Legal

Privacy Policy

Last updated 16 September 2026

This Privacy Policy explains how WorkPaid (operated by [LEGAL ENTITY NAME], registered in England and Wales) collects, uses, and protects your personal information when you use our platform at workpaid.uk.

We're committed to handling your data lawfully, fairly, and transparently in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Who we are

WorkPaid is a software platform for UK tradespeople to send quotes, take deposits, and collect payments from their customers. The data controller for the purposes of UK GDPR is [LEGAL ENTITY NAME], contact details below.

When a tradesperson uses WorkPaid to send a quote or invoice to one of their customers, the tradesperson is independently responsible for the customer information they choose to enter (who to contact, what work to describe, when to send reminders). We host and process that information to deliver the service, but the tradesperson controls what's added and when. Requests from customers about data their tradesperson entered may need to be raised with the tradesperson directly - we'll help where we can.

Information we collect

If you're a tradesperson using WorkPaid:

  • Account details: full name, email address, password (hashed - we never see your plain-text password)
  • Business profile: business name, phone number, trade type, business address, website URL, company registration number (if applicable), VAT registration status and number (if applicable)
  • Payment account information: when you connect a Stripe account, Stripe holds your bank and identity verification information; we hold a reference identifier only
  • Usage information: quotes you create, customers you add, payments processed, and how you use the platform
  • Refund and chargeback records: when a payment processed via your account is refunded or disputed by the customer's bank, we record the Stripe event details (charge identifier, refunded amount, Stripe's reason and outcome) and link them to the originating quote, so you have an audit trail to reconcile against your accounting records
  • Content you upload: your business logo, receipt images for expenses, and photos you take of a job. Job photos may show a customer's property or premises (and could incidentally include people). We store them so you have a record; they can be used as evidence if a payment is disputed (and submitted to Stripe as part of a dispute response); and, if you choose to attach one to a payment request, shown to that customer. You are responsible for the content you upload and for having the right to upload it (see our Terms)

If you're a customer receiving a quote:

  • Information your tradesperson enters about you: name, email address, optional phone, optional address
  • If your quote is for a business (a commercial quote), the business details your tradesperson enters: company name, contact name, purchase-order reference, billing address, and VAT number where provided
  • Photos your tradesperson takes of the job, which may show your property or premises - used for their own records and as evidence if a payment is disputed, and shown to you only if they attach one to a payment request
  • An email address you choose to add yourself on the quote or payment page, so we can send you a receipt and remind you when a payment is due - this is optional and only used for those transactional emails about your job
  • Your responses to the quote: whether you accepted or declined, optional reason if declined, the timestamp
  • Reviews you submit after the work is complete (star rating and optional written feedback)
  • Payment information: when you pay a quote, Stripe processes your payment details directly - your card details, or your bank authorisation if you pay by bank - and we don't see or store your card number or bank login

Automatically collected:

  • Login session cookies (httpOnly, used only to keep you signed in)
  • Server logs (IP address, browser, time of request) - kept for security and debugging
  • Email delivery records (whether transactional emails we send to you were delivered)
  • Diagnostic error reports if something crashes, sent to our error-monitoring provider (see Sentry under "Who we share your information with")

Who controls what: for the information a tradesperson enters or uploads about their own customers - including customer details and job photos - the tradesperson is the data controller and WorkPaid acts as their data processor, handling it on their behalf to run the service. WorkPaid is the controller for your own account data and for how we operate the platform.

How we use your information

  • To operate the WorkPaid platform - hosting your quotes, processing payments, sending transactional emails (quote shared, payment received, decline notifications, etc.)
  • To send late-payment reminders to customers on your behalf (you can opt jobs out)
  • To improve the platform - aggregated usage data, never tied back to individual identities for product analytics
  • To comply with legal obligations - tax records, anti-fraud, responding to lawful requests
  • To prevent fraud and abuse

We do not sell your personal information to anyone. We do not use your data for behavioural advertising.

