Legal
Privacy Policy
Last updated / Effective: 24 August 2026
This policy explains how TaxChad Ltd ("TaxChad", "we", "us") handles personal data when you use TaxChad (the "Service") at taxchad.com. TaxChad is the data controller for the personal data described here - we are the entity that holds and processes your data and is responsible for it. This page is maintained by us to answer common privacy questions about the Service; it is app-owned editable content and is not an independent certification.
1. Data controller
TaxChad Ltd, a company registered in England and Wales (company number 17346680), registered office 15 Westbury Court Road, Bristol, BS9 3BU, United Kingdom.
We are registered with the UK Information Commissioner's Office (ICO), registration reference CSN1960990.
For any privacy question or to exercise your rights, contact us at privacy@taxchad.com.
2. What we collect
- Account data: name, email address, hashed password, workspace/firm details.
- Client & bookkeeping data: data you enter about your clients or business, including company names, addresses, company numbers, postcodes, invoices, transactions, bank imports, VAT records, and supporting documents (including receipt images and PDF statements or invoices you upload).
- Tax identifiers (where provided): National Insurance number, UTR - access is restricted to the client owner and their appointed accountant.
- Contact & messaging data (where you use these features): the recipient names, email addresses and phone numbers you enter, and the content of the invoices, invitations and reminders you send by email through the Service. Where you use the WhatsApp option, the Service only builds a click-to-send link for you to share from your own WhatsApp - nothing is sent from our servers to WhatsApp or Meta.
- Open banking data (where you use it): with your explicit consent, read-only account information (balances and transactions) and the payment details needed to initiate a payment. See section 9.
- Voice recordings (where you use Voice to Invoice): if you create an invoice by speaking, a short audio recording of your dictation and the transcript produced from it - which may include the customer name, address and invoice details you say aloud.
- Billing data: subscription and payment metadata handled by Stripe.
- Usage data: basic logs (IP address, timestamps, error traces) needed to operate and secure the Service.
3. How we use your data
- To provide bookkeeping, invoicing, VAT and accounting features.
- To extract transaction, receipt and invoice details from documents you upload, so you don't have to key them in by hand.
- To send invoices, invitations and reminders by email on your instruction, and to build WhatsApp click-to-send links you share yourself.
- To transcribe and structure invoices you dictate through Voice to Invoice, so you can create an invoice by speaking instead of typing.
- To calculate mileage between the postcodes you enter.
- To submit VAT returns to HMRC on your instruction (Making Tax Digital).
- To look up UK company information from Companies House when you search for a client.
- To enable open banking account information and payments where you use TaxChad Payments (section 9).
- To bill you and manage your subscription.
- To secure the Service, prevent fraud and comply with legal obligations.
Legal bases under UK GDPR: performance of a contract; legitimate interests (security, service improvement); legal obligation (tax/accounting records); and consent where required (including open banking access, which always relies on your explicit consent).
4. Sharing & subprocessors
We do not sell personal data.
Processors - providers that handle your data on our instructions:
- Lovable Cloud - application hosting and infrastructure. This includes the Lovable AI Gateway (below), Lovable Emails (below) and the Lovable connector gateway, which proxies our outbound calls to Google Maps Platform.
- Cloudflare - edge network and compute host. The application itself runs as a Cloudflare Worker, so every request you make to TaxChad passes through Cloudflare's network before it reaches our code.
- Supabase - managed Postgres database, authentication, file storage and server-side functions that sit behind Lovable Cloud.
- Amazon Web Services (AWS) - document data extraction. When you use "Capture receipt" or "Import PDF statement/invoice", the receipt image or PDF is processed by AWS Textract (AnalyzeExpense / AnalyzeDocument) to read the transaction, receipt and invoice fields; larger multi-page PDFs are first stored in an AWS S3 bucket to enable asynchronous processing. This processing is carried out in the UK (AWS eu-west-2 region).
- Lovable AI Gateway (Google Gemini and OpenAI models) - AI-assisted figure reading and data mapping. We use the gateway to read sterling and VAT figures from your documents (Google Gemini 3.6 Flash), and to suggest nominal-code and description mappings when you migrate prior-period data (Google Gemini 2.5 Flash). We do not use it to make automated decisions about you. We also use the gateway to turn the transcript of a dictated invoice into structured customer and invoice-line fields for Voice to Invoice. Voice to Invoice dictation is transcribed by an OpenAI speech-to-text model accessed through this gateway (see OpenAI below). Google's Gemini models, accessed through the gateway, likewise process your data only on our instructions and are not used to train Google's models. Data obtained through open banking (your Finexer account and transaction data) is never sent to any AI model; transactions imported from your connected bank accounts are categorised by deterministic rules based on your own coding history, not by AI.
