Last updated: 25 June 2026
Who we are
TradeFlow is operated by AIPOS Ltd ("we", "our", "us"), a company registered in England & Wales. We are the data controller for information you give us about your business and the people who use it (account holders, team members, prospects, and end-customers of trades businesses that use our CRM). For data your business uploads into TradeFlow about your own customers, you are the controller and we are the processor acting on your instructions.
Contact for any privacy matter: admin@aiposuk.com.
Information we collect
Account & business information
- Your name, email, and phone number
- Business name, address, trade type, and logo
- Account credentials (passwords are hashed; we never see them in plaintext)
- Team member profiles, roles, and pay information you enter
Customer & job data you upload
- Contacts, addresses, quotes, jobs, invoices, payments, and notes
- Photos, signatures, and certificates you attach to jobs
- Voice-agent call recordings and transcripts (where you have enabled the voice agent)
- SMS, email, and WhatsApp messages sent or received through TradeFlow
Technical & usage data
- Device type, browser, operating system, and IP address
- Pages visited, features used, and timestamps
- Diagnostic and error logs (with personal identifiers redacted where possible)
Connected accounts
If you connect Google Calendar, Gmail, Google Business, Outlook, Meta (Facebook / Instagram), QuickBooks, FreeAgent, or any other integration, we receive the data listed in that integration's authorisation screen and store the access/refresh tokens required to call it. You can disconnect any integration from Settings → Integrations.
Lawful basis for processing (UK GDPR / GDPR)
We process your personal data under one or more of the following lawful bases set out in Article 6 of the UK GDPR:
- Contract (Art. 6(1)(b)): to create your account, deliver the TradeFlow service, take payment, and provide support.
- Legitimate interests (Art. 6(1)(f)): to keep the platform secure, prevent fraud and abuse, improve features, send operational notifications, and conduct limited product-improvement analytics. You can object at any time by emailing admin@aiposuk.com.
- Legal obligation (Art. 6(1)(c)): to keep accounting records (HMRC), respond to lawful requests from authorities, and comply with the ICO.
- Consent (Art. 6(1)(a)): for non-essential cookies, marketing emails to prospects (where required), and any integration that requires explicit user consent (Google Calendar / Gmail / Meta scopes). Consent can be withdrawn at any time without affecting prior processing.
How we use your information
- Provide, operate, and maintain the TradeFlow service
- Authenticate you and manage your account and team
- Process subscription payments and credit top-ups via our payment processor
- Sync calendar, email, accounting, and lead data between TradeFlow and connected services
- Send service-related and transactional notifications (email, SMS, in-app)
- Provide AI-assisted features (call summarisation, copilot, content generation)
- Detect, prevent, and investigate fraud, abuse, and security incidents
- Comply with our legal, regulatory, and tax obligations
Sub-processors we use
We use the following third-party processors to deliver TradeFlow. Each is bound by a written data-processing agreement and only processes personal data on our instructions:
- Supabase (Lovable Cloud) — EU / Ireland: database, authentication, file storage, and serverless functions (the entire app backend).
- Twilio — Ireland / United States: SMS sending and inbound number routing.
- ElevenLabs — United States: AI voice agent (inbound call handling, speech-to-text, transcription, and message capture).
- Meta Platforms Ireland Ltd — Ireland: Facebook Lead Ads, Messenger, Instagram Direct, and WhatsApp Business messaging (only where you have connected those integrations).
- Google Ireland Ltd — Ireland: Google Calendar, Gmail send, Google Business Profile, Google Maps / Places (only where you have connected those integrations).
- Microsoft Ireland Operations Ltd — Ireland: Outlook email send via Microsoft Graph (only where you have connected Outlook).
- Revolut Ltd — United Kingdom: card payments, subscription billing, and merchant-initiated transactions for plan fees and credit top-ups.
- Resend — United States: transactional email delivery (used as fallback when Gmail/Outlook OAuth is not connected).
- Google AI (Gemini) — United States / EU: AI-assisted content generation (blog drafts, image generation, copilot replies). No personal data from the voice-agent inbound pipeline is sent to Google.
- Intuit (QuickBooks) — United Kingdom / United States: two-way accounting sync (only where you have connected QuickBooks).
- FreeAgent — United Kingdom: two-way accounting sync (only where you have connected FreeAgent).
We will give reasonable advance notice of any new sub-processor by updating this page. To request a current copy of the list at any time, email admin@aiposuk.com.
International transfers
Where personal data is transferred outside the UK and European Economic Area (notably to United States–based processors such as Twilio, ElevenLabs, Meta, Google, and Resend), we rely on the following safeguards under Articles 44–49 of the UK GDPR:
- The UK Data Bridge and the EU–US Data Privacy Framework certifications, where the recipient is certified.
- The UK International Data Transfer Addendum to the European Commission's Standard Contractual Clauses (SCCs), where certification does not apply.
- Supplementary technical measures including encryption in transit (TLS 1.2+) and at rest, and access controls limiting who in our team and in our processors can see your data.
Data retention
We keep personal data only for as long as we need it for the purpose it was collected, then we delete or anonymise it. Indicative retention periods:
- Active account data (contacts, jobs, quotes, invoices, photos): for the lifetime of your TradeFlow subscription. If you close your account we delete it within 30 days, except as noted below.
- Invoices, payment receipts, and tax-relevant records: retained for 6 years after the end of the accounting period to meet HMRC requirements.
- Voice-agent call recordings and transcripts: retained for 12 months from the call date unless you delete them sooner from Settings.
- SMS, email, and WhatsApp message threads: retained while the associated contact exists in your account, or up to 24 months for inbox messages not linked to a contact.
- Diagnostic and security logs: 90 days, then automatically purged.
- Meta connection data: deleted immediately on in-app disconnect; see the Data Deletion page.
- Closed-account audit trail: the fact that an account existed plus a minimal billing record is kept for 6 years for accounting purposes; all other personal data is deleted.
Your rights under UK GDPR
You have the following rights in relation to the personal data we hold about you:
- Right of access — request a copy of your personal data.
- Right to rectification — ask us to correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten") — ask us to delete your data, subject to legal-retention exceptions.
- Right to restrict processing — ask us to pause processing in defined situations.
- Right to data portability — receive your data in a structured, machine-readable format and transmit it to another controller.
- Right to object — object to processing based on legitimate interests, including direct marketing.
- Rights related to automated decision-making — we do not make solely-automated decisions with legal or similarly significant effects on you.
- Right to withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
To exercise any of these rights, email admin@aiposuk.com. We will respond within one calendar month and we never charge a fee for genuine requests.
Complaints to the regulator. If you are unhappy with how we have handled your data, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint or by calling 0303 123 1113. We would, however, appreciate the chance to deal with your concerns first.
Data security
- Encryption of data in transit (TLS 1.2+) and at rest
- Per-business row-level security at the database layer (multi-tenant isolation)
- Role-based access controls inside the app and inside our team
- Encrypted storage of integration access and refresh tokens
- Audit logging of administrative actions
Cookies and similar technologies
We use a small number of strictly-necessary cookies to keep you logged in and to maintain your session, plus optional analytics/attribution cookies where you have consented. You can control cookies through your browser settings; disabling strictly-necessary cookies will stop the app from working.
Children
TradeFlow is a B2B service for trades businesses and is not intended for use by anyone under 18. We do not knowingly collect data from children.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced by email and in-app; the "Last updated" date at the top of this page reflects the most recent revision.
Contact
Questions about this Privacy Policy, or to exercise any of your rights:
AIPOS Ltd
Email: admin@aiposuk.com