Privacy Policy
Last updated: 20 May 2026
MyAllBuilder Ltd ("we", "us", "our") is the controller of the personal data we collect through www.myallbuilder.uk (the "Platform"). This Privacy Policy explains what data we collect, why we collect it, how we use it, and your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
MyAllBuilder is a UK platform connecting clients with verified tradespeople for home improvement, repair and construction projects. If you have questions about this policy, contact us at privacy@myallbuilder.uk.
2. What data we collect
Depending on how you use the Platform, we may collect:
- Account data: name, email, phone, password (hashed), profile photo, role (client or tradesperson).
- Job data: job descriptions, photos, location (postcode), budget, timeline.
- Tradesperson data: business name, certifications (Gas Safe, Part P, NICEIC, FENSA, DBS), insurance details, portfolio, service area.
- Communications: messages exchanged between clients and tradespeople via our messaging system.
- Financial data: payment records, invoices, payout details. Card details are processed by Stripe and never stored by us.
- Reviews and ratings: written reviews and ratings submitted after job completion.
- Technical data: IP address, browser type, device information, login timestamps.
- Cookies: see our Cookies Policy for details.
3. How we use your data
We process your data on the following lawful bases under UK GDPR:
- Contract performance: creating your account, matching jobs to tradespeople, processing payments, handling disputes.
- Legitimate interests: platform security, fraud prevention, service improvement, anonymised analytics.
- Legal obligation: tax, accounting, and consumer protection laws (e.g. Consumer Rights Act 2015).
- Consent: marketing emails — you can withdraw consent at any time in your account settings.
4. Sharing your data
We share data only when necessary:
- Other platform users: when you post a job, your first name, postcode area (not full postcode) and job details are visible to tradespeople. Full contact details are revealed only after you accept a quote.
- Service providers: Stripe (payments), Resend (email), MongoDB Atlas (hosting), Google Maps (geocoding). Each is bound by data processing agreements.
- Verification bodies: Companies House, Gas Safe Register and similar — only data you provide for verification.
- Legal requirements: when required by law, court order, or to prevent fraud.
We do not sell your personal data.
5. International transfers
Some service providers may process data outside the UK (typically in the EU or US). Where this happens, we rely on UK adequacy decisions or Standard Contractual Clauses approved by the UK Information Commissioner's Office (ICO).
6. How long we keep your data
- Active accounts: for as long as your account is open.
- Deleted accounts: personal details are anonymised within 30 days. Completed jobs, payments and reviews are retained for 6 years for tax and consumer protection compliance.
- Marketing data: deleted within 30 days of withdrawing consent.
- Audit logs: retained for 7 years for legal compliance and fraud investigation.
7. Your rights under UK GDPR
You have the right to:
- Access a copy of your personal data — available via "Download My Data" in your account settings.
- Rectify inaccurate data — update directly in your account.
- Erase your data ("right to be forgotten") — via "Delete My Account" in settings, subject to legal retention requirements.
- Restrict or object to processing in certain circumstances.
- Portability — export your data in machine-readable JSON format.
- Withdraw consent for marketing at any time.
- Lodge a complaint with the ICO at ico.org.uk or by calling 0303 123 1113.
8. Security
We implement industry-standard security measures: encrypted connections (HTTPS), hashed passwords (bcrypt), restricted database access, regular security audits and rate limiting on sensitive endpoints. No system is 100% secure, but we work to protect your data with the care it deserves.
9. Children
The Platform is not intended for users under 18. We do not knowingly collect data from anyone under 18. If you believe we have, contact us and we will delete it.
10. Changes to this policy
We may update this policy from time to time. Material changes will be notified to you by email or via a prominent notice on the Platform. The "Last updated" date at the top of this page indicates when it was most recently revised.
11. Contact
For any privacy-related questions or to exercise your rights, contact our Data Protection contact at privacy@myallbuilder.uk or via our contact form.