Data and privacy
A plain-English summary of what personal data TradesOps holds, who processes it, and how long it's kept. The definitive documents are the Privacy Notice and the Data Processing Addendum — this article is a friendlier read but not legally binding on its own.
About you (the trader)
TradesOps is the data controller of your personal data.
- Your name, email address, phone number (optional), business address details.
- Your Telegram username and chat ID (once paired).
- Your Stripe account ID (if you connect Stripe — we don't hold your bank details, Stripe does).
- Your Google Calendar refresh token (if you connect Google) — kept server-side only, never in the browser.
- Server logs and error reports, which may include your IP address at the time of the request.
Lawful basis: performance of a contract (running the service for you).
About your customers
For your customers' personal data, you are the data controller and TradesOps is the data processor. The Data Processing Addendum is the Article 28 processor contract that governs this relationship.
TradesOps processes:
- Their name, email address, phone number (if they gave it).
- Postcode / town / free-text enquiry content.
- Quote and invoice details.
- Booking date and duration.
We don't process:
- Card numbers (Stripe does, in a PCI-compliant environment).
- Special category data (health, religion, etc.) — the terms explicitly ban you from putting this into the platform.
- More than we need to run the service.
Who else sees your data
The sub-processors we use to run TradesOps, all under proper processor contracts:
- Supabase — hosted Postgres database and authentication (EU region).
- Vercel — application hosting.
- Cloudflare — DNS and edge protection for tradesops.uk.
- Anthropic — the large language model that drafts customer content.
- Resend — outbound email delivery.
- Stripe — subscription billing and (if you enable it) customer card payments.
- Telegram — messaging platform for the bot (only your chat ID, not your customers').
The full list with reasons is in the Data Processing Addendum.
Anthropic and your data
IntelliQuote drafts everything customer-facing. That means:
- The customer's raw enquiry text is sent to Anthropic to produce a summary.
- Your site-visit notes are sent to Anthropic to draft a quote.
- Your reply text (work date, general chat) is sent to Anthropic to parse dates or draft replies.
Anthropic does not train its models on API data by default — TradesOps uses standard API access.
Retention
- Your account data: kept while your subscription is active, plus 30 days after cancellation for export.
- Billing records: 7 years, per UK tax record-keeping.
- Server logs: 90 days.
- Backup snapshots: 30 days after the record's deletion date.
Your rights
You have UK GDPR rights to access, rectify, delete, restrict, port, and object to processing of your data. Contact legal@tradesops.uk and we respond within one month.
Same for your customers — but they should contact you (as their data controller), not us. If they contact us directly, we forward the request to you.
Cookies
TradesOps uses only strictly necessary cookies — the Supabase auth cookie so you stay signed in, and short-lived form / webhook verification tokens. No advertising, no analytics, no marketing cookies. That's why there's no cookie banner.
