Legal

Privacy Policy

Last updated: 25 July 2026 · version 2026-07-25-v4

This policy explains how Cratebooks handles personal data when you visit our site, create an account, import and organise records, pay for a subscription, create exports or use direct HMRC filing.

The essentials. Your original CSV or supported PDF statement is parsed in your browser and the file itself is never uploaded. The transaction rows it contains (date, description, amount) are sent to your account so they can be categorised, and you then decide which to keep. Cratebooks does not connect to your bank or receive bank-login credentials. We do not sell personal data, use transaction data for advertising or move money. HMRC data is processed only when you choose the direct-filing workflow.

1. Who we are and our role

Cratebooks is operated by Cratebooks Ltd, registered in England and Wales under company number 17325477. Our registered office is 10 Parham Road, Worthing, United Kingdom, BN14 0BL. Cratebooks Ltd is registered with the Information Commissioner's Office (registration reference ZC196409).

Cratebooks Ltd is the controller of personal data used to operate accounts, billing, security, support, product improvement and optional integrations. If you import personal data about another person in the course of your business, you are normally the controller of that data and we act as your processor. Section 9 of our Terms of Service contains the relevant processing terms.

Contact our privacy team at privacy@cratebooks.com.

2. The personal data we collect

Account and sign-in data

Your email address, account creation and verification status, a password hash if you use a password, sign-in method, session information, security settings, and the version and time of any recorded Terms acceptance. If you choose Google, Apple or Microsoft sign-in where offered, we receive the account details needed to identify and sign you in. We never store a readable copy of your password.

Imported records and your decisions

The transaction rows contained in the statements you import, including dates, amounts, merchant or payer labels, statement description text and source filename. Every row in a statement is sent for categorisation and stored, including rows you afterwards set aside as personal or non-business; setting a row aside records that decision rather than removing the row. We also store your keep, bin, category, business-use percentage, mileage, accounting settings and learned merchant decisions. You can delete an imported statement, and its rows, at any time.

Your original CSV or supported PDF file is parsed locally in your browser and is not uploaded. Statement text may contain names or information about other people. Please remove irrelevant personal information before import where you reasonably can.

PDF import diagnostics

After a PDF import attempt, we receive limited diagnostic data so we can identify bank layouts that fail without receiving the statement itself. This may include a SHA-256 file fingerprint used to link repeat attempts, parser version, success or error outcome, a restricted error code, a coarse bank name selected from a fixed list, page and row counts, balance-check counts, unresolved-sign counts and future-date counts. It does not contain the filename, statement text, transaction descriptions, dates, amounts or balances. A fingerprint is not used to reconstruct the file.

Payments and communications

Your Stripe customer reference, subscription status, purchase and refund information, and messages you send us. Stripe receives and processes your payment-card details. Cratebooks does not receive your full card number or security code.

Device, usage and security data

IP address, request time, browser and device information, security events, error diagnostics and rate-limit records. Sentry is configured to remove request bodies, cookies, query strings, environment details and user identity from error reports. We do not intentionally send transaction data to Sentry.

Direct HMRC filing data

If you choose direct HMRC filing, we process your encrypted National Insurance number, encrypted HMRC OAuth tokens, business and obligation details returned by HMRC, the period figures you instruct us to send, submission payloads and timestamps, calculation identifiers, status and HMRC correlation receipts. HMRC OAuth means Cratebooks does not receive your Government Gateway password.

HMRC also requires compatible software to send fraud-prevention information. For this web service, this may include an installation-specific device identifier, public IP address and time, timezone, screen and window size, browser user-agent and a reference showing that multi-factor authentication took place. We collect it only for the HMRC workflow and send it only where required for an HMRC API request.

How we obtain it

We obtain data from you, your browser or device, enabled integrations such as Stripe, WorkOS and HMRC, automatically from your use of the service, and from public or commercial business directories where we conduct lawful business outreach.

3. Why we use personal data and our legal bases

Choosing a file to import is an instruction under our contract, not data-protection consent. Where we rely on consent for a separate purpose, you may withdraw it at any time without affecting earlier lawful processing.

Business outreach

We may use a practice name, business address, professional role, work email address and source information to contact accountancy or bookkeeping practices about Cratebooks. Our UK GDPR basis is our legitimate interest in marketing a relevant business service. Before using a new source or campaign, we assess necessity, reasonable expectations and privacy impact. We comply separately with the Privacy and Electronic Communications Regulations. We may email corporate subscribers such as limited companies and LLPs without prior consent where permitted, but we do not send unsolicited marketing email to sole traders or ordinary partnerships unless we have valid consent or another PECR permission such as the soft opt-in.

