Privacy Policy
Privacy Policy
Version 2.2 · Plain-English version · Last updated 21 July 2026
This Privacy Policy explains how we keep your personal data (information about you) safe when you use Trusted Payments. It follows the UK’s main data protection laws: the UK GDPR and the Data Protection Act 2018 (updated by the Data (Use and Access) Act 2025). It covers everyone who works for us, including staff and contractors.
We may change this policy from time to time. Please check our App and website for the newest version of this Privacy Policy and our Terms of Use.
In this policy, “we”, “our” and “us” mean Trusted Payments Limited (“Trusted Payments”). “You” and “your” mean you — either a homeowner or a trade using our Service.
Our Service helps homeowners and trades manage home improvement projects with confidence. It gives you clear contracts, safe payments that are released in stages (called “milestone payments”), and money held back until the job is done properly (called “retention”). It also gives you a warranty backed by insurance, and fair help to settle any disagreements through the Ombudsman — an independent service that sorts out disputes fairly. We act on your side, as the consumer (the homeowner).
You use our Service through our mobile App (for iPhone and Android) if you’re a homeowner, and through our web App, email and WhatsApp if you’re a trade. By using our products, you agree to this Privacy Policy. Please read it together with our Terms of Use. If you think something is wrong, or you’d like something explained, email us at [email protected].
Trusted Payments Limited is a company registered in England and Wales. Our company number is 14045911. Our office is at Premier House, 1st Floor, 1-5 Argyle Way, Stevenage, SG1 2AD. Our ICO registration number is ZC096823.
Key Takeaways
- We keep your data safe, and we’re honest about how we use it. We have a security certificate called Cyber Essentials.
- We use your data to set up and run your home improvement project. That means writing the contract, taking and holding your payments, holding retention money, giving you your warranty, helping you, and sorting out any disagreements.
- Payments are handled by our payment company, Stripe. Your card details are turned into a secret code and are never stored by us as plain text, so no one can read them.
- Retention and milestone money is kept in a separate “Client Protection” account.
- To run the Service, we share some data with a few trusted groups: the other person on your project (your homeowner or tradesperson), Stripe, the Ombudsman, the insurance company behind the warranty, and the organisation that checks the trade. They all have to keep your data safe.
- We will never sell your data. We will never give it to other companies for their own advertising unless you say it’s okay.
- If there’s a problem with your building project, a fair, independent service called the Dispute Resolution Ombudsman helps sort it out. If your complaint is about how we handle your data, we deal with that separately (see below).
- You have rights over your data. You can see it, correct it, ask us to delete it, ask us to pause using it, tell us to stop using it, and ask us to move it.
- We answer to the UK’s data protection watchdog, the Information Commissioner’s Office (the “ICO”). If you’re not happy with how we handle your data, you can ask the ICO to look into it and make a decision.
Scope of this Privacy Policy
This policy covers all the personal data we use through our Service. It explains how we collect, use, store and protect your data, and what your rights are.
Personal data is any information about a real, living person — both facts and opinions. It doesn’t have to be private or sensitive; it can be as simple as a name and address. It can be kept on a computer or on paper. We always handle it in line with your rights.
Who this Policy Covers
Two groups of people use our Service, and this policy covers both:
- Homeowners (consumers) – people who use the App to set up and pay for a home improvement project, and to get the warranty and dispute resolution.
- Trades (contractors) – the businesses and people who do the work, get paid in stages, and use the web App, email and WhatsApp to manage their projects.
If a tradesperson works on their own (a sole trader) or can be identified as a person, their information counts as personal data too, and we protect it just like a homeowner’s.
Your Data
To run the Service, we use your data. Some data is called “Special Category Data”. This is extra-private information, such as: your race or ethnic background; your political views; your religion or beliefs; whether you’re in a trade union; genetic or biometric data (like fingerprints); health information; and information about your sex life or sexual orientation. We don’t expect to hold any of this unless you choose to give it to us. If you do, we only use it because you clearly said yes (this is called your “explicit consent”), or where another data protection rule allows it (see “How and Why We Use Your Data” below).
Sometimes, for a home improvement project, you might tell us — or we might need to write down — that you or someone in your home is vulnerable or needs extra support. For example, because of a health condition, a disability, or a personal situation that affects how the work is done. If this includes Special Category Data, we take extra care with it. We keep it in a secret code (encrypted), only use it to keep your project safe, and delete it as soon as we don’t need it any more.
The Data We Collect
From homeowners
- Your name and contact details – your name, email, phone number, and the project or property address.
- Project information – details of the work, your contract, quotes, milestones, photos, snagging (small fixes), and when you approve money to be paid out.
- Payment information – the card or Open Banking details you use to pay for your project. This is turned into a secret code and handled by Stripe. We don’t keep your full card number.
- Messages – messages in the App, emails, and any help you ask us for.
- Support and vulnerability information – anything you choose to share so your project can be done safely (see “Your Data” above).
From trades
- Your name and contact details – your name, business name, email, phone number and WhatsApp number.
