Privacy Policy
1. Information We Collect
We collect information you provide when creating an account (name, email, business details) and data you enter into the platform (customers, quotes, invoices, etc.).
2. How We Use Your Information
Your data is used solely to provide the ServicePay platform. We do not sell your data to third parties or use it for advertising.
3. Payment Data
If you enable ServicePay Payments to accept card payments from your customers, the following applies:
3.1 What We Process
ServicePay processes transaction metadata including invoice amounts, payout amounts, platform fees, and settlement dates. This data is necessary to calculate fees, schedule payouts, and provide you with transaction reporting.
3.2 What We Do Not Process
ServicePay never collects, stores, or has access to full card numbers, CVVs, or sensitive cardholder authentication data. All card data is collected and processed exclusively by Stripe Payments UK Ltd in a PCI DSS Level 1 certified environment.
3.3 Bank Account Information
When you onboard to ServicePay Payments, your bank details (sort code and account number) are collected directly by Stripe via their secure onboarding flow. ServicePay stores only the last 4 digits of your account number and last 2 digits of your sort code for display purposes.
3.4 Identity Verification
Stripe may collect identity documents (passport, driving licence) as part of their regulatory Know Your Customer (KYC) obligations. This data is processed by Stripe under their own privacy policy and is not shared with ServicePay.
3.5 Legal Basis
We process payment-related data under Article 6(1)(b) GDPR — performance of a contract (providing the ServicePay Payments service you opted into) and Article 6(1)(f) — legitimate interests (fraud prevention and platform security).
3.6 Retention
Transaction records are retained for 7 years from the transaction date to comply with UK tax and accounting requirements (HMRC obligations). You may request deletion of your account at any time, but transaction records required for regulatory compliance will be retained for the statutory period.
4. Data Storage & Security
Your data is stored securely using industry-standard encryption. Access is restricted to authorised personnel only. Payment-adjacent data is encrypted at rest and in transit using AES-256 and TLS 1.2+.
6. Your Rights
Under UK GDPR, you have the right to access, rectify, erase, restrict processing of, and port your personal data. You can request a copy of your data, ask us to correct inaccurate data, or delete your account and all associated data at any time by contacting us. Note that statutory retention periods (e.g., 7 years for financial records) may apply to certain data.
8. Contact
The data controller for ServicePay is Towpath Digital Ltd (Company No. 16913912), a company registered in England & Wales. For privacy-related enquiries, including data subject access requests, contact us at support@servicepay.uk.