Privacy Policy
Last updated: 2026-09-13
This policy explains what personal data BusyBee Hub collects, why, who we share it with, how long we keep it and the rights you have. It covers our website, the BusyBee Hub app and our support service.
1. Who we are
BusyBee Hub is provided by BusyBee Hub Ltd, a company registered in England and Wales with company number [COMPANY NUMBER], whose registered office is at [REGISTERED ADDRESS]. We're registered with the Information Commissioner's Office (ICO) under registration number [ICO REGISTRATION NUMBER].
For questions about this policy or your personal data, email support@busybeehub.co.uk or use our contact form with the topic "Data & privacy".
2. Our role
We're the controller of the personal data we use to run BusyBee Hub for you: your account, your subscription, your support conversations and the security and technical data described below.
When you keep information about other people in BusyBee Hub (for example your customers, suppliers, tenants or CIS contractors), you decide what's recorded and why. For that data, your business is the controller and we're your processor, acting on your instructions under our Data Processing Agreement.
3. The data we collect
Your account
- your first and last name, email address and password (stored only as a secure hash by our authentication provider)
- if you sign in with Google or Apple, the account identifier and email address they share with us
- two-factor authentication settings and hashed recovery codes
- the version of our Terms and Privacy Policy you accepted and when
- whether you opted in to marketing emails when you set up your business
Your business
- business name, business type and the settings you choose
- tax details you add, such as your National Insurance number, Unique Taxpayer Reference, VAT registration number and CIS status
- property details, including addresses, ownership share and co-owner names, purchase and sale prices
Your records
- invoices, estimates, credit notes, bills, expenses, payments, mileage, time entries, projects, journals and reports
- receipts, logos, bank statements and CIS statements you upload
- details of your customers, suppliers, tenants and contractors, such as names, company names, email addresses, phone numbers, addresses, VAT numbers, employer references and notes
Bank data
- if you connect a bank through TrueLayer: account names, the last 2 digits of the sort code and last 4 digits of the account number, balances, and transactions (date, amount, description, merchant and the other details your bank provides), plus when your consent expires
- if you import a CSV or PDF statement: the transactions and account details it contains
HMRC data
- your Making Tax Digital obligations, the updates, declarations and VAT returns you send and HMRC's responses, including the email address of the person who sent each one
- tax calculations, VAT liabilities and payments, CIS deductions, losses, and income HMRC holds for you, such as employment income (employer name and reference, pay and tax deducted), savings interest and dividends
Payments
- see section 10
Finble
- see section 11
Support
- when you contact us: your topic, name, email address, optional phone number and business type, your message and our replies, plus the IP address and browser information sent with the form
Security and technical data
- an activity log of sign-ins and important actions in your account, including IP address, browser information and the email address of the person who acted
- fraud prevention information HMRC requires us to send with each request we make to HMRC for you: a random device identifier stored in your browser, your IP address, time zone, screen and browser window size, browser details, your BusyBee Hub user ID and whether you signed in with two-factor authentication. We send this to HMRC and don't keep a copy of it.
- error reports when something goes wrong in the app, which we configure not to include personal details such as IP addresses or cookies
We don't use analytics or advertising cookies, and we don't sell your personal data.
4. How we use it and our lawful bases
- To provide BusyBee Hub (your account, records, bank feeds, HMRC connection, emails you send to your customers, and Finble): because it's necessary for our contract with you.
- To take payment for subscriptions and send service emails, such as trial reminders, payment notices, notifications and the weekly Radar digest: contract.
- To send your submissions to HMRC with the fraud prevention information it requires: legal obligation, and our contract with you.
- To keep BusyBee Hub secure, prevent fraud and abuse (including checking that sign-ups and contact form submissions come from people, not bots), keep an activity log and fix errors: our legitimate interests in running a safe, reliable service.
- To answer your support requests: contract, or our legitimate interests if you aren't a customer.
- To keep financial records about our own business and meet legal requests: legal obligation.
- To send marketing emails: your consent, which you can withdraw at any time by emailing us.
5. Who we share it with
We share personal data only as needed to provide BusyBee Hub, with:
- people in your organisation: team members see your business data according to their role; an accountant you invite sees everything, including your tax identifiers, and can file returns through your HMRC connection. You can remove anyone from Settings → Team at any time.
- HMRC: when you connect to HMRC and send an update, declaration or return, or when we fetch your obligations and calculations. HMRC is responsible for how it uses that information.
- your customers: when you send them an invoice, estimate or reminder, or they pay online.
- our BusyBee Hub support team: staff can view the account and organisation details they need to help you, such as members, subscription status and whether your HMRC and bank connections are working. They can't read your Finble conversations or see your National Insurance number, and staff actions such as suspending or deleting an account are recorded in our activity log.
- service providers who process data for us, listed in section 6.
- authorities, regulators or courts where the law requires it, and professional advisers under a duty of confidentiality.
- a buyer or successor if our business is sold or reorganised, who would have to respect this policy.
6. Our service providers
- Supabase, Inc.: database, authentication, file storage and background functions. Your data is hosted in London, UK.
- Vercel, Inc.: hosts our website and app. The app runs in London, UK; pages may be delivered through Vercel's global network.
