→ Terms of Service
🔒 UK GDPR Compliant

Privacy Policy

📅 Last updated: May 2025 🏢 Governed by UK GDPR & DPA 2018
🚫
We never sell your data
Your data is yours. We don't sell, rent or trade it to anyone.
🇪🇺
Data stored in the EU
Your data is stored on EU servers, compliant with UK GDPR.
🍪
No tracking cookies
We only use essential cookies for login. No ads, no analytics.
🗑️
Delete anytime
You can request deletion of your account and all data at any time.
Section 1

Who We Are

TradeBooks is a business management application for UK sole traders, operated by TradeBooks. We are the data controller for personal data you provide when using the service.

For any privacy questions or data requests, contact us at support@tradebooks.uk. We aim to respond within 5 working days.


Section 2

What Data We Collect

We only collect data that is necessary to provide the TradeBooks service:

We do not collect payment card details — these are handled directly by Stripe and never pass through our systems.


Section 3

Our Lawful Basis for Processing

Under UK GDPR, we must have a lawful basis for processing your personal data. We rely on the following:


Section 4

How We Use Your Data


Section 5

AI Feature Processing

When you use AI-powered features in TradeBooks (quote builder, receipt scanning, payment chaser, contract generator), the relevant content — such as a job description, receipt image, or client name — is sent to Anthropic's API for processing.

Anthropic processes this data on our behalf under a Data Processing Agreement. Anthropic does not use API data to train its models. Data sent to Anthropic is not stored beyond the duration of the request. Receipt images are compressed before transmission and are not retained after processing.

By using AI features in TradeBooks, you consent to this processing. You can use TradeBooks without using AI features — they are optional.


Section 6

Third Party Data Processors

We share data only with the service providers necessary to operate TradeBooks. All processors are bound by GDPR-compliant Data Processing Agreements.

Processor
Purpose
Location
Supabase
Secure cloud database — stores your account, business and financial data
EU (West)
Anthropic
AI processing — used only when you actively use an AI feature
USA
Stripe
Subscription payment processing — handles card data directly, we never see it
EU / USA
Cloudflare
Hosting, CDN delivery and AI request proxying
Global CDN

We do not share your data with advertisers, data brokers or any third party for marketing purposes.


Section 7

How Long We Keep Your Data


Section 8

Cookies

TradeBooks uses only essential cookies required for authentication and session management. These cookies are necessary for the app to function and cannot be disabled.

We do not use advertising cookies, analytics cookies, or any third-party tracking cookies. No cookie consent banner is shown because no non-essential cookies are set.


Section 9

Your Rights Under UK GDPR

As a UK data subject you have the following rights. To exercise any of them, email support@tradebooks.uk — we will respond within 30 days.

👁️
Access
Request a copy of all personal data we hold about you
✏️
Rectification
Ask us to correct inaccurate or incomplete data
🗑️
Erasure
Request deletion of your account and all associated data
📦
Portability
Export your data in a machine-readable format via the app
🛑
Objection
Object to processing based on legitimate interests
⏸️
Restriction
Request we restrict processing of your data in certain circumstances

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you are unhappy with how we handle your data.


Section 10

Changes to This Policy

We may update this policy from time to time. When we make significant changes, we will notify you by email and update the "last updated" date at the top of this page. The latest version is always available at tradebooks.uk/privacy and within the app under Settings.

Questions or Requests?

If you have any questions about this policy or want to exercise your data rights, get in touch. We aim to respond within 5 working days.