# Privacy Policy

**Last updated: July 2026**

How we collect, use, and protect your personal information.

---

SortedMate Ltd ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you visit our website or use our service.

## Information We Collect

### Contact Form Data

When you submit our contact form, we collect:

- First name and last name
- Email address
- Phone number (optional)
- Company name (optional)
- Your message

This information is used solely to respond to your enquiry and is stored securely in our database hosted by Supabase.

### Account Information

When you create an account, we collect your name, email address, profile photo, and business details (business name, address, VAT number, company registration) to provide our service. Authentication is managed by Clerk.

### Business Data

Data you enter into SortedMate (customers, quotes, jobs, invoices, file attachments, site photos) belongs to you and is processed solely to provide our service. See our [Data Processing Terms](https://sortedmate.com/legal/data-processing) for details on how we handle your clients' data.

### Communications Data

When you use our messaging features, we process email content (via Resend), SMS content, and WhatsApp messages (via Twilio) to deliver communications on your behalf.

### Payment Information

Subscription payments are processed by Stripe. We store only the last 4 digits of your card and billing address. Full card details are never stored on our servers.

### Payment Processing Information (Stripe Connect)

When you enable SortedPay, our integrated payment feature, we collect and process additional information in connection with Stripe Connect:

- Stripe connected account identifiers and onboarding status
- Business verification status (charges enabled, payouts enabled, details submitted)
- Payment transaction data (payment intent IDs, amounts, currency, status)
- Payout status and timing
- Account capabilities and requirements

This information is collected from Stripe via webhook events and API calls. We do not collect or store card numbers, bank account numbers, or other sensitive financial credentials — these are handled exclusively by Stripe.

When you provide personal data in connection with payment processing, Stripe receives that personal data and processes it in accordance with the [Stripe Privacy Policy](https://stripe.com/privacy).

### AI Interactions

When you use our AI features (quote enhancement, job title suggestions, enquiry parsing, AI assistant), your prompts and generated content are processed by OpenAI. We store conversation history to provide continuity.

### Analytics Data

With your consent, we collect anonymised analytics (pages visited, features used, device type) via PostHog to improve our service.

### Technical Information

We automatically collect browser type, device type, and IP address (hashed, not stored raw) to ensure security and improve performance.

### Integration Data (Optional)

If you connect third-party services (Xero, QuickBooks, Google Calendar, Outlook Calendar), we sync relevant data as directed by you. These integrations are optional and can be disconnected at any time.

### Facebook & Instagram (Social Auto-Publishing)

If you connect a Facebook Page so SortedMate can publish posts on your behalf, we collect and store:

- The connected Facebook Page's name and ID, and any linked Instagram business account ID
- A Page/Instagram access token, held encrypted in a secure vault and never exposed to your browser or to other users
- Your Meta user ID, used solely to map Meta data-deletion requests back to your connection
- The posts you approve for publishing and their publish status

We request only the permissions needed to publish content you have approved to your own Page (`pages_show_list`, `pages_read_engagement`, `pages_manage_posts`). We do **not** read your personal Facebook profile, friends, messages, or ad accounts.

You can delete this data at any time by disconnecting the integration in SortedMate, by removing the app in your Facebook settings, or via our [data deletion page](https://app.sortedmate.com/data-deletion).

### Marketing Attribution

When you arrive via a marketing campaign, we may capture UTM parameters (source, medium, campaign) from the URL to understand which marketing efforts are effective. This data is associated with contact form submissions only.

## How We Use Your Information

- Respond to your contact form enquiries
- Provide, maintain, and improve our service
- Process payments and manage subscriptions
- Send transactional emails, SMS, and WhatsApp messages on your behalf
- Provide AI-powered features (quote enhancement, enquiry parsing, job suggestions)
- Sync data with third-party integrations you connect (accounting, calendar)
- Send important service notifications
- Respond to your support requests
- Understand how our service is used (with consent)
- Detect and prevent fraud and abuse
- Comply with legal obligations (including HMRC record-keeping)

### Legal Basis for Processing (UK GDPR)

| Basis | Description |
|---|---|
| Consent | For analytics cookies and marketing communications |
| Contract | To provide our service when you have an account, including processing of Stripe Connect data to provide SortedPay payment features |
| Legitimate interests | To respond to enquiries and ensure security (Legitimate Interest Assessments conducted and available on request) |
| Legal obligation | When required by law |

## Data Sharing & Third Parties

We do not sell your personal information. We share data only with trusted service providers who are contractually bound to protect your data, including Stripe Payments UK Ltd, which provides payment processing and connected account services via Stripe Connect. We share your business information, transaction data, and verification status with Stripe to facilitate payment collection from your customers. See the [Stripe Privacy Policy](https://stripe.com/privacy) for details on how Stripe handles your data. For a full list of providers with details, see our [Sub-Processors page](https://sortedmate.com/legal/sub-processors).

