Legal
Privacy Policy
Last updated: 19 July 2026
This policy explains what personal information Patch collects, why we collect it, and what your rights are under the UK GDPR and the Data Protection Act 2018. Plain English where we can, precise where we have to be.
1. Who we are
"Patch", "we", "us" or "our" means Patch (a trading name — full registered company details available on request). We're the data controller for the personal information described in this policy.
Questions or requests? hello@claimyourpatch.com.
2. What we collect
- Account info — name, business name, email, phone, password (hashed), role.
- Enquiry and lead info — anything you type into our contact and patch-check forms: trade, town, notes.
- Billing info — handled by Stripe; we store the invoice, customer ID and subscription state, not your full card number.
- Portal usage — leads, jobs, photos, messages, files you upload while using the client portal / CRM.
- Integration data — if you connect Meta or Google accounts, we access the specific data those platforms allow (leads, ad performance, GBP insights).
- Support messages — anything you send us through the request/service desk.
- Technical data — IP address, device, browser, pages visited (see our cookie policy).
3. Why we collect it and lawful basis
- Contract — to provide the services you've asked for (website, ads, CRM, portal).
- Legitimate interests — to run and improve the business, prevent fraud, secure the platform, and follow up on enquiries.
- Consent — for marketing cookies, marketing emails you opt into, and any special-category information you volunteer.
- Legal obligation — for tax, accounting, and responding to lawful requests.
4. Who we share it with
We only share what's needed to run the service. Current subprocessors include:
- Hosting, database and email delivery providers.
- Stripe for payments.
- An AI provider for our automated first-response feature — personal identifiers are scrubbed before content is sent, and only anonymised historical context is used.
- Advertising and analytics platforms you've connected (Meta, Google) — only after you authorise it.
We do not sell your personal information.
5. International transfers
Some subprocessors may process data outside the UK/EEA. Where they do, we rely on approved safeguards such as the UK International Data Transfer Agreement or Standard Contractual Clauses.
6. How long we keep it
- Active customer data — for the life of your account.
- Billing records — 6 years after your final invoice (HMRC requirement).
- Marketing enquiries that don't convert — up to 24 months.
- Backups — up to 30 days from deletion.
You can ask us to delete sooner where we're not legally required to keep it.
7. Your rights
Under UK GDPR you can:
- Access a copy of the data we hold on you.
- Ask us to correct anything that's wrong.
- Ask us to delete it (where the law lets us).
- Ask us to restrict or object to how we use it.
- Take it elsewhere (data portability).
- Withdraw consent at any time.
- Complain to the ICO — ico.org.uk.
To exercise any right, email hello@claimyourpatch.com. We aim to respond within 30 days.
8. How we protect it
Passwords are hashed. Third-party access tokens are encrypted at rest (AES-256-GCM). Row-level security policies restrict access to your own data. Access is logged. Nothing is 100% secure, but we take it seriously.
9. Children
Patch is a B2B service for tradespeople. It's not intended for anyone under 18.
10. Changes
If we change this policy in a material way we'll email active customers and post the update here with a new "last updated" date.
11. Contact
hello@claimyourpatch.com — data queries, deletion requests, general questions.
