Privacy policy
How Get My Trader handles user information.
Last updated: 10 September 2026. This policy explains how we expect to collect and use information when customers post jobs and traders quote for work through Get My Trader.
Who is responsible for your information
GET MY TRADER LTD, registered in England and Wales under company number 17433323, operates Get My Trader and is the data controller for personal information processed through this marketplace. Our registered office is 5 Brayford Square, London, E1 0SG. Privacy enquiries and data-rights requests can be sent to support@getmytrader.co.uk.
Information we collect
When customers use Get My Trader, we may collect account details such as name, email address, phone number, postcode, job details, budget, contact preference, and uploaded job photos.
When traders apply, we may collect business name, contact name, email address, phone number, trade type, postcode, account status, public liability insurance certificates and expiry details, qualification and registration declarations, professional registration numbers, review notes and check dates, quotes sent, and related marketplace activity.
During account creation, we use your date of birth to check that you are at least 18. The date of birth is discarded during signup. We retain only that the check was passed and the date and time it was completed.
How we use information
We use information to create accounts, post jobs, match jobs with relevant traders, send quote updates, show accepted quote details, manage trader approvals, support users, and improve the service.
We use trader declarations and registration details to carry out manual checks, label checked registrations, restrict access to work that requires a checked registration, keep an audit record, and help prevent misleading claims.
We may use email notifications to let customers know when quotes are received and to let traders know about account or quote activity.
Our lawful bases
We process account, job, quote and message information because it is necessary to provide the service you request and perform our contract with you. We use legitimate interests for service security, fraud prevention, moderation, platform improvement and establishing or defending legal claims, after considering the effect on users.
We process information where necessary to comply with legal obligations. Where consent is the appropriate basis, you may withdraw it at any time without affecting earlier processing. We do not use consent where another lawful basis is more appropriate.
Digital platform tax reporting
Get My Trader does not currently collect or process payments for trade work. Customers pay traders directly, and we do not ordinarily know or record the final amount paid.
If applicable law requires Get My Trader to register as a reporting platform operator, carry out seller due diligence or report seller information to HM Revenue & Customs, we may need to collect and verify additional information such as a trader's legal identity, address, tax identification details, relevant transaction information and amounts paid or credited.
We would use that information to comply with our legal obligations and provide any legally required copy of the reported information to the trader. We will update this Privacy Policy and give affected traders appropriate notice before beginning any additional collection or reporting required for this purpose.
Sharing information
Customer contact details are not intended to be public. They may be shown to a trader after that trader has sent a quote, so the trader can discuss the job properly.
We do not sell personal information. We may use trusted service providers such as hosting, database, storage, and email delivery providers to run the platform.
Trader insurance certificates are stored privately and are available only to the trader and authorised administrators who need to review or manage them. Certificates are not shown to customers through the platform.
Service providers and international transfers
We use Vercel to host and deliver the website and run its server-side functions. Vercel may process request information such as IP address, device and browser details, URLs, timestamps, diagnostic logs and information submitted to a server-side function where this is necessary to provide, secure and troubleshoot the service.
We use Supabase for the database, account authentication and private file storage. Depending on how a person uses the marketplace, Supabase may hold account and contact details, authentication and security records, job, quote, message, review and moderation information, trader-check information and uploaded files.
We use Resend to deliver transactional and permitted marketing emails. Resend may process the recipient's email address, sender details, subject and message content, delivery status, timestamps and limited technical information needed to deliver, secure and troubleshoot the email.
We use Google Analytics 4 only after analytics-cookie consent. Google may receive an online identifier, cookie identifiers, approximate location derived from an IP address, device and browser information, page URLs and titles and interaction information. We must not send names, email addresses, phone numbers, job descriptions, precise addresses or other directly identifying information to Google Analytics. Advertising signals and ad personalisation are disabled in our tag configuration.
We use Meta Pixel only after marketing-cookie consent to measure visits and advertising results, build advertising audiences and improve Facebook and Instagram campaigns. Meta may receive page and referral URLs, browser and device information, IP-derived information, cookie identifiers and advertising-click information. We do not intentionally send names, contact details, job descriptions or information entered into forms through the Pixel.