Every marketing email identifies Cratebooks and provides a simple way to object. You have an absolute right to object to direct marketing. We keep a minimal suppression record after an objection so we do not contact you again. Business outreach never uses a Cratebooks user's transaction or account data.

4. Community categorisation

Community sharing is enabled by default. We use a limited part of eligible users' categorisation activity to make merchant suggestions more useful. Before any shared suggestion is made available, Cratebooks reduces the source to a normalised merchant label and chosen category, combines decisions across a minimum number of unrelated users, and requires a defined consensus threshold. The shared map does not contain names, user or account identifiers, amounts, dates, balances, payment references, source filenames or free-text statement descriptions.

Our legal basis for creating the map is our legitimate interest in improving categorisation accuracy for users. We have balanced that interest against the limited data used, aggregation threshold and controls. You may object at any time by turning off community sharing in account settings. Your account's decisions are then excluded when the community map is next rebuilt and your future decisions are not contributed. An already aggregated suggestion may remain until that rebuild. Output that can no longer identify you is not personal data and cannot be separated back out by account.

5. Automated suggestions

Cratebooks uses rules and learned merchant patterns to suggest categories and flag possible issues. These suggestions do not make a decision that produces legal or similarly significant effects. You review the records and decide what to keep, exclude, categorise, export or submit.

6. Who receives personal data

We disclose only what is reasonably necessary to operate the relevant service:

We may also disclose personal data to professional advisers under duties of confidentiality, law-enforcement or regulators where lawfully required, and a buyer or successor during a genuine financing, reorganisation or sale subject to appropriate confidentiality and data-protection safeguards. We do not sell personal data, disclose transaction data to advertisers or data brokers, or use transaction data to train a general-purpose artificial-intelligence model.

7. International transfers

Some providers may process data outside the UK. Where UK data-protection law requires a transfer safeguard, we use an adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to approved EU standard contractual clauses, or another lawful mechanism. We also assess supplementary technical and organisational protections where required. Contact us for information about the safeguard relevant to your data.

8. Security

We use measures appropriate to the nature of the service, including HTTPS in transit, provider-managed encryption at rest, password hashing, per-user access controls, login rate limiting, restricted error reporting and encryption of HMRC OAuth tokens, National Insurance numbers and multi-factor secrets. HMRC filing actions require an additional multi-factor step.

No online service can promise absolute security. You must use a strong unique password, keep your device and recovery methods secure, and tell us promptly at security@cratebooks.com if you suspect unauthorised access.

9. Personal data you import about other people

If your imported records include personal data about clients, suppliers, collaborators or other individuals, you confirm that you are entitled to process it and instruct us to do so. We process that customer-controlled data only to provide and secure the service, on your documented instructions, and as required by law. Our staff and suppliers are subject to confidentiality duties. We use subprocessors under written data-protection terms, assist with relevant data-subject and security obligations where reasonably possible, and delete or return the data at the end of service except where law requires retention.

Cratebooks is not designed to collect health, religious, political, trade-union, biometric, genetic, sexual-life or criminal-offence information. We do not intentionally infer or use such information from transaction text. Please redact or avoid importing it where it is not necessary for your bookkeeping and do not upload it unless you have a valid legal basis and condition to do so.

10. How long we keep data

Deleting an imported row does not remove anonymised community-map output that can no longer be linked back to you.

11. Browser storage and cookies

Cratebooks uses browser storage that is necessary to sign you in and remember settings such as theme, selected tax period, recent export summaries and guidance already shown. A sign-in token and account email are kept in local browser storage until you sign out or clear them. If HMRC filing is used, an installation-specific device identifier is also stored for HMRC fraud-prevention headers.

Short-lived, secure cookies may be used to protect third-party sign-in and HMRC authorisation redirects. We do not currently use advertising cookies or third-party analytics cookies. If that changes, we will provide any choice required by law before using non-essential storage.

12. Your data-protection rights

Depending on the circumstances, UK law gives you rights to:

These rights are not absolute. We may need to verify your identity and may retain information where law permits or requires it. We normally respond within one month. There is usually no fee.

Email privacy@cratebooks.com to exercise a right. You may also complain to the Information Commissioner's Office. We would appreciate the chance to address your concern first.

13. Children

Cratebooks is for people aged 18 and over using it for business purposes. It is not directed at children, and we do not knowingly collect children's data.

14. Changes to this policy

We may update this policy to reflect changes in law, providers or features. We will post the revised version and update the date above. If a change materially affects how we use existing personal data, we will give an appropriate additional notice and seek consent where law requires it.

15. Contact

Cratebooks Ltd
10 Parham Road
Worthing
United Kingdom
BN14 0BL

Email: privacy@cratebooks.com