### Core Service Providers

| Provider | Location | Purpose |
|---|---|---|
| Supabase | EU | Database, storage & serverless functions |
| Clerk | US | Authentication & identity management |
| Stripe | US/EU | Subscription billing & payment processing |
| Twilio | US/EU | SMS & WhatsApp messaging |
| Resend | US | Transactional email delivery |
| PostHog | EU | Product analytics (with consent) |
| Vercel | Global | Website hosting & CDN |
| OpenAI | US | AI text generation features |
| Google | US | Maps, Calendar sync & reCAPTCHA |
| HMRC | UK | Making Tax Digital submissions (statutory recipient) |

### User-Enabled Integrations

These providers only receive your data if you choose to connect the integration:

| Provider | Location | Purpose |
|---|---|---|
| Xero | AU/UK | Accounting sync |
| QuickBooks | US | Accounting sync |
| Microsoft | US/EU | Outlook Calendar sync |
| Meta (Facebook/Instagram) | US/EU | Publish approved posts to your Facebook Page & linked Instagram |

**Meta (Facebook/Instagram)** — when you connect a Page and approve a post, we send that post's text and image to Meta's Graph API to publish it to your Page on your behalf. Nothing is published without your approval; you can pause auto-posting or disconnect at any time.

We may also share data with legal authorities when required by law.

## Cookies & Tracking

### Essential Cookies (Required)

These are necessary for the website to function and cannot be disabled.

| Name | Purpose | Duration |
|---|---|---|
| `sortedmate-cookie-consent` | Remembers your cookie preferences | Persistent |
| `sm_contact_submissions` | Prevents duplicate form submissions | Persistent |
| `sm_contact_last_submit` | Rate limiting for form submissions | Persistent |

### Analytics Cookies (Optional)

With your consent, we use PostHog to track anonymous usage patterns. You can accept or reject these via the cookie banner, and change your preference at any time using the "Cookie Preferences" link in the footer.

| Name | Provider | Purpose | Duration |
|---|---|---|---|
| `ph_phc_*` | PostHog | Identifies unique users for analytics | 1 year |
| `ph_*_posthog` | PostHog | Stores session and feature flag data | 1 year |

## Data Retention & Security

| Data Category | Retention Period |
|---|---|
| Contact form data | 2 years |
| Account & profile data | Account lifetime + 30-day deletion window |
| Financial records (quotes, invoices) | 7 years after account closure (HMRC requirement) |
| Client data (names, addresses, phone numbers) | Account lifetime + 30-day deletion window |
| Communications (email/SMS delivery logs) | 90 days |
| Analytics data | 12 months |
| Audit logs | 1 year rolling |
| Integration data (calendar, accounting) | While integration is active |
| Stripe Connect data (account status, transactions) | Account lifetime + 7 years (HMRC). Raw event data: 90 days |

When you delete your account, your personal data and business data will be permanently removed within 30 days. Backup copies are purged within 90 days of deletion.

We implement industry-standard security measures including encryption in transit (TLS) and at rest, secure data centres, and regular security reviews. You can request deletion of your data at any time.

## Your Rights (UK GDPR)

- Access your personal data
- Correct inaccurate data
- Request deletion of your data
- Restrict processing of your data
- Export your data in a portable format
- Object to certain processing
- Withdraw consent where applicable
- Lodge a complaint with the ICO (ico.org.uk)

To exercise these rights, contact us at [privacy@sortedmate.com](mailto:privacy@sortedmate.com). We will respond to your request within 30 days. In exceptional circumstances, where your request is particularly complex, we may extend this by a further 60 days and will inform you of any such extension.

## Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach, as required under UK GDPR Article 33.

Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay, providing details of the breach, its likely consequences, and the measures we have taken or propose to take to address it.

## Automated Decision-Making

We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on you.

