Privacy Policy
How TradesSync handles personal data — yours, and your clients'.
Last updated 10 September 2026
1. Who we are
TradesSync is operated by GC Software Systems of Office 4, 25 High Street, Rainham, Gillingham, Kent, ME8 7HX.
For anything in this policy, contact us at support@gcsoftwaresystems.co.uk.
2. We act in two different roles
This matters, because your rights differ depending on which applies.
| Data | Our role | What that means |
|---|---|---|
| Your TradesSync account — your name, email, password, sign-in records, billing | Controller | We decide what to collect and why. This policy governs it. |
| Your ServiceM8 data — your clients' names, addresses, phone numbers, job details | Processor | You are the controller. We only handle it to run the sync you've configured. Our obligations are set out in the Data Processing Agreement, which is Schedule 1 of our Terms of Service. |
3. What we hold about you
Account information
Your name, email address and a password. Passwords are hashed with Argon2ID — we never store or see the password itself, and we cannot recover it for you.
Sign-in records
Each sign-in, sign-out and failed attempt is recorded with the time, your IP address and your browser's user-agent string. This is genuinely for security — spotting someone trying to get into your account — and it's kept for 180 days, then deleted automatically.
We can also access your account to help you with a support question. When we do, it's recorded, and anything we do while in your account is marked as done by us rather than by you.
Your ServiceM8 and GoHighLevel credentials
Encrypted at rest with AES-256-GCM. They're used only to make the API calls needed to run your sync.
Payment information
Payments are handled by PayPal. Your card or PayPal account details go directly to PayPal and never touch our server — we only hold a subscription reference, its status, and records of payment for HMRC, which we keep for six years as tax law requires.
Support correspondence
Emails you send us, kept while relevant to supporting you.
If you enquire through the website
The form on our homepage records your name, email, business name, phone number and anything you type in the message box, so we can reply. If you don't become a customer we delete it within 12 months.
4. What we do not do
- No advertising, and no sharing with advertisers.
- No selling of personal data. Ever.
- No analytics or tracking cookies. The only cookie we set is the one that keeps you logged in.
- No using your clients' details for anything except running your sync.
- No automated decision-making that has legal effects.
5. Why we're allowed to hold it
| Purpose | Lawful basis |
|---|---|
| Running your account and the sync | Performance of a contract |
| Taking payment | Performance of a contract |
| Sign-in and security logging | Legitimate interests — keeping accounts secure |
| Replying to an enquiry | Legitimate interests — responding to you |
| Keeping invoices | Legal obligation — tax law |
6. How long we keep things
| What | How long |
|---|---|
| Account details | While your account is open, then 30 days |
| Sign-in history | 180 days |
| Sync logs | 30 days |
| Cached ServiceM8 data | Under 24 hours |
| Enquiries that don't become accounts | 12 months |
| Invoices | 6 years (HMRC) |
When you close your account we delete your credentials and your synced data within 30 days. Anything already sent to your GoHighLevel account stays there — it's your account and we can't reach into it.
7. Who else is involved
Only one company other than us touches your data on our behalf:
| Who | What for | Where |
|---|---|---|
| Heart Internet Ltd | Hosting — our server and database | United Kingdom |
| PayPal (Europe) S.à r.l. et Cie, S.C.A. | Payments and subscriptions | Luxembourg / EU adequacy decision |
ServiceM8 and GoHighLevel are not our sub-processors. They're your systems, under your own agreements with them. We connect to them using credentials you give us and at your instruction. What those companies do with your data is governed by their own terms, not ours.
We'll tell you before adding anyone else who would handle your data.
8. Where your data lives
On our hosting provider's infrastructure in the United Kingdom. Some of their systems sit in the EU, which the UK recognises as providing an adequate level of protection, so no additional transfer safeguards are needed.
9. Keeping it safe
- Everything travels over HTTPS.
- Passwords hashed with Argon2ID; API credentials encrypted with AES-256-GCM.
- Every database query is parameterised, so injection isn't possible through the application.
- Session cookies are HttpOnly, Secure and SameSite=Strict.
- Sign-ins, failed attempts and administrative access are all logged.
No system is perfectly secure. If there's ever a breach that puts your rights at risk, we'll tell you and the ICO without undue delay.
10. Your rights
Under UK GDPR you can ask us to:
- give you a copy of what we hold about you
- correct anything that's wrong
- delete it, where we're not required to keep it
- restrict or object to how we use it
- hand it over in a portable format
Email support@gcsoftwaresystems.co.uk and we'll respond within one month. There's no charge.
If you're one of our customer's clients and your details reached GoHighLevel through TradesSync, please contact that business directly — they're the controller and we can only act on their instructions. Tell us and we'll point you to the right place.
You can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We'd rather you came to us first so we can put it right.
11. Cookies
One cookie, used to keep you signed in. It isn't used for tracking and there's no third-party cookie on this site, which is why you aren't being asked to accept anything.
12. Changes
If we change this policy we'll update the date at the top, and for anything significant we'll email you before it takes effect.