Draft for review. This is a draft. Jobiit Technologies Limited has not finished reviewing it, it is not yet in force, and its wording may change before Tradrbox is offered to customers.
Legal
Privacy notice
Last updated
What personal data Tradrbox holds, why, on what legal basis, who else handles it and where, how long it is kept, and what you can do about it — written from how the Service works.
1. Who we are, and the two roles we play
Tradrbox is a trading name of Jobiit Technologies Limited, a company registered in Ireland under company number 810674, whose registered office is at 79 Berford, Duleek, Co. Meath, A92 E67F, Ireland. We make software that trades businesses in Ireland and the United Kingdom use to run their work: this website at tradrbox.com, the office app, the field app for phones, and the pages a business’s own customers open from its emails (together, the Service).
Which role we play depends on whose data it is:
- We are the controller of data about the people who deal with us directly: the person who sets a business up on Tradrbox, everybody who signs in to it for a business (Users), the business’s billing contact, people who visit this website, and people who write to us. section 3 to section 17 describe that.
- We are a processor for the records a business keeps in Tradrbox about its own customers, their contacts and the places it works, the work it does for them, and its own staff (Firm Personal Data). The business is the controller of that data and decides what goes in; we handle it only on the business’s instructions, under the data processing terms in our terms of service. If you are a customer or an employee of a business that uses Tradrbox, that business is the right place to start; section 11 says how we help.
2. In short
- We collect what the Service needs in order to work, and nothing for advertising.
- The website has no analytics, no advertising and no tracking cookies. It sets one cookie, and only when you choose a country.
- We never see or store your password: sign-in is handled by Google’s Firebase Authentication.
- Card and bank details go to Stripe, never to us.
- The Service, its database and the documents it draws run on Google Cloud in Belgium. A few named providers handle parts of the data, some of them outside Europe, under the safeguards in section 6.
- We do not sell personal data, use it for advertising, or use it to train AI models.
- A business owns its records, can export them whenever it likes, and closing the business deletes them.
- You have rights under the EU GDPR and the UK GDPR (section 11), and you can complain to the Data Protection Commission in Ireland or the Information Commissioner’s Office in the United Kingdom.
3. What we hold as controller, and why
Most Users work for a business that subscribes to Tradrbox, and our contract is with the business rather than with them. For those Users our legal basis is our legitimate interest in providing the Service to the business they work for. Where you are the person who contracted with us — a sole trader, say — the basis is the contract itself.
| Data | What it is | Why we hold it | Legal basis |
|---|---|---|---|
| Your account | Your name, email address and role (administrator or staff), the business you belong to, an identifier from Firebase Authentication, whether your email address has been confirmed, who invited you and when, and the one-time codes in the password-reset and address-confirmation emails we send you | To let you sign in, to put your name on the work you record, and to keep your account secure | Contract, where you contracted with us; otherwise legitimate interests, as above |
| The business | Its name, country, nation (for a UK business), address, telephone number and contact email; whether it is registered for VAT and its VAT number; for a UK business with no VAT number, its declaration that it is buying the subscription for its trade business and when it was made, and any Companies House or trade registration number it gives as further evidence; and its logo. For a sole trader these identify a person | To set the business up for its own country, to head the documents it sends, to bill the subscription and to charge the right VAT on it | Contract; legal obligation (VAT records) |
| Acceptance of our terms | Which edition of the terms of service and this notice was accepted, when, and by which User | To be able to show what was agreed | Contract; legitimate interest in keeping a record of it |
| Billing | Stripe customer and subscription identifiers, the plan, its status and history, the trial’s end date, and the reason given when a subscription is cancelled in the billing portal. Any comment typed there is emailed to us and not stored with the subscription. Card and bank details are held by Stripe, never by us | To bill the subscription, to answer questions about it and to understand why businesses leave | Contract; legal obligation to keep tax records; legitimate interests |
| Email records | For each email the Service sends: the recipient’s address, which email it was, its subject and whether it was delivered, bounced or blocked | To answer “it never arrived”, and to stop sending to an address that bounces | Legitimate interest in reliable delivery |
| Notifications | The notices shown to you in the office app, and whether you have read them | So what you were told is not lost if you missed it | Contract; legitimate interests |
| Activity trail | Which record was created, changed or deleted, what changed, by which User, when, from which IP address, and — for work recorded offline — the time the device gave | Security, and settling a dispute about who did what and when. It is also part of the business’s own records | Legitimate interests |
| Correspondence | Emails you send us and our replies | To help you | Legitimate interest in supporting the Service; contract |
| Server logs | IP address, the request made, the time, the browser and the response | Security, rate limiting and finding faults | Legitimate interest in keeping the Service secure |
| Bot checks | Technical signals about your browser, assessed by Cloudflare Turnstile on the signup form and, where it is switched on, by Google reCAPTCHA Enterprise on the office app and the account pages | To tell a person from an automated script before a business is created or a request is answered | Legitimate interest in keeping the Service secure |
| Error reports | When something fails on our servers: the error, the request that caused it, and the identifier of the User who made the request | To find and fix faults | Legitimate interest in a Service that works |
You must give a name and an email address to have an account. Everything else above is either produced by your use of the Service or optional.
