Privacy Policy
How Firmit collects, uses, and protects your personal information
Last updated: 24 July 2026
Firmit ("Firmit", "we", "us", "our") is a software platform that helps trade and service businesses send quotes and payment requests, take payments from their customers, and keep a record of their work. This policy explains what personal data we collect, why, who we share it with, and the rights you have.
We've written it in plain English. If anything is unclear, contact us at admin@firmit.app.
1. Who we are
Firmit is provided by Firmit Technologies Ltd, a company registered in England & Wales (company number 17313142), registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.
For the purposes of UK data protection law, we are the data controller for the personal data described in this policy, except where we act on a business's behalf as described in section 3.
If you have any questions about this policy or how we handle your data, contact admin@firmit.app or write to us at the address above.
2. Who this policy is for
Firmit is used by two kinds of people, and we handle data slightly differently for each:
• Businesses - tradespeople and service businesses who create a Firmit account to run their work (we call them "businesses" or "users").
• Customers - the people who receive a quote or payment request from a business and pay through Firmit (we call them "customers").
It also covers anyone who simply visits our website.
3. Our role - controller and processor
When you are a business using Firmit, we are the controller of your account and usage data - we decide how it's handled to run the service.
When you are a customer paying a business through Firmit, some of your data is handled by us to run the platform (as controller), and some is handled on the business's behalf - the business is the one who has the relationship with you and decides how to use your details. In respect of that customer data, the business is the controller and Firmit acts as a processor on the business's behalf; a data-processing addendum with businesses may apply.
Either way, the business you're dealing with is responsible for the work, the quote, and their own dealings with you. Firmit is the software they use.
4. The personal data we collect
Category | What it includes | Who it's about |
|---|---|---|
Account & profile | Name, email, phone number, business name and details, trade/service type, login credentials (passwords are stored hashed, never in plain text; we also support passkeys) | Businesses |
Quote, job & payment records | Quotes, line items, job details, amounts, payment status, receipts, feedback and ratings, tips | Businesses & customers |
Customer contact details | Name, email, phone number, and (where provided) service address of a business's customer | Customers |
Payment data | Payments are processed by Stripe - we do not collect or store full card numbers or bank credentials. We hold payment metadata (amount, status, last-4/reference from Stripe, timestamps) | Businesses & customers |
Communications | Messages, notifications, and their delivery status (SMS, WhatsApp, email) sent through the platform | Businesses & customers |
Technical & usage | IP address, device and browser type, pages visited, and cookies/similar technologies (see section 9) | All visitors |
We do not intentionally collect special-category data (such as health or ethnicity), and ask that you don't send it to us through free-text fields.
5. How we use your data, and our legal basis
Under UK GDPR we must have a lawful basis for using your data. Here's what we do and why:
What we use it for | Lawful basis |
|---|---|
Creating and running your account; providing the quoting, payments and record-keeping service | Performance of a contract with you (or steps to enter one) |
Processing payments through Stripe and keeping payment records | Contract, and legal obligation (record-keeping) |
Sending service messages - payment requests, receipts, reminders, security notices | Contract and our legitimate interests in operating the service |
Keeping the platform secure, preventing fraud and abuse | Legitimate interests in protecting Firmit, our users and their customers |
Improving and developing Firmit, including product-analytics and session-replay tools (with on-screen text masked) and creating aggregated and anonymised insights (see section 6) | Legitimate interests in operating and improving our product |
Marketing to businesses about Firmit features and offers | Consent (where required) or legitimate interests, with an opt-out in every message |
Meeting our legal, tax and accounting obligations | Legal obligation |
Where we rely on legitimate interests, we've balanced our interests against your rights; you can ask us about that balancing test at any time.
6. Aggregated and anonymised data
We may create aggregated and anonymised data and insights from the information in Firmit - for example, benchmarks, trends, and statistics that do not identify any business or customer. Because this data can't be used to identify you, we may use and share it for any business purpose, including operating and improving Firmit. This does not change our obligations for the personal data it was derived from.
7. Who we share your data with
We don't sell your personal data. We share it only with the following categories of recipient, and only as needed to run the service:
• Payment processing - Stripe. Payments are processed by Stripe, a regulated payment provider. When a customer pays a business, Stripe handles the card or bank details directly. Stripe processes that data under its own terms and privacy policy, and for payment data acts as a controller in its own right.
• Our service providers (sub-processors) - the trusted providers that host and power Firmit. See the table below.
• Professional advisers, and authorities - e.g. our lawyers, accountants, or a regulator, where we're legally required or it's necessary to protect our rights.
• A buyer or successor - if Firmit or its business is reorganised, sold or transferred, your data may transfer as part of that, subject to this policy.
Our sub-processors (the third parties that process personal data on our behalf):
Sub-processor | What they do | Data involved |
|---|---|---|
Stripe | Payment processing and Connect onboarding | Payment details, business identity/KYC, payment metadata |
Twilio | SMS, WhatsApp and verification messages (WhatsApp is delivered via Meta) | Phone numbers, message content |
Twilio SendGrid | Transactional email | Email addresses, message content |
MongoDB Atlas | Database hosting | All stored account, job and payment data |
Vercel | Application hosting and delivery | Data processed in transit and in our application |
Microsoft Clarity | Product analytics and session replay, to understand and improve how Firmit is used | Usage and interaction data; session recordings with on-screen text masked |
We keep this list up to date and will update it before adding any new provider.
8. Where your data is processed (international transfers)
We aim to keep data within the UK or European Economic Area. Some of our sub-processors may process data outside the UK. Where they do, we make sure appropriate safeguards are in place - such as the UK's International Data Transfer Agreement / Addendum or the equivalent standard contractual clauses - so your data stays protected. You can ask us for details of these safeguards.
9. Cookies
Our website uses cookies and similar technologies to make it work, keep it secure, and understand how it's used. You can control non-essential cookies through our cookie banner and your browser settings. See our Cookie Policy for the full detail.
10. How long we keep your data
We keep personal data for as long as you have an account and for as long as we need it for the purposes in this policy. After that, we keep certain records for longer where the law requires it - for example, payment and tax records for 6 years. When we no longer need data, we delete it or anonymise it securely.
11. Your rights
Under UK data protection law you have the right to:
• Access the personal data we hold about you;
• Correct data that's wrong or incomplete;
• Erase your data ("right to be forgotten") in certain circumstances;
• Restrict or object to how we use it, including objecting to marketing at any time;
• Portability - receive certain data in a portable format;
• Withdraw consent where we rely on it, without affecting past processing.
If you're a customer and want to exercise these rights over data a business holds about you, you may need to contact that business as well, since they control their relationship with you - but you can always start by contacting us and we'll help route it.
To exercise any right, contact admin@firmit.app. We'll respond within one month. Using these rights is free, and we won't treat you differently for it.
You also have the right to complain to the Information Commissioner's Office (ICO) - ico.org.uk, helpline 0303 123 1113 - though we'd appreciate the chance to put things right first.
12. Security
We protect your data with appropriate technical and organisational measures - including encryption in transit, hashed passwords, access controls, and reputable infrastructure providers. No system is perfectly secure, but we take security seriously and will notify you and the ICO of a breach where the law requires.
13. Children
Firmit is for businesses and their adult customers. It isn't directed at children, and we don't knowingly collect data about anyone under 18. If you think a child has given us their data, contact us and we'll delete it.
14. Changes to this policy
We may update this policy from time to time. If we make a material change, we'll update the "last updated" date and, where appropriate, tell you directly. Please check back for the latest version.
15. Contact us
Questions, requests, or complaints about your data: admin@firmit.app, or Firmit Technologies Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.