Privacy Policy
Effective 12 June 2026
1. Who we are
GrumpyWhales (“we”, “us”, “our”) provides a free, web-based invoicing tool for UK freelancers, sole traders and small businesses, available at grumpywhales.com. We are the data controller for personal data you give us when you create an account and use the service. For data you upload about your own clients (their names, emails, billing addresses) we act as a processor on your behalf, and you remain the controller of that data.
For questions about this policy or to exercise your rights, email privacy@grumpywhales.com.
2. What personal data we collect
- Account data: your name, email address, and (if you set a password) a salted bcrypt hash of that password.
- Google sign-in: if you sign in with Google, we receive your Google email, name and profile picture URL via Google OAuth.
- Business details: any company name, VAT registration number and business address you choose to add to your profile so they appear on invoices.
- Client records: the names, emails and addresses of the clients you invoice, which you provide.
- Invoice data: the invoices you create — amounts, line items, descriptions, dates, payment references.
- Payment data (Stripe): if you pay for an event by card, Stripe processes the card transaction and returns to us a payment intent identifier and the paid status. We never see or store your full card number, CVC or expiry date — these stay with Stripe.
- Email activity: the email address invoices and chase emails are sent to, the Resend message ID, the timestamp, and (when available) whether the email was opened.
- Technical data: IP address, browser user agent, pages viewed (via Google Analytics 4 with IP anonymisation).
- Cookies: a session cookie for authentication (essential) and a Google Analytics cookie (analytics).
3. Why we use it (lawful basis — UK GDPR Article 6)
| Purpose | Lawful basis |
|---|---|
| Creating and managing your account; letting you log in | Performance of a contract with you |
| Sending invoices and chase emails to your clients on your instruction | Performance of a contract with you |
| Processing card payments for paid events via Stripe | Performance of a contract with you |
| Keeping the service secure (rate-limiting, abuse detection, error logs) | Our legitimate interest in operating a secure service |
| Anonymised product analytics | Our legitimate interest in improving the product |
| Responding to legal requests | Legal obligation |
4. Card payments — what Stripe does on our behalf
Paid events are processed by Stripe Payments UK, Ltd, an FCA-authorised electronic money institution. When you click Pay, you're redirected to Stripe's hosted checkout where you enter your card details. Those details never touch GrumpyWhales servers — Stripe handles them under PCI-DSS Level 1 compliance.
- We receive from Stripe only: a payment intent identifier, the paid amount and currency, and the paid timestamp.
- Refunds are arranged directly between you and the event host; GrumpyWhales doesn't hold or move funds.
- Stripe's own privacy notice: stripe.com/gb/privacy.
5. Who we share data with (third-party processors)
We use the following processors to run the service. Each is bound by a data processing agreement and only uses data on our instructions:
| Processor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Hosting the application | EU / United States (SCC-protected transfer) |
| Supabase Inc. | Storing accounts, invoices and transactions | European Union (Frankfurt region) |
| Stripe Payments UK, Ltd. | Card payment processing | United Kingdom / United States (SCC-protected transfer) |
| Resend, Inc. | Delivering invoice and reminder emails | European Union |
| Google LLC | Optional OAuth sign-in and anonymised analytics | United States (SCC-protected transfer) |
Where data is transferred outside the UK / EEA, we rely on the UK Addendum to the EU Standard Contractual Clauses.
6. How long we keep your data
- Account, invoices, clients: while your account is active. After you close your account, we retain accounting-relevant records for 6 years to comply with UK accounting and tax-record obligations (Companies Act 2006 / HMRC).
- Bank access tokens: deleted immediately on disconnect; in any case within 30 days.
- Payment records: the payment intent identifier, amount and timestamp for each paid session, kept for 6 years for UK tax record-keeping.
- Email send logs: 12 months.
- Server logs (IP, user agent): 30 days.
7. Your rights
Under the UK GDPR you have the right to:
- Ask us for a copy of the personal data we hold about you (right of access).
- Correct anything that's wrong (right to rectification).
- Ask us to delete your data (right to erasure / right to be forgotten), subject to legal retention requirements.
- Receive your data in a portable format (right to data portability).
- Object to or restrict processing.
- Withdraw consent at any time, where we rely on consent.
- Complain to the Information Commissioner's Office at ico.org.uk if you believe we've mishandled your data.
To exercise any of these rights, email privacy@grumpywhales.com. We respond within 30 days.
8. Cookies
We use one essential cookie to keep you signed in (NextAuth session), and one analytics cookie set by Google Analytics 4 to measure aggregate usage. The analytics cookie does not include personally identifying information and IPs are anonymised before processing. We do not run any advertising cookies.
9. Security
Data is encrypted in transit (TLS 1.2+) and at rest. Passwords are hashed with bcrypt. Bank access tokens are only readable by our server-side service role and are never sent to the browser. Access to production data is limited to GrumpyWhales personnel under audited credentials.
10. Children
The service is not directed at people under 18. We do not knowingly collect data from minors.
11. Changes to this policy
If we change this policy in a way that meaningfully affects you, we'll email you and post a notice in the app. The “Effective” date at the top will always show when this policy was last revised.