PRIVACY POLICY
Last Updated: 27 August 2026 ICO Registration Number: ZC107930
1. Introduction
This Privacy Policy explains how Mark Dodson T/A We Sweep ("We Sweep", "we", "us", "our") collects, uses, stores, and protects personal data in connection with the We Sweep SaaS platform (the "Platform").
We Sweep operates exclusively within the United Kingdom and is committed to compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This Privacy Policy forms part of the Agreement, as defined in the Master Terms of Service.
2. Data Protection Contact
We Sweep has designated a data protection contact responsible for overseeing compliance with data protection law:
Mark Dodson Email: management@we-sweep.co.uk Address: Lower Moorlands, Sherburn‑in‑Elmet, LS25 6DN
You may contact us at any time regarding your personal data or to exercise your rights under data protection law.
3. Roles Under Data Protection Law
We Sweep acts in different capacities depending on the type of data processed:
- 3.1 Business User Data — We Sweep as Controller: We Sweep is the Data Controller for personal data relating to Business Users, including account information, billing details, usage logs, and security data. We determine the purposes and means of processing this data.
- 3.2 Customer Data — We Sweep as Processor: For personal data relating to your Customers (homeowners), We Sweep acts as a Data Processor and processes such data solely on your documented instructions. This is governed by the Data Processing Agreement (DPA).
4. Categories of Personal Data We Process
4.1 Business User Data (Controller Role)
- Identity & Contact Data: name, business name, email address, phone number.
- Billing & Financial Data: Stripe account details, transaction metadata; where you enable pay‑on‑completion, the business bank account details you enter (account name, sort code, account number) and platform‑fee billing records (Stripe customer reference, payment method type, card brand and last four digits or Direct Debit mandate reference, invoice history).
- VAT Data: where you register as VAT‑registered, your VAT registration number, the registered business name returned by HMRC, and verification timestamps.
- Technical & Log Data: IP address, device identifiers, browser type, timestamps, authentication logs.
- Support & Communication Data: messages, support tickets, and correspondence.
4.2 Customer Data (Processor Role)
Processed on behalf of Business Users:
- Contact Data: name, address, email, phone number (including mobile number where SMS messages are enabled by the Business User).
- Location Data: geographic coordinates derived from the Customer's postcode (used for scheduling and route planning).
- Service Data: appliance details, chimney type, service history, and any booking notes the Customer chooses to provide when booking.
- Payment Records: payment method chosen, payment status, amount, when and by whom a payment was recorded, and payment link references. Card details are handled by Stripe and never stored by We Sweep.
- Inspection Records: photos (taken by the Business User's technicians, or uploaded voluntarily by the Customer when booking — embedded photo metadata such as GPS location is removed on upload), safety notes, digital certificates.
- Referral Data: where the Business User enables their customer referral scheme — the Customer's unique referral code, a record of which Customer referred them (where they were referred by another Customer), a count of successful referrals, and reward credit records (amount, status, and dates). A reward notification sent to a referring Customer never names the Customer they referred.
- Authentication Data: magic link tokens and portal login sessions.
5. Lawful Bases for Processing (Controller Role)
We Sweep processes Business User Data under the following lawful bases:
| Purpose | Lawful Basis |
|---|---|
| Account creation and management | Contract (Art. 6(1)(b)) |
| Payment processing | Contract (Art. 6(1)(b)) |
| Security, fraud prevention, logging | Legitimate Interests (Art. 6(1)(f)) |
| Service communications (transactional) | Legitimate Interests (Art. 6(1)(f)) |
| Platform monitoring and rate limiting | Legitimate Interests (Art. 6(1)(f)) |
| Platform fee invoicing and collection | Contract (Art. 6(1)(b)) |
| VAT number verification with HMRC | Contract (Art. 6(1)(b)) / Legitimate Interests (Art. 6(1)(f)) |
| Legal compliance (e.g., tax records) | Legal Obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we have conducted a Legitimate Interests Assessment to ensure our interests do not override your rights and freedoms. A copy is available on request.
Customer Data is processed under the lawful basis determined by the Business User (Controller).
6. How We Use Personal Data
We use personal data to:
- Provide and maintain the Platform.
- Authenticate users via magic links.
- Process card payments through Stripe, and record payments Customers make directly to the Business User (cash or bank transfer).
- Invoice and collect We Sweep's platform fee from Business Users, including via a saved card or Bacs Direct Debit mandate.
- Verify Business Users' VAT registration numbers against HMRC's "Check a UK VAT number" service (only the VAT number is sent to HMRC; we store the registered name HMRC returns).
- Generate and store safety certificates.
- Convert Customer postcodes into geographic coordinates (via Google Maps) for scheduling and route planning.
- Synchronise bookings with Google Calendar (where connected by the Business User).
- Transmit customer contact details and sales invoice, payment, and refund records to the accounting software the Business User connects (Xero, QuickBooks, or Sage) — see Section 7C.
- Operate the Business User's customer referral scheme, where they enable it: generate referral codes, record referrals between Customers, and apply reward credits as booking discounts.
