Skip to content

    Privacy Policy

    1. Information We Collect

    We collect information you provide when creating an account (name, email, business details) and data you enter into the platform (customers, quotes, invoices, etc.).

    2. How We Use Your Information

    Your data is used solely to provide the ServicePay platform. We do not sell your data to third parties or use it for advertising.

    3. Payment Data

    If you enable ServicePay Payments to accept card payments from your customers, the following applies:

    3.1 What We Process

    ServicePay processes transaction metadata including invoice amounts, payout amounts, platform fees, and settlement dates. This data is necessary to calculate fees, schedule payouts, and provide you with transaction reporting.

    3.2 What We Do Not Process

    ServicePay never collects, stores, or has access to full card numbers, CVVs, or sensitive cardholder authentication data. All card data is collected and processed exclusively by Stripe Payments UK Ltd in a PCI DSS Level 1 certified environment.

    3.3 Bank Account Information

    When you onboard to ServicePay Payments, your bank details (sort code and account number) are collected directly by Stripe via their secure onboarding flow. ServicePay stores only the last 4 digits of your account number and last 2 digits of your sort code for display purposes.

    3.4 Identity Verification

    Stripe may collect identity documents (passport, driving licence) as part of their regulatory Know Your Customer (KYC) obligations. This data is processed by Stripe under their own privacy policy and is not shared with ServicePay.

    3.5 Legal Basis

    We process payment-related data under Article 6(1)(b) GDPR — performance of a contract (providing the ServicePay Payments service you opted into) and Article 6(1)(f) — legitimate interests (fraud prevention and platform security).

    3.6 Retention

    Transaction records are retained for 7 years from the transaction date to comply with UK tax and accounting requirements (HMRC obligations). You may request deletion of your account at any time, but transaction records required for regulatory compliance will be retained for the statutory period.

    4. Data Storage & Security

    Your data is stored securely using industry-standard encryption. Access is restricted to authorised personnel only. Payment-adjacent data is encrypted at rest and in transit using AES-256 and TLS 1.2+.

    5. Data Sharing & Third Parties

    We share data only with the following categories of processor, and only as necessary to provide the Service:

    • Stripe Payments UK Ltd — card payment processing, identity verification, and bank payouts (FCA-authorised, FRN 900461)
    • Infrastructure providers — cloud hosting and database services, under strict data processing agreements

    We do not share your data with advertisers, data brokers, or any other third party for marketing purposes.

    6. Your Rights

    Under UK GDPR, you have the right to access, rectify, erase, restrict processing of, and port your personal data. You can request a copy of your data, ask us to correct inaccurate data, or delete your account and all associated data at any time by contacting us. Note that statutory retention periods (e.g., 7 years for financial records) may apply to certain data.

    7. Cookies

    We use essential cookies for authentication and session management. We do not use tracking or advertising cookies.

    8. Contact

    The data controller for ServicePay is Towpath Digital Ltd (Company No. 16913912), a company registered in England & Wales. For privacy-related enquiries, including data subject access requests, contact us at support@servicepay.uk.