Legal

Privacy Policy

Effective date: 04 May 2026

Last reviewed: 04 May 2026

Website: buyabusinessltd.com

This Privacy Policy explains how BUYABUSINESS LTD collects, uses, stores and shares personal data when you use the Buy a Business Ltd website, marketplace, listings, account features, enquiry tools, subscriptions, support services, feedback forms and related pages.

It also explains your data protection rights and how to contact us.

Buy a Business Ltd is a marketplace, not a broker. Information, search results and recommendations on this site are for general guidance only and do not constitute legal, tax, financial, investment, valuation or regulated advice.

1. Who we are

This website is operated by BUYABUSINESS LTD, a company registered in England and Wales under company number 11440681.

Our registered office is:

For data protection purposes, BUYABUSINESS LTD is the data controller for personal data processed through this website and marketplace.

Our ICO registration number is .

You can contact us about privacy or data protection by using:

Email: gdpr@buyabusinessltd.com

Contact page: https://buyabusinessltd.com/contact

Post: BUYABUSINESS LTD,

2. What this policy covers

This policy applies when you:

  • visit the website;
  • create an account;
  • browse listings;
  • submit an enquiry;
  • list a business for sale;
  • use seller, broker or buyer features;
  • subscribe to a paid plan;
  • contact support;
  • submit feedback through a webform;
  • use search, recommendation or marketplace guidance features;
  • interact with our cookie banner or preference settings;
  • receive emails from us.

This policy should be read alongside our Terms and Conditions and Cookie Policy.

3. Personal data we collect

The personal data we collect depends on how you use the website.

3.1 Website visitors

When you visit the website, we may collect:

  • IP address;
  • device and browser information;
  • pages viewed;
  • approximate location based on browser or network data;
  • referring website or search source;
  • cookie preferences;
  • basic security and fraud-prevention logs.

Where analytics cookies or similar technologies are used, they are controlled through our Cookie Policy and cookie preference tools.

3.2 Account users

When you register or use an account, we may collect:

  • name;
  • email address;
  • account role, such as buyer, seller or broker;
  • account login and authentication records;
  • account preferences;
  • saved listings or saved searches;
  • subscription status;
  • support history;
  • records of account actions, such as listing submissions, enquiries or changes.

We do not store your password in plain text.

3.3 Buyers and enquirers

When you submit an enquiry about a business listing, we may collect:

  • name;
  • email address;
  • enquiry message;
  • phone number, if you choose to provide it;
  • budget or buying preference information, if you choose to provide it;
  • the listing you enquired about;
  • related communication and support records.

When you submit an enquiry, the relevant enquiry information is shared with the seller or broker connected to that listing so they can respond.

3.4 Sellers and brokers

When you list or apply to list a business, we may collect:

  • name;
  • email address;
  • business name;
  • business sector;
  • business location;
  • asking price;
  • listing description;
  • seller or broker contact details;
  • uploaded images, documents or listing content;
  • records confirming authority to list the business;
  • moderation, report and compliance records.

Financial figures and business information in listings are supplied by sellers or brokers. Buy a Business Ltd does not independently verify financial figures or business claims.

3.5 Payments and subscriptions

When you subscribe to a paid plan, we may process:

  • subscription plan;
  • payment status;
  • billing history;
  • receipts or invoice records;
  • payment provider customer references;
  • payment failure, refund or chargeback records.

We do not store full card numbers, bank account details or direct debit details. Payment processing is handled by a third-party payment provider.

3.6 Support, complaints, reports and feedback forms

Where you submit feedback, contact us through a webform, report a listing, request support, or send a general message, we may collect:

  • your name;
  • email address;
  • message content;
  • listing or account reference, where relevant;
  • supporting information you choose to provide;
  • records of our response;
  • complaint, report or moderation outcome.

We use this information to respond to you, improve the platform, review marketplace safety, handle complaints, and keep appropriate compliance records.

We do not use webform feedback to provide legal, tax, financial, investment, valuation or regulated advice.

3.7 Data we do not intentionally collect

We do not intentionally collect special-category personal data, such as health data, political opinions, religious beliefs, biometric data, sexual orientation or trade union membership.

Please do not include special-category data in listings, enquiry messages, support messages or free-text fields.

If special-category data is accidentally provided, we may delete it or ignore it unless we are legally required to keep it.

We do not handle business sale deposits, escrow, completion funds, client money or sale proceeds.

