Privacy Policy
Draft — not reviewed by a lawyer. Do not publish as-is.
Last updated: [NEEDS YOUR INPUT — date of the reviewed version]
1. Who is responsible
[NEEDS YOUR INPUT — registered company name and address] is the data
controller for the personal data described here.
Data protection contact: [NEEDS YOUR INPUT — email address]
2. What we hold
Your account. Your email address, your name if you give one, your username,
the language and timezone you choose, and the devices you are signed in from —
the last so you can see them and end any you do not recognise.
Your business data. Companies, costs, capacity, services, prices, customers,
suppliers, quotes. This is commercially sensitive and we treat it that way.
Your customers' details, where you enter them: name, email, address. You are
the controller for these; we process them on your behalf.
Payment data. Handled by Stripe. We store which plan you are on and what was
charged. We never see or store your card number.
Technical data. Error reports, which carry an account identifier and no
names, addresses or figures.
3. Why we hold it, and on what basis
| What | Why | Lawful basis |
|---|---|---|
| Account and business data | To provide the service you pay for | Performance of a contract |
| Payment data | To take payment and meet tax obligations | Contract; legal obligation |
| Error reports | To find and fix faults | Legitimate interest |
| Marketing email | To tell you about the product | Consent — recorded, and withdrawable |
We record consent separately for each purpose, and you can withdraw any of them
without losing access to the service.
4. Where it is held
In the European Union, in Frankfurt. Our database, authentication and file
storage are all in that region.
Some of the processors below operate outside the EU. Where they do, transfers
rely on Standard Contractual Clauses.
[NEEDS YOUR INPUT — confirm with each processor and list the mechanism]
5. Who else processes it
| Processor | What for | Where |
|---|---|---|
| Supabase | Database, authentication, file storage | EU (Frankfurt) |
| Vercel | Application hosting | [NEEDS YOUR INPUT — confirm region] |
| Stripe | Payments | [NEEDS YOUR INPUT] |
| Resend | Transactional email | [NEEDS YOUR INPUT] |
| Sentry | Error reporting | [NEEDS YOUR INPUT] |
We do not sell your data. We do not use it to train anyone's models.
6. How it is protected
Some specifics, because "we take security seriously" tells you nothing:
- One customer's data is separated from another's by database policies, not by
application code. There are several hundred automated tests whose only job is
to prove one tenant cannot reach another's rows.
- Company tax and VAT numbers are encrypted and readable only through a
controlled path.
- Error reports carry an account identifier only — never a name, an address or
a figure.
- Access to the production database is restricted and audited.
7. How long we keep it
While your account exists, and for [NEEDS YOUR INPUT — retention period]
after you close it, except as described immediately below.
8. Finalised records — a limit on erasure
Some records become final when something happens to them: a quote once it
has been sent and answered, and invoices in future.
A final record cannot be edited or erased in place. If it could, the history it
represents would not be evidence of anything — that is the whole purpose of
keeping one. Corrections are made by adding a new record that supersedes the
old, never by changing what was there.
**So if you ask us to delete your data, we remove the personal data around
these records and keep the financial record itself**, for as long as we are
required to.
**[NEEDS YOUR INPUT — the statutory retention period where you are established;
commonly six or seven years for accounting records]**
We are telling you this plainly because it is a real limit on your right to
erasure, and burying it would be the wrong way to handle that.
9. Your rights
You can ask for a copy of your data, correct it, delete it, restrict or object
to how we use it, or take it elsewhere. You can withdraw consent at any time.
The export in the application gives you your business data immediately, without
having to ask.
To exercise any of these, contact [NEEDS YOUR INPUT — email address]. We
answer within one month.
You can complain to your national supervisory authority. Ours is
[NEEDS YOUR INPUT — the authority where you are established].
10. Cookies
We use cookies that are necessary to keep you signed in. We do not use
advertising cookies.
**[NEEDS YOUR INPUT — if you add analytics, this section and the consent record
both need to change]**
11. Changes
We will tell you before a material change takes effect.