Stripe is our intended payment provider if paid trader subscriptions are enabled. Stripe is not currently integrated and does not currently receive payment information from this website. Before enabling it, we will confirm the final payment flow and update this policy if necessary. Stripe would process payment, transaction, contact, billing, device and fraud-prevention information as an independent controller and/or processor under its applicable terms. Card information should be entered into Stripe's payment interface rather than stored by Get My Trader.
These suppliers and their approved subprocessors may process information in the United Kingdom, the European Economic Area, the United States and other countries where they operate. The privacy laws in those countries may differ from UK law.
For a restricted transfer, we use a lawful transfer mechanism appropriate to the destination and supplier. This may be UK adequacy regulations, including the UK Extension to the EU-US Data Privacy Framework where the relevant recipient is certified, or an Article 46 safeguard such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. Where required, we complete and document the applicable data-protection or transfer-risk assessment and consider supplementary technical and organisational measures such as encryption, access controls, data minimisation, retention limits and supplier reviews.
We enter into the applicable supplier data-processing terms, restrict each supplier to the information and purposes needed for its service, review material subprocessor changes and keep the transfer position under review. You may contact us for more information about a relevant supplier, destination or safeguard and, where available, request a copy of the safeguard with confidential information removed.
Trader insurance evidence
We use public liability insurance certificates, the expiry date supplied by the trader, and review records to decide whether a trader may access jobs and send quotes.
An authorised administrator makes the approval decision. If automated extraction is introduced later, it will only assist the review and will not approve, reject, or suspend a trader by itself.
Rejected and replaced insurance certificates are scheduled for deletion six years after the rejection or replacement. Approved certificates are scheduled for deletion six years after they expire. The private file and its database record are both deleted at the end of that period unless a documented legal, regulatory or safeguarding hold requires us to pause deletion.
Qualifications and registration checks
Traders confirm that they hold the qualifications, licences, registrations, permits and insurance legally required for the work they offer. We retain the declaration version and the date and time it was accepted.
Where registration details are provided, authorised administrators may check them against an official public register or evidence provided by the trader. We retain the registration number, status, check date, administrator responsible and limited review notes for account safety, audit, complaints and legal claims.
Checked registration details and their status may be shown to customers. Rejection notes and internal administrator information are not shown publicly.
Current registration details are kept while they are needed for the trader account. When Gas Safe, waste-carrier or electrical registration details are replaced, removed or superseded by a later decision, the previous verification record is kept in a restricted archive for six years and then deleted unless a documented legal, regulatory or safeguarding hold applies.
Photos and job content
Uploaded photos and job descriptions are used to help traders understand the work requested. Customers should avoid uploading sensitive documents or images that are not relevant to the job.
Job content may be visible to approved traders where it is needed for quote matching.
Job photos and message attachments are deleted when their related job, message or account is deleted. If a particular file is needed for an active report, dispute, fraud investigation or legal matter, only that identified file is moved to restricted evidence storage. We record the reason and review and deletion dates; ordinary uploads are not retained as evidence by default.
An automatic report hold is reviewed after six months and expires after twelve months unless a continuing, documented reason justifies a different period or legal hold. Evidence is deleted when the reason ends. Copies in supplier backups become unavailable and are overwritten through the applicable backup lifecycle.
Reports, moderation and blocking
When content or conduct is reported, we collect the reporter's account ID, the reported account, content type, reason, description, time, a snapshot of the reported content, its related job or quote, and the status and history of administrator decisions. We use this information to enforce our terms, protect users, investigate safety, fraud, legal and privacy concerns, handle complaints and appeals, and establish or defend legal claims.
Reporter identities and internal moderation notes are restricted to authorised administrators and are not ordinarily disclosed to the reported user. We may disclose information where required by law, to protect someone, or to cooperate with an appropriate authority. Reports are allegations and we take reasonable steps to distinguish them from established facts.
Blocking records identify the two accounts and when the block was created. Blocking prevents new messages but existing messages, images and relevant moderation evidence may be retained so we can investigate reports, handle disputes or appeals and meet legal or safety obligations.
