Privacy Policy

Version 2.4 · Effective: 31 August 2026. This policy covers the PayTrader platform (mobile app and payment service) and this website. It forms Part B of the PayTrader Terms of Service & Privacy Policy.

Part B — Privacy Policy

PayTrader Ltd ("we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, share, retain, and protect your personal information when you use the PayTrader Platform.

We are the data controller for personal data collected through the Platform. We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018).

16. Data controller and contact

Controller: PayTrader Ltd, a company registered in England and Wales (company number 17164786) with registered office at 9 The Readings, Chorleywood, Rickmansworth, England, WD3 5SY.

Data Protection Lead: Ryan Edwards. Privacy enquiries: privacy@paytrader.net. A statutory Data Protection Officer is not currently required under UK GDPR Art. 37 in respect of PayTrader's current scale and activities; we have appointed a Data Protection Lead with overall responsibility for our privacy programme. We keep this assessment under review and will appoint a DPO if and when the requirement is met.

ICO registration: PayTrader Ltd is registered with the Information Commissioner's Office under the Data Protection (Charges and Information) Regulations 2018, registration reference ZC224270.

17. Data we collect

Account data: Name, email address, mobile number, password (hashed and salted — never stored in plaintext), account type (Client or Tradesperson), date of registration.

Identity verification data: For Tradespeople, identity verification (KYC) is performed within our Payment Provider's stack via a hosted onboarding flow — on the launch rail by Trustap via its payment partner Stripe's hosted onboarding, and on the fallback rail by Ryft's hosted KYC flow. PayTrader holds zero KYC PII: no identity documents, no selfies, no biometric data ever reach PayTrader's systems. The data fields PayTrader stores in respect of KYC are the provider account reference (`providerAccountId`) and an enum-valued `kycStatus` (Verified / Required / Rejected / Failed) derived from provider webhook events. This minimal data set supports milestone funding gating and admin operational visibility. See clause 19 (Special category data) and clause 20 (Sub-processors).

Transaction data: Job details, Milestone descriptions and amounts, payment amounts, transaction references, timestamps, escrow hold periods, and release events. This data is retained in accordance with clause 23.

Communication data: Messages and any media (images, video) sent between Clients and Tradespeople through the in-app messaging system, and messages exchanged in the dispute-resolution channel. We may access these in the context of dispute resolution, fraud investigation, and complaint handling.

Proof of work data: Photographs and other media uploaded by Tradespeople and Clients as evidence of Milestone completion or as dispute evidence.

Device and technical data: IP address, device type, operating system, app version, and (where you have opted in) push notification token.

Payment data: Card and bank-account details are processed directly by our Payment Provider and are never stored on PayTrader's servers. We store only masked card details (e.g. last four digits) for display purposes.

18. How we use your data and lawful bases

We use your personal data for the following purposes, relying on the lawful bases set out below.

PurposeLawful basisNotes
Operate the Platform; process payments; manage Jobs and Milestones; facilitate communication between Clients and Tradespeople; deliver dispute resolution. UK GDPR Art. 6(1)(b) — performance of contract. Direct contractual relationship with you.
KYC identity verification of Tradespeople, including selfie-to-ID matching. UK GDPR Art. 6(1)(c) — legal obligation under MLR 2017 (channelled through our Payment Provider's regulated framework). For biometric data: UK GDPR Art. 9(2)(g) read with DPA 2018 Sch 1 Part 2 para 11 — preventing or detecting unlawful acts. See clause 19 for the Special Category Data position. Provision of identity verification data by Tradespeople is required by law; if not provided, you cannot use the Platform as a Tradesperson.
Transaction monitoring for fraud and AML compliance. UK GDPR Art. 6(1)(c) — legal obligation; UK GDPR Art. 6(1)(f) — legitimate interests in fraud prevention. Legitimate interest assessment recorded internally.
Service communications (transactional emails and push notifications about your account, Jobs, Milestones, payments, and disputes). UK GDPR Art. 6(1)(b) — performance of contract. Not marketing; PECR Reg. 22 does not apply. Certain payment, security, and account-status messages cannot be turned off.
Marketing emails about new features, partner offers, or platform updates. UK GDPR Art. 6(1)(a) — consent. Single, unbundled opt-in at signup. You can withdraw consent at any time using the unsubscribe link in any marketing email or in your in-app notification preferences.
Audit logs and record-keeping for regulatory and legal-claims defence purposes. UK GDPR Art. 6(1)(c) — legal obligation under FCA SYSC 9.1.1R, MLR 2017 Reg. 40, and Companies Act 2006 s. 388; UK GDPR Art. 6(1)(f) — legitimate interests; UK GDPR Art. 17(3)(e) — legal claims. Retention as set out at clause 23.
Limited automated processing in the optional AI quote-scanning feature (Tradespeople only). UK GDPR Art. 6(1)(b) — performance of contract; processed only if you opt in by uploading a quote. The AI scanner extracts text from a photographed paper quote and returns suggested Milestones for the Tradesperson to confirm. The output is non-binding and the Tradesperson reviews and edits before any Job is created. No automated decision with legal or similarly significant effects on you is made.

