// Legal
Privacy Policy
Last updated: 21 June 2026
This Privacy Policy explains what personal information TradesMate UK (“TradesMate”, “we”, “our”, “us”) collects when you use https://tradesmateuk.co.uk and the connected web application, how we use it, who we share it with, and your rights under UK GDPR.
1. Who we are
TradesMate UK is a software tool that helps UK tradespeople build quotes, run trade calculators and manage customer quotes. The data controller is the operator of TradesMate UK. You can contact us at tyler@tradesmateuk.co.uk.
2. What we collect
- Account information — name, email address, password (hashed using bcrypt), business name, optional business address, phone number, VAT number and logo image.
- Quote & calculator inputs — line items, materials, labour, customer name/address/email/phone, notes and amounts you enter into the estimator and calculators.
- Subscription information — your TradesMate plan (Free / Pro / Pro+), Stripe customer ID, subscription status. Payment card details are handled entirely by Stripe and never reach our servers.
- Usage analytics — anonymised pageviews (path, timestamp and a hashed visitor identifier). We do not use third-party trackers such as Google Analytics or Facebook Pixel.
- Cookies — see our Cookie Policy. Only strictly-necessary cookies are used.
- Communications — any message you send us by email or via the in-app feedback form.
3. Why we collect it (lawful basis)
- To provide the service (Article 6(1)(b) UK GDPR — performance of a contract): saving your quotes, running calculations, generating PDFs, emailing share-link notifications.
- To take payment (Article 6(1)(b)): managing your subscription via Stripe.
- To keep the service secure (Article 6(1)(f) — legitimate interest): rate-limiting, authentication cookies, audit logs.
- To improve TradesMate (Article 6(1)(f)): anonymised pageview analytics.
4. Who we share it with
- Stripe — subscription billing and payment processing (stripe.com/privacy).
- Resend — transactional email delivery for share-link notifications and account emails (resend.com privacy).
- OpenAI — only when you use the AI Estimator: the prompt text you send is processed by OpenAI to generate the response (openai.com privacy). Do not include sensitive personal information in AI prompts.
- Hosting / infrastructure providers — for running and securing the service.
5. International transfers
Some of our processors (Stripe, Resend, OpenAI) are based outside the UK. Where data is transferred outside the UK, we rely on the UK’s adequacy regulations or standard contractual clauses to protect it.
6. How long we keep it
- Account data: while your account is active, plus up to 30 days after deletion.
- Quotes and customer data you enter: while your account is active. You can delete individual quotes at any time.
- Payment records: kept for 6 years to comply with HMRC record-keeping rules.
- Pageview analytics: kept for 24 months in anonymised form.
7. Your rights
Under UK GDPR you have the right to:
- Access a copy of your personal data.
- Have inaccurate data corrected.
- Request erasure (right to be forgotten).
- Object to or restrict processing.
- Receive your data in a portable format.
- Withdraw consent at any time where consent is the basis for processing.
- Lodge a complaint with the Information Commissioner’s Office (ico.org.uk).
Email tyler@tradesmateuk.co.uk to exercise any of these rights.
8. Security
Passwords are hashed with bcrypt. Authentication uses HTTP-only, secure JWT cookies. Connections are encrypted with HTTPS. No system is 100% secure — if you suspect a security issue, email us immediately.
9. Changes to this policy
We may update this Privacy Policy from time to time. The latest version will always be at this URL with an updated "Last updated" date.