Privacy Policy
Last updated: 9 September 2026.
TradeKick provides scheduling and invoicing software to self-employed tradespeople (“providers”). This policy explains what personal data we process and why. For providers, TradeKick is the data controller of their account data. For a provider's own customers, the provider is the controller and TradeKick is a processor acting on their instructions.
What we collect
- Provider account: name, business name, email, phone, address, VAT number, hashed password, and an encrypted two-factor secret.
- End customers (entered by the provider or their AI agent): name, phone, email, job address, and a free-text description of the work requested.
- Operational data: bookings, invoices, and transcripts of conversations with the booking assistant.
- Technical: IP address and rate-limiting counters, audit logs of key actions.
Why we process it
- To provide the service (performance of a contract).
- To send booking confirmations, reminders and invoices (legitimate interests / contract).
- To secure the service — 2FA, rate limiting, audit logging, fraud and abuse prevention (legitimate interests).
- To meet UK tax and accounting record-keeping duties (legal obligation).
AI processing
The booking assistant sends the customer's messages and a summary of the provider's services and availability to a large-language-model provider to generate replies. Messages are sanitised and length-limited first, and the customer's text is never treated as an instruction to the system.
The current provider is Google (Gemini API) on its free tier. On that tier, Google states that prompts and responses may be reviewed by humans and used to improve Google's products, including training its models. We minimise what is sent and ask that customers and providers do not include sensitive detail beyond what a booking needs. We may switch to a provider that does not train on submitted data (for example a paid Anthropic, OpenAI or Groq tier); contact us for the provider in use at any given time.
Sharing
We use sub-processors to run the service: hosting (Vercel), database (Neon), email (Resend), rate limiting (Upstash), mapping/geocoding (OpenRouteService), payments (Stripe), and the AI provider named above (currently Google). Data is hosted in the UK/EU region where the sub-processor offers it; requests to the AI provider may be processed outside the UK/EU.
Retention
Account and operational data is kept while the account is active. On a deletion request we hard-delete after a 30-day grace period. Invoice records may be retained for up to 6 years to meet HMRC requirements.
Your rights
You can access, correct, export or delete your data. Providers can export (Business profile → Your data) and request deletion from the same screen. A provider's customers should contact that provider; we will assist them as processor. You can complain to the UK Information Commissioner's Office (ico.org.uk).
Contact
privacy@yourdomain.co.uk
This is a plain-language summary and not legal advice. Have it reviewed by a solicitor before relying on it commercially.