Legal basis for processing (UK GDPR)

  • Performance of contract: most processing is necessary to deliver the service you signed up for
  • Legitimate interests: security, fraud prevention, service improvements, and reasonable communications about your account
  • Legal obligation: tax records, ICO requirements, lawful requests from authorities
  • Consent: any optional marketing communications (you can withdraw at any time)

Who we share your information with

We use a small number of trusted third-party processors to run WorkPaid. We share only what's necessary, and each is bound by data-processing terms:

  • Stripe (payment processing, Stripe Connect for tradesperson payouts) - card details, bank-payment (open banking) authorisation, identity verification, payouts. Stripe is itself a data controller for the payment information you provide directly to them. stripe.com/gb/privacy
  • Resend (transactional email delivery) - email addresses and message content for emails we send on your behalf. resend.com/legal/privacy-policy
  • Hetzner Online GmbH (server infrastructure, Germany) - all platform data is stored on encrypted servers in the EU. hetzner.com/legal/privacy-policy
  • Database provider (Neon, PostgreSQL hosting) - your quote, payment, and account data
  • Sentry (Functional Software, Inc. - error monitoring and crash diagnostics) - technical error reports when something goes wrong: the page or request that failed, browser and device details, and, for signed-in users, your account's user ID, so we can find and fix faults. No card details or bank credentials are ever sent to Sentry. sentry.io/privacy
  • Plausible Analytics (incorporated in Estonia - privacy-first website statistics) - the page visited, where you arrived from, and your browser, device type and approximate location. No cookies, no identifiers, and your data never leaves the EU. We exclude the private customer quote, payment, invoice and review pages entirely. plausible.io/data-policy

We may also disclose information if legally required (court order, law enforcement request) or to protect our rights or others' safety.

Cookies

We use a single essential cookie:

  • access_token - an httpOnly session cookie used only to keep you signed in. The cookie itself expires after 30 days, but session validity is also tied to your account's security state - signing out or changing your password invalidates the cookie server-side immediately, so an old token cannot be re-used after either of those actions.

We do not use cookies for tracking, behavioural advertising, or analytics. To understand how our public pages are found and used, we use Plausible Analytics - a privacy-first, cookieless tool that sets no cookies and stores nothing at all on your device, does not track you across other websites or devices, and does not build a profile of you. It records only aggregated visit data (the page visited, where you arrived from, your browser, device type and approximate location), it does not retain your IP address, and all of it is processed and stored inside the EU.

We exclude the private customer quote, payment, invoice and review pages from analytics entirely, and we strip the web address of anything identifying before it is recorded - so the one-off links we email you are never shared. Because our only cookie is the strictly necessary access_token, no consent banner is required under PECR.

How long we keep your information

  • Account data: for as long as your account is active, plus 6 years after closure (UK tax record-keeping requirements)
  • Quote and payment records: 6 years (tax + financial-record requirements)
  • Email delivery logs: 12 months
  • Server logs: 30 days
  • Customer information added by tradespeople: as long as the linked tradesperson account is active

Your rights

Under UK GDPR you have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate information
  • Erase your information (subject to our legal record-keeping obligations)
  • Restrict or object to certain processing
  • Data portability - request a copy of your data in a structured, machine-readable format
  • Withdraw consent at any time where processing is based on consent

These rights apply whether you signed up to WorkPaid as a tradesperson or received a quote from one. If you received a quote and want to know what we hold on you, email privacy@workpaid.uk with the name of the tradesperson who quoted you and we'll help. Otherwise, to exercise any of these rights generally, email privacy@workpaid.uk. We'll respond within one month.

If you're unhappy with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113. We'd appreciate the chance to address your concerns first.

International transfers

Our infrastructure is based in the UK and EU. Some of our service providers (e.g. Stripe, Resend, Sentry) may process data outside the UK in countries the UK government recognises as providing adequate protection, or under approved transfer mechanisms (Standard Contractual Clauses + UK addendum).

Security

We use industry-standard practices to protect your data:

  • All connections use TLS encryption (HTTPS)
  • Passwords are stored hashed (never plain text)
  • Database access is restricted and authenticated
  • Payment data - card details, and bank authorisation when paying by bank - is handled exclusively by Stripe (PCI-DSS Level 1 certified); we never see or store card numbers or bank credentials
  • Authentication uses signed JWT tokens in httpOnly cookies

No system is 100% secure. If we ever become aware of a breach affecting your data, we'll notify you and the ICO as required by law.

Children

WorkPaid is intended for use by adults aged 18 or over. We do not knowingly collect data from children under 18.

Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top reflects the latest revision. For material changes, we'll notify active users by email.

Contact us

For privacy questions, data requests, or concerns:

Your money lands straight in your bank through Stripe. WorkPaid never holds it.

WorkPaid is operated by [LEGAL ENTITY NAME], a company registered in England and Wales (company no. [COMPANY NUMBER]). Registered office: [REGISTERED OFFICE ADDRESS].