Privacy Policy
Last updated: JULY 2026
1. Overview & Data Controller
Gophur Ltd ("we", "us", or "our") is committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, process, store, and protect your information when you use our mobile application, website, and services, in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
For the purposes of UK data protection legislation, Gophur Ltd is the Data Controller for personal data collected directly from users of our software.
2. Information We Collect
We collect information directly from you, automatically when you use our app, and from third-party services:
A. Account & Business Information (information you provide)
- Contact details: full name, business name, email address, UK phone number, business address.
- Account credentials: username, password, and security preferences.
- Business profile details: trade type, VAT registration status (if applicable), and company registration numbers.
B. Customer Directory Data (data you upload)
- Names, phone numbers, email addresses, job notes, gate codes, and service histories of your clients entered into your Gophur directory. You act as Data Controller for your clients' personal data, and Gophur acts as a Data Processor.
C. Financial & Transaction Data
- Bank account details, payout histories, and transaction metadata. Financial card data processed via payment links is collected and tokenized directly by Stripe, and is never stored on Gophur servers.
D. Usage & Technical Data (automated collection)
- Device data: IP address, mobile device ID, operating system, and app version.
- Usage metrics: log-in activity, feature usage, app performance diagnostics, and crash reports.
3. Legal Basis & How We Use Your Data
We process your personal data under the following legal bases under UK GDPR:
- To register and onboard your account — Contractual Necessity (contact, account, business data).
- To provide job scheduling, invoicing, and SMS / WhatsApp link tools — Contractual Necessity (account, customer data, usage).
- To facilitate payments and bank payouts via Stripe Connect — Contractual Necessity & Legal Obligation (financial, transaction).
- To prevent fraud, financial crime, and unauthorized access — Legal Obligation & Legitimate Interests (technical, usage, financial).
- To send service updates, security alerts, and customer support — Legitimate Interests (contact, technical).
- To send product update newsletters or promotional offers — Consent, opt-out available anytime (contact).
4. Data Sharing & Third-Party Processors
We do not sell, rent, or trade your personal data or your customer directories to third parties. We only share necessary data with trusted service providers under strict data processing agreements:
- Stripe Payments UK Ltd: payment processing, identity verification, KYC checks, and payouts.
- Cloud Infrastructure Providers: secure database hosting and server backup located within the UK or EEA.
- SMS & Messaging Gateways: telecommunication partners (e.g. Twilio / WhatsApp Business API) used strictly to deliver payment links and job notifications to your clients on your behalf.
- Accounting Integration Services: Xero / QuickBooks, only if you enable integration in the Pro tier.
- Legal & Regulatory Authorities: if required by law, court order, or HM Revenue & Customs (HMRC).
5. Data Security & Retention
- Security Standards: all data in transit is protected using SSL/TLS encryption. Data at rest is encrypted using industry-standard protocols. Financial credentials are held exclusively within PCI-DSS Level 1 compliant environments managed by Stripe.
- Data Retention: we retain your account data for as long as your subscription is active. If you close your account, we retain essential transaction and financial records for up to 6 years to comply with UK accounting, tax, and anti-money laundering obligations, after which data is securely destroyed.
6. International Data Transfers
Your data is primarily stored and processed within the United Kingdom and the European Economic Area (EEA). If any of our subprocessors transfer data outside the UK/EEA, we ensure appropriate safeguards (such as UK International Data Transfer Agreements or Standard Contractual Clauses) are in place to guarantee an equivalent level of protection.
7. Your Statutory Rights under UK GDPR
Under UK data protection laws, you have the following rights regarding your personal data:
- Right of Access: request a copy of the personal data we hold about you.
- Right to Rectification: request correction of inaccurate or incomplete data.
- Right to Erasure ("Right to be Forgotten"): request deletion of your data where we have no legal requirement to retain it.
- Right to Restrict Processing: request that we temporarily suspend data processing under certain conditions.
- Right to Data Portability: request transfer of your data to another provider in a machine-readable format.
- Right to Object: object to processing based on legitimate interests or direct marketing.
To exercise any of these rights, please email our Data Protection Lead at support@gophurapp.com.
8. Complaints
If you have concerns about how we handle your data, we encourage you to contact us first. You also have the right to lodge a complaint with the UK data protection authority, the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF — ico.org.uk.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements or platform features. We will notify you of any material changes via email or app notice prior to the changes taking effect.