01Data Controller
TradeKit is operated by KIH Technologies Ltd, a company registered in England and Wales (company number 17214671). Our registered office details are held on the public Companies House register. Registered with the UK Information Commissioner’s Office (ICO), registration number: ZC161051. Data protection contact: support@tradekitapp.co.uk.
02Data We Collect
We collect information necessary to provide trade management services:
- Account Info: Name, email address, trade type.
- Trade Data: Quotes, invoices, expenses, job records and customer contact details you input.
- Media: Photos of receipts or job sites uploaded to our secure storage (EXIF metadata is automatically stripped).
- Voice Notes (optional): If you tap the microphone button to dictate job notes, the speech recognition built into your browser handles the recording. Depending on your browser, the audio may be sent off your device to that browser's speech service to be transcribed, and the transcript is returned to TradeKit and added to the notes you are editing. Voice input starts only when you tap the microphone, and you can always type instead.
- Imported Bank Transactions (optional): If you import a bank statement (CSV or PDF), the transactions you choose to import (date, description, amount) are stored with your trade data. We never receive your online banking credentials.
- Payment Data: Processed securely via Stripe. We do not store credit card numbers.
- Device Info: A random device identifier for session management (max 2 devices).
- Error Logs: Anonymised error messages to help us fix bugs. Personal data patterns (email, phone, National Insurance numbers, UTRs, sort codes) are automatically redacted where detected.
- HMRC Integration Data (optional): If you connect your Government Gateway account to enable Making Tax Digital for Income Tax (MTD ITSA) submissions, we collect and store: your National Insurance Number (encrypted at rest with AES-256-GCM), your HMRC business identifier and trading name, OAuth access and refresh tokens (encrypted), and an audit log of submissions made on your behalf. This data is collected only after you authorise the connection and is deleted when you disconnect HMRC or delete your account.
- Two-Step Sign-in Data (optional): If you enable Two-Step Sign-in, we generate and store an encrypted TOTP secret (AES-256-GCM, separate encryption key from HMRC data), a counter that prevents reuse of one-time codes, hashed (one-way) recovery codes, and the timestamp and reference of your most recent challenge. We never see your authenticator app codes in plaintext after verification. Disabling Two-Step Sign-in or deleting your account erases all of this data within 24 hours.
- Quote Acceptance Evidence: When a customer accepts a quote through a TradeKit link we record their name, the time, their IP address and browser details, and the signature they draw, as evidence of acceptance. The link stops working after 30 days and the record is removed from the copy on the link 30 days after that; the accepted quote itself stays in the trader's records.
- Fraud Prevention Headers: When you submit data to HMRC under MTD, HMRC requires us to send a set of technical headers describing your browser and device (timezone, screen size, public IP at the time of submission, browser user-agent). These are forwarded to HMRC for fraud-prevention purposes only and are not stored by us. This is mandated by HMRC and is not optional once you connect.
03Lawful Basis for Processing
- Contract: Processing your trade data is necessary to provide the TradeKit service you signed up for.
- Legal Obligation / Contract: Where you connect TradeKit to HMRC under Making Tax Digital, the processing of your tax data is necessary for compliance with your statutory tax obligations and for the performance of the service you have requested.
- Legitimate Interest: Error logging and security measures to maintain service quality.
- Consent: Marketing communications (if you opt in).
04How We Use Your Data
- To provide and maintain the TradeKit app and all its features.
- To calculate CIS deductions and VAT estimates (note: these are estimates only, not professional tax advice).
- To sync your data across your devices using Firebase.
- To process your subscription payments via Stripe.
- To send you service-related emails (password resets, verification).
- To submit your authorised quarterly updates, end-of-period statements, and final declarations to HMRC under Making Tax Digital for Income Tax (MTD ITSA).
- To retrieve your business details, obligations, and tax calculations from HMRC on your authorisation.
05Third-Party Processors and HMRC
Your data is shared with the following providers to make the app work:
- Google Firebase (Google LLC): Database hosting, authentication, file storage and App Check security. Data processed in accordance with Google Cloud terms. Privacy
- Stripe Inc: Payment processing and subscription management. Privacy
- postcodes.io (Ideal Postcodes): UK postcode lookups for address autofill. No personal data sent beyond the postcode entered.