### AI Features

SortedMate uses AI (powered by OpenAI) to provide optional features such as quote enhancement, enquiry parsing, job title suggestions, and a chat assistant. These features process text you provide to generate suggestions, but do not make decisions on your behalf. You always retain full control over whether to accept, modify, or reject AI-generated suggestions. AI interactions are logged for service continuity and are not used to train third-party AI models.

## HMRC Making Tax Digital (MTD)

If you use SortedMate's Making Tax Digital features to submit tax returns to HMRC, we process additional personal data as described below.

### What Additional Data We Collect

| Data | Purpose | Legal Basis |
|---|---|---|
| National Insurance Number (NINO) | Required by HMRC to identify your tax record | Contract (to provide MTD service) |
| VAT Registration Number (VRN) | Required for VAT MTD submissions | Contract |
| Income and expense figures | Quarterly and annual tax submissions | Contract + Legal obligation |
| Device and connection data | HMRC fraud prevention headers (Gov-Fraud-Prevention) | Legal obligation (HMRC requirement) |

### HMRC Fraud Prevention Headers

HMRC requires all MTD software to send fraud prevention headers with every API call. These headers include:

- **Device identifiers:** Screen size, browser plugins, user agent string
- **Connection data:** IP addresses, connection method, timezone
- **Vendor data:** Our software name and version

This data is sent directly to HMRC with each API request. Collection is a mandatory legal requirement — MTD software that does not send these headers cannot operate. For full details, see HMRC's [fraud prevention specification](https://developer.service.hmrc.gov.uk/guides/fraud-prevention/).

### NINO Storage and Encryption

Your National Insurance Number is encrypted at rest using AES-256-GCM encryption. It is only decrypted when making API calls to HMRC. NINOs are redacted from all logs and audit trails.

### HMRC as Data Recipient

When you submit tax data through SortedMate, HMRC receives your tax information as a statutory recipient. HMRC processes this data under their own privacy policy. We are the data controller for the processing within SortedMate; HMRC is an independent controller for data they receive.

### MTD Data Retention

| Data | Retention | Reason |
|---|---|---|
| Tax submissions (quarterly, annual) | 7 years | HMRC statutory requirement (TMA 1970 s.12B) |
| NINO (encrypted) | While integration is active | Deleted on disconnection or GDPR erasure |
| Fraud prevention header logs | 7 years | HMRC audit requirement |
| OAuth tokens | While integration is active | Revoked on disconnection |
| HMRC API audit logs | 7 years | Compliance evidence |

### Your Rights Regarding HMRC Data

You can disconnect your HMRC integration at any time. On disconnection, your OAuth tokens are revoked and your NINO is deleted. Tax submission records are retained for 7 years per HMRC requirements (Article 17(3)(b) exemption — legal obligation). You can request GDPR erasure of all HMRC data through SortedMate, subject to the legal retention requirements above.

## International Transfers

Your core business data is stored in the EU (Supabase, AWS eu-west-1, Ireland). PostHog analytics data is also EU-hosted. Several service providers process data in the United States, including Clerk (authentication), Stripe (payments), Twilio (messaging), Resend (email), OpenAI (AI features), and Google (Maps, Calendar, reCAPTCHA).

For transfers to the US, our providers participate in the EU-US Data Privacy Framework (UK Extension) or we rely on the UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU Standard Contractual Clauses. Transfer Impact Assessments have been conducted for all transfers to countries without a UK adequacy decision.

Stripe processes data in the EU and US. Transfers are protected under Stripe's Data Processing Agreement, which incorporates UK Standard Contractual Clauses. See [Stripe's DPA](https://stripe.com/legal/dpa) for details.

## Data Protection Contact

While we are not required to appoint a Data Protection Officer, our designated data protection contact is responsible for overseeing data protection matters. You can reach them at [privacy@sortedmate.com](mailto:privacy@sortedmate.com).

## Children's Privacy

Our service is not intended for children under 18. We do not knowingly collect data from children.

## Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or through our service. The "Last updated" date at the top indicates when changes were made.

## Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, contact us:

- Email: [privacy@sortedmate.com](mailto:privacy@sortedmate.com)
- SortedMate Ltd
- 3rd Floor, 86-90 Paul Street
- London, EC2A 4NE
- United Kingdom
- Company Registration No: 16880125
- ICO Registration No: ZC090709
