Privacy & Confidentiality Policy
We take privacy seriously
Last updated: 05 June 2026
This Privacy Policy explains how Next Fabrication collects, uses, stores and protects personal data when you use https://nextfabrication.com, contact us, request services, use client areas, interact with forms, or use website features connected to our plugins, tools, apps or services.
This general Privacy Policy applies to the Next Fabrication website as a whole. The Extended Privacy sections below provide additional information about specific plugins, tools or app-related features where they may process extra categories of data. Those extended sections add detail; they do not replace this main policy.
Who we are
Next Fabrication operates this website and is responsible for the personal data it collects through this site, unless another organisation is clearly identified as the controller for a specific service, payment, platform or integration.
For privacy questions, data requests or concerns, please use the contact options provided on this website.
Personal data we may collect
The personal data we collect depends on how you use the website and which features you interact with. We may collect:
- Identity and contact details, such as your name, email address, phone number, company name or job role.
- Enquiry and project information, such as messages, service interests, project details, budgets, timescales, requirements and uploaded files you choose to provide.
- Client, account or portal information, where client areas or private workflows are enabled, including user account details, project records, timeline entries, comments, documents and service notifications.
- Purchase, licence and support information, such as product names, purchase email addresses, licence keys, activation status, site URLs, plugin versions, support messages and terms acceptance records.
- Technical and usage information, such as IP address, browser type, device information, page URLs, referrers, timestamps, security logs, cookie preferences and general website activity.
- Marketing and communication preferences, such as newsletter choices, consent records or opt-out requests where these features are used.
- Any other information you choose to send to us through forms, email, uploads, comments, support requests or other website interactions.
We do not intentionally collect more personal data than we need for the relevant purpose. Please avoid sending unnecessary sensitive information unless it is genuinely required for your enquiry, project, support request or service.
How we collect personal data
We may collect personal data directly from you when you complete a form, send an enquiry, request a quote, upload a file, create or access an account, use a client portal, request support, purchase or activate a product, subscribe to updates, manage cookie preferences, or otherwise communicate with us.
We may also collect technical information automatically through WordPress, hosting logs, security tools, cookies, analytics, spam protection, performance tools, forms, page builders, translation tools, SEO tools, licensing systems or other integrations used to operate the website.
Where another service provides information to us, such as a payment provider, licensing platform, form integration, email service, analytics provider or security tool, we only use that information for the relevant operational, contractual, legal, security or support purpose.
Why we use personal data
We may use personal data to:
- Respond to enquiries, messages, quote requests and support requests.
- Provide, manage and improve our services, plugins, apps, tools and website features.
- Create and manage client records, project workflows, account access, private portal areas, documents, comments and notifications where these features are enabled.
- Process purchases, licence activations, product updates, service access and related support.
- Send service messages, account messages, password setup links, support replies, operational alerts and important updates.
- Protect the website, users, plugins, forms and systems from spam, abuse, fraud, unauthorised access or security issues.
- Maintain website functionality, diagnose errors, analyse performance and improve usability.
- Meet legal, tax, accounting, regulatory, contractual and record-keeping obligations.
- Send marketing or promotional communications where permitted by law and where you have not opted out.
Lawful bases for using personal data
We only use personal data where we have a lawful basis to do so. Depending on the context, we may rely on one or more of the following lawful bases:
- Contract: where processing is needed to provide a service, product, licence, account, support response or requested action.
- Legitimate interests: where processing is needed to operate, secure, improve and administer the website, respond to business enquiries, manage client relationships, prevent abuse, maintain records, and protect our services, provided those interests are not overridden by your rights and freedoms.
- Consent: where we ask for permission for a specific activity, such as certain cookies, marketing preferences, optional form features or location-related features.
- Legal obligation: where processing is needed to comply with legal, tax, accounting, regulatory, security or disclosure obligations.
Where we rely on consent, you can withdraw that consent at any time. This will not affect processing that took place before consent was withdrawn.
