TradeKit® ← Back to site
Legal

Privacy Policy

Effective 21 September 2026

01Data Controller

TradeKit is operated by KIH Technologies Ltd, a company registered in England and Wales (company number 17214671). Our registered office details are held on the public Companies House register. Registered with the UK Information Commissioner’s Office (ICO), registration number: ZC161051. Data protection contact: support@tradekitapp.co.uk.

02Data We Collect

We collect information necessary to provide trade management services:

03Lawful Basis for Processing

04How We Use Your Data

05Third-Party Processors and HMRC

Your data is shared with the following providers to make the app work:

HM Revenue & Customs (HMRC): When you authorise an MTD ITSA connection, we transmit data you have entered (income totals, allowable expenses by HMRC category, mileage claims, business details, and the fraud prevention headers HMRC mandates) to HMRC's Making Tax Digital APIs over encrypted connections (TLS 1.2+). HMRC is the data controller for the data they receive under their statutory authority. You can disconnect at any time from Settings, which revokes our access tokens and deletes your stored HMRC linkage data within 24 hours.

Online invoice payments (where enabled). If you choose to connect your own Stripe account in Settings so that customers can pay your invoices by card, you enter into Stripe's terms directly: Stripe collects your identity and bank details for its own verification and pays you out itself. TradeKit stores only your Stripe account identifier, whether Stripe reports the account as able to take payments, and for each payment link the invoice number, amount, status and Stripe's session and payment identifiers. Your customer's card details go to Stripe's hosted checkout page and never pass through TradeKit. TradeKit does not receive, hold or transmit your customers' money and takes no fee from those payments. You can disconnect your Stripe account at any time in Settings; existing payment links then stop working.

06Accountant Access

You can invite your accountant or bookkeeper to view your TradeKit records. Access is read-only: an invited accountant can see your quotes, invoices, expenses, mileage, customer details, receipt photos, your business details and your HMRC filing history (what was submitted and when), but never your HMRC connection, bank data, job photos or security settings, and they cannot submit anything to HMRC. By default they cannot edit anything either. You may separately allow a named accountant to change the category and notes on your expenses (nothing else): every such change is recorded with who made it, when, and the before and after values, and shown to you in Settings. Your accountant can also ask you questions about individual records and mark a tax period as reviewed or in need of changes; those notes and your replies are stored with your account so both of you can see them. A review mark is your accountant's opinion, not an HMRC status, and you remain responsible for what you submit. You can revoke their access, or take edit access away, at any time from Settings, which takes effect immediately. We do not share your data with any accountant you have not invited or accepted.

Invitations from an accountant. An accountant who uses TradeKit can also invite you. In that case the accountant gives us your email address (and, optionally, your name) so we can send you a single invitation email on their behalf; we use it for nothing else, and we do not add it to any marketing list. Nothing is shared with the accountant unless you create or sign in to a TradeKit account with that email address and accept. Invitations expire after 30 days if not accepted. We keep a record of each invitation (the sender, the invited email, and whether it was accepted, cancelled or expired) for 12 months so that we can investigate misuse of the invitation feature.

If you join TradeKit's mailing list for MTD updates (the "keep me posted" form), we store the email address you give us for that purpose only, and every email we send includes an unsubscribe link. We do not add app users to marketing lists automatically.

07Data Retention

08Your Rights (UK GDPR / Data Protection Act 2018)

You have the right to:

09Cookies & Local Storage

TradeKit uses browser localStorage (functionally equivalent to cookies) for:

We do NOT use tracking cookies or analytics cookies inside the TradeKit app. The landing page uses Google Ads conversion tracking and Google Analytics 4, which load only if you accept them on the cookie banner and set nothing if you decline. It does not track your activity within the TradeKit app itself.

10International Transfers

Firebase (Google), the Google Gemini API, Stripe and Sentry may process data in the United States. The primary lawful basis for these transfers is the UK-US Data Bridge (also called the UK Extension to the EU-US Data Privacy Framework), which is the UK Government’s adequacy arrangement for personal data transfers to certified US organisations. Both Google and Stripe are certified under the Data Privacy Framework. Standard Contractual Clauses (SCCs) approved by the UK ICO remain in place as a fallback safeguard. HMRC processes your submitted tax data within the UK only.

11Children

TradeKit is designed for business use by adults aged 18 and over. We do not knowingly collect data from anyone under 18.

12Data Breaches

In the event of a data breach, we will notify the ICO within 72 hours as required by UK GDPR and will notify affected users without undue delay.

13Complaints

If you have concerns about how we handle your data, you can contact the Information Commissioner’s Office (ICO) at ico.org.uk/make-a-complaint

14Changes to This Policy

We may update this policy from time to time. The effective date at the top will be updated accordingly.

Contact: support@tradekitapp.co.uk