- Vercel AI Gateway (Vercel, Inc.) and Google: generate Finble's answers and read receipts and bank and CIS statements you upload. The model we currently use is Google's Gemini.
- Resend: sends our emails and the invoices, estimates and reminders you send.
- Stripe: processes subscription payments and online payments from your customers.
- TrueLayer Limited: connects to your bank.
- Cloudflare, Inc. (Turnstile): checks that sign-in, registration, password reset and contact forms are used by people, not bots.
- Functional Software, Inc. (Sentry): error monitoring.
- Google and Apple: only if you choose to sign in with them.
7. International transfers
Your core data is hosted in the UK. Some of our providers (including Vercel, Google, Resend, Stripe, Cloudflare and Sentry) may process personal data in the United States or other countries outside the UK. When that happens, we rely on UK adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework where the provider is certified), or on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, so that your data stays protected.
8. How long we keep it
- Your organisation's data is kept while your organisation is active. If an organisation stays read-only (because the trial ended without a plan, the subscription ended or a payment wasn't made) for 12 months, we warn the owner by email at least 30 days in advance and then delete the organisation and all its data, including uploaded files and HMRC and bank connections.
- Items you delete in the app, such as an invoice or expense, are kept as deleted records within your organisation for audit purposes, and removed when the organisation is deleted.
- Your account is kept until you ask us to delete it. We delete it within 30 days of your request, together with every organisation where you're the only member; your support conversations are anonymised.
- Finble conversations are kept until you or an owner or admin deletes them, or the organisation is deleted.
- Bank connections stop updating when your 90-day consent expires or you disconnect; we delete the access tokens when you disconnect.
- The activity log keeps entries for 30 days.
- Payment event records from Stripe are kept for 90 days. Stripe keeps its own records of payments as required by law.
- IP addresses used to limit contact form and public page requests are kept for 24 hours.
- The device identifier for HMRC stays in your browser until you clear your browser storage.
- Backups: deleted data may remain in encrypted backups for a short period until they're overwritten.
Remember that you may need to keep your business records for years for HMRC. Download what you need before you close your account or let an organisation become read-only for 12 months.
9. Security
- everything you send to BusyBee Hub travels over encrypted connections (TLS), and data is encrypted at rest in our database
- HMRC and bank access tokens are stored encrypted in a secrets vault
- each organisation's data is separated at database level, so only its members can access it
- two-factor authentication is available for every account and required for our staff
- passwords must be at least 12 characters, and repeated sign-in attempts are limited
- we never see your online banking login details or your card details
No system is completely secure. If a breach affects your personal data in a way that puts you at high risk, we'll tell you without undue delay.
10. Payments
Subscription payments are processed by Stripe Payments Europe, Ltd. When you subscribe, your card details are entered on a page hosted by Stripe and are never stored or seen by BusyBee Hub; we keep only the card brand and last four digits so you can recognise it, plus your subscription status and invoices. We share your name, email address and organisation with Stripe to set up your subscription, and Stripe collects your billing address at checkout. Stripe's own privacy policy is at stripe.com/gb/privacy.
If you connect a Stripe account to take payments from your customers, that account is yours: Stripe is the payment processor and Stripe's privacy policy applies to your customers' card details, which are entered on a page hosted by Stripe and never reach BusyBee Hub. We share your email address and business name with Stripe to create the account, and the invoice number and your customer's email address when they pay. We keep the payment reference, amount, fees, refund status and, where Stripe provides it, the customer's email address, so that we can update your invoices and books.
11. Finble and AI processing
When you use Finble, the question you type, the recent messages in that conversation and a summary of your organisation's figures (balances, amounts owed, tax estimates, VAT and cash-flow figures, document numbers and customer or supplier names) are sent to Vercel, Inc.'s AI Gateway and on to the model provider (currently Google) to generate the answer. We never send tax identifiers, bank account numbers, email addresses, addresses or free-text notes to Finble. Conversations are stored in your account so you can read and delete them; message counts and token usage are recorded to manage costs.
When you upload a receipt, bank statement or CIS statement for us to read, the whole file is sent the same way, together with the context needed to read it (your expense categories, the bank account name, or your contractors' names and employer references). The file is sent as it is, so anything printed on it is included.
12. Your rights
Under UK data protection law you have the right to:
- access the personal data we hold about you
- have inaccurate data corrected
- have your data deleted
- restrict or object to how we use it
- receive your data in a portable format
- withdraw consent, where we rely on it
You can download your reports and accountant pack from BusyBee Hub at any time. To use any of these rights, email support@busybeehub.co.uk or use our contact form with the topic "Data & privacy". We'll reply within one month. If your request is about data a BusyBee Hub customer holds about you (for example, as their customer or tenant), please contact that business first; we'll help them respond.
If you're unhappy with how we've handled your data, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We'd appreciate the chance to put things right first.
13. Children
BusyBee Hub is for adults running a business and isn't intended for anyone under 18.
14. Cookies
We only use cookies and browser storage that BusyBee Hub needs to work. See our Cookie Policy.
15. Changes to this policy
We'll update this policy when the way we handle personal data changes. If a change significantly affects you, we'll tell you by email or in BusyBee Hub before it takes effect. The date at the top of this page shows when it was last updated.
Version 2026-09-13

