Our Privacy Policy
Personal Data Description
Identity and Contact Data such as your name, email address and password, telephone number and address.
- Directly from you (online, e.g. via our Website/App or offline, e.g. via phone calls with customer service)
- Third parties, e.g. the users of our services who provide you with a requested service
- Automatic Collection
Account Data such as your login information (email and password) and profile information (contact details including your name, surname, postcode, phone and employer entity).
- Directly from you
- Third parties
Transaction Data such as truncated credit or debit card details, payment method, transaction statements, your billing address, payments and orders to and from you, and other details of products that you have supplied to or purchased through the website.
We do not collect or store your full credit or debit card details (which are processed by payment service providers who are separate controllers of your data. Please refer to your payment service provider’s privacy notice for further details on their data collection practices).
- Directly from you
- Third parties
- Automatic collection
Communications Data such as your feedback on our products and services or the performance of our website and other communications with us (including when you interact with our customer service agents offline), any queries you raise, referrals, chat, email or call history on the website or with third-party service providers. This will include information as to how you contact customer services and the channel of communication that you use or any information that you send to us (for example, if you complain about the performance of our website and send us screenshots).
- Directly from you
- Third parties
- Automatic collection
Advertising and Marketing Data such as your interests based on your use of our website and other websites and online services, your purchases, survey responses, promotions you enter, preferences in relation to receiving marketing materials from us, communication preferences, your preferences for particular products or services and your subscription details.
- Directly from you
- Third parties
- Automatic collection
Device Data collected using tags and pixels, including your IP address, your ISP, and the browser you use to visit our website, device type, unique device identification numbers or other identifiers including advertising identifiers.
- Automatic collection
Website Usage Data such as activity and Website page and App interaction, information that we capture using cookies and similar technologies (see the “Cookies and similar tracking technology” section below). This will include page views and searches, log-in information, clicks, operating system, information about content viewed, watched or downloaded for offline access, length of visits to certain pages, length of website use, purchase history and other functional information on website performance (for example, application version information, diagnostics, and crash logs).
- Automatic collection
Location Data collected using WiFi access points and / or GPS from which we can identify your precise geographic location, e.g., technical information that associates your location to your use of the website to enable “live tracking”, “historical tracking” & “route scheduling”.
- Automatic collection
Uploaded Content such as any personal data in photographs / videos or audio recordings that you upload onto a review website, our website (such as website profile pictures) or provide as part of product reviews or when sharing content as part of the socialisation functions on the website, requests for assistance from customer service, or when you refer a customer, or upload photos to social media (where you allow us to use such images).
- Directly from you
- Automatic Collection
We do not collect any sensitive personal data about you, such as health-related information or information about your race or ethnicity, or sexual orientation.
3. How we use your personal data (our purposes) and our legal basis for processing it
We use the personal data that we collect from and about you only for the purposes described in this Privacy Notice or for purposes that we explain to you at the time we collect your information. Depending on our purpose for collecting your information, we rely on one of the following legal bases:
- Consent – in certain circumstances, we may ask for your consent before we collect, use, or disclose your personal data, in which case you can voluntarily choose to give or deny your consent without any negative consequences to you
- Legitimate interests – we may use or disclose your personal data for the legitimate business interests of either House Tag or a third-party, but only when we are confident that your privacy rights will remain appropriately protected. If we rely on our (or a third-party’s) legitimate interests, these interests will normally be to: operate, provide and improve our business, including our website; communicate with you and respond to your questions; improve our website or use the insights to improve or develop marketing activities and promote our products and services; detect or prevent illegal activities (for example, fraud); and/or to manage the security of our IT infrastructure, and the safety and security of our employees, customers, vendors and visitors. Where we require your data to pursue our legitimate interests or the legitimate interests of a third-party, it will be in a way which is reasonable for you to expect as part of the running of our business and which does not materially affect your rights and freedoms. We have identified below what our legitimate interests are
- Legal obligation – there may be instances where we must process and retain your personal data to comply with laws or to fulfil certain legal obligations.
The following information provides more details on our purposes for processing your personal data and the related legal bases. The legal basis under which your personal data is processed will depend on the data concerned and the specific context in which we use it.
4. How We Use Your Personal Data and Our Legal Bases for Processing
We process your personal data only for the purposes outlined in this Privacy Policy or as explained to you at the time of collection. The legal basis for processing depends on the specific purpose and the type of data involved.
Legal Bases for Processing
- Consent: In certain cases, we will request your consent before collecting, using, or disclosing your personal data. You can choose to give or withhold your consent without adverse consequences.
