional email delivery, and Google Analytics where analytics consent has been given.
We do not currently use Meta Pixel, Google Ads remarketing, TikTok Pixel, LinkedIn Insight Tag or other retargeting pixels.
12. International transfers
Some suppliers or service providers may process personal data outside the United Kingdom.
Where personal data is transferred internationally, we take steps designed to protect it in accordance with UK data protection law.
Where relevant, this includes using the UK Addendum to the EU Standard Contractual Clauses or equivalent lawful safeguards with processors and sub-processors.
This may include using:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to the EU Standard Contractual Clauses;
- equivalent lawful transfer safeguards.
13. How long we keep personal data
We keep personal data only for as long as reasonably necessary for the purpose it was collected, including legal, accounting, tax, fraud-prevention, dispute, safety and compliance purposes.
Our standard retention periods are:
Active account records
While the account is active
Closed account records
Up to 2 years after closure, unless longer retention is required
Listings
Up to 12 months after expiry, removal or rejection
Buyer enquiries and marketplace messages
Up to 2 years
Payment, receipt and invoice records
Up to 7 years
Support tickets, reports and webform feedback
Up to 2 years
Cookie consent records
Up to 3 years
Audit, moderation and fraud-prevention logs
Up to 3 years
Legal claim or dispute records
As long as needed to handle the claim or dispute
Where data is no longer needed, we will delete, anonymise or securely archive it.
Some records may be retained for longer where required by law, tax rules, accounting obligations, fraud prevention, regulatory requests or legal claims.
14. Account deletion and erasure requests
You may request deletion of your account or personal data.
Where account deletion is available through the account dashboard, you may use that option.
You may also make a data subject access request, erasure request, or other privacy rights request through the contact page or by emailing gdpr@buyabusinessltd.com.
If your account is deleted, live listings connected to that account may be removed.
We may still retain records where required for legal, tax, accounting, fraud-prevention, dispute, safety or compliance purposes.
15. Security
We use appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.
These measures may include access controls, staff restrictions, monitoring, secure service providers, account protection, record keeping and incident response procedures.
No online service can be guaranteed to be completely secure. You are responsible for keeping your account details safe and telling us promptly if you suspect unauthorised access.
16. Personal data breaches
If we become aware of a personal data breach, we will assess it and take appropriate action.
Where required by UK data protection law, we will report relevant breaches to the Information Commissioner's Office.
Where a breach is likely to result in a high risk to affected individuals, we will notify those individuals without undue delay.
17. Automated decisions
We do not make solely automated decisions that have a legal or similarly significant effect on users.
Automated systems may help with search results, recommendations, fraud signals, listing quality checks, moderation queues or platform support.
Where automated systems flag an issue, users may request human review by contacting us.
18. Your data protection rights
Depending on the circumstances, you may have the right to:
- request access to your personal data;
- request correction of inaccurate personal data;
- request deletion of personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- object to direct marketing;
- request data portability where applicable;
- withdraw consent where processing is based on consent;
- complain to the ICO.
To exercise your rights, contact:
Contact page: https://buyabusinessltd.com/contact
We may need to verify your identity before responding.
We aim to respond within one month. Where a request is complex, we may extend the response period where permitted by law.
19. Complaints
If you are unhappy with how we handle your personal data, please contact us first so we can try to resolve the issue.
Email: gdpr@buyabusinessltd.com
Contact page: https://buyabusinessltd.com/contact
You also have the right to complain to the UK data protection regulator:
Information Commissioner's Office
Website: ico.org.uk
Telephone: 0303 123 1113
20. Children
The website is not intended for children.
You must be at least 18 years old to create an account, submit an enquiry, list a business, subscribe to a paid plan or use account-based marketplace features.
We do not knowingly collect personal data from children.
21. Changes to this Privacy Policy
We may update this Privacy Policy from time to time.
Changes may be made to reflect:
- changes to the website;
- changes to marketplace features;
- changes to suppliers or data practices;
- changes to law, regulation or guidance;
- security, fraud-prevention or compliance updates;
- new listing, payment, account or support features.
The latest version will be published on this page.
Where changes are significant, we may take additional steps to notify users, such as by email or account notice.
22. Contact us
For privacy and data protection questions, contact:
BUYABUSINESS LTD
Email: gdpr@buyabusinessltd.com
Contact page: https://buyabusinessltd.com/contact
© 2026 Thought Council.