4. How we use personal data

We use personal data for the following purposes:

  • to operate the website and marketplace;
  • to create and manage accounts;
  • to allow buyers to browse, save and enquire about listings;
  • to allow sellers and brokers to submit and manage listings;
  • to route buyer enquiries to the relevant seller or broker;
  • to manage subscriptions, payments, receipts and refunds;
  • to provide support and respond to complaints;
  • to receive and review feedback submitted through webforms;
  • to moderate listings and detect misleading, fraudulent or prohibited content;
  • to protect the website, users and marketplace from abuse, fraud and misuse;
  • to provide limited automated or AI-assisted platform support;
  • to send service emails, such as account, enquiry, billing, security and subscription messages;
  • to send marketing emails where you have opted in;
  • to manage cookie choices and analytics preferences;
  • to understand how visitors use the website where analytics consent has been given;
  • to comply with legal, tax, accounting and regulatory obligations;
  • to establish, exercise or defend legal claims.

Any automated or AI-assisted output is for general guidance only. It does not constitute legal, tax, financial, investment, valuation, commercial or regulated advice.

Users remain responsible for checking information independently before relying on it.

5. Lawful bases for processing

Under UK data protection law, we must have a lawful basis for using personal data.

We rely on the following lawful bases:

Processing activityLawful basis

Creating and managing your account

Contract

Providing marketplace features

Contract and legitimate interests

Publishing and managing listings

Contract and legitimate interests

Routing buyer enquiries to sellers or brokers

Contract and legitimate interests

Managing subscriptions and payments

Contract and legal obligation

Sending service emails

Contract and legitimate interests

Sending marketing emails

Consent

Managing cookie preferences

Legal obligation and legitimate interests

Google Analytics and non-essential cookies

Consent

Fraud prevention, moderation and platform security

Legitimate interests

Handling feedback forms, support messages and reports

Legitimate interests and contract

Limited automated or AI-assisted platform support

Legitimate interests

Keeping financial and accounting records

Legal obligation

Handling legal disputes or regulatory requests

Legal obligation and legitimate interests

Where we rely on legitimate interests, we consider whether our interests are overridden by your rights and freedoms.

6. Buyer enquiry sharing

When a buyer submits an enquiry about a listing, we share the enquiry with the relevant seller or broker.

This may include:

  • buyer name;
  • buyer email address;
  • enquiry message;
  • phone number, if provided;
  • any other information the buyer chooses to include.

Sellers and brokers must only use buyer enquiry data to respond to the specific enquiry.

They must not use buyer enquiry data for unrelated marketing, spam, resale, data harvesting or unrelated commercial purposes unless they have obtained separate lawful permission from the buyer.

7. Sellers, brokers and independent responsibility

Sellers and brokers are responsible for the personal data they choose to include in listings and communications.

Where a seller or broker receives buyer enquiry data, they may become an independent controller of that data for their own response and follow-up activity.

Sellers and brokers must handle buyer enquiry data lawfully and securely.

8. Marketing

We only send marketing emails where you have opted in or where we are otherwise legally permitted to do so.

Marketing emails will include an unsubscribe option.

You can withdraw marketing consent at any time by clicking unsubscribe or contacting us.

Withdrawing marketing consent does not stop essential service emails, such as account, security, billing, subscription or enquiry-related messages.

9. Cookies and similar technologies

We use cookies and similar technologies to operate the website, remember preferences, protect accounts, support payments, measure website use and improve the marketplace.

Essential cookies are needed for the website to work.

We use Google Analytics to understand how visitors use the website and to improve the platform. Google Analytics should only run where legally valid cookie consent has been given.

We do not currently use Meta Pixel, Google Ads remarketing, TikTok Pixel, LinkedIn Insight Tag or other retargeting pixels.

Non-essential cookies, including analytics cookies, will only be used where legally valid consent has been obtained.

You can manage cookie choices using the cookie banner or the Cookie Preferences link on the website.

More information is available in our Cookie Policy.

10. Search, recommendations and automated support

The website may include search results, listing suggestions, automated support features or general marketplace guidance.

These features are for general guidance only.

They are not based on a personalised assessment of your financial circumstances, investment objectives, risk appetite, tax position, legal position or business suitability.

Search results and recommendations must not be treated as a recommendation to buy, sell, invest in, value, finance or proceed with any business.

We do not keep AI/chatbot conversation logs as a standard feature.

Where users submit feedback, support requests or webform messages, those messages may be retained in accordance with the retention periods set out in this Privacy Policy.

11. Who we share personal data with

We may share personal data where necessary with:

  • sellers or brokers, where you submit a buyer enquiry;
  • buyers, sellers or brokers, where marketplace communication requires it;
  • payment processors;
  • email and communication service providers;
  • website hosting, storage and infrastructure providers;
  • authentication and account service providers;
  • Google Analytics, where analytics consent has been given;
  • cookie consent providers;
  • limited automated or AI-assisted service providers, where used for platform operation or content support;
  • professional advisers, such as accountants, solicitors, insurers or auditors;
  • regulators, law enforcement, courts, HMRC, the ICO or other public authorities where required;
  • fraud prevention, security or abuse-prevention services;
  • a buyer or successor if our business or assets are sold, reorganised or transferred.