19. Special category data

Selfie-to-ID matching during KYC is processing of biometric data for the purpose of uniquely identifying a natural person under UK GDPR Art. 9(1). We rely on Art. 9(2)(g) (substantial public interest) read with DPA 2018 Sch 1 Part 2 para 11 (preventing or detecting unlawful acts) as the Article 9 condition. PayTrader maintains an "appropriate policy document" under DPA 2018 Sch 1 Part 4 covering this processing, available on request to privacy@paytrader.net.

The biometric matching itself is performed within the relevant Payment Provider's identity stack (see clause 20): on the launch rail, by Stripe as part of Trustap's seller-onboarding arrangement; on the fallback rail, by Ryft's identity-verification partner. In each case the verifying firm acts as a separate controller for the biometric inferences it produces, and the Payment Provider acts as a separate controller for the regulated KYC outcome it holds. PayTrader does not receive copies of identity documents or selfie images — those documents are held within the provider stack under the applicable regulated retention regime. PayTrader's records contain only the provider account reference (`providerAccountId`) and an enum-valued `kycStatus` derived from provider webhook events.

20. Data sharing and sub-processors

We share your personal data with the following categories of recipients to operate the Platform. A current named sub-processor list with hosting regions and roles is available at paytrader.net/sub-processors and is refreshed periodically.

ProviderServiceRegionRole
Trustap Ltd (Cork, Ireland) — launch-primary Payment ProviderPayment processing, merchant-of-record fund holding (escrow function), transaction lifecycle, buyer/seller transactional emails; seller KYC via its payment partner's hosted onboarding; PayTrader holds zero KYC PIIIreland / EEA (UK adequacy applies)Separate controller for the regulated records it holds (transactions, funds, KYC outcomes); recipient of transaction and party data passed by PayTrader to operate each Job
Stripe (Stripe Technology Europe Ltd, an e-money institution authorised by the Central Bank of Ireland, ref. C187865)The regulated e-money infrastructure underlying the Trustap rail: fund holding, card processing, and hosted seller identity verification within Trustap's stackIreland / EEA (UK adequacy applies)Separate controller for its regulated processing within the Trustap arrangement
Ryft Ltd (UK-incorporated, FCA-authorised electronic money institution) — fallback Payment ProviderPayment processing, escrow, KYC (via hosted onboarding flow) on Jobs routed to the fallback rail; PayTrader holds zero KYC PIIUKSeparate controller for regulated records (KYC, escrow, payment instructions); processor for transaction data passed by PayTrader for payment instructions
Ryft's identity-verification partner (bundled with the Ryft onboarding flow)Identity verification (selfie + ID matching) on the fallback railUK / EEA (region confirmed on the sub-processor list)Likely separate controller for biometric processing; contractually subject to UK GDPR safeguards
RailwayCloud hosting (database and application)EU (region pinned — see the sub-processor list for the named region)Processor
CloudinaryMedia storage (proof images, dispute evidence, chat media)Region confirmed on the sub-processor listProcessor
Resend (Resend, Inc.)Transactional and (where you opt in) marketing email deliveryUnited States (Resend, Inc.); outbound email dispatched via Amazon SES in the EU (eu-west-1, Ireland)Processor; transfer mechanism: SCCs with UK Addendum / UK IDTA; Resend Data Processing Addendum
ExpoPush notification dispatchUnited StatesProcessor; transfer mechanism: UK Extension to the EU–US Data Privacy Framework / Standard Contractual Clauses with UK Addendum
Anthropic (Claude API)AI quote-scanning feature (optional, Tradesperson-initiated)United StatesProcessor; transfer mechanism: Standard Contractual Clauses with UK Addendum
Sentry (Functional Software, Inc.)Crash diagnostics and performance monitoring for the mobile app (no analytics or advertising SDK is present in the app)United StatesProcessor; transfer mechanism: Standard Contractual Clauses with UK Addendum
Law enforcement, regulators, or courtsWhere required by law, including reports to the National Crime Agency under MLR 2017UKIndependent controller for any onward use

