Privacy Policy
This policy explains how Cratebooks handles personal data when you visit our site, create an account, import and organise records, pay for a subscription, create exports or use direct HMRC filing.
The essentials. Your original CSV or supported PDF statement is parsed in your browser and the file itself is never uploaded. The transaction rows it contains (date, description, amount) are sent to your account so they can be categorised, and you then decide which to keep. Cratebooks does not connect to your bank or receive bank-login credentials. We do not sell personal data, use transaction data for advertising or move money. HMRC data is processed only when you choose the direct-filing workflow.
Who controls your data · What we collect · Purposes and legal bases · Who receives it · Retention · Your rights · Contact
1. Who we are and our role
Cratebooks is operated by Cratebooks Ltd, registered in England and Wales under company number 17325477. Our registered office is 10 Parham Road, Worthing, United Kingdom, BN14 0BL. Cratebooks Ltd is registered with the Information Commissioner's Office (registration reference ZC196409).
Cratebooks Ltd is the controller of personal data used to operate accounts, billing, security, support, product improvement and optional integrations. If you import personal data about another person in the course of your business, you are normally the controller of that data and we act as your processor. Section 9 of our Terms of Service contains the relevant processing terms.
Contact our privacy team at privacy@cratebooks.com.
2. The personal data we collect
Account and sign-in data
Your email address, account creation and verification status, a password hash if you use a password, sign-in method, session information, security settings, and the version and time of any recorded Terms acceptance. If you choose Google, Apple or Microsoft sign-in where offered, we receive the account details needed to identify and sign you in. We never store a readable copy of your password.
Imported records and your decisions
The transaction rows contained in the statements you import, including dates, amounts, merchant or payer labels, statement description text and source filename. Every row in a statement is sent for categorisation and stored, including rows you afterwards set aside as personal or non-business; setting a row aside records that decision rather than removing the row. We also store your keep, bin, category, business-use percentage, mileage, accounting settings and learned merchant decisions. You can delete an imported statement, and its rows, at any time.
Your original CSV or supported PDF file is parsed locally in your browser and is not uploaded. Statement text may contain names or information about other people. Please remove irrelevant personal information before import where you reasonably can.
PDF import diagnostics
After a PDF import attempt, we receive limited diagnostic data so we can identify bank layouts that fail without receiving the statement itself. This may include a SHA-256 file fingerprint used to link repeat attempts, parser version, success or error outcome, a restricted error code, a coarse bank name selected from a fixed list, page and row counts, balance-check counts, unresolved-sign counts and future-date counts. It does not contain the filename, statement text, transaction descriptions, dates, amounts or balances. A fingerprint is not used to reconstruct the file.
Payments and communications
Your Stripe customer reference, subscription status, purchase and refund information, and messages you send us. Stripe receives and processes your payment-card details. Cratebooks does not receive your full card number or security code.
Device, usage and security data
IP address, request time, browser and device information, security events, error diagnostics and rate-limit records. Sentry is configured to remove request bodies, cookies, query strings, environment details and user identity from error reports. We do not intentionally send transaction data to Sentry.
Direct HMRC filing data
If you choose direct HMRC filing, we process your encrypted National Insurance number, encrypted HMRC OAuth tokens, business and obligation details returned by HMRC, the period figures you instruct us to send, submission payloads and timestamps, calculation identifiers, status and HMRC correlation receipts. HMRC OAuth means Cratebooks does not receive your Government Gateway password.
HMRC also requires compatible software to send fraud-prevention information. For this web service, this may include an installation-specific device identifier, public IP address and time, timezone, screen and window size, browser user-agent and a reference showing that multi-factor authentication took place. We collect it only for the HMRC workflow and send it only where required for an HMRC API request.
How we obtain it
We obtain data from you, your browser or device, enabled integrations such as Stripe, WorkOS and HMRC, automatically from your use of the service, and from public or commercial business directories where we conduct lawful business outreach.
3. Why we use personal data and our legal bases
- Provide the service and support: account administration, statement import, categorisation, storage, checks, exports and user-instructed HMRC submissions. Our basis is performance of our contract with you.
- Take and administer payment: our basis is contract. We use legal obligation where we must keep tax, accounting or transaction records.
- Secure and improve Cratebooks: preventing fraud and abuse, diagnosing faults, monitoring reliability and protecting users. Our basis is our legitimate interests in operating a safe and effective service.