Cookies and similar technologies
This website may use cookies, local storage, session storage or similar technologies for essential site operation, security, forms, account access, preferences, analytics, translation, spam protection, performance, embedded content or marketing features.
Some cookies are necessary for the website to work. Others may depend on your cookie choices. You can manage cookie preferences through the cookie controls provided on the website and can also adjust cookie settings in your browser.
More detail is provided in our Cookie Policy.
Who we may share personal data with
We do not sell personal data. We may share personal data only where needed for the purposes described in this policy, including with:
- Hosting, infrastructure, database, backup, security and website maintenance providers.
- WordPress, theme, page builder, form, SEO, analytics, translation, cookie, spam protection and performance tools used on the website.
- Email, SMTP, notification, support and communication providers.
- Payment, checkout, invoicing, accounting or licence management providers where products, services or licences are purchased or activated.
- Professional advisers, insurers, accountants, legal advisers or regulators where reasonably necessary.
- Law enforcement, courts, public authorities or other parties where disclosure is required by law or necessary to protect rights, safety, users, services or systems.
Where third-party services process personal data on our behalf, they should only process it for the relevant service purpose. Where a third-party service acts as its own controller, its own privacy policy will also apply.
Payments
Where payments are taken through a third-party checkout, payment processor or marketplace, payment details are processed by that provider. We do not intentionally store full payment card numbers on this website. We may receive limited transaction information such as product name, purchase email, transaction reference, payment status, billing details or licence-related information where needed to provide access, support, fulfilment, accounting or fraud prevention.
Plugin, app and licensing data
Some services, plugins or apps connected with Next Fabrication may require licence activation, update checks, support diagnostics or service validation. This may involve processing data such as product slug, product version, licence key, purchase email, site URL, home URL, administrator email, activation status, terms acceptance metadata and technical information needed to operate the service.
The Extended Privacy sections below explain additional processing that may apply to specific plugins or app-related features.
Files, uploads and user-provided content
If you upload files, send documents, submit project material, provide screenshots, share support files or use portal/document features, those files may contain personal data. We use this information only for the relevant enquiry, project, support, account, service, security or administrative purpose.
Please only upload files you are authorised to share and avoid including unnecessary personal or sensitive information.
How long we keep personal data
We keep personal data only for as long as reasonably necessary for the purpose it was collected, including to provide services, manage projects, respond to enquiries, operate client accounts, support products, maintain licence records, comply with legal obligations, resolve disputes, protect systems and keep appropriate business records.
Retention periods may vary depending on the type of data, the nature of the relationship, legal requirements, accounting rules, backup cycles, security needs and whether the data remains necessary for an active service, account, licence, project or support matter.
Deleting data from the live website may not immediately delete copies held in backups, email records, exported files, logs, cache systems or third-party services, but such copies will be handled according to the relevant retention and deletion processes.
Security
We take reasonable technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration or disclosure. These measures may include access controls, secure hosting, WordPress user permissions, security tools, HTTPS, updates, limited administrator access, backups and monitoring.
No website, email system or online service can be guaranteed to be completely secure. If you believe your data or account access has been affected by a security issue, please contact us using the contact options provided on this website.
International transfers
Some providers used to operate the website, deliver email, process payments, provide analytics, manage licences, store backups, support plugins or secure the site may process data outside the UK or the country where you are based.
Where required, we rely on appropriate safeguards for international transfers, such as adequacy regulations, standard contractual clauses, data processing agreements or equivalent safeguards provided by the relevant service provider.
Your rights
Depending on your location and the circumstances, you may have rights in relation to your personal data. These may include the right to:
- Request access to the personal data we hold about you.
- Ask us to correct inaccurate or incomplete personal data.
- Ask us to delete personal data in certain circumstances.
- Ask us to restrict how we use personal data in certain circumstances.
- Object to certain types of processing, including processing based on legitimate interests or direct marketing.
- Request a copy of certain personal data in a portable format.
- Withdraw consent where processing is based on consent.
