FreelanceFlow

Privacy Policy

Last updated: 1 June 2026

This Privacy Policy explains how FreelanceFlow ("we", "us", "our") collects, uses, and protects your personal data. We are committed to processing your data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who we are

FreelanceFlow is operated by Chekwube Philip Chukwu, a sole developer based in the United Kingdom. For the purposes of UK GDPR, we are the data controller in respect of personal data processed through the FreelanceFlow service. You can reach us at philipediatech@gmail.com.

2. What personal data we collect

  • Account data: email address, display name, hashed password, multi-factor authentication settings.
  • Preference data: currency, timezone, persona type, GDPR consent choices.
  • Verification data: hashed tokens issued for email verification and password reset (these expire automatically).
  • Future feature data (collected from Week 5 onwards): invoice records, expense records, client contact details, bank-account metadata (via TrueLayer Open Banking — no full account numbers stored), contract documents, IR35 assessments, and forecasts. These will be added to this policy as each feature launches.

3. Why we process it (lawful basis)

  • Contract (UK GDPR Article 6(1)(b)): processing necessary to provide the FreelanceFlow service you subscribed to.
  • Legitimate interest (Article 6(1)(f)): security, fraud prevention, service stability.
  • Consent (Article 6(1)(a)): non-essential processing such as marketing, beta enrolment, peer benchmarking, and analytics. You can withdraw consent at any time via Settings → Privacy.
  • Legal obligation (Article 6(1)(c)): retention of certain financial records where UK tax law requires.

4. Where we store your data

Account data is stored in MongoDB Atlas in the EU (Ireland) region. Verification tokens are stored alongside the user record. Transactional emails are sent via Resend (EU infrastructure). Rate-limiting state is stored in Upstash Redis in EU (Ireland). When the service offers Open Banking integration (from Week 5), TrueLayer (FCA-regulated, UK infrastructure) will act as our data processor. All data processors are bound by data processing agreements consistent with UK GDPR Articles 28 and 32.

5. How long we keep it

  • Account data: for as long as your account is active. Deleted immediately on user request (Settings → Data → Delete account).
  • Verification tokens: auto-expired after 24 hours (email verification) or 60 minutes (password reset). Expired tokens are automatically deleted from the database.
  • Rate-limit counters: auto-expire within minutes-to-hours per limit window.
  • Audit logs of consent changes: retained for 7 years to demonstrate UK GDPR compliance, as recommended by the ICO.

6. Your rights

Under UK GDPR you have the right to: access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20), and objection (Article 21). You also have the right to lodge a complaint with the Information Commissioner's Office.

You can exercise the access and erasure rights directly through Settings → Data. For the others, email us at philipediatech@gmail.com and we'll respond within 30 days.

7. Security

We employ technical and organisational measures appropriate to the risks of processing, including: bcrypt password hashing (cost 12), AES-256-GCM encryption of MFA secrets, TLS in transit, HttpOnly session cookies, rate-limiting on authentication endpoints, and edge-network deployment through Vercel.

8. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email to all active users. The "Last updated" date at the top reflects the most recent revision.

9. Contact

For any questions about this policy or our processing activities, contact the data controller at philipediatech@gmail.com.