What a business records as controller is up to the business (section 1). Typically it is: its customers’ and their contacts’ names, addresses, email addresses and telephone numbers; the sites it works at, with access notes, and the equipment installed there; jobs, visits, hours and materials; quotes, and the name typed by the person who accepted one; invoices, credit notes, payments, statements and withholding-tax records about subcontractors; forms and certificates with their answers, photographs, video and signatures; and, about its own staff, pay and cost rates, working patterns, absences, and registration numbers such as a gas or electrical registration. We treat all of it as personal data.
Special categories of data. When a business records that somebody was off sick, that is health data. We hold it only as the business’s processor, and the business needs its own condition for processing it, ordinarily its obligations as an employer. The kind of absence and any note are shown only to the business’s administrators and the person concerned, and they are never copied to the field app on a phone. We collect no other special category of data, no biometric data (a signature is kept as a picture, not as a biometric template), and nothing about children.
Location. The Service does not collect or store the location of your device.
4. Where it comes from
- You, when you set up a business, sign in, or use the Service.
- Your business’s administrators, who invite you by name and email address and who record your rates, working pattern, absences and registrations. The business is responsible for having a lawful basis for that — ordinarily that you work there — and for telling you about it.
- Firebase Authentication, which tells us whether you have confirmed your email address.
- Stripe, which tells us the state of the subscription and sends us its invoices; and, for a business that takes payments through its own Stripe account, how those payments went.
- Twilio SendGrid, which tells us when an email could not be delivered.
- Address lookup: as an address or an Eircode is typed, the characters are sent to Autoaddress, which suggests matching addresses. We keep the address that is chosen.
5. Who processes it for us, and where
We use a small number of providers, each for one job. Each receives only what that job needs, under a written data processing agreement, and none may use the data for its own purposes. This table is also the list of sub-processors a business authorises under our terms of service. Where a provider handles data outside the European Economic Area or the United Kingdom, section 6 says how that transfer is protected.
| Provider | What it does for us | What it sees | Where |
|---|---|---|---|
| Google Cloud | Runs the Service: the website, the office app and our servers; the database; the documents the Service draws; logs, monitoring and scheduled tasks | Everything the Service holds | European Union — Belgium (europe-west1) |
| Google Firebase Authentication | Sign-in: accounts, passwords, and the one-time codes behind password reset and address confirmation | Your email address, your password (which Google stores in a form nobody can read back), and sign-in events | Google’s global infrastructure, which may include the United States |
| Google reCAPTCHA Enterprise | Where it is switched on, confirms that requests to the office app and the account pages come from a real browser (Firebase App Check) | Technical signals about your browser | Google’s global infrastructure |
| Stripe | Bills the subscription, works out the VAT on it (Stripe Tax), checks VAT numbers, and runs the billing portal | The business’s name, billing email address and address, its VAT number or other evidence that it is a business, and the subscription; card and bank details | European Union (Stripe Payments Europe, Limited, Ireland), with some processing in the United States |
| Twilio SendGrid | Sends every email the Service sends | The recipient’s address, the subject, the contents and any attached document, and whether it was delivered | United States |
| Cloudinary | Stores and delivers photographs, video, signatures and logos, uploaded straight from the device | Those files and their details | European Union and United States |
| Cloudflare | Runs the DNS for our domain and forwards email sent to our own addresses; runs the Turnstile check on the signup form | Technical signals about the browser completing the signup form; emails sent to us | United States and Cloudflare’s global network |
| Google Workspace | Our own email | What you write to us, and our replies | Google’s global infrastructure |
| Autoaddress | Address and Eircode lookup | The characters typed into an address search | Ireland |
| Sentry | Error reports from our servers | The error, the request that caused it, and the identifier of the User who made it | United States or European Union |
We change this table before a new provider handles personal data, and we email the administrators of every business at least thirty days beforehand, as our terms of service promise.