- Complain to a data protection supervisory authority.
To make a privacy request, please use the contact options provided on this website. We may need to verify your identity before responding to certain requests.
Marketing communications
Where we send marketing communications, you can opt out at any time using the unsubscribe link in the message or by contacting us through the website. We may still send service, account, licence, security, transactional or administrative messages where these are necessary and not promotional.
Third-party links and embedded content
This website may contain links to third-party websites, services, platforms or embedded content. Those third parties may collect or process data according to their own privacy policies. We are not responsible for the privacy practices of third-party websites or services that we do not control.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, website features, plugins, apps, legal requirements or operational practices. The latest version will be posted on this page with an updated date.
Extended Privacy Information
The sections below provide additional privacy information for specific plugins, apps, tools or website features. They should be read alongside this general Privacy Policy.
Extended Privacy – VibePressTools
1. What the plugin does
VibePressTools is used on this website as a modular Vibe Suite utility plugin for WordPress and Elementor. Depending on which modules are enabled, it may provide maintenance/coming-soon mode, WooCommerce data import/export tools, Elementor conditional logic, enhanced Elementor Pro Form fields, an Advanced Form widget, form submissions/export tools, next-generation image sidecar generation, lightweight local Elementor template rendering through VibePlates and VibeLicenseMe licensing checks.
2. Personal data this plugin may process
This plugin may process personal data where those features are enabled or configured by the website owner. Possible data categories include names, email addresses, phone numbers, company details, addresses, account identifiers, form field values, uploaded files, signatures, consent timestamps, UTM or marketing attribution data, page URLs, referrers, timestamps, user IDs, user-agent/context details, WooCommerce customer/order/refund/coupon records, media attachment metadata, saved Elementor template content selected for rendering, admin settings, maintenance bypass tokens, license activation data and diagnostic/module state data.
3. How the data is collected
Data may be collected when a visitor submits an Advanced Form or Elementor Pro Form enhanced by VibePressTools, completes a consent field, uploads a file, signs a signature field, uses a location/map field, interacts with authentication/password-reset forms, submits data protected by spam/security fields, or when an authorised administrator imports, exports, edits or processes records. Data may also be generated by WordPress, WooCommerce, Elementor, hosting, email/SMTP services, security plugins, analytics tools or other integrations configured by the website owner.
4. Why the data is used
The website owner may use data processed through VibePressTools to operate website forms, respond to enquiries, process requests, manage WooCommerce migrations, maintain a coming-soon or maintenance screen, protect forms from spam or abuse, generate and serve WebP image sidecars, store and export form submissions, capture consent records, route authentication journeys, troubleshoot errors, render locally saved Elementor templates chosen by the site owner and maintain site administration records.
5. Lawful basis
The website owner should identify and document the lawful basis that applies to their use of VibePressTools. Depending on the context, this may include performance of a contract, legitimate interests, consent, legal obligation or another lawful basis recognised in the relevant region. VibePressTools does not decide the lawful basis for the website owner.
6. Who can access the data
Data may be visible to authorised WordPress administrators, authorised team members, users with access to exported files, configured email recipients, connected webhook endpoints, the relevant user where frontend account or form features are enabled, and any third-party processors configured by the website owner. Access should be limited to people who need it for the website or service to operate.
7. Third-party services and integrations
VibePressTools may work alongside WordPress, Elementor, Elementor Pro, WooCommerce, the active theme, hosting, email/SMTP services, Google reCAPTCHA, mapping/location services, analytics tools, spam protection, security plugins, webhook endpoints, VibeCRM, Vibe Effex, VibeLicenseMe, Elementor template libraries, media storage, cache/CDN tools or other third-party services configured by the website owner. The website owner should list the services they actually use.
8. Emails, webhooks and notifications
Where enabled, VibePressTools forms may send service emails, admin notifications or webhook requests. These may contain submitted form data, context values or operational messages chosen by the website owner. Website owners should avoid placing unnecessary sensitive information inside email templates, webhook payloads or notification content.
