# Privacy Policy

**Last updated: 29 August 2026**

This Privacy Policy explains how **Mike Brown trading as ServDiary** (“**ServDiary**”, “**we**”, “**us**”, “**our**”) uses personal data when you visit our website, create an account, or use the ServDiary web app, APIs, or Android and iOS apps (together, the “**Service**”).

We are a data controller for personal data we collect about you as a visitor, enquirer, or ServDiary account holder. When a home service business stores their own customers’ and staff details in ServDiary, **that business is the controller** of that information and we act as their **processor**. Section 9 explains the difference.

This policy is intended to meet the UK GDPR and the Data Protection Act 2018. It also covers electronic marketing and cookies under the Privacy and Electronic Communications Regulations (PECR).

## 1. Who we are and how to contact us

**Data controller (for ServDiary account, website, and enquiry data):**  
Mike Brown trading as ServDiary

**Data protection contact / Data Protection Officer:**  
Mike Brown  
38 Carleton Street  
Morecambe  
LA4 4NY  
United Kingdom  

Email: [dpo@2880.co.uk](mailto:dpo@2880.co.uk)

If you are a customer of a business that uses ServDiary (for example you booked a cleaning visit through their portal), please contact **that business** first. They decide why your details are held. We will support them where we are required to as their processor.

## 2. Personal data we collect

### 2.1 Information you give us

- **Account and team data:** name, email address, password (stored hashed, not in plain text), team name, role, profile details you choose to add, and two-factor authentication settings if you enable them.
- **Billing contact:** the team owner’s name and email are sent to Stripe as the customer on the subscription. We do not store full card numbers; Stripe handles card details.
- **Marketing enquiries:** name, email, company, phone, and message from the public contact form.
- **Support correspondence:** emails or messages you send us.

### 2.2 Information generated when you use the Service

- **Usage and security logs:** IP address, device and browser type, timestamps, pages or API routes requested, and similar diagnostic data.
- **Session data:** cookies needed to keep you signed in and to protect against cross-site request forgery (see Section 8).
- **Mobile apps:** device name you supply at login, and authentication tokens stored on the device.
- **Staff check-in:** GPS latitude and longitude from a staff member’s device when they check in at an appointment, plus the calculated distance from the service site and the geofence radius in force at that time.

### 2.3 Customer Data you store in the Service (processor)

If you run a team workspace, you may store personal data about your own customers, contacts, staff, and providers, including:

- names, emails, phone numbers, and notes;
- billing and service addresses, postcodes, and map coordinates derived from postcodes;
- property details (for example bedrooms, bathrooms, square footage, access notes);
- jobs, appointments, quotes, invoices, payments, and messages;
- portal login accounts you create for customers or providers.

We process that Customer Data on your instructions to provide the Service. You are responsible for telling those people how you use their data.

### 2.4 Information from third parties

- **Invitations and portal accounts:** a team owner may give us a colleague’s, customer’s, or provider’s email so we can create or attach a login.
- **QuickBooks Online:** if you connect a team, Intuit may send us payment notifications that we match to invoices.
- **Postcode lookup:** when you save a service-site postcode we send that postcode to the Order Market Areas service to obtain latitude and longitude.

We do not buy marketing lists about you.

## 3. How we use personal data and our lawful bases

- **Provide the Service** (accounts, authentication, team workspaces, subscription billing, transactional email such as welcome, password, invitations, and invoice copies) — contract (UK GDPR Art 6(1)(b)).
- **Operate Customer Data on your behalf** (CRM, jobs, invoices, messages, SMS via ClickSend, QuickBooks when you connect it) — we act as processor on your instructions; you need your own lawful basis.
- **On-site check-in** (record that assigned staff were within your geofence) — processor on your instructions.
- **Security and abuse prevention** (logs, rate limiting, investigating misuse) — legitimate interests (Art 6(1)(f)) in keeping the Service and other users safe.
- **Enquiries** (contact form) — legitimate interests, or steps toward a contract if you are asking to use ServDiary.
- **Legal obligations** (tax, accounting, lawful requests) — legal obligation (Art 6(1)(c)).
- **Product improvement** (aggregated or de-identified diagnostics) — legitimate interests in improving reliability.

We do not use your data for automated decisions that produce legal or similarly significant effects.

We do not send electronic marketing unless you would reasonably expect it in the context of an enquiry or we have a PECR-compliant basis. You can opt out of optional marketing by emailing [dpo@2880.co.uk](mailto:dpo@2880.co.uk). Transactional messages about your account or jobs are not marketing.

## 4. Who we share data with

We do not sell personal data.

