Privacy Policy
This policy explains what personal data we collect, why we use it, and your rights under UK GDPR.
Last updated: August 2026
1. Who is responsible
The data controller for your StartMyPatch account is StartMyPatch (26, Heather Crescent, Douglas, IM2 1BB). Privacy requests: hello@startmypatch.com.
When you collect client or lead details through your public site, you are the controller of that customer data and we act as your processor.
2. What we collect
Account: email address, name, postcode, starting budget and goal (entered at onboarding), authentication identifiers.
Business / site content: business name, services, photos, copy, calculator settings, marketing pixel IDs you paste, bank pay-in details you choose to store for invoices.
Client records you store: names, contact details, addresses, quotes, booking times, invoice history and message logs for your customers — visible to you as the site owner.
Usage & diagnostics: with consent, product analytics (see below); technical logs and crash reports needed to keep the service reliable.
Billing: subscription status and Paddle customer / subscription identifiers. Card numbers are handled entirely by Paddle and never stored by us.
3. Lawful bases
We process personal data under these UK GDPR bases:
- Contract — to provide the account, website, bookings, invoices and subscription you signed up for;
- Legitimate interests — to secure the platform, prevent abuse, and improve features (balanced against your rights);
- Consent — for optional analytics cookies and any marketing communications you opt into;
- Legal obligation — where we must retain records (for example tax or accounting rules applying to us or Paddle).
4. Processors and services we use
We use these processors to run StartMyPatch:
- Supabase — authentication, database and file storage;
- Vercel — application hosting and edge delivery;
- Paddle — merchant of record for platform subscription billing;
- Resend — transactional email (confirmations, invoices, review requests);
- Google Maps / Places — address lookup and area measuring on certain calculators;
- Meta pixel — only on your public site when you connect your own Pixel ID / Conversions API token; separately, our own marketing pages use our own Meta pixel after you accept analytics cookies (never on customer sites);
- PostHog — product analytics (EU cloud), only after you accept analytics cookies;
- Sentry — error monitoring (no intentional personal data in crash reports);
- Twilio — SMS, only when that feature is enabled for your account.
5. Cookies
Essential cookies keep you signed in and help prevent scan abuse (an anonymous device id). Analytics cookies (PostHog and our Meta pixel) run only if you tap "Accept" on the consent banner — "Essential only" is a first-class choice and the product still works.
First-party analytics: we also keep a cookieless, privacy-preserving count of page visits on our own pages (never on customer sites). We do not store IP addresses — visits are recorded against a salted hash that changes every day, so it cannot track you across days or across other websites. No cross-site tracking, no data sold. These records are deleted after 180 days.
6. Retention
We keep account and business data while your account is active. After you delete your account we remove associated records from our systems promptly, except where we must retain limited information for legal, security or accounting purposes. Message and invoice records you generated may be retained for a short wind-down period before permanent deletion. Paddle retains its own billing records under its policies.
7. Your rights
Under UK GDPR you can request:
- access to the personal data we hold about you;
- correction of inaccurate data;
- deletion (including via Profile → Delete my account);
- export / portability (Profile → Download my data);
- restriction of, or objection to, certain processing;
- withdrawal of consent where processing is consent-based.
Email hello@startmypatch.com for privacy requests. You may also complain to the UK Information Commissioner's Office (ICO).
8. International transfers
We prefer EU/UK-hosted processors where practical. Where data is transferred outside the UK/EEA, we rely on appropriate safeguards (such as standard contractual clauses) required by UK GDPR.
9. Changes
We may update this policy from time to time. The "Last updated" date at the top reflects the current version. Material changes will be communicated in the app or by email where appropriate.
Also see our Terms of Service and Refund Policy.