9. Passwords and security-sensitive fields
VibePressTools includes authentication-related Advanced Form actions such as login, password reset and set-password flows. Password-centric forms are designed to suppress normal submission storage, email and webhook delivery for sensitive password data. Passwords should never be stored in normal submissions, logs, exports, snapshots, email bodies, webhook payloads or post meta. Password reset and setup links should use secure WordPress mechanisms or documented companion-plugin flows.
10. Files, uploads and exports
Where enabled, forms or WooCommerce migration tools may handle uploads or exports. Exports such as CSV, JSON or WooCommerce migration files should be treated as personal data if they contain user records. The website owner should explain what may be uploaded or exported, who can access those files, where they are stored, how long they are kept, and how users can request access, correction or deletion.
11. Cookies, local storage and frontend state
VibePressTools may rely on WordPress cookies for logged-in/admin behaviour and may use browser or request context for form protection, conditional logic, UTM/session capture, location controls, authentication journeys or frontend behaviour where configured. Any third-party tools used alongside the plugin, such as analytics, security, map, cache/CDN, reCAPTCHA or marketing tools, may set their own cookies or browser storage. The website owner should disclose the tools they actually use.
12. Image/media processing
The Next Gen Images module may generate WebP sidecar files, store conversion metadata, show Media Library statuses, process batches of images and optionally swap image URLs on the frontend. Vibe Effex sequence frame integration may optimise retained frame attachments by creating dedicated WebP sidecars while preserving original frame masters. The website owner remains responsible for the media they upload and publish.
13. Licensing data
VibePressTools may send license activation and verification data to a VibeLicenseMe licensing endpoint chosen/configured by the website owner. This may include product slug, license key, purchase email, site URL, home URL, admin email, plugin version, source URL, adapter type and site-binding metadata. License keys and secrets should be treated as sensitive and masked wherever possible.
14. Retention and deletion
The website owner is responsible for setting and documenting retention periods. Personal data should not be kept for longer than necessary for the purpose for which it was collected. Deleting plugin data from WordPress may not automatically delete backups, exports, emails, cache copies, converted media files, webhook records or records held by connected third-party services.
15. User rights
Users may have rights to request access to their personal data, correction, deletion, restriction, objection, portability, withdrawal of consent, or to complain to a supervisory authority, depending on their location and the website owner’s legal obligations. The website owner should explain how users can make these requests.
16. International transfers
If the website owner uses hosting, email providers, analytics, payment services, licensing services, CDNs, security tools, webhook endpoints or other processors outside the user’s region, the website owner should disclose this and identify the transfer safeguards they rely on where required.
17. Website owner responsibilities
The website owner should review the active VibePressTools modules, form fields, submission settings, email templates, webhook actions, exports, reCAPTCHA keys, user roles, media settings, licensing settings, retention practices and third-party services before publishing their policy. This guidance must be adapted to the site owner’s actual setup.
Extended Privacy – VibeCRM
1. What VibeCRM does
VibeCRM is used on this website to provide a private client portal, request/enquiry intake workflow, client/project records, timeline updates, document sharing, client comments, service notifications and password setup access for client accounts.
2. Personal data VibeCRM may process
Depending on the website configuration, VibeCRM may process names, email addresses, phone numbers, company names, WordPress user IDs, client account status, project titles, project requirements, budget ranges, timescales, submitted form fields, messages, timeline entries, client comments, uploaded documents, file names, attachment IDs, intake snapshots, page URLs, timestamps, administrator notes, notification settings, recipient email addresses, password setup link metadata, remote intake metadata, IP addresses where captured by WordPress or the hosting stack, and diagnostic information required to operate the plugin.
3. How data is collected
Data may be collected when a person submits an enquiry or request form, is created as a client, accesses a client portal, receives a service notification, uploads or downloads a document, adds a comment, sets up a password, or when an authorised administrator creates, edits, imports or converts client/project/timeline records. Data may also be generated by the website’s hosting, WordPress installation, form tools, email provider or security stack.