We only share personal data where we have a lawful basis to do so and where the sharing is reasonably necessary.

We do not sell personal data.

Current named processors and infrastructure providers used to maintain the service may include Vercel for hosting, Supabase for database and account infrastructure, Stripe for payments and billing, Resend for transactional email delivery, and Google Analytics where analytics consent has been given.

We do not currently use Meta Pixel, Google Ads remarketing, TikTok Pixel, LinkedIn Insight Tag or other retargeting pixels.

12. International transfers

Some suppliers or service providers may process personal data outside the United Kingdom.

Where personal data is transferred internationally, we take steps designed to protect it in accordance with UK data protection law.

Where relevant, this includes using the UK Addendum to the EU Standard Contractual Clauses or equivalent lawful safeguards with processors and sub-processors.

This may include using:

  • UK adequacy regulations;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to the EU Standard Contractual Clauses;
  • equivalent lawful transfer safeguards.

13. How long we keep personal data

We keep personal data only for as long as reasonably necessary for the purpose it was collected, including legal, accounting, tax, fraud-prevention, dispute, safety and compliance purposes.

Our standard retention periods are:

Data categoryTypical retention period

Active account records

While the account is active

Closed account records

Up to 2 years after closure, unless longer retention is required

Listings

Up to 12 months after expiry, removal or rejection

Buyer enquiries and marketplace messages

Up to 2 years

Payment, receipt and invoice records

Up to 7 years

Support tickets, reports and webform feedback

Up to 2 years

Cookie consent records

Up to 3 years

Audit, moderation and fraud-prevention logs

Up to 3 years

Legal claim or dispute records

As long as needed to handle the claim or dispute

Where data is no longer needed, we will delete, anonymise or securely archive it.

Some records may be retained for longer where required by law, tax rules, accounting obligations, fraud prevention, regulatory requests or legal claims.

14. Account deletion and erasure requests

You may request deletion of your account or personal data.

Where account deletion is available through the account dashboard, you may use that option.

You may also make a data subject access request, erasure request, or other privacy rights request through the contact page or by emailing gdpr@buyabusinessltd.com.

If your account is deleted, live listings connected to that account may be removed.

We may still retain records where required for legal, tax, accounting, fraud-prevention, dispute, safety or compliance purposes.

15. Security

We use appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.

These measures may include access controls, staff restrictions, monitoring, secure service providers, account protection, record keeping and incident response procedures.

No online service can be guaranteed to be completely secure. You are responsible for keeping your account details safe and telling us promptly if you suspect unauthorised access.

16. Personal data breaches

If we become aware of a personal data breach, we will assess it and take appropriate action.

Where required by UK data protection law, we will report relevant breaches to the Information Commissioner's Office.

Where a breach is likely to result in a high risk to affected individuals, we will notify those individuals without undue delay.

17. Automated decisions

We do not make solely automated decisions that have a legal or similarly significant effect on users.

Automated systems may help with search results, recommendations, fraud signals, listing quality checks, moderation queues or platform support.

Where automated systems flag an issue, users may request human review by contacting us.

18. Your data protection rights

Depending on the circumstances, you may have the right to:

  • request access to your personal data;
  • request correction of inaccurate personal data;
  • request deletion of personal data;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • object to direct marketing;
  • request data portability where applicable;
  • withdraw consent where processing is based on consent;
  • complain to the ICO.

To exercise your rights, contact:

gdpr@buyabusinessltd.com

Contact page: https://buyabusinessltd.com/contact

We may need to verify your identity before responding.

We aim to respond within one month. Where a request is complex, we may extend the response period where permitted by law.

19. Complaints

If you are unhappy with how we handle your personal data, please contact us first so we can try to resolve the issue.

Email: gdpr@buyabusinessltd.com

Contact page: https://buyabusinessltd.com/contact

You also have the right to complain to the UK data protection regulator:

Information Commissioner's Office

Website: ico.org.uk

Telephone: 0303 123 1113

20. Children

The website is not intended for children.

You must be at least 18 years old to create an account, submit an enquiry, list a business, subscribe to a paid plan or use account-based marketplace features.

We do not knowingly collect personal data from children.

21. Changes to this Privacy Policy

We may update this Privacy Policy from time to time.

Changes may be made to reflect:

  • changes to the website;
  • changes to marketplace features;
  • changes to suppliers or data practices;
  • changes to law, regulation or guidance;
  • security, fraud-prevention or compliance updates;
  • new listing, payment, account or support features.

The latest version will be published on this page.

Where changes are significant, we may take additional steps to notify users, such as by email or account notice.

22. Contact us

For privacy and data protection questions, contact:

BUYABUSINESS LTD

Email: gdpr@buyabusinessltd.com

Contact page: https://buyabusinessltd.com/contact

© 2026 Thought Council.