- Business and payment details – the bank or payout details you use to get paid in stages (handled by Stripe), plus business and tax numbers.
- Membership and checks – confirmation from your membership or certification scheme that you’ve been checked and are allowed to use the Service.
- Project information – the projects you manage, milestones, documents, and your messages with homeowners.
- Messages – emails, WhatsApp messages and web App messages about your projects.
From everyone (operational data)
When you use our Service, we might also record your device type, your operating system version, the App version, your browser and its version, your rough location, and session information (details about your visit). We collect this as a normal part of running the Service and keeping your session working, and to help you and fix problems if something goes wrong.
Financial and Payment Data
We take the safety of your money and payment details very seriously.
- Payments are made by card or Open Banking, and are handled by Stripe. Stripe meets a strict payment security standard called PCI-DSS.
- Your card details are turned into a secret code (tokenised) and are never stored by us as plain text. We don’t keep your full card number.
- Milestone and retention money is kept in a client protection account. We don’t hold this money and we can’t get to it. It’s only paid to the trade when a milestone is approved, or when a dispute is settled.
- We keep records of your payments, milestones and money released, so we can run your project and follow the law on tax, accounts and stopping fraud.
How We Collect Your Data
We collect your data in these ways:
- Directly from you – when you sign up, set up or manage a project, pay or get paid, or contact us.
- Through a partner – when you come to us through a membership or certification group (for example TrustMark, Book a Builder or Buy with Confidence). If a partner fills in your details for you, they do that under their own privacy policy. We’ll show you this Privacy Policy before your project is set up.
- Automatically – through the usage information described above.
How and Why We Use Your Data
We only use your data when the law lets us. Here are the reasons we’re allowed to use it:
- To carry out our contract with you – to set up your project, write the contract, take and hold your milestone payments, hold retention money, give you your warranty, sort out disputes, and help you.
- Because the law says we must – to follow rules on stopping money laundering and fraud, on tax and accounts, and other legal rules.
- For our “legitimate interests” – this means sensible reasons like keeping the Service safe, stopping fraud, making the Service better, and talking to you about your project. When we use this reason, we check it’s fair to you first. A few limited things — like stopping fraud or crime, and sharing data with regulators when we have to — are “recognised legitimate interests”, which means we don’t need to do that fairness check.
- Because you said yes (consent) – for things like optional marketing and non-essential cookies. You can change your mind at any time.
Special Category Data (extra-private information). If we use extra-private information (for example, about a health condition, disability or need for extra support that you choose to share so your project can be done safely), we only do this because you clearly said yes (your “explicit consent” under a rule called Article 9(2)(a)). If we ever use another rule for this kind of information, we follow Article 9 of the UK GDPR and Schedule 1 of the Data Protection Act 2018, and we keep a special written policy where one is needed. You can change your mind at any time, but this might affect how safely we can do your project.
Automated decisions. We don’t make decisions that have a big or legal effect on you using computers alone. If we use automated tools (for example, to help spot fraud), a real person is involved in any decision that would seriously affect you — and you can ask us to explain it.
Who We Share Your Data With
We only share your data when it’s needed to run the Service, and only with people who must keep it private and safe. These are:
- The other person on your project — your homeowner or your trade — so the project can be set up, done and paid for.
- Stripe, our payment company, to handle payments safely.
- The Dispute Resolution Ombudsman, which settles disputes fairly and helps with warranty claims.
- The warranty insurance company (the insurer behind your warranty), if you make a warranty claim.
- Membership and certification groups (like TrustMark, Book a Builder and Buy with Confidence), to check a trade has been vetted and is allowed to use the Service.
- Companies that help us run the Service — for example, companies that host our systems, send messages, or do analytics. They follow our instructions under written contracts that protect your data.
- Authorities, regulators and advisers, when the law says we must share data, or to deal with legal claims.
When you use our Service, some of your information may be shared with chosen suppliers who do jobs for us. We only work with them if they keep your data private and safe, use it only for the job we ask, and follow this Privacy Policy.
Communications
How we contact you depends on whether you’re a homeowner or a trade:
- Homeowners — mainly through the App (notifications and messages) and by email, about things like approving milestones, payments and help.
- Trades — by email, WhatsApp and the web App, for organising projects, notifications and help.
WhatsApp is run by Meta and has its own rules and privacy policy. We only use WhatsApp to organise projects and send notifications. We don’t ask for private personal information or full payment details on WhatsApp. Messages about your project are saved in our systems and CRM (the software we use to keep track of customers) so we can help you. Once your project and any case are closed, we delete these messages in line with our timescales.
Marketing
We won’t contact you with marketing unless you say it’s okay. If a partner shows you offers, those come under the partner’s own privacy policy, not this one. We don’t give your personal information to other companies for their own advertising unless you say yes, and you can opt out of our marketing at any time.
Cookies
Cookies are small files that a website saves on your device to help it work and remember things. We use cookies on our website and web App to make them work and to see how they’re used. You can say no to non-essential cookies, accept only the essential ones, or accept all of them.