- Diagnose statement imports: using the limited PDF diagnostic data described above to identify parser failures and repeated attempts. Our basis is our legitimate interests in maintaining a reliable import service while minimising the financial data received.
- Meet HMRC fraud-prevention requirements: where the filing feature is used, our basis is compliance with legal obligations applying to compatible software and our legitimate interests in preventing fraud and maintaining access to HMRC services.
- Send service messages: verification, password reset, security, billing and material service notices. Our basis is contract and our legitimate interests in administering the service.
- Send marketing: with consent, under the electronic-mail soft opt-in, or to corporate subscribers where the Privacy and Electronic Communications Regulations permit. Our UK GDPR basis is consent where used and otherwise our legitimate interest in marketing a relevant business service. Every marketing message will offer an unsubscribe route. Service messages are not marketing.
- Establish or defend legal claims and comply with law: our basis is legal obligation or our legitimate interests in protecting our legal rights.
Choosing a file to import is an instruction under our contract, not data-protection consent. Where we rely on consent for a separate purpose, you may withdraw it at any time without affecting earlier lawful processing.
Business outreach
We may use a practice name, business address, professional role, work email address and source information to contact accountancy or bookkeeping practices about Cratebooks. Our UK GDPR basis is our legitimate interest in marketing a relevant business service. Before using a new source or campaign, we assess necessity, reasonable expectations and privacy impact. We comply separately with the Privacy and Electronic Communications Regulations. We may email corporate subscribers such as limited companies and LLPs without prior consent where permitted, but we do not send unsolicited marketing email to sole traders or ordinary partnerships unless we have valid consent or another PECR permission such as the soft opt-in.
Every marketing email identifies Cratebooks and provides a simple way to object. You have an absolute right to object to direct marketing. We keep a minimal suppression record after an objection so we do not contact you again. Business outreach never uses a Cratebooks user's transaction or account data.
4. Community categorisation
Community sharing is enabled by default. We use a limited part of eligible users' categorisation activity to make merchant suggestions more useful. Before any shared suggestion is made available, Cratebooks reduces the source to a normalised merchant label and chosen category, combines decisions across a minimum number of unrelated users, and requires a defined consensus threshold. The shared map does not contain names, user or account identifiers, amounts, dates, balances, payment references, source filenames or free-text statement descriptions.
Our legal basis for creating the map is our legitimate interest in improving categorisation accuracy for users. We have balanced that interest against the limited data used, aggregation threshold and controls. You may object at any time by turning off community sharing in account settings. Your account's decisions are then excluded when the community map is next rebuilt and your future decisions are not contributed. An already aggregated suggestion may remain until that rebuild. Output that can no longer identify you is not personal data and cannot be separated back out by account.
5. Automated suggestions
Cratebooks uses rules and learned merchant patterns to suggest categories and flag possible issues. These suggestions do not make a decision that produces legal or similarly significant effects. You review the records and decide what to keep, exclude, categorise, export or submit.
6. Who receives personal data
We disclose only what is reasonably necessary to operate the relevant service:
- Hosting Render hosts the application and database. Render privacy information.
- Payments Stripe provides checkout, subscription and billing services. Stripe also acts as an independent controller for some payment and fraud-prevention processing. Stripe privacy information.
- Email Resend sends account and service emails. Resend privacy information.
- Sign-in WorkOS supports Google, Apple or Microsoft sign-in where offered and if you choose it. The identity provider and WorkOS may also process data under their own notices. WorkOS privacy information.
- Monitoring Sentry receives restricted technical diagnostics configured as described above. Sentry privacy information.
- Tax filing HM Revenue & Customs, when you instruct a connection or direct submission. HMRC is an independent controller for its use of data. HMRC and GOV.UK privacy information.
We may also disclose personal data to professional advisers under duties of confidentiality, law-enforcement or regulators where lawfully required, and a buyer or successor during a genuine financing, reorganisation or sale subject to appropriate confidentiality and data-protection safeguards. We do not sell personal data, disclose transaction data to advertisers or data brokers, or use transaction data to train a general-purpose artificial-intelligence model.