- Companies House: Company register lookups. If you search by company number to fill in business details, that company number is sent to the Companies House public register API and the public record for that company (name, status, registered office address and similar) is returned to TradeKit.
- Google Fonts: Font delivery (your IP address may be logged by Google).
- Google Gemini API (Google LLC): Document and image understanding, and category suggestions, for five optional features: extracting amounts and dates from receipt photos you scan; extracting transactions from bank statement PDFs you upload for import; reading appliance data plates you photograph; suggesting an expense category, with a confidence score, for a scanned receipt and for each line of an imported bank statement; and checking whether a logged trip reads as business, commuting or personal. The image or PDF you submit, the extracted text of a receipt, the description and payee of each statement line, and a trip’s start, destination and purpose may be sent to Google’s Gemini API, and may contain personal data (for example payee names, transaction details, or the places you travel between). Suggestions are shown for you to check before you save. Content is processed under Google’s paid API terms and is not used to train Google’s models. Terms
- Browser speech recognition: The optional voice-to-text dictation for job notes uses the speech recognition built into your browser. On Chrome this is Google's speech service, and other browsers use their own provider. When you tap the microphone, the recorded audio may be sent off your device to that service and the transcript returned to TradeKit. Voice input starts only when you tap the microphone.
- ipify: A service that reports the public IP address a request comes from. When you submit to HMRC, your browser calls it to read your public IP for the fraud prevention header HMRC requires, and our servers separately call it to read the service's own outgoing IP used in the vendor fraud prevention headers. No other information is exchanged.
- Sentry (Functional Software, Inc.): Crash and error reporting so we can find and fix faults. Before any report leaves your device we strip email addresses, National Insurance numbers, UTRs, phone numbers and sort codes from it, and we never send personally identifying fields deliberately. Privacy
- GoDaddy (email delivery): Outbound email - your welcome email, invoice and quote reminders you switch on, and MTD deadline reminders - is delivered through GoDaddy's SMTP service. Where you ask TradeKit to email one of your customers (for example an invoice reminder), we process that customer's name and email address on your instruction, as your processor.
HM Revenue & Customs (HMRC): When you authorise an MTD ITSA connection, we transmit data you have entered (income totals, allowable expenses by HMRC category, mileage claims, business details, and the fraud prevention headers HMRC mandates) to HMRC's Making Tax Digital APIs over encrypted connections (TLS 1.2+). HMRC is the data controller for the data they receive under their statutory authority. You can disconnect at any time from Settings, which revokes our access tokens and deletes your stored HMRC linkage data within 24 hours.
Online invoice payments (where enabled). If you choose to connect your own Stripe account in Settings so that customers can pay your invoices by card, you enter into Stripe's terms directly: Stripe collects your identity and bank details for its own verification and pays you out itself. TradeKit stores only your Stripe account identifier, whether Stripe reports the account as able to take payments, and for each payment link the invoice number, amount, status and Stripe's session and payment identifiers. Your customer's card details go to Stripe's hosted checkout page and never pass through TradeKit. TradeKit does not receive, hold or transmit your customers' money and takes no fee from those payments. You can disconnect your Stripe account at any time in Settings; existing payment links then stop working.
06Accountant Access
You can invite your accountant or bookkeeper to view your TradeKit records. Access is read-only: an invited accountant can see your quotes, invoices, expenses, mileage, customer details, receipt photos, your business details and your HMRC filing history (what was submitted and when), but never your HMRC connection, bank data, job photos or security settings, and they cannot submit anything to HMRC. By default they cannot edit anything either. You may separately allow a named accountant to change the category and notes on your expenses (nothing else): every such change is recorded with who made it, when, and the before and after values, and shown to you in Settings. Your accountant can also ask you questions about individual records and mark a tax period as reviewed or in need of changes; those notes and your replies are stored with your account so both of you can see them. A review mark is your accountant's opinion, not an HMRC status, and you remain responsible for what you submit. You can revoke their access, or take edit access away, at any time from Settings, which takes effect immediately. We do not share your data with any accountant you have not invited or accepted.