We do not sell personal data to third parties. We do not share personal data for advertising purposes.

21. International transfers

Where personal data is transferred to a country outside the United Kingdom that has not been the subject of a UK adequacy decision, we use approved safeguards including the International Data Transfer Agreement issued by the Information Commissioner, the UK Addendum to the EU Standard Contractual Clauses, or the UK Extension to the EU–US Data Privacy Framework where the recipient has self-certified. We carry out a Transfer Risk Assessment for each such transfer.

A current list of countries to which data may be transferred is available on request and at paytrader.net/sub-processors.

22. Your rights under UK GDPR

You have the following rights regarding your personal data:

To exercise any of these rights, contact us at privacy@paytrader.net. We will respond within one month under UK GDPR Art. 12(3); we may extend this by a further two months for complex requests, in which case we will tell you within the first month.

Where multiple retention periods apply to the same record, the longest applicable period prevails.

23. Data retention

The principal retention periods are:

Where multiple retention periods apply to the same record, the longest applicable period prevails. Detailed mechanics, including the anonymise-not-delete approach to user records, are set out in our User Deletion & Data Retention Design (available to regulators and on request).

24. Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, disclosure, or destruction. These include:

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the Information Commissioner's Office (ICO) as required by UK GDPR Art. 33–34.

25. Cookies and similar technologies

The PayTrader website (paytrader.net) uses cookies and similar storage technologies. The PayTrader mobile app uses native secure storage for authentication tokens and may use SDK identifiers and analytics events that read or write to device storage; PECR Reg. 6 applies to information stored on terminal equipment regardless of whether cookies are used.

We categorise our cookies and similar technologies as follows:

No non-essential cookies, SDKs, or storage technologies are accessed before you make a choice. We do not treat continued browsing or use as consent. You can change your choices at any time via the "Manage cookies" link in the website footer or in your in-app settings.

26. Marketing communications

We will only send you marketing communications by email if you have given us specific, unbundled consent at signup or in your in-app settings. The marketing-consent option is presented separately from the acceptance of these Terms; ticking it is optional.

Every marketing email includes a one-click unsubscribe link. You can also withdraw consent at any time in your in-app notification preferences. Withdrawing consent does not affect any service communications related to your account, Jobs, payments, security, or compliance, which we are required to send under UK GDPR Art. 6(1)(b) or Art. 6(1)(c).

27. Contact and complaints

Data controller: PayTrader Ltd, registered in England and Wales (company number 17164786). Registered office: 9 The Readings, Chorleywood, Rickmansworth, England, WD3 5SY.

Privacy enquiries: privacy@paytrader.net

General support: support@paytrader.net

If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by telephone on 0303 123 1113. We would, however, appreciate the opportunity to address your concerns first by email at privacy@paytrader.net.

28. This website (paytrader.net)

In addition to the platform processing described above, this website collects the following (carried forward from the site privacy notice effective 20 July 2026):

Netlify, Inc. hosts this site and stores waitlist form submissions (United States — safeguarded by standard contractual clauses with the UK addendum under Netlify's data processing terms). When we email the waitlist, we send via Resend, Inc. (United States — same safeguard class).