Legal

Privacy Notice

Effective: 29 July 2026

1. Who is responsible for your data

Sparkify Software Ltd is the controller for personal data used to operate SnapTax File. We are registered in England and Wales under company number 16519988, at 167–169 Great Portland Street, Fifth Floor, London, W1W 5PF. Our ICO registration is ZB947507.

Contact support@snaptaxfile.com for privacy questions or to exercise your rights.

2. Scope

This notice covers our website, web application, mobile application, customer support, transactional communications and integrations. Where you put another person’s information in your bookkeeping records, you are responsible for having a lawful reason to do so and for giving any notice the law requires.

3. Personal data we collect

  • identity and account data, such as name, email, user ID and authentication events;
  • business and tax data, including UTR, National Insurance number, accounting periods and business details;
  • financial records, transactions, bank-feed data, receipts, invoices, mileage and counterparties;
  • subscription and billing status (Stripe keeps full payment-card details);
  • support messages, preferences and consent records;
  • device, browser, IP address, security, diagnostic and audit-log data;
  • HMRC authorisation status, obligations, submission results and correlation identifiers.

4. How we obtain it

We receive data from you, your device, your authorised bank connection, authentication providers, Stripe, HMRC and people who lawfully send invoices or records through the service. We do not obtain your Government Gateway or online-banking password.

5. Purposes and lawful bases

PurposeUK GDPR basis
Provide accounts, bookkeeping, exports, support and requested integrationsPerformance of our contract
Process subscriptions and communicate essential service informationContract and legal obligation
Security, audit, abuse and fraud prevention, and service improvementOur legitimate interests in a safe, reliable service
Tax record preservation, accounting and responding to lawful authoritiesLegal obligation
Optional marketing or non-essential device accessConsent where required; you may withdraw it

6. HMRC and Open Banking

HMRC access uses its authorisation process and is initiated by you. We use the permission only to provide the tax features you request. You may disconnect it, although we may keep submission and audit evidence where legally required. Open Banking is optional and uses a regulated account-information provider (TrueLayer). The consent screen identifies the provider and the data requested.

7. AI-assisted features

We may use automated tools to suggest receipt fields or bookkeeping categories. These suggestions can be wrong and must be reviewed. We do not make a decision producing legal or similarly significant effects solely by automated processing. Do not upload unnecessary special-category data.

8. Recipients and processors

We share only what is necessary with these service categories:

  • Supabase: authentication, database and private document storage.
  • Stripe: subscription checkout, billing and fraud prevention.
  • TrueLayer: Open Banking account information when you choose to connect a bank.
  • HMRC: tax authorisation, obligations and submissions when you expressly connect HMRC.
  • OpenAI: assisted extraction and categorisation; suggestions require your review.
  • Resend: transactional and invoice email delivery.
  • Vercel and Railway: web and API hosting, security and operational logs.
  • Mapbox: mapping, mileage and address-related features.

We may also disclose information to professional advisers, insurers, courts, regulators, law enforcement or a buyer in a corporate transaction where lawful. We do not sell personal data or share customer data with third parties for their own marketing.

9. International transfers

Some suppliers may process data outside the UK. For restricted transfers, we use a UK adequacy regulation, the UK International Data Transfer Agreement or UK Addendum to approved standard contractual clauses, together with appropriate technical and organisational safeguards where required.

10. Retention

Business and tax records are normally retained for at least five years after the relevant 31 January filing deadline, and longer for late returns, enquiries, investigations, disputes, legal holds or another applicable requirement. Original records and the history of corrections are preserved for the applicable period. Security logs, support records, consent evidence and billing records have documented periods based on necessity and legal obligations. After the applicable period, data is securely deleted or anonymised.

11. Security

We use access controls, encryption in transit and at rest, private document storage, row-level database policies, encrypted HMRC tokens, audit logging, secret management, backups and supplier controls. No online service is risk-free; please use a strong unique password, protect your device and report concerns promptly.

12. Your rights

Depending on the circumstances, you may ask for access, correction, erasure, restriction, objection or portability, and may withdraw consent without affecting earlier lawful processing. We may need to verify your identity and may retain records where tax or another law overrides deletion. We normally respond within one month.

You may complain to the Information Commissioner’s Office at ico.org.uk. We would appreciate the opportunity to resolve your concern first.

13. Marketing and communications

Essential account, security, billing and tax-service messages are not marketing. We send electronic marketing only where permitted and provide an unsubscribe option. We do not share customer personal data with another organisation for its own marketing without the required permission.

14. Cookies and changes

See our Cookie Notice. We review this notice when our service, suppliers or law changes. We will prominently communicate material changes where appropriate. The effective date identifies the current version.