Invitations from an accountant. An accountant who uses TradeKit can also invite you. In that case the accountant gives us your email address (and, optionally, your name) so we can send you a single invitation email on their behalf; we use it for nothing else, and we do not add it to any marketing list. Nothing is shared with the accountant unless you create or sign in to a TradeKit account with that email address and accept. Invitations expire after 30 days if not accepted. We keep a record of each invitation (the sender, the invited email, and whether it was accepted, cancelled or expired) for 12 months so that we can investigate misuse of the invitation feature.
If you join TradeKit's mailing list for MTD updates (the "keep me posted" form), we store the email address you give us for that purpose only, and every email we send includes an unsubscribe link. We do not add app users to marketing lists automatically.
07Data Retention
- Your account data is retained as long as your account is active.
- If you delete your account, all your data including jobs, quotes, expenses, media, error logs and feedback is permanently deleted.
- Error logs are retained for a maximum of 90 days.
- HMRC submission audit logs (date of submission, period covered, totals submitted) are retained for 7 years to meet HMRC record-keeping requirements, even after account deletion. Personal identifiers in these logs are pseudonymised after account deletion.
- HMRC OAuth access and refresh tokens, your encrypted NINO, and stored business details are deleted within 24 hours of you disconnecting the integration or deleting your account.
- Two records survive account deletion on purpose. A one-way hash of your email address is kept to prevent the same person claiming a second free trial; it contains no readable personal data and is never used to contact you. If you joined our MTD updates mailing list, your email address is kept until you unsubscribe, so we do not lose your subscription at account deletion; every email includes an unsubscribe link.
08Your Rights (UK GDPR / Data Protection Act 2018)
You have the right to:
- Access: Request a copy of all data we hold about you (use "Download My Data" in Settings).
- Rectification: Update your profile information at any time in Settings.
- Erasure: Delete your account and all associated data (use "Delete Account" in Settings).
- Portability: Export your data in JSON format.
- Restriction: Contact us to restrict processing of your data.
- Object: Contact us to object to processing based on legitimate interest.
- Withdraw Consent: For any consent-based processing, withdraw at any time.
- Disconnect HMRC: You can revoke TradeKit's HMRC access at any time from Settings → HMRC → Disconnect, or directly from your Government Gateway account. Disconnecting does not delete your TradeKit account or the trade data you have entered.
- Disable Two-Step Sign-in: You can turn off Two-Step Sign-in at any time from Settings, providing a current authenticator code or recovery code to confirm. Your encrypted TOTP secret and recovery codes are deleted on disable.
09Cookies & Local Storage
TradeKit uses browser localStorage (functionally equivalent to cookies) for:
- Essential: Authentication tokens, device ID, app settings. These are strictly necessary for the app to function.
- Functional: Dark mode preference, onboarding status.
We do NOT use tracking cookies or analytics cookies inside the TradeKit app. The landing page uses Google Ads conversion tracking and Google Analytics 4, which load only if you accept them on the cookie banner and set nothing if you decline. It does not track your activity within the TradeKit app itself.
10International Transfers
Firebase (Google), the Google Gemini API, Stripe and Sentry may process data in the United States. The primary lawful basis for these transfers is the UK-US Data Bridge (also called the UK Extension to the EU-US Data Privacy Framework), which is the UK Government’s adequacy arrangement for personal data transfers to certified US organisations. Both Google and Stripe are certified under the Data Privacy Framework. Standard Contractual Clauses (SCCs) approved by the UK ICO remain in place as a fallback safeguard. HMRC processes your submitted tax data within the UK only.
11Children
TradeKit is designed for business use by adults aged 18 and over. We do not knowingly collect data from anyone under 18.
12Data Breaches
In the event of a data breach, we will notify the ICO within 72 hours as required by UK GDPR and will notify affected users without undue delay.
13Complaints
If you have concerns about how we handle your data, you can contact the Information Commissioner’s Office (ICO) at ico.org.uk/make-a-complaint
14Changes to This Policy
We may update this policy from time to time. The effective date at the top will be updated accordingly.
Contact: support@tradekitapp.co.uk