Beyond those providers we share personal data only: within your business (your name is on the work you record and in its list of people); with a business’s customers, when the business sends them a quote, an invoice, a certificate or another document; with our professional advisers, in confidence; with a buyer of or successor to our business, who must keep to this notice; and with a court, regulator or public authority where the law requires it, in which case we tell the business concerned unless the law forbids us to.
6. Transfers outside Europe
Our servers and our database are in the European Union. Some of the providers above handle data in the United States or in the United Kingdom, and a business in the United Kingdom sends its data to us in the European Union.
- Under the EU GDPR, a transfer to the United Kingdom relies on the European Commission’s adequacy decision for it; a transfer to the United States relies on the EU-U.S. Data Privacy Framework for a provider certified under it, and otherwise on the Commission’s Standard Contractual Clauses in the provider’s data processing terms.
- Under the UK GDPR, a transfer to the European Economic Area relies on the United Kingdom’s adequacy regulations for it; a transfer to the United States relies on the UK Extension to the Data Privacy Framework for a certified provider, and otherwise on the International Data Transfer Addendum to the Standard Contractual Clauses.
We check a provider’s certification before we engage it and when its contract renews. A copy of the relevant clauses is available on request.
7. Automated decisions
We make no decision about you by automated means that has a legal or similarly significant effect on you, and nothing in the Service profiles Users or a business’s customers. No feature of the Service sends personal data to an AI model.
Some things happen automatically to a business, under our terms of service, and are worth naming. Seven days after its subscription lapses, a business can no longer start new work, though it can still finish what it has begun, read everything and export it. Seven days after a business holds more sign-ins than its plan includes, only its administrators can sign in until it is back within the plan. And the records of a business whose subscription has lapsed are deleted after the notice described in the retention table. The administrators are emailed before each of these takes effect.
8. How long we keep it
| Data | Kept for | Then |
|---|---|---|
| A sign-in account that never became part of a business (a signup that did not finish) | Until it is used to set up or join a business | Email privacy@tradrbox.com and we will delete it. It holds an email address, a password and a Firebase identifier, and nothing else |
| Your account | For as long as you belong to a business | — |
| Your account, after your business removes you | You can no longer sign in | The work recorded under your name stays in the business’s records, because a business must be able to show who did the work — on a certificate above all — and goes when the business’s records go |
| A business’s records, while it is on a trial or subscribes | For as long as that lasts | — |
| A business’s records, after its subscription lapses or ends | At least ninety days from the lapse, readable and exportable throughout | Deleted, after at least thirty days’ notice by email to its administrators, which gives the date |
| A business’s records, when an administrator closes the business | Deleted from our database at once; photographs, video, signatures and documents deleted from storage straight afterwards | Gone from our database backups as those expire, within thirty days |
| Our record of each business’s subscription: plan, status and dates, with no names or contact details | At least six years, including after a business closes | Deleted. It is our accounting and tax record |
| Invoices for the subscription | Six years from the end of the year they relate to, as Irish tax law requires | Deleted. Stripe holds them too |
| Email records and notifications | With the business’s records | As above |
| Server logs | Thirty days | Deleted automatically |
| Error reports | Ninety days | Deleted automatically |
| Correspondence with us | Three years after the conversation ends | Deleted |
| Links in a business’s emails to its customers (a quote to answer) and invitations to Users | The link stops working once the quote is answered, withdrawn or out of date, or the invitation is used, withdrawn or out of date | The answer stays with the business’s records |
Where the law obliges us to keep something for longer — a tax record, or data subject to a legal hold — we keep only that, and go on protecting it.
9. How we protect it
- Each business’s records are walled off by the database itself. Every record carries the business it belongs to, and the database refuses to return it to anybody else’s session — on every table, not by trusting the application to remember.
- No passwords are held by us: sign-in is Firebase Authentication’s.
- Photographs, video, signatures and documents are never public. They are reached only through signed links that expire, from storage that refuses public access.
- Encrypted in transit and at rest.
- Least privilege. Our servers reach the database as a role that cannot step around the walls between businesses, and every change to a business’s records is written to its activity trail.
- A link that answers a quote or accepts an invitation is treated as a key. Those pages send no referrer to anybody and ask search engines not to list them. Please do not forward such a link.
- The field app keeps only what the work needs. It holds a copy of the business’s records on the phone so that work goes on without a signal; signing out removes it; and the reason for a colleague’s absence never reaches a phone.
