Privacy policy
This policy describes how we process personal data when you use selfsubmit.co.uk and the SelfSubmit application.
Last updated: 20 July 2026
1. Scope
This policy covers personal data we process when you browse our website, create an account, subscribe, upload records, contact support, or receive reminders. It does not govern how HMRC or your accountant processes data when you deal with them directly.
2. Data we collect
- Identity & contact: name, email address, phone number (if you provide it for SMS reminders), and account identifiers from our authentication provider.
- Tax identifiers: Unique Taxpayer Reference (UTR) and National Insurance number — encrypted at the application layer before storage.
- Business records: income and expense figures, profession, business names, submission history, and receipt images you upload.
- Billing: subscription status and Stripe customer identifiers — card details are handled by Stripe, not stored on our servers.
- Technical & security: IP address, device/browser data, logs, and security events needed to operate and protect the service.
- Communications: support emails and optional marketing preferences where you opt in.
3. Purposes and lawful bases
We process data to:
- Provide the service (contract) — accounts, record-keeping, submissions, receipts, reminders.
- Bill and administer subscriptions (contract / legal obligation).
- Secure the platform (legitimate interests) — fraud prevention, abuse detection, and incident response.
- Comply with law (legal obligation) — tax, accounting, and regulatory requirements.
- Improve the product (legitimate interests) — aggregated usage insight without selling personal data.
- Marketing (consent where required) — only if you opt in.
See our GDPR & data protection page for more on lawful bases and rights.
4. Processors and sharing
We use carefully selected service providers under contract to operate SelfSubmit. We do not sell personal data. We may disclose data if required by law, to protect rights and safety, or in connection with a business transfer.
In broad terms, personal data may be processed by providers that help us with:
- Cloud application hosting, content delivery, and serverless compute
- Managed database hosting for account and business records
- Secure file storage for receipts and documents you upload
- Optional SMS notifications (where you opt in)
- Technical error monitoring and reliability diagnostics
- Authentication, payments, transactional email, and UK address lookup (named below)
Those infrastructure and communications services are engaged under data-processing terms appropriate to UK GDPR. We do not publish a full directory of every infrastructure vendor on this page. Named providers you are most likely to interact with (or see branded flows for) are:
| Processor | Purpose | Typical data | Location |
|---|---|---|---|
| Clerk | Authentication, MFA, sessions | Email, name, sign-in metadata, session tokens | United States / UK (see Clerk DPA) |
| Stripe | Subscription billing (including free trials) | Customer ID, payment status (card data held by Stripe only) | See Stripe DPA |
| Resend | Transactional email | Email address, reminder message content | See Resend DPA |
| Ideal Postcodes | UK address lookup | Postcode and address search queries | United Kingdom |
Business customers may need a signed agreement — see our DPA.
5. Data minimisation
We collect only what we need to provide the service, including:
- Identity and contact details to create and support your account
- Tax identifiers (UTR and NI) when you choose to store them — encrypted at rest
- Business records, receipts, and submissions you enter or upload
- Technical logs for security and reliability
We do not collect special category data unless you voluntarily include it in free-text fields — please avoid doing so.
6. Retention
We keep data only as long as needed. Tax and business records may be retained to support HMRC record-keeping expectations while your account is active and for a limited period after closure. See our Data retention policy.
7. Security
We use HTTPS, encrypted storage for sensitive tax identifiers, access controls, and monitoring. See Security and Responsible disclosure.
8. Your rights
UK individuals have rights of access, rectification, erasure, restriction, objection, portability, and complaint to the ICO, subject to conditions. In the app, you can export your data or delete your account from Settings. You can also email support@selfsubmit.co.uk or see GDPR & data protection.
9. Cookies
See our Cookie policy.
10. Children
The service is not directed at children under 16 and we do not knowingly collect their data.
11. International transfers
Some processors may process data outside the UK. We use appropriate safeguards where required — see our GDPR page.
12. Changes
We will update this policy when practices change and revise the “Last updated” date.