← Back to Quidder

Privacy Policy

Last updated: 12 August 2026

This policy is not finished. The operator's details have not been filled in yet, so the sections below are incomplete. Please don't rely on this document until this notice is gone.

Who is responsible for your data

Quidder is operated by [NOT SET — see src/lib/legal.ts], of [NOT SET — see src/lib/legal.ts]. We are the data controller for the information described here.

For anything to do with your data — a question, a correction, a copy, or a deletion — email [NOT SET — see src/lib/legal.ts].

What we hold

Two kinds of thing, and nothing else:

  • Your account. Your email address, a securely hashed password, your business name and tax-year setting, and the date you signed up.
  • What you enter. Purchases, inventory, sales, expenses, suppliers, and any photos you upload. This is your bookkeeping, and it may name the people and businesses you buy from and sell to.

We do not use tracking or analytics, we do not build a profile of you, and we do not sell or share your data with anyone for their own purposes.

Why we hold it, and our lawful basis

We process your account details and your bookkeeping data to provide the service you signed up for. The lawful basis is performance of a contract — without this data there is no Quidder to give you.

We also use your email to send service messages, such as password resets and, if you switch it on, your weekly backup. Where we contact you about the service itself rather than to advertise anything, the basis is our legitimate interest in running it properly.

There is no automated decision-making and no profiling. Nothing about your account is decided by a machine without a person involved.

Who else touches it

We use three companies to run Quidder. Each acts on our instructions as a processor and cannot use your data for its own purposes:

  • Supabase — stores the database and your uploaded photos.
  • Vercel — hosts and serves the application.
  • Resend — sends email, including password resets and, if you enable it, your weekly backup.

We may also disclose data if the law requires it. If Quidder is ever sold or transferred, we will tell you before your data moves.

Where your data goes

Your database and photos are held in [NOT SET — see src/lib/legal.ts].

Email is different, and worth being plain about. Resend is based in the United States, so any email we send you passes through the US. If you turn on the weekly backup, that email contains a full copy of your bookkeeping — so enabling it means your complete records leave the UK once a week. Transfers to the US rely on the UK's International Data Transfer Agreement or an equivalent safeguard.

The weekly backup is off unless you turn it on, and you can turn it off at any time.

How long we keep it

Your data stays for as long as your account exists. Delete your account and it goes immediately — the records, the photo files, and any bug reports you sent us. It is not archived and there is no hidden copy.

The one exception is our provider's routine encrypted backups, which roll off on their own schedule within 30 days. We do not mine those; they exist so the service can be restored after a failure.

An account that is never used is not deleted automatically. If we ever change that, we will email you well before anything is removed.

Your rights

Under UK data protection law you can ask us to:

  • show you what we hold about you;
  • correct anything that is wrong;
  • delete your data;
  • give you a copy in a portable format, to keep or take elsewhere;
  • stop or limit what we do with it, or object to a particular use.

Two of these you can do yourself, right now, without asking us: Export gives you everything as spreadsheet files, and Delete account in Settings removes it all. For anything else, email us. We will reply within one month, and we will not charge you.

If you think we have handled your data badly, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or on 0303 123 1113. You do not need our permission to do that.

Keeping it safe

Traffic is encrypted in transit. Passwords are hashed, never stored as text. Every query is scoped to your account, and photos are served through short-lived private links rather than public URLs, so they cannot be found by guessing an address.

No system is perfect. If a breach ever put you at risk, we will tell the ICO within 72 hours and tell you without undue delay.

Cookies

One cookie, to keep you signed in. It is essential to the service, so no consent banner is required. There is no advertising or third-party tracking cookie, and nothing follows you to other sites.

Children

Quidder is a business tool and is not intended for under-18s. We do not knowingly hold data about children.

Changes

If we change this policy we will update the date at the top, and email you first if the change is significant.