Hidden content is not deleted merely because it is hidden. We keep moderation information only for as long as it is reasonably needed for the stated purpose, apply the documented retention schedule, and delete or anonymise it when it is no longer needed unless a legal hold or safeguarding obligation applies.
We process moderation and blocking information where necessary for our legitimate interests in operating a safe service, protecting users and preventing misuse, and where necessary to meet legal obligations.
Keeping information safe
We use account login, database permissions, storage rules, and admin controls to help protect platform data.
No online service can guarantee complete security, so users should keep passwords private and contact us if they think an account has been accessed incorrectly.
Your choices
Customers and traders can schedule account closure from Account settings. There is a 28-day cooling-off period during which the request can be cancelled. After that period, the active profile is deleted or anonymised and sign-in access is removed. You may also make an erasure request by email; requests are handled without undue delay and normally within one calendar month.
We review accounts that have not logged in for 24 months. If there is no active subscription or unresolved job, report, verification check, dispute or other matter, we send a service email giving at least 30 days to log in. A successful login keeps the account. If there is no response, the inactive profile is deleted or anonymised using the same restricted-retention process. If the warning cannot be delivered, automatic inactivity closure is not scheduled.
Information that is no longer needed is removed. A restricted copy of records necessary for disputes, fraud prevention, legal claims or tax may be kept for up to six years and is then deleted unless a documented legal hold applies. Retained records are not used as an active profile.
Depending on the circumstances, you may ask for access to your information, correction, erasure, restriction, portability, or object to processing. Where processing relies on consent, you may withdraw it. You may also complain to the Information Commissioner's Office at ico.org.uk, although we would appreciate the opportunity to address your concern first.
Cookies, analytics and advertising
We use technologies that are necessary for sign-in, security, core site functions and remembering cookie choices. Where the law permits these without consent, we use them only for those necessary purposes.
Google Analytics 4 is optional. Its tag is not requested or run unless a visitor actively accepts analytics cookies. Visitors can reject optional cookies as easily as accepting them and can later withdraw consent using the Cookie settings link in the site footer.
When analytics is permitted, we use aggregated usage information to understand visits, navigation and site performance. We configure the tag without Google advertising signals or ad personalisation and must not send names, contact information, job details or other directly identifying information to Google Analytics. More detail is in our Cookie policy.
Meta Pixel is optional. Its script is not requested and PageView events are not sent unless a visitor actively accepts marketing cookies. When permitted, it helps us measure Facebook and Instagram advertising and build advertising audiences. Visitors can withdraw consent at any time using Cookie settings.
Marketing emails
We send marketing emails only where a customer or trader has actively opted in. Marketing consent is optional, separate from accepting our terms, and is not required to use the service. Essential messages about accounts, jobs, quotes, reviews, security and legal notices are not marketing and are sent where needed to provide or protect the service.
We record who opted in, when and how they did so, and the wording shown at the time. You can change the preference in Account settings or use the unsubscribe link in any marketing email. Withdrawal takes effect immediately for future marketing messages.
We keep a minimal suppression record after an opt-out so that the address is not accidentally added back to marketing. Consent and withdrawal records are restricted and kept only for as long as needed to demonstrate and respect the preference or meet a documented legal requirement.
Email delivery records
When we send a service email, we keep a restricted delivery record containing the recipient address, subject, notification type, delivery status, provider reference or error, and relevant dates. This helps us investigate delivery problems and demonstrate important account communications.
For routine emails, the full rendered message, preview and operational metadata are removed after 30 days. The remaining delivery record is deleted after 12 months. A particular record may be kept longer only where it is necessary for a documented dispute, report, fraud investigation or legal matter; the reason and review date must be recorded and the hold removed when it is no longer justified.
Our email provider may keep its own delivery information under its contract and retention controls. We review those supplier settings and do not treat our internal 12-month schedule as automatically deleting a provider's separate records.
Before go-live
Supplier contracts, transfer safeguards, processing locations, subprocessor lists and the retention schedule must still be checked and recorded against the final live setup before launch. Stripe wording must be reviewed again when the final payment flow is enabled.
Privacy questions: support@getmytrader.co.uk