Privacy policy

Last updated: April 2026.

Data controller and contact information

For the purposes of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR), the data controller is:

Registered or postal address: we do not publish a postal address on this page. If you need it for formal notices or to exercise your rights, email support@landlordsorted.co.uk and we will provide it where appropriate.

We are established in the United Kingdom. Enquiries about our processing should be sent to the contact email above. If we appoint an EU representative under Article 27 GDPR, their name and contact details will be added to this policy.

Data Protection Officer (DPO): we are not required to appoint a DPO under UK GDPR for our current processing. For all privacy and data-protection questions, including exercising your rights, contact support@landlordsorted.co.uk.

You have the right to lodge a complaint with the UK supervisory authority, the Information Commissioner's Office (ICO): ico.org.uk/make-a-complaint.

What we process

  • Account data: email, name, and authentication data held by our auth provider (Supabase) when you sign up or sign in.
  • Product data: information you enter in the app (properties, ledger entries, rent ledger, compliance dates, submissions metadata, etc.) stored in our database.
  • Receipt images from the scan flow are stored on your device (IndexedDB) unless and until we offer cloud storage — check the in-app notice when you use the feature.
  • HMRC connection: OAuth tokens needed to submit Making Tax Digital updates are held according to our integration design — treat Government Gateway credentials as highly sensitive.
  • Billing: if you subscribe, Stripe processes card data; we receive subscription status from Stripe, not your full card number.
  • Emails: transactional email (e.g. welcome) may be sent via Resend; auth-related messages may also be sent by Supabase where you use email sign-in.
  • OCR: if you use receipt scanning with cloud OCR enabled, the image is sent to the configured provider (e.g. Google Cloud Vision) under their terms.

Services and technologies (subprocessors)

The list below names third parties that may receive, host, or otherwise process personal data on our instructions or alongside our service (for example authentication, payments, hosting, or optional analytics). It also covers technologies that may set cookies or similar identifiers when you use those features. We do not use social-network “Like” or “Share” widgets, Facebook Login, or similar embedded buttons that load third-party tracking for marketing on our pages. If we add an integration that collects personal data through a widget or embed, we will update this policy and, where the law requires it, obtain your consent first. Each entry links to the provider's privacy information (and cookie or opt-out pages where they publish them). If we add or replace a provider, we will update this policy.

Sign-up, waitlist, and contact forms

When you create an account, we collect the information you submit (such as email and name) and authentication data processed by Supabase as described above. That processing is necessary to perform our contract with you and to secure your account. If you join a waitlist or use our contact form, we process the details you provide (for example email and message content) to respond to your request or to keep you informed about the product where you have asked us to. We do not use those submissions for unrelated marketing unless we have a lawful basis and, where required, your clear consent.

Marketing

We may send service and transactional messages (for example sign-up confirmations, security, or billing notices) without separate marketing consent, where permitted. If we send promotional emails or similar marketing, we will do so in line with applicable law (including offering a clear way to opt out, such as an unsubscribe link in the message). You can also contact support@landlordsorted.co.uk to object to marketing at any time.

Analytics, logs, and product improvement

Where enabled, Google Analytics 4 is used only after you accept non-essential cookies on our cookie banner (see our Cookie policy). Our servers and hosting providers may generate technical and security logs (such as IP address, user agent, and timestamps) when you use the site; we use these for operating the service, security, and troubleshooting. We may also analyse aggregated or pseudonymous product usage derived from data you enter in the app to improve features, subject to this policy and our legal bases below.

Records of consent (cookies and similar technologies)

When optional analytics is available on this site, your choice on our cookie banner (Reject or Accept) is stored in your browser under a single localStorage key, together with a timestamp of when the choice was saved, so you can see when consent was last updated on that device. That record stays on your device unless you clear site data or use Cookie settings to change your mind (see the Cookie policy). We do not synchronise that record to a separate commercial “consent database” or consent management platform by default; if you need centralised consent logs for your organisation beyond what the browser stores, contact us to discuss options. Withdrawing or changing consent for analytics does not by itself delete account data held for providing the service — use account settings or contact us for erasure requests.

Legal bases (UK GDPR)

We process data to perform our contract with you (providing the service), for legitimate interests (security, abuse prevention, product improvement), and where required for legal obligations. Marketing, if any, will be opt-in where the law requires it.

Retention

We keep account and product data while your account is active. After you delete your account or ask us to erase data, we delete or anonymise personal data within a reasonable period, subject to legal retention needs (e.g. tax or fraud records).

Your rights

You may have rights to access, rectify, erase, restrict, or object to processing, to withdraw consent where processing is based on consent, and to data portability where applicable. You may complain to the ICO (UK) — see the link under Data controller and contact information above. To exercise rights, contact us at the email above; we may need to verify your identity. For cookie and analytics consent specifically, you can change or withdraw your choice as described in our Cookie policy (for example via Cookie settings in the footer).

Cookies

We use cookies and similar storage needed for sign-in, preferences, and security. Where Google Analytics 4 is enabled for our deployment, it and other non-essential measurement scripts are not loaded until you choose Accept on our cookie banner (our app does not request GA4 JavaScript from Google before that point). See the full Cookie policy for categories, third-party links, and how to change your choice. You can also use your browser settings to block or clear storage.

International transfers

Subprocessors listed above may process data outside the UK or EEA (for example in the United States). Where required, we rely on appropriate safeguards such as the UK Addendum or EU standard contractual clauses, as offered by those providers.

Children

LandlordSorted is not directed at children under 13.

Changes

We may update this policy; the “Last updated” date will change and we will post the revision here.

Not sure if this applies to you?

Answer a few plain-English questions — about 60 seconds.

Check if you need MTD