Privacy Policy
Last updated: 16 June 2026
TradeFlow (“we”) helps UK trades handle calls, bookings and deposits. This policy explains what personal data we process, why, and your rights under UK GDPR and the Data Protection Act 2018.
Who is the controller
For the account you create, TradeFlow is the controller. For your customers' data that flows through your account (callers, bookings), you are the controller and TradeFlow is your processor, acting on your instructions.
What we collect
• Account data — your email, business name, trade and settings.
• Operational data — flows, services, availability, bookings, and the phone numbers/SMS your flows handle.
• Customer contacts — names, phone numbers and emails of people who call or book you.
• Payments — deposits are processed by Stripe; we never see or store full card details.
• Technical — minimal logs and an essential session cookie.
Why we use it (lawful bases)
To provide the service (contract), to keep it secure and prevent abuse (legitimate interests), and to meet legal obligations. Marketing SMS to your customers relies on your lawful basis and respects STOP/opt-out (PECR).
Sharing
We use sub-processors to run the service: Supabase (database/auth), Vercel (hosting), Twilio (calls/SMS), Stripe (payments), Anthropic (build-time flow generation), Resend (email), and optionally Google (calendar). We don't sell your data.
Retention
We keep account and booking data while your account is active. Abandoned booking-hold PII is scrubbed after 7 days and contact-form messages after 90 days. You can request deletion at any time.
Your rights
You have the right to access, correct, delete, restrict, port, and object to processing of your data, and to complain to the ICO. To exercise any of these, email us.
Contact
Questions or requests: hello@tradeflow.app.
This is a plain-English summary provided for transparency and should be reviewed by your own legal adviser before launch — it isn't legal advice.