- Backups are taken every day, with point-in-time recovery, under the same controls.
- A check before a business is created, and limits on how often anybody can try, keep automated signups out.
No system is perfectly secure. If you think an account or the Service has been compromised, email hello@tradrbox.com straight away.
10. If something goes wrong
If personal data we hold as controller is breached, we will tell the Data Protection Commission — and the Information Commissioner’s Office where people in the United Kingdom are affected — within 72 hours where the breach is likely to put people’s rights at risk, and tell the people affected without undue delay where that risk is high. If Firm Personal Data is affected, we will tell the business without undue delay, and in any event within 72 hours of becoming aware, as our terms of service promise. We keep a record of every incident.
11. Your rights
Under the EU GDPR and the UK GDPR you may ask us for access to the personal data we hold about you and a copy of it; to correct it; to erase it; to restrict what we do with it; to have it in a portable form (portability); and you may object to what we do on the basis of our legitimate interests.
To use a right, email privacy@tradrbox.com, from the address you sign in with if you can. We answer within one month. Where a request is complex, or there are several, we may take up to two months more, and will tell you why. We may ask you to confirm who you are first. There is no charge, unless a request is manifestly unfounded or excessive.
If you are a customer or an employee of a business that uses Tradrbox, your data is in that business’s records and the business is its controller. We will pass your request to the business, tell you we have, and help it to answer. The Service lets a business find, correct, export and delete a customer’s record itself. If you cannot reach the business, we will still help.
Much of this you can do yourself. An administrator can correct a User’s name; the office app’s Exports screen downloads “Your own data” — everything recorded about you in your business — at any time; and an administrator can export the business’s records at any time, whatever the state of its subscription.
You may also complain to a supervisory authority. We are established in Ireland, so our lead authority is the Data Protection Commission: www.dataprotection.ie, 21 Fitzwilliam Square South, Dublin 2, D02 RD28. If you are in the United Kingdom you may complain to the Information Commissioner’s Office: ico.org.uk, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. We would rather hear from you first, and will always try to put things right directly.
12. The website, the office app and the pages customers open
This website’s marketing pages load no analytics and no third-party scripts, and use the fonts already on your device. They set a single cookie, and only when you choose a country or region, so that the choice is offered first next time. The cookie policy lists everything the Service stores in your browser.
The signup, invitation, password-reset and address-confirmation pages use Firebase Authentication only while the page is open, and keep no sign-in in your browser afterwards. The signup form also loads Cloudflare’s Turnstile check. The office app keeps you signed in, in your browser’s storage for that site, until you sign out.
The page on which a business’s customer answers a quote sets no cookie and sends no referrer. Whatever the customer types there — their name, and which options they chose — goes to that business, for which we act as processor.
Our hosting keeps ordinary server logs (IP address, request, time, browser) for thirty days.
13. Email
We email Users about the Service: invitations, address confirmation and password resets, the welcome, the end of a trial, a lapsed subscription, a business holding more sign-ins than its plan, and notice that a lapsed business’s records are to be deleted. These are part of the Service and cannot be switched off while you have an account. We do not send marketing email; if we ever do, it will say how to stop it.
The emails a business’s customers receive — quotes, confirmations, invoices, reminders, receipts, statements and credit notes — are sent on that business’s behalf, under its name, and replies go to the business once its address has been confirmed. We send no marketing to a business’s customers.
14. Card payments
Where a business takes card payments from its customers through the Service, it does so through its own Stripe account. The card details go directly to Stripe; we never see or store a card number, and receive only the outcome, the amount and Stripe’s own references. The business is the merchant, and Stripe handles that payment data under its agreement with the business and its own privacy policy.
15. Children
The Service is for businesses. Users must be at least sixteen — the age an apprentice can start. We do not knowingly collect personal data about anybody younger, and if we learn that we have, we delete it.
16. Changes to this notice
When this notice changes, the date at the top changes with it. We email the administrators of every business before a change that affects them takes effect, and at least thirty days before a change that adds a provider or a purpose. The current version is always at tradrbox.com/legal/privacy.
17. Contact
Controller: Jobiit Technologies Limited, trading as Tradrbox, 79 Berford, Duleek, Co. Meath, A92 E67F, Ireland. Registered in Ireland, company number 810674.
Data protection: privacy@tradrbox.com. Anything else: hello@tradrbox.com.
We have not appointed a data protection officer, because the GDPR does not require one of a business like ours; the addresses above reach the people responsible.