Privacy Policy

Last updated: 24 April 2026

1. Introduction

HouseCheckup ("we", "us", "our") is committed to protecting your personal data. This privacy policy explains how we collect, use, store, and share your information when you use our website at housecheckup.co.uk and related services (the "Service").

We are the data controller for the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. If you have any questions about this policy, please contact us at privacy@housecheckup.co.uk.

2. Data We Collect

We collect and process the following categories of personal data:

Account Information

Name, email address, and password hash when you create an account. If you sign up via a social provider, we receive your name and email from that provider.

Payment Information

When you purchase a report, payment is processed by Stripe. We do not store your full card number. We retain Stripe customer ID, transaction IDs, purchase history, and billing address for tax and accounting purposes.

Usage Data

IP address, browser type, device information, pages visited, property searches performed, and timestamps. This data is collected via server logs and analytics cookies (where consent is given).

Communication Data

Any information you provide when contacting our support team, including email correspondence and feedback submissions.

3. Lawful Basis for Processing

We process your personal data under the following lawful bases as defined by UK GDPR Article 6:

Lawful BasisPurpose
ContractTo create your account, process payments, and deliver purchased property reports.
Legitimate InterestTo maintain platform security, prevent fraud, improve our Service, and send transactional emails (e.g. order confirmations).
ConsentTo set non-essential cookies (analytics, functional) and to send marketing communications. You can withdraw consent at any time.
Legal ObligationTo retain financial records as required by HMRC and UK tax legislation.

4. Third-Party Data Processors

We share personal data with the following third-party processors, each of whom is contractually bound to process data only on our instructions and in compliance with UK GDPR:

  • Stripe, Inc. -- Payment processing. Stripe acts as an independent data controller for payment card data. See Stripe's Privacy Policy.
  • Google LLC (Google Analytics) -- Website analytics (only with your consent). We use IP anonymisation. Data may be transferred to the US under Google's approved transfer mechanisms. See Google's Privacy Policy.
  • Hosting & Infrastructure -- Our platform is hosted on cloud infrastructure within the UK/EEA. Server logs containing IP addresses are retained for security purposes.

We do not sell your personal data to any third party. We do not share your data with third parties for their own marketing purposes.

5. Data Retention

We retain your data only for as long as necessary to fulfil the purposes for which it was collected:

  • Account data -- Retained for the lifetime of your account plus 30 days after deletion request.
  • Financial/transaction records -- Retained for 7 years as required by HMRC.
  • Server logs -- Retained for 90 days, then automatically purged.
  • Analytics data -- Aggregated and anonymised after 26 months.

6. Your Rights

Under UK GDPR, you have the following rights regarding your personal data:

Right of Access

Request a copy of the personal data we hold about you.

Right to Rectification

Request correction of inaccurate or incomplete personal data.

Right to Erasure

Request deletion of your personal data ("right to be forgotten"), subject to legal retention requirements.

Right to Restrict Processing

Request that we limit how we use your data in certain circumstances.

Right to Data Portability

Receive your data in a structured, commonly used, machine-readable format.

Right to Object

Object to processing based on legitimate interest or direct marketing.

Right to Withdraw Consent

Withdraw consent at any time where processing is based on consent.

To exercise any of these rights, email us at privacy@housecheckup.co.uk. We will respond within one calendar month as required by law.

7. Cookies

We use cookies and similar technologies on our website. For full details on the cookies we use, their purpose, and how to manage them, please see our Cookie Policy.

8. International Data Transfers

Where we transfer personal data outside the UK, we ensure appropriate safeguards are in place, including UK International Data Transfer Agreements (IDTAs) or reliance on adequacy decisions. Stripe and Google both maintain approved transfer mechanisms for UK personal data.

9. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including encryption in transit (TLS 1.2+), encryption at rest, access controls, regular security audits, and secure development practices. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

10. Children's Privacy

Our Service is not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately.

11. Complaints

If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office

Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

ico.org.uk/make-a-complaint

Helpline: 0303 123 1113

12. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any material changes by posting the updated policy on our website and, where appropriate, by email. We encourage you to review this policy periodically.

Contact Us

For any privacy-related queries or to exercise your data rights:

Email: privacy@housecheckup.co.uk

Company: HouseCheckup