Plain-English summary of how TactPay handles your data and your clients' data. Not legalese — just clear answers.
To do its job, TactPay needs the details you'd put on an invoice anyway: your clients' names and email addresses, invoice amounts and due dates, and any notes you add about the job. If you connect your email account, TactPay also reads the messages in the threads it creates — your chase reminders and any replies that come back — so it can spot when a client has responded or an email has bounced.
We don't ask for anything beyond what the product genuinely needs. No browsing history, no contact lists imported from your inbox, no selling of data to anyone.
Your data is used for one thing: sending and tracking chase reminders on your behalf. Client names and emails let us address the reminders properly. Invoice amounts and due dates tell us when to chase and how firm to be. Connected email threads let us pause chasing the moment a client replies, so nobody gets nagged twice. That's it — your data is never sold, shared with third parties, or used for advertising.
Your data is stored securely with a reputable cloud database provider. All communication between your browser, our servers, and the database is encrypted in transit using HTTPS/TLS. Data is hosted in [UK/EU data centres] — we'll confirm the exact region before this page goes live, so please treat that bracketed detail as a placeholder for now.
Access to your data is controlled by row-level security policies on the database — your invoices, clients and chase history are visible only to you and anyone you invite to your account. Email sending and reading is handled by Nylas, our email infrastructure provider, using secure OAuth connections — TactPay never sees or stores your email password.
Two providers process data on TactPay's behalf: Nylas handles email sending and reading (connected via secure OAuth, so we never see your password), and our cloud database provider stores your invoice and client data. We don't share your data with any other subprocessors.
Under GDPR, TactPay acts as a data processor for the invoice and client data you enter — you're the data controller, and you decide what goes in. You can request an export of all your data, or ask us to delete it, at any time by emailing support@tactpay.co.uk.
We keep your data only as long as your account is active, plus a reasonable period after cancellation so you can re-activate or retrieve it. The exact retention window is something we'll confirm before this goes live — please treat it as not yet finalised.
If anything here isn't clear or you'd like to exercise one of your rights, just contact us. This page is a plain-English summary — for detailed or formal requests, a full contact-us channel exists and we'll respond properly.
This is a plain-English summary, not a formal legal document. For detailed privacy requests or questions, contact us and we'll get back to you.