TaxMate

Privacy

How TaxMate uses your information.

Last updated: 20 August 2026

What information does TaxMate use?
TaxMate can process business names and types; income, expense, mileage, category, date and note records; tax-year adjustments; receipt images; backup files; partnership membership and shared records; and app preferences. Google sign-in supplies an account identifier and may supply your name, email and profile image. Billing records can include a Stripe customer identifier, subscription status, plan, renewal or cancellation status and promotion redemption. Support messages and limited technical diagnostics are also processed. Do not enter special-category information or another person’s information unless it is genuinely needed for your records and you are entitled to use it.
Why does TaxMate use it?
TaxMate uses account, bookkeeping, receipt, backup, sync, partnership and entitlement information to provide the service or take steps you request before a contract. Payment and accounting records are used to perform paid services and meet legal obligations. Necessary security, abuse-prevention, promotion-integrity and strictly minimised error diagnostics support the legitimate interests of protecting and operating TaxMate. Optional usage measurement is based on consent and is off unless you enable it. TaxMate does not sell personal information or use bookkeeping records for advertising.
Where is my data stored?
The app can work locally without an account; local records remain in your browser until you clear, reset or delete them. Signed-in personal records use Firebase Authentication, Cloud Firestore and Cloud Storage. The production Firestore database and server functions use the London region. Receipt Storage uses its configured United States location.
Who receives my data?
Google and Firebase process sign-in, app security checks, cloud records, receipts and server functions. Stripe processes checkout, payment methods, invoices and subscriptions; TaxMate does not receive complete card details. Sentry processes minimised error reports. If you opt in, Google Analytics 4 processes a small approved set of value-free usage events. Namecheap forwards messages sent to the support address and Microsoft Outlook is the destination mailbox service. Browsers also connect to Google Fonts and software content-delivery networks for app assets. Professional advisers, regulators, courts or law-enforcement bodies may receive information where necessary and lawful.
How long is it kept?
Local data remains until you remove it. Active-account cloud records remain while the account is used. Provider backups, logs, fraud-prevention records and legally required transaction records may remain for limited provider-defined or legally required periods.
How do I delete my data?
Use Delete all my data for the authenticated deletion workflow. This removes the personal Firestore tree, receipt objects, promotion-redemption records, TaxMate’s Stripe customer object and Firebase Auth identity. If a partnership has another member, shared records remain for them and your membership is removed; if you are the last member, the partnership is deleted. A deletion request is complete only when the app reports server-side success.
What are my privacy rights?
You can use TaxMate locally, correct records, export JSON, export a full ZIP containing available receipt binaries, withdraw analytics consent and request deletion. Depending on the lawful basis and circumstances, you may have rights of access, correction, erasure, restriction, objection and portability. You may object to processing based on legitimate interests by contacting TaxMate. Withdrawing consent does not affect earlier processing.
Who runs TaxMate & how do I contact them?
TaxMate UK (“TaxMate”) is a trading name used by Hau Ying Ou-Yang, a UK sole trader and the controller for this service. ICO registration: ZC174150. Email support@taxmate.uk. Public correspondence and contact address: Unit 170198, PO Box 7169, Poole, BH15 9EL. TaxMate has not appointed a data protection officer.
International transfers
Google, Stripe, Sentry and their subprocessors may process information in the UK, EEA, United States and elsewhere. Provider terms describe applicable adequacy arrangements, the UK Extension to the Data Privacy Framework and contractual safeguards such as the UK Addendum to standard contractual clauses. Contact TaxMate for further information about applicable safeguards.
Analytics & error reporting
Optional analytics is off by default and limited to approved value-free events. Error reports are minimised to remove account identity, bookkeeping values, business names, notes, receipt content and unnecessary request details. You can change analytics consent in Settings.
Complaints
Email support@taxmate.uk about privacy or to exercise a right. You may complain to the Information Commissioner’s Office. Material policy changes will be dated and communicated appropriately.