- Provide customer support.
- Monitor system performance and security.
- Send transactional notifications by email and, where the Business User enables them, transactional service messages by SMS (e.g. appointment reminders).
- Comply with legal obligations.
We do not sell personal data or use it for advertising or marketing.
7. Third‑Party Providers and Sub‑Processors
We use trusted third‑party providers to deliver the Platform. A full list is maintained in Annex B of the DPA. Current providers include:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database and infrastructure | EU/UK/USA |
| Vercel | Frontend hosting | Global |
| Stripe | Payment processing | UK/USA |
| Postmark | Transactional email | USA |
| The SMS Works | Transactional SMS (service messages such as appointment reminders) | UK |
| Google Maps | Address lookup and routing | Global |
All providers are bound by data processing agreements and maintain appropriate security certifications. Further details are available in the DPA.
In addition, where a Business User registers as VAT‑registered, we send their VAT registration number to HM Revenue & Customs (HMRC) via its "Check a UK VAT number" service to verify it. HMRC acts as an independent controller of that lookup, not as our processor.
Connected Services: Business Users can also connect the Platform to their own accounts with certain third‑party services — Google Calendar (Section 7A) and the accounting packages Xero, QuickBooks, and Sage (Section 7C). Data sent to a Connected Service goes to the Business User's own account with that provider, at the Business User's direction, and is processed under the Business User's own agreement with the provider. Connected Services are not our sub‑processors; see clause 2.4 of the DPA.
7A. Google API Data — Use, Storage, and Disclosure
WeSweep's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What we access: When a Business User connects their Google Calendar, we access calendar event data (event times, titles) solely for booking conflict detection, and we create, update, and delete calendar events to synchronise bookings.
What we store: We store only an encrypted OAuth refresh token (to maintain the connection) and Google Calendar event identifiers (to track which bookings are synced). We do not store, copy, or cache any other Google Calendar content.
Sharing, transfer, and disclosure: We do not share, transfer, or disclose Google user data to any third party. Google Calendar data is not used for advertising, analytics, profiling, or any purpose other than the calendar synchronisation features described above. Google user data is not provided to any artificial intelligence or machine learning model.
Revocation: Users can disconnect their Google Calendar at any time from the Integrations page, which immediately deletes the stored refresh token and all event link records.
7B. Website Enquiries and Applications
Our marketing website (www.we-sweep.co.uk) collects personal data when you contact us or apply to join the platform. We Sweep is the Controller for this data.
- Contact form: business name, your name, email address, and your message. Submissions are stored in our database and a copy is emailed to us using Google's Gmail service.
- Application form: the business and contact details you provide when applying for a We Sweep account. Applications are stored in our database and reviewed by We Sweep staff.
- US waitlist form: contact name, email, business details, and the optional information you provide. Submissions are stored in our database and a copy is emailed to us using Google's Gmail service.
This data is used only to respond to your enquiry, assess your application, or contact you about availability — never for advertising. The lawful basis is our legitimate interest in responding to enquiries (Art. 6(1)(f)) and, for applications, steps taken at your request prior to entering into a contract (Art. 6(1)(b)). The marketing website does not use analytics or tracking cookies.
7C. Accounting Software Integrations (Xero, QuickBooks, Sage)
Business Users can connect their own Xero, QuickBooks, or Sage account so that the Platform keeps their books up to date automatically.
What we send: When a job is completed or paid (or refunded), the Platform sends the related sales invoice, payment, or credit note — including the Customer's name, email address, phone number, and address (to create or match the customer contact), service descriptions, and amounts — to the Business User's own account with the connected provider.
What we read: We read only configuration reference data from the connected account — the chart of accounts (or service items), bank accounts, and tax rates — so the Business User can choose where entries are posted. We do not read, copy, or analyse the Business User's other accounting data.
What we store: We store an encrypted connection token (to maintain the connection), the identifiers of documents and contacts we created (so retries never create duplicates), and a temporary snapshot of each document sent. Personal data in these snapshots is automatically removed 30 days after the document is successfully transmitted; the remaining transmission record holds only references, amounts, and status.
Sharing and purpose limitation: Data is sent only to the provider account the Business User connected, solely for the bookkeeping features described above. It is not used for advertising, analytics, or profiling, and is not provided to any artificial intelligence or machine learning model.
Revocation: Business Users can disconnect their accounting software at any time from the Integrations page, which stops all transmission and deletes the stored connection tokens. Documents already created in the accounting software remain there, under the Business User's own account and agreement with that provider.
8. International Data Transfers
Some of our third‑party providers process data outside the United Kingdom. Where personal data is transferred outside the UK, We Sweep ensures appropriate safeguards are in place, including:
- UK Addendum to the EU Standard Contractual Clauses.
- The UK–US Data Bridge (where applicable).
- Adequacy regulations issued by the UK Government.
We have conducted transfer risk assessments for each international transfer. Details are available on request.
9. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected:
| Data Category | Retention Period | Basis |
|---|---|---|
| Business User account data | Duration of the Agreement | Contract |
| Customer Data | Tenant lifetime + 60 days post‑termination | Contractual necessity |
| Financial transaction data | 7 years | HMRC legal obligation |
| Platform audit logs | 2 years | Legitimate interests / Legal obligation |
| Security logs | 12 months | Legitimate interests |
| API usage logs | 90 days | Legitimate interests |
| Magic link tokens | 1 hour (single use) | Security necessity |
| Customer portal sessions | Until logout (stored in the Customer's own browser) | Security necessity |
| Platform fee ledger & invoices | 6 years | HMRC legal obligation |
| Geocoding cache (coordinates only, no identifiers) | 30 days | Legitimate interests |
| Rate limit records | 24 hours | Legitimate interests |
| Data exports | 7 days (files), 24 hours (download links) | Data portability |
| Connected Service tokens (calendar & accounting) | Until the integration is disconnected | Contract |
| Accounting sync document snapshots | Personal data removed 30 days after successful transmission | Contract / Legitimate interests |
When a Business User terminates their account, all associated data (including Customer Data) is retained for 60 days to allow for reactivation or data export, then permanently deleted via automated processes. Platform fee ledger and invoice records are retained for 6 years after deletion to meet HMRC record‑keeping obligations; they do not contain Customer personal data.
Where SMS messages are sent, our SMS provider (The SMS Works) retains delivery reports on its own systems for 90 days, with archived records held for up to 7 years, in accordance with its own retention policy.
10. Cookies
We Sweep uses a small number of cookies, all of which are strictly necessary for the operation of the Platform. We do not use any analytics, advertising, or tracking cookies.
| Cookie | Purpose | Duration |
|---|---|---|
sb-* | Supabase authentication session | Session |
wesweep_admin_last_activity | 2FA inactivity timeout (admin panel) | Session |
wesweep_admin_session_start | Maximum session length (admin panel) | 4 hours |
wesweep_platform_last_activity | 2FA inactivity timeout (platform admin) | Session |
wesweep_platform_session_start | Maximum session length (platform admin) | 4 hours |
wesweep_mfa_verified | 2FA verification timestamp (platform admin) | 4 hours |
wesweep_impersonation_auth | Impersonation session security (HttpOnly) | Session |
wesweep_impersonation | Impersonation display banner | Session |
The customer portal also uses your browser's local storage to hold your login session after you sign in with a magic link (removed when you log out). Because all cookies and local storage used by the Platform are strictly necessary for the provision of the service, consent is not required under the Privacy and Electronic Communications Regulations 2003 (PECR), Regulation 6.
For full details, see our Cookie Policy.
11. Security Measures
We Sweep implements technical and organisational measures (TOMs) including:
- Encryption in transit (TLS 1.2+) and at rest (AES‑256).
- Multi‑factor authentication for all administrative access.
- Role‑based access controls and principle of least privilege.
- Schema‑per‑tenant database isolation.
- Continuous monitoring, logging, and regular encrypted backups.
- Confidentiality obligations for all personnel with data access.
- Secure development lifecycle and vulnerability scanning.
12. Your Rights (Business Users)
As a Data Controller for Business User Data, We Sweep upholds your rights under the UK GDPR:
- Right of Access (Art. 15) — obtain a copy of your personal data.
- Right to Rectification (Art. 16) — correct inaccurate or incomplete data.
- Right to Erasure (Art. 17) — request deletion of your data.
- Right to Restriction (Art. 18) — restrict processing in certain circumstances.
- Right to Data Portability (Art. 20) — receive your data in a structured format.
- Right to Object (Art. 21) — object to processing based on legitimate interests.
To exercise any of these rights, contact: management@we-sweep.co.uk
We will respond to your request within one calendar month. This may be extended by two further months for complex requests, in which case we will inform you within the first month.
13. Customer Rights (Homeowners)
For Customer Data, We Sweep acts as a Processor. Homeowners must direct their data rights requests to the relevant Business User (the Controller). We Sweep will assist Controllers in fulfilling such requests in accordance with the DPA, including through our data export and erasure tools.
14. Automated Decision‑Making
We Sweep does not use automated decision‑making or profiling that produces legal or similarly significant effects on individuals. Rate limiting and security monitoring are automated but do not constitute automated individual decision‑making under Art. 22 of the UK GDPR.
15. Children's Data
The Platform is not intended for individuals under 18. We do not knowingly collect children's data. If we become aware that we have collected data from a child, we will delete it promptly.
16. Business Transfers
If We Sweep is involved in a merger, acquisition, or sale of assets, personal data may be transferred. We will provide at least 30 days' notice and ensure the successor entity is bound by equivalent data protection obligations.
17. Complaints
If you are unhappy with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Telephone: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We would appreciate the opportunity to address your concerns before you contact the ICO. Please contact us at management@we-sweep.co.uk in the first instance.
18. Changes to This Policy
We may update this Privacy Policy to reflect legal, technical, or operational changes. Material changes will be notified via email or dashboard notification. The "Last Updated" date at the top of this page indicates when the Policy was last revised.