Last updated: March 2025 · TradeFlow AI Ltd
Summary: We collect only what we need to provide our service, we never sell your data, and you can request deletion of your account and data at any time by emailing privacy@tradeflowai.app.
1. Who We Are
TradeFlow AI Ltd ("TradeFlow AI", "we", "us", or "our") is a software-as-a-service company providing quoting, invoicing and payments tools for UK tradespeople. We are registered in England and Wales.
For data protection purposes, TradeFlow AI Ltd is the data controller for personal information collected through our website (tradeflowai.app) and our platform (app.tradeflowai.app).
Contact us about privacy matters at: privacy@tradeflowai.app
2. What Data We Collect
2.1 Account & Profile Data
When you create an account we collect: your name, email address, phone number, business name, business address, and trade type. This is necessary to provide your account and personalise your experience.
2.2 Business & Transactional Data
To provide the quoting, invoicing and payment features, we store: quotes you create, invoices you generate, customer contact details you add to the platform, payment amounts and statuses, and job/project notes.
2.3 Payment Data
Subscription payments are processed by Stripe. We do not store your full card details on our servers. Stripe's privacy policy governs how payment data is handled — see stripe.com/gb/privacy.
2.4 Usage & Technical Data
We automatically collect: IP address, browser type and version, device type, operating system, pages visited, time spent on pages, and feature usage patterns. This helps us improve the product and diagnose technical issues.
2.5 Communications
If you contact our support team, we retain those communications to resolve your query and improve our service.
3. Legal Basis for Processing (UK GDPR)
We rely on the following legal bases to process your personal data:
- Contract performance — processing necessary to deliver the service you signed up for
- Legitimate interests — product analytics, fraud prevention, and improving our platform
- Consent — marketing emails (you can unsubscribe at any time)
- Legal obligation — retaining financial records as required by HMRC
4. How We Use Your Data
We use your data to:
- Provide, maintain and improve the TradeFlow AI platform
- Process your subscription payments
- Send transactional emails (account confirmations, invoice reminders on your behalf)
- Send product updates and tips (if you opted in — unsubscribe any time)
- Respond to support requests
- Detect and prevent fraud and abuse
- Comply with legal obligations
5. Who We Share Data With
We do not sell your personal data. We share data only with trusted third-party service providers who process data on our behalf, bound by data processing agreements:
- Stripe — payment processing
- Supabase — database hosting and authentication
- Resend / SendGrid — transactional email delivery
- Vercel — web application hosting
- Sentry — error monitoring (anonymised)
All providers are either UK/EEA based or operate under standard contractual clauses for international data transfers.
6. Data Retention
We retain your account and business data for as long as your account is active. If you cancel your account, we retain data for 90 days to allow you to reactivate. After 90 days, personal data is permanently deleted, except where we are required by law to retain financial records (typically 7 years under HMRC guidelines).
7. Your Rights Under UK GDPR
You have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — correct inaccurate data
- Erasure — request deletion of your data ("right to be forgotten")
- Restriction — limit how we process your data in certain circumstances
- Portability — receive your data in a portable format
- Objection — object to processing based on legitimate interests
- Withdraw consent — opt out of marketing emails at any time
To exercise any of these rights, email privacy@tradeflowai.app. We will respond within 30 days.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe we have not handled your data appropriately.
8. Security
We implement industry-standard security measures including: encrypted data in transit (TLS 1.2+), encrypted data at rest, access controls limiting who within our team can access your data, regular security reviews, and multi-factor authentication for our internal systems.
Despite these measures, no system is completely secure. If you suspect a security issue, please contact us immediately at security@tradeflowai.app.
9. Cookies
We use cookies to keep you logged in, remember your preferences, and understand how our product is used. See our Cookie Policy for full details.
10. Children
TradeFlow AI is a business tool intended for adults (18+). We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, please contact us at privacy@tradeflowai.app.
11. Changes to This Policy
We may update this policy from time to time. When we make significant changes, we will notify you by email or via a banner in the app. The "Last updated" date at the top of this page reflects the most recent revision.
12. Contact
For any privacy-related questions or requests:
Email: privacy@tradeflowai.app
Company: TradeFlow AI Ltd, England & Wales