← Back to home

Privacy Policy

Effective 12 June 2026

1. Who we are

GrumpyWhales (“we”, “us”, “our”) provides a free, web-based invoicing tool for UK freelancers, sole traders and small businesses, available at grumpywhales.com. We are the data controller for personal data you give us when you create an account and use the service. For data you upload about your own clients (their names, emails, billing addresses) we act as a processor on your behalf, and you remain the controller of that data.

For questions about this policy or to exercise your rights, email privacy@grumpywhales.com.

2. What personal data we collect

  • Account data: your name, email address, and (if you set a password) a salted bcrypt hash of that password.
  • Google sign-in: if you sign in with Google, we receive your Google email, name and profile picture URL via Google OAuth.
  • Business details: any company name, VAT registration number and business address you choose to add to your profile so they appear on invoices.
  • Client records: the names, emails and addresses of the clients you invoice, which you provide.
  • Invoice data: the invoices you create — amounts, line items, descriptions, dates, payment references.
  • Payment data (Stripe): if you pay for an event by card, Stripe processes the card transaction and returns to us a payment intent identifier and the paid status. We never see or store your full card number, CVC or expiry date — these stay with Stripe.
  • Email activity: the email address invoices and chase emails are sent to, the Resend message ID, the timestamp, and (when available) whether the email was opened.
  • Technical data: IP address, browser user agent, pages viewed (via Google Analytics 4 with IP anonymisation).
  • Cookies: a session cookie for authentication (essential) and a Google Analytics cookie (analytics).

3. Why we use it (lawful basis — UK GDPR Article 6)

PurposeLawful basis
Creating and managing your account; letting you log inPerformance of a contract with you
Sending invoices and chase emails to your clients on your instructionPerformance of a contract with you
Processing card payments for paid events via StripePerformance of a contract with you
Keeping the service secure (rate-limiting, abuse detection, error logs)Our legitimate interest in operating a secure service
Anonymised product analyticsOur legitimate interest in improving the product
Responding to legal requestsLegal obligation

4. Card payments — what Stripe does on our behalf

Paid events are processed by Stripe Payments UK, Ltd, an FCA-authorised electronic money institution. When you click Pay, you're redirected to Stripe's hosted checkout where you enter your card details. Those details never touch GrumpyWhales servers — Stripe handles them under PCI-DSS Level 1 compliance.

  • We receive from Stripe only: a payment intent identifier, the paid amount and currency, and the paid timestamp.
  • Refunds are arranged directly between you and the event host; GrumpyWhales doesn't hold or move funds.
  • Stripe's own privacy notice: stripe.com/gb/privacy.

5. Who we share data with (third-party processors)

We use the following processors to run the service. Each is bound by a data processing agreement and only uses data on our instructions:

ProcessorPurposeLocation
Vercel Inc.Hosting the applicationEU / United States (SCC-protected transfer)
Supabase Inc.Storing accounts, invoices and transactionsEuropean Union (Frankfurt region)
Stripe Payments UK, Ltd.Card payment processingUnited Kingdom / United States (SCC-protected transfer)
Resend, Inc.Delivering invoice and reminder emailsEuropean Union
Google LLCOptional OAuth sign-in and anonymised analyticsUnited States (SCC-protected transfer)

Where data is transferred outside the UK / EEA, we rely on the UK Addendum to the EU Standard Contractual Clauses.

6. How long we keep your data

  • Account, invoices, clients: while your account is active. After you close your account, we retain accounting-relevant records for 6 years to comply with UK accounting and tax-record obligations (Companies Act 2006 / HMRC).
  • Bank access tokens: deleted immediately on disconnect; in any case within 30 days.
  • Payment records: the payment intent identifier, amount and timestamp for each paid session, kept for 6 years for UK tax record-keeping.
  • Email send logs: 12 months.
  • Server logs (IP, user agent): 30 days.

7. Your rights

Under the UK GDPR you have the right to:

  • Ask us for a copy of the personal data we hold about you (right of access).
  • Correct anything that's wrong (right to rectification).
  • Ask us to delete your data (right to erasure / right to be forgotten), subject to legal retention requirements.
  • Receive your data in a portable format (right to data portability).
  • Object to or restrict processing.
  • Withdraw consent at any time, where we rely on consent.
  • Complain to the Information Commissioner's Office at ico.org.uk if you believe we've mishandled your data.

To exercise any of these rights, email privacy@grumpywhales.com. We respond within 30 days.

8. Cookies

We use one essential cookie to keep you signed in (NextAuth session), and one analytics cookie set by Google Analytics 4 to measure aggregate usage. The analytics cookie does not include personally identifying information and IPs are anonymised before processing. We do not run any advertising cookies.

9. Security

Data is encrypted in transit (TLS 1.2+) and at rest. Passwords are hashed with bcrypt. Bank access tokens are only readable by our server-side service role and are never sent to the browser. Access to production data is limited to GrumpyWhales personnel under audited credentials.

10. Children

The service is not directed at people under 18. We do not knowingly collect data from minors.

11. Changes to this policy

If we change this policy in a way that meaningfully affects you, we'll email you and post a notice in the app. The “Effective” date at the top will always show when this policy was last revised.