Privacy Policy
Last updated: 22 May 2026
This policy explains how Trade Copilot (“we”, “us”), a service operated by [FlowPilot UK legal entity name] (company no. [company number]), registered at [registered business address], handles personal data. We are registered with the UK Information Commissioner’s Office (ICO) under registration [ICO registration number].
Questions or requests about your data: hello@flowpilotuk.com.
Our two roles
We act in two different capacities, and which one applies affects your rights:
- Controller — for the data of tradespeople who sign up to use Trade Copilot (your account, business details and rates). This policy governs that data.
- Processor — when a tradesperson uses our tools to collect information about their customers (for example, an enquiry chat or a job brief). There, the tradesperson is the controller and we only process that data on their instructions. If you are a customer of a tradesperson, please direct data requests to them; we will assist them in responding.
What we collect
From tradespeople (account holders):
- Identity & contact: your name, email address, business name, phone, business address.
- Business settings: day rates, markups, pricing, VAT details, company logo.
- Quotes and projects you create.
From your customers, on your behalf (we are processor):
- Name, email, phone and postcode they provide.
- Job descriptions — typed, dictated (voice transcribed to text), or captured by chat.
- Photos they or you upload.
- Enquiry chat transcripts.
Technical:
- A hashed form of IP address, used only for rate-limiting and abuse prevention on public links.
- Essential authentication/session cookies (see Cookies below).
How we use data, and our legal basis
- To provide the service (create accounts, generate estimates and quotes, run the enquiry chat) — performance of a contract.
- AI processing of the inputs you provide (notes, photos, chat) to produce estimates and briefs — performance of a contract; see “AI processing” below.
- Service emails (quote delivery, enquiry notifications) — performance of a contract.
- Security, fraud and abuse prevention — legitimate interests.
- Product updates or marketing, if any — consent, which you can withdraw at any time.
AI processing
To turn your notes, photos and chat messages into structured estimates and briefs, we send those inputs to our AI provider, OpenAI, via their API. OpenAI processes the content to return a result and, under their API terms, does not use API data to train their models. Do not enter information you would not want processed this way. AI output is generated automatically and may contain errors — always review it before relying on or sending it.
Who we share data with (sub-processors)
We don’t sell your data. We use these trusted providers to run the service:
- Supabase — database, file storage and authentication.
- OpenAI — AI processing of inputs (see above).
- Vercel — application hosting.
- Resend — sending emails (quotes, notifications).
- Meta (WhatsApp Business) — optional WhatsApp notifications, only if you enable them.
International transfers
Some providers (for example OpenAI, Vercel and Resend) may process data outside the UK/EEA. Where they do, the transfer is protected by appropriate safeguards such as the UK International Data Transfer Agreement or Standard Contractual Clauses.
How long we keep it
- Account data — for as long as your account is active, then deleted or anonymised within [retention period, e.g. 12 months] of closure.
- Customer/enquiry data processed on a tradesperson’s behalf — kept per that tradesperson’s instructions and deleted on their request or on account closure.
- Hashed IP data — retained only briefly for rate-limiting.
Your rights
Under UK GDPR you can ask to access, correct, delete, restrict or port your data, and to object to certain processing. To exercise these, email hello@flowpilotuk.com. If your data is held by us on behalf of a tradesperson, we will pass your request to them as the controller.
You also have the right to complain to the ICO (ico.org.uk), though we’d appreciate the chance to put things right first.
Cookies
We use only essential cookies needed to keep you signed in. We do not use advertising or third-party tracking cookies. [Update this section if you add analytics such as PostHog.]
Children
Trade Copilot is a business tool not intended for, or directed at, anyone under 18.
Changes
We may update this policy; we’ll change the “last updated” date above and, for material changes, let account holders know.
Contact
[FlowPilot UK legal entity name] · [registered business address] · hello@flowpilotuk.com
See also our Terms of Service.