- Legitimate Interests: We may process your personal data to pursue our own or a third party’s legitimate business interests, provided your privacy rights are not overridden. Legitimate interests typically include operating and improving our business (e.g., our website, IT systems, and services), responding to communications, marketing and promoting our products, ensuring security, and detecting or preventing illegal activities such as fraud.
- Legal Obligations: We may process and retain your personal data when required to comply with legal or regulatory obligations.
Purposes for Processing and Legal Bases
Account Management and Services
- Purpose: To register and administer your account, facilitate purchases, deliver services, and process transactions (e.g., history and receipts).
- Data Used: Identity and Contact Data, Account Data, Transaction Data, Communication Data, Device Data.
- Legal Basis: Legitimate interests (to provide and manage accounts and services).
Customer Support and Communication
- Purpose: To respond to your enquiries, complaints, and requests; provide updates, invoices, security alerts, and other notices; ensure quality assurance and training.
- Data Used: Identity and Contact Data, Account Data, Transaction Data, Communication Data, Uploaded Content, Device Data, Website/App Usage Data.
- Legal Basis: Legitimate interests (to operate and improve our business and facilitate communication).
Security and Fraud Prevention
- Purpose: To protect safety and security, detect and prevent fraud, safeguard IT systems, and monitor activity (e.g., using security tools).
- Data Used: Identity and Contact Data, Account Data, Transaction Data, Device Data, Website/App Usage Data, Communication Data.
- Legal Basis: Legitimate interests (to ensure security and prevent illegal activities).
Legal and Regulatory Compliance
- Purpose: To meet legal obligations (e.g., tax, fraud prevention, data protection), manage compliance, and respond to legal claims or law enforcement.
- Data Used: Identity and Contact Data, Account Data, Transaction Data, Website/App Usage Data, Communication Data, Uploaded Content Data, Social Media Data.
- Legal Basis: Legal obligations and legitimate interests (to protect business and legal rights).
Website and System Administration
- Purpose: To maintain IT systems, troubleshoot, analyse data, and manage tracking technologies (e.g., cookies).
- Data Used: Identity and Contact Data, Account Data, Device Data, Website/App Usage Data.
Legal Basis:
- Consent (for non-essential cookies or where legally required).
- Legitimate interests (to operate and improve our systems and website).
Marketing and Advertising
- Purpose: To personalise and deliver targeted advertising, evaluate campaigns, and promote services, including through social media campaigns and referrals.
- Data Used: Account Data, Marketing Data, Website/App Usage Data, Device Data, Social Media Data, Communication Data, Uploaded Content Data.
- Legal Basis:
- Consent (where legally required).
- Legitimate interests (to promote services and marketing activities).
Analytics and Service Improvement
- Purpose: To analyse customer behaviour, assess trends, evaluate marketing campaigns, and improve services and offerings.
- Data Used: Identity and Contact Data, Account Data, Transaction Data, Device Data, Website/App Usage Data, Marketing Data, Social Media Data.
- Legal Basis:
- Consent (where legally required).
- Legitimate interests (to enhance services and understand customer needs).
Location Services
- Purpose: To enable live and historical tracking or route scheduling.
- Data Used: Location Data.
- Legal Basis:
- Customer instructions (via employer policies).
- Consent (with settings to enable/disable location services).
Data Processing Principles
We strive to process data efficiently and avoid duplication, using the same data for multiple compatible purposes, such as account management, fraud prevention, and service improvement, where lawful.
For questions or to exercise your rights, please contact us.
5. Who we share your personal data with
We share your personal data with the following categories of recipients:
- third-party service providers and partners who provide data processing services to us as necessary to provide you with our services (to support the delivery of, provide functionality on, or help to enhance the security of our website), or who otherwise process personal data for purposes described in this Privacy Notice
- third-party services when you use third-party services linked through our Website/App, for example, third-party payment services, your personal data will be collected by the provider of such services. Please note that when you use third-party services, their own terms and privacy notices will govern your use of their services
- any competent law enforcement body, regulatory, government agency, court or other third-party (such as our professional advisers) where we believe disclosure is necessary (i) as a matter of applicable law or regulation, (ii) to exercise, establish or defend our legal rights, or (iii) to protect your vital interests or those of any other person
- a buyer (and its agents and advisers) in connection with any actual or proposed purchase, merger or acquisition of any part of our business, provided that we inform the buyer it must use your personal data only for the purposes disclosed in this Privacy Notice; or
- any other person with your consent to the disclosure (obtained separately from any contract between us).
