Privacy Policy

Last updated: 13 August 2026

Who we are

Tradeable is an iOS app published by PeacoLabs Ltd. If you have any questions about this policy, contact us at mark@peacolabs.co.uk.

What data we collect, why, and our lawful basis

Under UK GDPR, we must have a lawful basis for processing personal data. “Contract” means the processing is necessary to provide the service you signed up for. “Legal obligation” means we are required to process the data by law (primarily HMRC Making Tax Digital regulations).

DataWhyLawful basis
Your name and email addressTo create and manage your accountContract
Customer names, phone numbers, email addresses, and postal addressesTo create quotes, jobs, and invoices on your behalfContract
Invoice, quote, and expense amounts and datesTo run your business records and submit quarterly updates to HMRCContract / Legal obligation
Expense receipt photosTo keep records for tax purposesLegal obligation
National Insurance numberRequired by HMRC to file Making Tax Digital submissionsLegal obligation
Device identifiers, IP address, screen dimensions, OS version, and device modelSent to HMRC as mandatory fraud prevention data with every Making Tax Digital API call. HMRC requires this under their Fraud Prevention Headers specification. This data is not stored by Tradeable.Legal obligation
HMRC OAuth tokensStored only on your device (Keychain) — never sent to our serversContract

We do not collect location data, browsing history, or any data for advertising purposes.

Where your data is stored

Your data is stored securely using Supabase (PostgreSQL database and file storage). Receipt images are stored in Supabase Storage. HMRC authentication tokens are stored exclusively in your device's Keychain and never leave your device.

Who we share your data with

  • HMRC — When you file a quarterly Making Tax Digital update or Final Declaration, your income and expense figures are submitted directly to HMRC via their API. HMRC also receives mandatory fraud prevention data (device identifiers, IP address, screen and OS information) with every API call, as required by their Fraud Prevention Headers specification.
  • Supabase — Our database and storage provider. Data is processed in accordance with their privacy policy.
  • Stripe — If you use Stripe payment collection (a premium feature), invoice payment data is processed by Stripe in accordance with their privacy policy.
  • Resend— Used to send transactional emails on your behalf (quote approvals, invoice delivery). Your customer's name and email address are passed to Resend solely to deliver these emails.
  • Twilio— Used to send SMS notifications on your behalf where applicable. Your customer's phone number is passed to Twilio solely to deliver these messages.
  • Apple— Standard iOS usage data as per Apple's platform policies.

We do not sell your data to any third party.

How long we keep your data

HMRC requires sole traders to keep tax records for at least 5 years after the 31 January submission deadline of the relevant tax year. We retain your financial records for this period to comply with that legal obligation. Your account data (name, email, customers, and contact details) is deleted within 30 days of an account deletion request.

Your rights under UK GDPR

You have the right to:

  • Accessthe personal data we hold about you
  • Correctinaccurate data
  • Deleteyour account and all associated data
  • Exportyour data in a portable format
  • Objectto how we process your data

To exercise any of these rights, email mark@peacolabs.co.uk. We will respond within 30 days. To delete your account, go to Me → Settings → Delete Account in the app, or email us and we will delete your account and all associated data within 30 days. Note that financial records subject to the 5-year HMRC retention obligation cannot be deleted before that period expires.

Complaints

If you believe we have handled your data incorrectly, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.

Changes to this policy

We will notify you of any material changes to this policy by updating the "Last updated" date above and, where appropriate, via in-app notification.