4. Why the data is used
The website owner may use this data to respond to enquiries, create and manage client accounts, provide access to the client portal, manage request/project workflows, share updates and documents, send service notifications, secure account access, maintain operational records, handle client feedback, troubleshoot issues and evidence activity where appropriate.
5. Lawful basis
The website owner should identify and document the lawful basis that applies to their use of VibeCRM. Depending on the context, this may include performance of a contract, legitimate interests, consent, legal obligation, or another lawful basis recognised in the relevant region. VibeCRM does not decide the lawful basis for the website owner.
6. Who can access the data
Client and project data may be visible to authorised website administrators and authorised team members. Where portal features are enabled, relevant clients may see their own account details, projects, timeline updates, documents and comments. Connected services configured by the website owner, such as hosting, email delivery, security, backup, storage, analytics or support tools, may also process related data depending on the site setup. Access should be limited to people and processors who need it for the website or service to operate.
7. Emails and notifications
Where enabled, VibeCRM may send service emails such as request/intake confirmations, client account setup messages, password setup links, client update alerts, internal request-intake alerts and internal client-comment alerts. Website owners should avoid placing unnecessary sensitive information inside email templates and should explain who receives operational alerts.
8. Passwords and security-sensitive fields
VibeCRM uses WordPress password mechanisms for client password setup and password changes. Passwords should never be stored in normal submissions, timeline entries, snapshots, exports, logs, post meta or email bodies. Password setup links should be treated as security-sensitive and should expire according to WordPress behaviour. License keys, API keys and shared secrets should be masked where possible and kept only where needed for plugin operation.
9. Files, uploads, snapshots and exports
If file or document features are enabled, the website owner should explain what users may upload, where files are stored, who can access them, how long they are retained, how downloads are controlled, and how users can request access, correction or deletion. Intake snapshots, CSV/JSON exports, downloaded files, backups and email copies may contain personal data and should be handled accordingly.
10. Licensing and activation data
To activate and verify the plugin, the website may send licensing data to the Vibe Suite licensing service. This may include the product slug, plugin version, licensing source, purchase email, license key, site URL, home URL, administrator email, terms acceptance metadata and activation status. This data is used to verify ownership, bind the license to a site, manage updates and prevent unauthorised use.
11. Remote intake and integrations
If remote intake or supported form integrations are enabled, VibeCRM may receive normalised form payloads, uploaded file references, form names, form IDs, field labels, field values, timestamps and source context. The website owner should describe any external forms, connected websites or services that send data into VibeCRM.
12. Cookies, local storage and frontend state
VibeCRM is primarily a WordPress plugin that uses server-side records and WordPress account sessions. The website owner should review whether their theme, page builder, forms, analytics, security tools, cookie banner, caching layer or other integrations use cookies, local storage, session storage or similar browser storage in connection with VibeCRM pages.
13. Retention and deletion
The website owner is responsible for setting and documenting retention periods for client records, project records, timeline entries, uploaded documents, comments, intake snapshots, emails, backups and exports. Personal data should not be kept for longer than necessary for the purpose for which it was collected. Deleting records from WordPress may not automatically delete backups, exported files, sent emails or records held by connected services.
14. User rights
Users may have rights to request access to their personal data, correction, deletion, restriction, objection, portability, withdrawal of consent, or to complain to a supervisory authority, depending on their location and the website owner’s legal obligations. The website owner should explain how users can make these requests.
15. International transfers
If the website owner uses hosting, email providers, analytics, payment services, license services, CDNs, security tools, backup providers, storage providers or other processors outside the user’s region, the website owner should disclose this and identify the transfer safeguards they rely on where required.
16. Website owner responsibilities
The website owner should review VibeCRM’s configuration, form fields, email templates, user roles, portal pages, document settings, export tools, licensing settings, integrations, retention practices and third-party services before publishing their policy. This guidance must be adapted to the site’s actual setup.
