Legal
Privacy Notice
Effective: 29 July 2026
1. Who is responsible for your data
Sparkify Software Ltd is the controller for personal data used to operate SnapTax File. We are registered in England and Wales under company number 16519988, at 167–169 Great Portland Street, Fifth Floor, London, W1W 5PF. Our ICO registration is ZB947507.
Contact support@snaptaxfile.com for privacy questions or to exercise your rights.
2. Scope
This notice covers our website, web application, mobile application, customer support, transactional communications and integrations. Where you put another person’s information in your bookkeeping records, you are responsible for having a lawful reason to do so and for giving any notice the law requires.
3. Personal data we collect
- identity and account data, such as name, email, user ID and authentication events;
- business and tax data, including UTR, National Insurance number, accounting periods and business details;
- financial records, transactions, bank-feed data, receipts, invoices, mileage and counterparties;
- subscription and billing status (Stripe keeps full payment-card details);
- support messages, preferences and consent records;
- device, browser, IP address, security, diagnostic and audit-log data;
- HMRC authorisation status, obligations, submission results and correlation identifiers.
4. How we obtain it
We receive data from you, your device, your authorised bank connection, authentication providers, Stripe, HMRC and people who lawfully send invoices or records through the service. We do not obtain your Government Gateway or online-banking password.
5. Purposes and lawful bases
| Purpose | UK GDPR basis |
|---|---|
| Provide accounts, bookkeeping, exports, support and requested integrations | Performance of our contract |
| Process subscriptions and communicate essential service information | Contract and legal obligation |
| Security, audit, abuse and fraud prevention, and service improvement | Our legitimate interests in a safe, reliable service |
| Tax record preservation, accounting and responding to lawful authorities | Legal obligation |
| Optional marketing or non-essential device access | Consent where required; you may withdraw it |
6. HMRC and Open Banking
HMRC access uses its authorisation process and is initiated by you. We use the permission only to provide the tax features you request. You may disconnect it, although we may keep submission and audit evidence where legally required. Open Banking is optional and uses a regulated account-information provider (TrueLayer). The consent screen identifies the provider and the data requested.
7. AI-assisted features
We may use automated tools to suggest receipt fields or bookkeeping categories. These suggestions can be wrong and must be reviewed. We do not make a decision producing legal or similarly significant effects solely by automated processing. Do not upload unnecessary special-category data.
8. Recipients and processors
We share only what is necessary with these service categories:
- Supabase: authentication, database and private document storage.
- Stripe: subscription checkout, billing and fraud prevention.
- TrueLayer: Open Banking account information when you choose to connect a bank.
- HMRC: tax authorisation, obligations and submissions when you expressly connect HMRC.
- OpenAI: assisted extraction and categorisation; suggestions require your review.
- Resend: transactional and invoice email delivery.
- Vercel and Railway: web and API hosting, security and operational logs.
- Mapbox: mapping, mileage and address-related features.
We may also disclose information to professional advisers, insurers, courts, regulators, law enforcement or a buyer in a corporate transaction where lawful. We do not sell personal data or share customer data with third parties for their own marketing.
9. International transfers
Some suppliers may process data outside the UK. For restricted transfers, we use a UK adequacy regulation, the UK International Data Transfer Agreement or UK Addendum to approved standard contractual clauses, together with appropriate technical and organisational safeguards where required.
10. Retention
Business and tax records are normally retained for at least five years after the relevant 31 January filing deadline, and longer for late returns, enquiries, investigations, disputes, legal holds or another applicable requirement. Original records and the history of corrections are preserved for the applicable period. Security logs, support records, consent evidence and billing records have documented periods based on necessity and legal obligations. After the applicable period, data is securely deleted or anonymised.
11. Security
We use access controls, encryption in transit and at rest, private document storage, row-level database policies, encrypted HMRC tokens, audit logging, secret management, backups and supplier controls. No online service is risk-free; please use a strong unique password, protect your device and report concerns promptly.
12. Your rights
Depending on the circumstances, you may ask for access, correction, erasure, restriction, objection or portability, and may withdraw consent without affecting earlier lawful processing. We may need to verify your identity and may retain records where tax or another law overrides deletion. We normally respond within one month.
You may complain to the Information Commissioner’s Office at ico.org.uk. We would appreciate the opportunity to resolve your concern first.
13. Marketing and communications
Essential account, security, billing and tax-service messages are not marketing. We send electronic marketing only where permitted and provide an unsubscribe option. We do not share customer personal data with another organisation for its own marketing without the required permission.
14. Cookies and changes
See our Cookie Notice. We review this notice when our service, suppliers or law changes. We will prominently communicate material changes where appropriate. The effective date identifies the current version.