We share data with:

- **Your team members and portal users**, according to the roles you set (for example staff see assigned jobs; customer portal users see their own jobs).
- **Service providers** who host or help us run ServDiary (UK hosting and infrastructure, transactional email).
- **Stripe**, to take payment, run the 30-day trial, and provide the customer billing portal. Stripe is the payment processor; we receive subscription status, a Stripe customer identifier, and limited payment-method metadata (for example card brand and last four digits).
- **Order Market**, for postcode-to-coordinate lookup of service sites you save.
- **Order Market**, for postcode-to-coordinate lookup of service sites you save.
- **Intuit (QuickBooks Online)**, only if a team owner connects QuickBooks — invoice and related customer fields needed to create and send invoices, and payment webhook data coming back.
- **ClickSend**, for service SMS when you enable appointment templates — we send the recipient phone number and message body to ClickSend.
- **Professional advisers** (for example accountants or lawyers) under confidentiality, where needed.
- **Authorities**, if required by law or to protect rights, safety, or the Service.

Everyone who processes personal data for us is required to treat it appropriately.

## 5. International transfers

Our primary hosting is in the United Kingdom.

Some providers you choose to use may process data outside the UK. In particular, **Intuit / QuickBooks Online** may process data in the United States and other countries. **Stripe** may also process payment data outside the UK (including the United States) under its own terms and transfer mechanisms. **ClickSend** may process SMS content and recipient numbers outside the UK under its own terms. Where we transfer personal data from the UK to a country without an adequacy decision, we use a lawful mechanism such as the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, unless another permitted ground applies.

Optional integrations you connect (including QuickBooks) also involve transfers under that provider’s terms. You should review those terms before enabling the integration.

## 6. How long we keep data

- **Account data:** for as long as the account remains open, then deleted or anonymised within a reasonable period after closure, unless we must keep a record (for example to show we deleted an account or to deal with a dispute).
- **Customer Data in a team:** until you delete it, or the team/account is deleted, subject to backup rotation.
- **Contact-form submissions:** currently written to application logs so we can reply; we keep them no longer than needed to handle the enquiry and for a limited follow-up period (typically up to 24 months), unless you ask us to delete them sooner and we have no overriding need to retain them.
- **Security logs:** for a limited operational period (typically up to 12 months) unless needed longer to investigate an incident.
- **Check-in coordinates:** stored with the appointment audit record until that record is deleted with the related job data.
- **SMS dispatch records:** kept as an audit of queued/sent/failed messages until you or we delete the related team data.

## 7. Security

We use measures appropriate to a small business SaaS product, including:

- HTTPS in production;
- hashed passwords;
- session and API-token authentication (Sanctum for mobile);
- team-scoped access control and role permissions;
- encryption of QuickBooks access tokens at rest.

No method of transmission or storage is completely secure. Please use a strong unique password and enable two-factor authentication if you can.

If you believe there has been a security incident affecting ServDiary, email [dpo@2880.co.uk](mailto:dpo@2880.co.uk) promptly.

## 8. Cookies

We use **strictly necessary** cookies to:

- keep you signed in (session cookie);
- protect forms from cross-site request forgery (XSRF-TOKEN).

These cookies are required for the Service to work. Under PECR they do not need a consent banner.

We do not currently set analytics or advertising cookies. If we add them later, we will update this policy and, where required, ask for consent.

You can block cookies in your browser, but you will not be able to stay signed in.

## 9. Business customers using ServDiary (controllers)

If you store other people’s personal data in ServDiary, you are the controller. You must:

- have a lawful basis and privacy information for your customers and staff;
- only enter data you are entitled to process;
- handle data-subject requests about Customer Data (we will assist — see the Terms of Service, data processing section);
- configure SMS, QuickBooks, and portal accounts in line with your own policies.

People whose data you store should contact **you**, not ServDiary, to exercise their rights, unless they believe you are not responding and they wish to contact us or the ICO.

## 10. Your rights (when we are the controller)

Where we are the controller, you have the right to:

- **access** your personal data;
- **rectify** inaccurate data;
- **erase** data in certain circumstances;
- **restrict** processing in certain circumstances;
- **object** to processing based on legitimate interests;
- **data portability** for data you provided, where processing is based on contract and is automated;
- **withdraw consent** where we rely on consent (this does not affect processing already carried out).

To exercise these rights, email [dpo@2880.co.uk](mailto:dpo@2880.co.uk) or write to the address in Section 1. We may need to verify your identity.

You also have the right to complain to the UK regulator:

**Information Commissioner’s Office (ICO)**  
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF  
[https://ico.org.uk](https://ico.org.uk)  
Helpline: 0303 123 1113

We would appreciate the chance to resolve your concern first.

Account holders can also update many profile details in the Service and delete their account from account settings.

## 11. Children

The Service is aimed at businesses and adults. We do not knowingly collect personal data from children under 18. If you believe we have, please contact us and we will delete it.

## 12. Changes to this policy

We may update this Privacy Policy. The “Last updated” date will change, and we will post the new version at this URL. If changes are material, we will take reasonable steps to notify account holders.

## 13. Contact

For privacy questions or requests:

**Mike Brown** (Data Protection Officer)  
38 Carleton Street  
Morecambe  
LA4 4NY  
United Kingdom  

[dpo@2880.co.uk](mailto:dpo@2880.co.uk)