Non-essential cookies (for example, ones that count visits or do analytics) are only used if you say yes. You can change your cookie choices at any time using the cookie settings on our website and web App. For more, see our Cookies Policy.
Third Party Links
Our Service might link to other websites or apps that we don’t run, including our partners’. We’re not responsible for how those other sites handle your data or what’s on them, so visiting them is at your own risk.
Security of Your Data
We protect your data with the right technical and practical measures, including:
- Cyber Essentials certification – a security standard that covers firewalls, safe settings, keeping software updated, controlling who can get in, and blocking malware (harmful software).
- Encryption – turning your personal and payment data into a secret code, both when it’s sent and when it’s stored, plus turning card data into a token through Stripe.
- Strict access rules – including extra login checks (multi-factor authentication) and only letting people see data if they really need to.
- A “Bring Your Own Device” policy – rules for using a personal phone or computer to get to Trusted Payments information.
- Staff training and checks – plus a plan for handling any security problem quickly, so it’s spotted, stopped and reported.
Our developers can’t get into the live database. Testing is done on a separate practice system. We regularly check the list of people who can see data.
Data Protection Responsibilities and Training
Everyone who works for us — full-time or temporary — and all our suppliers, including anyone who handles data for us, must follow our data protection rules. These rules help us follow the UK GDPR. We check and update them regularly to keep them current.
All staff learn our data protection rules when they join and through ongoing training. No one — staff, supplier or data handler — can see data unless they need to, and we regularly check the list of who can.
Transfers of Data Outside the UK and EEA
We try to keep your data inside the UK and the European Economic Area (the EEA — the EU countries plus a few others). Some of our providers, like Stripe, might handle data in other countries. If your data goes outside the UK, we make sure it’s still well protected — for example, because the other country has strong data protection rules (checked using a test from the Data (Use and Access) Act 2025), or because we use an approved safeguard, like the International Data Transfer Agreement or the UK Addendum to the European Commission’s Standard Contractual Clauses.
Data Retention
We only keep your data for as long as we need it, and to follow the law on tax, accounts and stopping fraud. In general:
- Project, contract, payment and warranty records – kept for the life of the project, and for as long afterwards as we need to run the warranty, settle any dispute, and meet our legal and money rules.
- Support messages – deleted once your project and any case are closed.
- Non-personal and grouped-together data (like service statistics) – may be kept for analysis.
You can ask us to delete your data at any time — just email [email protected]. If you contact us after your data has been deleted, we might ask you for some details to check who you are and find your project before we can help.
Your Data Protection Rights
Under UK data protection law, you have several rights. Which ones you have depends on why we’re using your data.
Right to see your data (a “Subject Access Request”, or “SAR”)
You can ask us to tell you whether we’re using your data, and to give you a copy of it, for free. We’ll check who you are first. Then we’ll reply within one month of confirming who you are and getting anything we need to find your data. If your request is complicated, or you send us several, we might take up to two extra months — and we’ll tell you if we do, and why.
Right to be told
This policy tells you what you need to know about how we collect and use your data.
Right to fix mistakes
You can have your data corrected if it’s wrong or incomplete.
Right to be deleted
In some cases, you can ask us to delete the data we hold about you.
Right to pause or say no
You can ask us to pause using your data, for example while we sort out a question. If we’re using your data because you said yes, you can change your mind at any time. You can also tell us to stop using your data, though this might affect the Service we can give you.
Right to move your data
You can ask us to send a copy of your data to you or to another company, in a format a computer can read.
Right to complain
You can complain to us about how we handle your data, and take it to the Information Commissioner’s Office (the “ICO”) if you’re still unhappy. There’s more on how to do this in “Complaints and Issue Procedure” below. Whenever we reply to you about one of your rights, we’ll also remind you that you can complain.
Contacting Us
When you contact us by email, social media or another way, we save some information about it — usually your name, email or social media handle, and our messages with you — so we can sort out your question. We do this because of our contract with you, and because it helps us give you a good service.
Complaints and Issue Procedure
You can complain to us if you think we haven’t handled your data properly. You can make a data protection complaint in any of these ways:
- fill in the data protection complaint form on our website;
- email our Data Protection Officer at [email protected], or email [email protected]; or
- write to us at our office: Premier House, 1st Floor, 1-5 Argyle Way, Stevenage, SG1 2AD.
When we get your complaint, we will:
- let you know we’ve got it within 30 days;
- look into it and reply as quickly as we can, keeping you updated on how it’s going and how long it might take; and
- tell you the outcome, and what we’ve done, as quickly as we can.
We keep a record of the complaints we get and how we deal with them.
If you don’t think we’ve dealt with your complaint fully, you can take it to our senior managers at [email protected].
If you’re still not happy, you can complain to the Information Commissioner’s Office (the “ICO”), the UK’s independent data protection watchdog, for an independent decision. You can contact them at ico.org.uk. We’d really like the chance to fix things first, though, before you go to the ICO.
One more thing: if your complaint is about your home improvement project (not about your data), that’s handled by the fair, independent Dispute Resolution Ombudsman — not through this process.