Privacy policy

Version 1.0 · July 2026 · Written in plain English on purpose.

Who we are

TaxMate is operated by JJPlatform Studio ("we"). We are the data controller for the information you give us through the app. For anything privacy-related, contact hello@jjplatformstudio.de. Where your assigned accountant processes your information to prepare your tax return, they act under their own professional duties alongside us.

What we collect, and why

Account details (name, email, phone): to create and secure your account. Identity verification (photo ID check results): because accountants are legally required to verify their clients under UK anti-money-laundering law. Tax references (UTR, National Insurance number): needed to file your tax return — stored encrypted, so that even our own systems display only the last four digits. Financial records (transactions you add or tag, receipts, mileage): this is the bookkeeping service itself. Payment details: handled entirely by Stripe — your card number never touches our servers. Security records: we keep a permanent log of who accessed what, to protect you.

Our legal bases

We process your data to perform our contract with you (running the service), to meet legal obligations (anti-money-laundering checks, tax record-keeping), and in our legitimate interest of keeping the service secure. We do not use your data for advertising, and we will only ever send you marketing if you separately opt in.

Who can see your data

Your assigned accountant (only yours — database rules make other clients' data invisible to them). Our service providers, each under contract: Supabase (database and login, hosted on AWS in London, UK), Stripe (payments), and Hetzner (web hosting, Germany/EU). We never sell your data. We disclose data to authorities only where the law requires it.

Where your data lives

Your records are stored in the United Kingdom (London). The web application is served from within the EU (Germany). We do not transfer your personal data outside the UK/EU.

How long we keep it

While your account is open, we keep your records so your accountant can act for you. HMRC requires self-employment records to be kept for roughly six years, so if you delete your account we erase or anonymise everything we can immediately, and retain only what tax law obliges us (and your accountant) to keep, for only as long as it obliges us to keep it.

Your rights

You can download everything we hold about you and request deletion of your accountdirectly from Settings inside the app — no support tickets needed. You also have the right to correct your data, restrict or object to processing, and to complain to the Information Commissioner's Office (ico.org.uk) if you think we've got something wrong — though we'd appreciate the chance to fix it first.

Cookies

We use only strictly necessary cookies — the ones that keep you logged in securely. No advertising cookies, no third-party tracking, no analytics cookies. That's why there's no cookie banner: there is nothing to opt out of.

Security

Mandatory two-step login, encryption of data at rest and in transit, additional field-level encryption for tax references, role-based access enforced inside the database, and a tamper-proof audit log. See our Security page for the full picture. If we ever suffered a breach that put you at risk, we would notify the ICO within 72 hours and tell you promptly and honestly.

Changes

If we change this policy in any meaningful way, we'll tell you in the app before the change takes effect, and keep the version history available on request.