Legal
Privacy Policy
Last updated: 23 July 2026
This policy explains what personal information Patch collects, why we collect it, and what your rights are under the UK GDPR and the Data Protection Act 2018. Plain English where we can, precise where we have to be.
1. Who we are
"Patch", "we", "us" or "our" means Patch (a trading name — full registered company details available on request). Questions or requests? hello@claimyourpatch.com.
2. Our two roles: controller and processor
Patch handles personal data in two distinct capacities. Which one applies changes your rights and who you should ask about the data.
Controller. Patch is the data controller for:
- Our own customers and prospective customers (tradespeople).
- Prospect research we carry out to identify tradespeople to approach — including publicly available business details (name, trade, town, website, listing information) and any notes generated by our sourcing and AI validation tools.
- Outreach we send from Patch (email, in-app messaging), and any replies we receive.
- Website visitors, account holders, billing records, referrals and support conversations.
For anything in this list, Patch decides the purposes and means of processing. Send subject-access, correction, deletion, objection or complaint requests to hello@claimyourpatch.com.
Processor. Patch acts as a data processor on behalf of each customer (their business is the controller) for:
- End-customer enquiries and leads captured through the customer's website, portal forms, integrations or manual entry.
- Job photos, notes, files, messages and status updates the customer (or their end-customers) add to the CRM.
- Data pulled in from advertising and listing integrations (Meta, Google Ads, Google Business Profile) that the customer has connected.
For processor data, the customer's business is the controller. Enquiries about a specific tradesperson's records should go to that business first. Patch will only act on documented instructions from the controller and will forward or assist with any rights request received directly. Our processing terms are set out in our Data Processing Addendum (DPA), available on request.
3. What we collect
- Account info — name, business name, email, phone, password (hashed), role.
- Enquiry and lead info — anything typed into contact and patch-check forms: trade, town, notes.
- Billing info — handled by Stripe; we store the invoice, customer ID and subscription state, not full card numbers.
- Portal / CRM data (processor) — leads, jobs, photos, messages, files uploaded by our customers or their end-customers.
- Integration data (processor) — the specific data Meta or Google share once connected (leads, ad performance, GBP insights).
- Prospecting data (controller) — public business information about tradespeople we may approach: name, trade, town, website URL, listing details, and internal notes.
- Support messages — anything sent through the request / service desk.
- Technical data — IP address, device, browser, pages visited (see the cookie policy).
4. Why we collect it and lawful basis
- Contract — to provide services you've asked for (website, ads, CRM, portal).
- Legitimate interests — to run and secure the platform, prevent fraud, follow up on enquiries, and carry out B2B prospecting to tradespeople whose services align with ours. We balance this against your interests and you can object at any time.
- Consent — for marketing cookies and marketing emails you opt into.
- Legal obligation — for tax, accounting and lawful requests.
5. Who we share it with
Current subprocessors include:
- Hosting, database and email delivery providers.
- Stripe for payments.
- An AI provider used for automated first-response and outreach drafting — personal identifiers are minimised, and processor data is not used to train third-party models.
- Advertising and analytics platforms connected by the customer (Meta, Google).
We do not sell personal information.
6. International transfers
Some subprocessors may process data outside the UK/EEA. Where they do, we rely on approved safeguards such as the UK International Data Transfer Agreement or Standard Contractual Clauses.
7. Retention
Default retention periods:
- Active customer data — kept for the life of the account.
- CRM leads (processor data) — retained while the customer's account is active. Customers can delete individual leads at any time from the portal. On request we will auto-purge leads older than a defined age (e.g. 24 months) on a rolling basis.
- Prospecting records (controller data) — kept for up to 24 months from last activity, then deleted or anonymised. Anyone can ask to be suppressed from future outreach permanently.
- Marketing enquiries that don't convert — up to 24 months.
- Billing records — 6 years after your final invoice (HMRC).
- Backups — encrypted backups age out within 30 days of deletion.
8. Offboarding — export and deletion
If a customer leaves Patch, their data is theirs. We commit to the following as standard:
- Full export within 7 days of a written request — leads, notes, files, invoices and integration data — in a portable format (CSV / JSON / original file downloads).
- Permanent deletion within 30 days of confirmation that the export has been received, or of a direct deletion request if no export is wanted. This covers live databases and file storage.
- Backups — deleted records fall out of encrypted backups within a further 30 days.
- Legal holds — the only data we retain past this window is what we're legally required to keep (billing records for tax, and any information covered by an active legal claim).
Nothing is held hostage. Ask for an export or deletion any time at hello@claimyourpatch.com.
9. Erasure requests from end-customers
Where an end-customer (someone whose data sits in a Patch customer's CRM) asks the tradesperson to delete their information, the tradesperson is the controller and must action the request. Patch makes this a first-class feature:
- Every lead in the portal has a delete / erase control that removes the record from the live database.
- Deletions cascade to notes, messages and associated files stored with that lead.
- The deletion is reflected in backups within 30 days.
- If the end-customer contacts Patch directly, we will forward the request to the relevant customer and (on their instruction) action the deletion ourselves.
10. Your rights
Under UK GDPR you can:
- Access a copy of the data we hold on you.
- Ask us to correct anything that's wrong.
- Ask us to delete it (where the law lets us).
- Ask us to restrict or object to how we use it.
- Object to prospecting or marketing — we'll add you to our suppression list immediately.
- Take it elsewhere (data portability).
- Withdraw consent at any time.
- Complain to the ICO — ico.org.uk.
To exercise any right, email hello@claimyourpatch.com. We aim to respond within 30 days.
11. How we protect it
Passwords are hashed. Third-party access tokens and sensitive fields (such as payout bank details) are encrypted at rest (AES-256-GCM). Row-level security policies restrict access to your own data. Access is logged. Nothing is 100% secure, but we take it seriously.
12. Children
Patch is a B2B service for tradespeople. It's not intended for anyone under 18.
13. Changes
If we change this policy in a material way we'll email active customers and post the update here with a new "last updated" date.
14. Contact
hello@claimyourpatch.com — data queries, export requests, deletion requests, opt-outs, DPA copies.