- OpenAI - provides the speech-to-text model that transcribes your Voice to Invoice dictation. Your audio is sent to this model through the Lovable AI Gateway (above), not directly by us; OpenAI acts as a sub-processor to our AI gateway provider, does not use the data to train its models, and processes it in the United States.
- Postcodes.io (operated by Ideal Postcodes, UK) - UK postcode lookup. Where you enter or dictate a postcode (including in Voice to Invoice), we send that postcode to retrieve the corresponding town and county. This is a UK-based open-data service.
- Stripe - subscription payments and billing.
- GoCardless Ltd - Bacs Direct Debit collection of your TaxChad subscription fees, where you pay by direct debit. We share your name or company name, email address, the mandate and payment identifiers and the amounts collected. GoCardless is UK-based and is regulated by the FCA.
- Resend and Mailgun (via Lovable Emails) - outbound email delivery (invoices, invitations and reminders); we share the recipient's name, email address and the message content. Lovable Emails is the sending path, Resend and Mailgun are the underlying delivery providers, and bounce, complaint and unsubscribe events are reported back to us by Mailgun.
- Google Maps Platform - postcode-to-postcode mileage calculation; we send the postcodes you enter. These calls are routed through the Lovable connector gateway rather than sent to Google directly by us.
- Finexer Ltd - open banking account information and payment initiation, where you use TaxChad Payments (section 9).
Authorities and independent controllers - organisations we send data to that handle it under their own terms, not as our processors:
- HMRC - VAT/MTD submissions you initiate.
- Companies House - public UK company register lookups when you search for a client.
Where you engage an accountant (for example, your own appointed practice) to work on your books through TaxChad, that accountant accesses your data at your direction and on your instruction.
5. International transfers
Most processing takes place in the UK or the EU, and our document data extraction (AWS Textract) is pinned to the UK (AWS eu-west-2 region). Where personal data is transferred outside the UK - for example by some of our providers such as Stripe, Resend, Google or OpenAI (the OpenAI speech-to-text model used for Voice to Invoice, accessed via the Lovable AI Gateway, runs in the United States) - we rely on UK adequacy decisions or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.
6. How long we keep your data
We keep your accounting records for as long as your account is active.
After your account closes, we do not delete your records automatically. UK companies are generally required to keep accounting records for at least six years for tax purposes, and those records are yours - we keep them so that you can continue to meet that obligation.
You can ask us for a copy of your data, or ask us to delete it, at any time by emailing privacy@taxchad.com. We will respond within one month. If you ask us to delete your data, we will delete everything we are not legally required to keep, and we will tell you what we are keeping and why.
We do not run automated deletion. Deletion happens when you ask for it.
7. Security
Access is controlled by authentication and row-level security so that users can only see data belonging to their own workspace. Sensitive credentials (such as HMRC access tokens) are encrypted at rest. Payments are handled by Stripe and, for open banking, by Finexer - we do not store card numbers, and we never see or store your bank login credentials.
8. Your rights
Under UK GDPR you have the right to access, correct, delete, restrict, port or object to processing of your personal data, and to withdraw consent. To exercise these rights, email privacy@taxchad.com. We will respond within one month.
You can also complain to the UK Information Commissioner's Office (ico.org.uk) if you are unhappy with how we handle your data.
9. Open banking and payments (TaxChad Payments)
Once bank feeds are live and where enabled for your account, open banking services within TaxChad Payments are provided by Finexer Ltd (company number 12191948), which is authorised and regulated by the Financial Conduct Authority (FRN 925695). TaxChad acts as a registered agent of Finexer Ltd for these services; Finexer is the regulated provider of the account information and payment initiation services, and we act on its behalf.
We only access bank data or initiate a payment where you have given explicit consent for that specific purpose. Each consent records what it covers, when it was given, and when it expires. Account information consents last no longer than 90 days unless you renew them. You can withdraw any consent at any time from the Compliance page in your account, or by emailing us - withdrawal stops future access immediately and does not affect anything already lawfully done.
Payments settle directly between the payer's bank and the payee's own bank account. TaxChad does not hold, control or come into possession of your funds at any point.
Payer details we hold to complete a payment (name, reference, and the payment metadata returned by Finexer) are retained for six years in line with UK tax and payment record-keeping requirements, then removed. We never see or store your bank login credentials - you authenticate directly with your bank.
If a personal data breach affects these services, we notify Finexer within 24 hours of detection and, where the breach is likely to risk your rights and freedoms, the ICO within 72 hours.
10. Cookies
We use strictly necessary cookies to keep you signed in and to remember basic preferences. We do not use advertising cookies.
11. Changes
We may update this policy from time to time. Material changes will be notified in-app or by email.
© 2026 TaxChad Ltd. Bookkeeping software.