Privacy Policy
SigeByte Ltd
ICO Registration: ZC181546
Version 2.3 · Effective date: 18 August 2026
The short version
- We collect only what we need to run the platform.
- We never sell your data. Ever.
- We share data with providers only to fulfil your booking, and with our service providers only so the platform works.
- Some sharing is required by law (for example, reporting provider earnings to HMRC) — we tell you exactly what and why.
- You can request your data, correct it, or ask us to delete what we no longer need and are not required to keep.
1. Who we are
SigeByte Ltd (Companies House 17282758), 12 Canberra House, Pitman Road, Cheltenham GL51 7UB. ICO registration ZC181546. Contact: support@sigebyte.co.uk.
2. What we collect
Customers: name and contact details; service address and postcode; job descriptions, photos and requirements; booking history, messages and dispute records; device and usage data.
Providers: name and contact details; business address and postcode; identity and right-to-work verification records; trade qualifications and registration numbers; insurance certificates; DBS certificates where required; National Insurance number (for legally required HMRC reporting only); your registered business address and chosen service radius — used to match jobs to your declared coverage area; and, while you are online and available for work, your live location — used to show your availability and how recently you were active, never to decide which jobs you are offered. We do not track your location when you are offline.
Business users: organisation name and type, contact details, booking and audit records.
3. Why we process it, and the lawful basis for each
Performing our contract with you: matching, bookings, payments via Stripe, booking documents, notifications, dispute handling.
Legal obligation: verifying providers’ right to work; retaining booking and financial records for tax law; reporting provider income and identification to HMRC under the Digital Platform Reporting rules (MRDP 2023, implementing DAC7). These are not optional and we do not rely on consent for them — we tell providers about them clearly at onboarding.
Legitimate interests: fraud prevention; platform security and improvement; the safety and traceability of work arranged through the platform; and establishing, exercising or defending legal claims — balanced against your rights.
Consent: marketing communications only. You can withdraw at any time and nothing else changes.
4. Automated pricing and matching
Pricing and matching on SigeByte are automated. Wilbert proposes prices from market data, job details and photos — you always see the price before you commit. Provider matching and ranking are automated and affect which Provider is offered a job first, taking into account things such as reliability, reviews, activity and distance.
How our systems work internally is SigeByte’s own technology and remains confidential. If an automated outcome significantly affects you, you may ask us about it and request human review — a human will review it.
5. Who we share data with
Providers: when you book, we share your name, service address, job description and contact details with your matched Provider, solely to fulfil the booking, and only after your booking is confirmed and paid. Providers are contractually prohibited from using it for anything else.
Stripe (payments): payment and booking information necessary to process transactions. Card details go directly to Stripe — we never store them.
OpenAI (Wilbert’s AI): the messages you exchange with Wilbert, job descriptions and requirements, and photos you submit for scoping — only what is needed to run the conversation, propose prices and generate booking documents. Processed under our signed Data Processing Agreement dated 26 June 2026 (OpenAI acts as our processor and does not use your data to train its models).
Supabase (database and storage): our database and secure document storage — account and booking data, and provider verification documents in private storage accessible only to SigeByte administrators.
Railway (backend hosting): runs our application backend; booking and account data is processed on its infrastructure on our behalf.
Vercel (website hosting): serves the website and frontend; processes technical data such as IP addresses and request logs.
The other party to your Booking: the record of a Booking — accepted scope and job card, photos, messages, variations, completion and payment status — is by its nature shared between the Customer and the Provider on that Booking. Where a party requests the Booking’s evidence record to resolve an issue or pursue a lawful claim (see section 7 of the Terms), we provide that record; it includes both parties’ Booking data. We only ever share what belongs to that Booking — never anyone’s wider history.
HMRC: provider income and identification information, reported annually as the law requires. NI numbers are encrypted at rest and used solely for this.
Legal authorities: where required by law or to protect user safety.
We never sell your data to anyone, ever.
6. How long we keep it
The law does not set a single deletion deadline. It requires that we keep personal data only for as long as it remains necessary for the purposes we have explained — and where it remains necessary and vital to those purposes, keeping it is lawful. Some periods below are minimums fixed by other laws; others are our own necessity-based periods, reviewed periodically.
- Booking and financial records: at least 7 years (tax law minimum).
- Provider verification and job-trail records (who was verified, and who attended which job): retained for as long as they remain necessary for the safety and traceability of work arranged through the platform and for establishing, exercising or defending legal claims. Traceability is a core safety promise of this platform — being able to say, even years later, who attended a job — and these records stay while that purpose remains.
- Dispute records: at least 7 years, and while relevant to any actual or reasonably anticipated claim.
- Wilbert (AI assistant) conversations: 90 days.
- Inactive customer accounts: 3 years, then deleted or anonymised.
- Inactive provider accounts: account data reviewed from 7 years after the last booking; verification and job-trail records remain subject to the necessity test above.
We review retained data periodically and delete or anonymise anything that is no longer necessary for a stated purpose.
7. Your rights
Under UK GDPR you can: access a copy of your data; correct it; ask us to delete what we no longer need and are not required to keep; object to or restrict certain processing; take your data elsewhere (portability); withdraw consent for marketing; and ask for human review of automated outcomes that significantly affect you. Contact support@sigebyte.co.uk. You can also complain to the ICO (ico.org.uk).
8. Cookies, security, transfers, children
Cookies: we use essential cookies and privacy-respecting analytics; details and choices are shown in the site’s cookie notice.
Security: row-level security on all database tables; private storage for sensitive documents; encrypted NI numbers; JWT-authenticated APIs; audit logging and monitoring.
International transfers: some processors store data outside the UK; where they do, transfers are protected by UK-approved safeguards (adequacy or standard contractual clauses).
Children: the platform is for users aged 18 and over.
9. Changes and contact
Material changes to this policy are notified by email and in-app with an effective date, mirroring the Terms. Questions: support@sigebyte.co.uk — SigeByte Ltd, 12 Canberra House, Pitman Road, Cheltenham GL51 7UB.
© 2026 SigeByte Ltd. All rights reserved.