6. Cookies and similar tracking technology
We use cookies and similar tracking technology (collectively, “Cookies”) to collect and use personal data about you, including to serve interest-based advertising. For further information about the types of Cookies we use, why, and how you can control Cookies, please see our Cookie Notice.
7. How we keep your personal data secure
We use appropriate technical and organisational measures to protect the personal data that we collect and process about you. The measures are designed to provide a level of security appropriate to the risk of processing. Specific measures we use include encrypting your personal data in transit; access management; penetration testing and regular benchmarking and testing with industry standards.
Where you have created an account with us that uses a unique password to enable you to access our website, it is your responsibility to keep this password secure and confidential.
8. International data transfers
In some cases, where your personal data is transferred to another House Tag company or third-party, it is processed in countries other than the country in which you are resident. These countries may have data protection laws that are different to the laws of your country (and, in some cases, may not be as protective).
Specifically, our website servers are located in the UK. Our third-party service providers and partners operate around the world. This means that when we collect your personal data we will process it in any of these countries.
Where the transfer is not subject to an adequacy decision or regulations, we have taken appropriate safeguards to ensure that your personal data will remain protected in accordance with this Privacy Notice and applicable laws. The safeguards we use to transfer personal data in the case of our group companies are the European Commission’s Standard Contractual Clauses as issued on 4 June 2021 under Article 46(2) using the controller to controller, controller to processor, processor to processor and processor to controller modules for transfers, as well as the UK Addendum for the transfer of data originating in the UK.
9. Data retention
We retain the personal data we collect from you where we have an ongoing legitimate business need to do so (for example, to provide you with a service you have requested or to comply with applicable legal, tax or accounting requirements). In certain circumstances, we will need to keep your information for legal reasons after our contractual relationship has ended. The specific retention periods depend on the nature of the information and why it is collected and processed and the nature of the legal requirement. We keep your information when we have a legal obligation to do so:
- for tax and accounting purposes
- to deal with and resolve requests and complaints (e.g. if there is an ongoing complaint with respect to the services)
- to protect individuals’ rights and property
- for litigation or regulatory matters (e.g. we would retain your information if there was an ongoing legal claim and the information was relevant to the claim. This information would be retained until the legal claim had been concluded.)
When we have no ongoing legitimate business need or legal reason to process your personal data, we will either delete or anonymise it or, if this is not possible (for example, because your personal data has been stored in backup archives), then we will securely store your personal data and isolate it from any further processing until deletion is possible.
10. Your data protection rights
Individuals located in the UK and EEA have the following data protection rights. To exercise any of them see specific instructions below or contact us using the contact details provided under the “How to contact us” heading below.
- You may access, correct, update or request deletion of your personal data.
- You can object to processing of your personal data, ask us to restrict processing of your personal data or request portability of your personal data, (i.e. your data to be transferred in a readable and standardised format).
- You have the right to opt-out of marketing communications we send you at any time. You can exercise this right by clicking on the “unsubscribe” or “opt-out” link in the marketing e-mails we send you. To opt-out of other forms of marketing (such as postal marketing or telemarketing), please contact us using the contact details provided under the “How to contact us” heading below. If you choose to opt out of marketing communications, we may still send you non-promotional emails, such as emails about your account or our ongoing business relations.
- If we have collected and processed your personal data with your consent, then you can withdraw your consent at any time by using the contact details provided under the “How to contact us” heading below. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your personal data conducted in reliance on lawful processing grounds other than consent.
- You have the right to complain to a supervisory authority about our collection and use of your personal data. For more information, please contact your local supervisory authority. Contact details for supervisory authorities in the UK Europe are available. Certain supervisory authorities may require that you exhaust our own internal complaints process before looking into your complaint.
We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws.
11. Updates to this Privacy Notice
We may update this Privacy Notice from time to time in response to changing legal, regulatory, technical or business developments. When we update our Privacy Notice, we will take appropriate measures to inform you, consistent with the significance of the changes we make. We will obtain your consent to any material Privacy Notice changes if and where required by applicable data protection laws.
You can see when this Privacy Notice was last updated by checking the “last updated” date displayed at the top of this Privacy Notice.
12. How to contact us
If you have any questions or concerns about our use of your personal data, please contact us using the following details: privacy@housetag.co.uk.
The data controller of your personal data is House Tag Limited, which is registered with the Information Commissioner’s Office with registration number ZA903119.