7. International transfers
Some providers may process data outside the UK. Where UK data-protection law requires a transfer safeguard, we use an adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to approved EU standard contractual clauses, or another lawful mechanism. We also assess supplementary technical and organisational protections where required. Contact us for information about the safeguard relevant to your data.
8. Security
We use measures appropriate to the nature of the service, including HTTPS in transit, provider-managed encryption at rest, password hashing, per-user access controls, login rate limiting, restricted error reporting and encryption of HMRC OAuth tokens, National Insurance numbers and multi-factor secrets. HMRC filing actions require an additional multi-factor step.
No online service can promise absolute security. You must use a strong unique password, keep your device and recovery methods secure, and tell us promptly at security@cratebooks.com if you suspect unauthorised access.
9. Personal data you import about other people
If your imported records include personal data about clients, suppliers, collaborators or other individuals, you confirm that you are entitled to process it and instruct us to do so. We process that customer-controlled data only to provide and secure the service, on your documented instructions, and as required by law. Our staff and suppliers are subject to confidentiality duties. We use subprocessors under written data-protection terms, assist with relevant data-subject and security obligations where reasonably possible, and delete or return the data at the end of service except where law requires retention.
Cratebooks is not designed to collect health, religious, political, trade-union, biometric, genetic, sexual-life or criminal-offence information. We do not intentionally infer or use such information from transaction text. Please redact or avoid importing it where it is not necessary for your bookkeeping and do not upload it unless you have a valid legal basis and condition to do so.
10. How long we keep data
- Account, imported records, settings and submission history: while the account is open, then deleted or irreversibly anonymised following account deletion unless a legal hold or statutory duty requires limited retention. Export anything you need before deleting the account.
- PDF import diagnostics: while the account is open or for a shorter period where no longer reasonably needed to diagnose the import service. They are deleted with the account.
- HMRC connection credentials: until you disconnect HMRC, delete the account, or the credential expires or is revoked. HMRC submission history is kept separately while the account remains open so you retain an audit trail after disconnecting HMRC.
- Contracts, invoices and payment records: normally up to six years after the relevant financial year or the end of our relationship, where needed for tax, accounting or legal claims.
- Security logs and support records: only for as long as reasonably necessary for security, support, dispute resolution and legal compliance, taking account of sensitivity and risk.
- Business outreach: until the contact is no longer relevant or you object. We retain a minimal suppression record for as long as reasonably necessary to honour an objection.
- Backups: deleted live data may remain temporarily in access-restricted backups until overwritten through the provider's normal backup cycle. It is not restored except for disaster recovery and will be deleted again following a restore.
Deleting an imported row does not remove anonymised community-map output that can no longer be linked back to you.
11. Browser storage and cookies
Cratebooks uses browser storage that is necessary to sign you in and remember settings such as theme, selected tax period, recent export summaries and guidance already shown. A sign-in token and account email are kept in local browser storage until you sign out or clear them. If HMRC filing is used, an installation-specific device identifier is also stored for HMRC fraud-prevention headers.
Short-lived, secure cookies may be used to protect third-party sign-in and HMRC authorisation redirects. We do not currently use advertising cookies or third-party analytics cookies. If that changes, we will provide any choice required by law before using non-essential storage.
12. Your data-protection rights
Depending on the circumstances, UK law gives you rights to:
- receive a copy of your personal data and information about its use;
- correct inaccurate or incomplete data;
- ask us to delete data;
- restrict processing;
- receive data you provided in a portable format;
- object to processing based on legitimate interests, including community categorisation;
- object at any time to direct marketing, after which we will stop using your personal data for that purpose;
- withdraw consent where consent is the basis; and
- complain to a supervisory authority.
These rights are not absolute. We may need to verify your identity and may retain information where law permits or requires it. We normally respond within one month. There is usually no fee.
Email privacy@cratebooks.com to exercise a right. You may also complain to the Information Commissioner's Office. We would appreciate the chance to address your concern first.
13. Children
Cratebooks is for people aged 18 and over using it for business purposes. It is not directed at children, and we do not knowingly collect children's data.
14. Changes to this policy
We may update this policy to reflect changes in law, providers or features. We will post the revised version and update the date above. If a change materially affects how we use existing personal data, we will give an appropriate additional notice and seek consent where law requires it.
15. Contact
Cratebooks Ltd
10 Parham Road
Worthing
United Kingdom
BN14 0BL
Email: privacy@cratebooks.com