Privacy Policy

This Privacy Policy explains how Trade Synq Ltd ("TradeSynq", "we", "us", "our") collects, uses, and protects personal data when you use the TradeSynq platform, mobile app, and website (the "Service"). Trade Synq Ltd is the data controller for personal data we collect about you as a user. Where you use the Service to store information about your own customers, you are the controller of that data and we act as your processor (see "Data you store about your customers").

1. Who we are

Data controller: Trade Synq Ltd. Registered address: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. Company number: 17197243. Privacy contact: support@tradesynq.co.uk.

2. What personal data we collect

Information you give us: your name, email, phone number; business name, address and details; authentication information (we support phone one-time-passcode login); payment information for your subscription (processed by Stripe — we do not store full card details); and content you create (jobs, schedules, quotes, invoices, notes, photos).

Your bank details: if you enter them, we store the business bank details you provide — account name, bank name, sort code, account number and payment reference — so they can appear on your invoices for your clients to pay you. They are shown on invoices and included when you send a payment request or share an invoice PDF. These are your own business's details, not your customers': customers never enter payment data in the Service, and card payments they make to you are handled by Stripe (see section 5). We never store card details for anyone.

Collected automatically: device and usage information, including a push notification token and your device's name (for example "Sam's iPhone") if you enable notifications in the mobile app; and essential/functional cookies (see our Cookie Policy).

Device location: the one time we ask for your device's precise location is when you tap Start on a job, a recurring visit, or a site visit — in the mobile app, or via your browser's location prompt if you use the Service on the web. It is a single, one-off reading taken in the foreground at that moment, stored with that job as a record of where work began. It is entirely optional: if you decline permission, or a position cannot be obtained within a few seconds, the work starts without it. There is no background or continuous location tracking of any kind, photos you take in the app never include location data, and nothing else in the Service reads your device's location. This is separate from the addresses of your clients and their sites, which are typed in by you and your team and looked up (geocoded) on our servers — those describe the workplace, not your device's position.

Voice dictation in the mobile app is transcribed entirely on your device by your phone's operating system — audio is never sent to us or to any third party. We do not use analytics or marketing tracking.

From third parties: payment and subscription status from Stripe.

3. Data you store about your customers and staff

TradeSynq is a tool for tradespeople to run their business. When you use it, you enter information about your own customers — names, addresses, contact details, site locations, job and service history, quotes, invoices, and site-visit photographs. For this data: you are the data controller and are responsible for having a lawful basis and for informing your customers as required by law; we are your data processor, processing it only to provide the Service on your instructions. If you require one, we can provide a Data Processing Agreement (DPA) — contact support@tradesynq.co.uk. You are responsible for ensuring you have the right to enter your customers' data.

The same applies to your team. Where you enter information about your staff — such as contact details, home address, date of birth, emergency contacts, pay rates, or employment documents — this is employment data: you are its controller and we process it only to provide the Service on your instructions. You are responsible for having a lawful basis for holding it and for informing your staff as required by law.

4. How we use your data and our lawful bases

We use your personal data for the following purposes, relying on the lawful bases set out below:

  • To provide, operate and maintain the Service — necessary to perform our contract with you.
  • To authenticate you and keep your account secure — necessary to perform our contract with you, and in our legitimate interests in protecting the Service.
  • To process payments and manage your subscription — necessary to perform our contract with you.
  • To send service messages (for example, the SMS reminders you set up) — necessary to perform our contract, and where applicable, with your consent.
  • To improve and develop the Service — in our legitimate interests in providing and enhancing the Service.
  • To provide support and respond to your enquiries — in our legitimate interests and to perform our contract with you.
  • To comply with legal obligations, such as tax and accounting requirements — necessary to comply with a legal obligation.

Where we rely on your consent, you can withdraw it at any time.

5. Who we share your data with (sub-processors)

We use trusted third-party providers to run the Service. They process personal data on our behalf, under contract, and only for the purposes we specify:

ProviderWhat they doLocation
SupabaseDatabase hosting and authenticationLondon (eu-west-2)
VercelApplication hostingLondon (lhr1)
StripePayment processing and subscription billingUK / EU / US
TwilioSMS reminders and phone one-time-passcode authenticationUS / global
Google Maps PlatformMapping, geocoding and address lookupUS / global
MapboxTravel-time and route calculationUS / global
AnthropicAI text generation and parsing, such as drafting quote notes, summarising completed work, and reading pasted messages into quotesUS

Card payments you take from your own clients work differently: when you connect Stripe in the Service, you create a Stripe account in your own name and you are the merchant of record for payments your clients make to you. Stripe handles that payment data under its own terms and privacy policy, with you as its customer; we receive only the payment's status — never card details.

We do not sell your personal data, and we do not use it for advertising.

6. International data transfers

Some providers are outside the UK (e.g. Stripe, Twilio, Google, Mapbox, Anthropic operate in the US). Where personal data is transferred outside the UK we rely on appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. Our primary database and hosting are in the UK (Supabase London, Vercel London), so the core of your data is stored in the UK.

7. How long we keep your data

We keep personal data for as long as your account is active and as long as needed to provide the Service. You can delete your account at any time in the mobile app: open the More tab and tap Delete account. Deletion is immediate and permanent. If you are a team member, your login and personal details are erased straight away; records of work you completed remain with your employer's company as its business records. If you are the business owner, deleting your account permanently removes your entire company and its data. We retain records beyond deletion only where we must comply with legal, tax, or accounting obligations (up to 7 years). Backups may persist for a limited period as part of our standard backup and disaster-recovery process, after which they are overwritten.

8. Your rights

Under UK data protection law you have the right to access, rectify, erase, restrict or object to processing, data portability, and to withdraw consent. To exercise any of these, contact support@tradesynq.co.uk; we will respond within one month. You can also complain to the Information Commissioner's Office (ICO) at ico.org.uk. Where the request concerns data your business stored about its customers, you (as controller) are responsible for handling that request; contact us and we will assist as your processor.

9. Cookies

We use only strictly necessary cookies (such as those that keep you logged in) and functional cookies (which remember your preferences). We do not use analytics or marketing cookies. See our Cookie Policy for details.

10. How we protect your data

We use appropriate technical and organisational measures, including encryption in transit, access controls that ensure each business can only access its own data, restricted administrative access, and secure UK-based hosting. No system is completely secure, but we work to protect your data and to notify you and the relevant authority of any breach as required by law.

11. Children

The Service is intended for businesses and is not directed at children under 16. We do not knowingly collect data from children.

12. Changes to this policy

We may update this policy. We will post the updated version here with a revised "Last updated" date and, where changes are significant, notify you.

13. Contact

Trade Synq Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. support@tradesynq.co.uk. To complain to the regulator: Information Commissioner's Office, ico.org.uk, 0303 123 1113.

Version 1.3 · Last updated 6 September 2026

© 2026 TradeSynq