Welcome to BusiTools ("we," "our," or "us"). This Privacy Policy explains what personal data we collect when you use the BusiTools mobile app, web dashboard and website, how we use it, who we share it with, and the rights you have over it.
BusiTools is a cloud service. Your business data is stored on our servers so that it can be shared across your team, across your devices, and restored if you lose your phone. This policy describes that clearly — including the parts that are your responsibility rather than ours.
This policy applies to individuals in the United Kingdom, the European Economic Area, and the United States. Where a specific law gives you extra rights, those are set out in the sections below.
If you do not agree with this policy, please stop using BusiTools and contact us to have your data deleted.
Understanding this section makes the rest of the policy much clearer, because BusiTools handles two different kinds of data in two different legal roles.
When you sign up, we decide how your account data is handled, so we are the data controller for it. This covers your email address, your business details, your subscription and billing record, and our security logs.
When you add your employees, clients, invoices, rotas, tasks or stock records, you decide what goes in and why. You are the controller of that data; we are your data processor, handling it only to run the service for you and only on your instructions.
What this means for you as a business owner: if you store employee or client records in BusiTools, you have your own obligations under UK and EU data protection law. You must have a lawful basis for holding that data, tell your staff and clients that you use BusiTools to process it, and respond to their requests about it. We give you the tools to access, export and delete it; we cannot decide those questions on your behalf.
Contact details:
BusiTools, operated by Dungeon Studio Solutions, Northern Ireland, United Kingdom.
Email: busitools.contact@gmail.com
Advice
Confirm: full registered name, company number and address, and ICO registration.
BusiTools stores your business data on our servers. The list below is complete and describes what is actually held.
We never receive or store your card number. Card details are entered directly on our payment provider's hosted checkout page and never pass through BusiTools servers.
The app keeps a local copy of data so screens load quickly, together with your device settings and login session. Clearing the app's storage or uninstalling removes that local copy, but it does not delete your data from our servers — see the Your Rights section.
Advice
Confirm: whether any feature is still device-only. If so, name it in 2.8.
Under UK and EU GDPR we must have a lawful basis for each purpose. Where we act as your processor (see Who We Are and Our Two Roles), the lawful basis is yours to determine, not ours.
To provide the service — legal basis: performance of a contract.
Creating your account, authenticating you, storing and syncing your business records, generating invoices, managing team access, and making your data available across devices and team members.
To take payment — legal basis: performance of a contract, and legal obligation.
Managing your subscription, processing renewals and cancellations, and keeping financial records for the period tax law requires.
To send service emails — legal basis: performance of a contract.
Team invitations, and confirmations when an account or group is deleted. These are operational messages, not marketing.
To keep the service secure — legal basis: our legitimate interests.
Detecting and investigating unauthorised access, maintaining the owner-visible audit trail, preventing abuse, and diagnosing faults. Our interest is running a secure platform; we have assessed this against your rights and limited the data to what is needed. You may object to this processing at any time.
To fix and improve the app — legal basis: our legitimate interests.
Reviewing crash reports and aggregated, anonymised usage patterns.
To comply with the law — legal basis: legal obligation.
Responding to lawful requests and meeting our regulatory duties.
Your data is stored in a managed PostgreSQL database operated by our hosting provider, located in [EU West - Amsterdam], with authentication handled by a separate provider.
An honest limit. Your data is encrypted in transit and at rest, but fields such as bank account numbers and National Insurance numbers are stored in ordinary database columns, not separately encrypted per field. They are protected by the access controls above rather than by additional application-level encryption. No internet service can promise absolute security.
You remain responsible for keeping your password confidential, using a device lock, removing team members who leave, and granting access only to people who need it. We cannot protect data against someone using your credentials or an unlocked device.
If a breach occurs that risks your rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it, and tell you without undue delay where the risk to you is high.
Advice
Replace [EU West - Amsterdam] after pasting (e.g. "the European Union", "the United Kingdom", "the United States"). Don't reuse the old "EU data centres" claim unless verified.
We do not sell your data and we do not share it with advertisers. We use a small number of service providers who process data on our behalf under contract, and who are permitted to use it only to provide their service to us.
Hosting and database — Railway. Runs the application and stores all business data. Location: [EU West - Amsterdam].
Authentication — Supabase. Stores your email address and password hash and issues login tokens. No business data is stored there. Location: [EU West - Amsterdam].
Payments — Stripe. Subscription billing and checkout. Receives your name, email and billing details. Stripe holds your card data; we do not.
Transactional email — Resend. Delivers team invitations and deletion confirmations. Receives recipient email addresses and message content.
Website hosting and analytics — Vercel. Hosts busitools.net and provides cookieless, aggregated visitor statistics.
App distribution — Google Play. Distributes the Android app. Google's own privacy policy governs the store.
We may also disclose data where the law requires it — in response to a valid court order or a lawful request from a public authority — or to establish or defend legal claims. If BusiTools is ever sold or merged, your data may transfer to the buyer, who would remain bound by this policy; we will tell you before that happens.
Advice
Replace both [EU West - Amsterdam] placeholders. Confirm signed DPAs with Railway, Supabase, Stripe and Resend.
BusiTools offers optional AI suggestions, such as proposing a category for a new stock item.
Your business data: kept while your account is active, so your team can use it.
After you delete a group: the group and all its records — members, employees, clients, invoices, stock, tasks, rotas, payroll — are deleted from our database.
After you delete your account: your profile, business details and groups are deleted. Your subscription is cancelled with our payment provider before the deletion runs, so billing stops.
Backups: deleted data may persist in encrypted backups for up to 30 days, after which it is overwritten in the normal backup cycle.
Billing and tax records: we keep the minimum invoice and transaction records that UK tax law requires us to retain, normally six years, even after account deletion. This is a legal obligation and is not affected by a deletion request.
Security and audit logs: retained for twelve months and then deleted or anonymised.
Historical purchase records: if you bought the one-off in-app unlock that the app offered before September 2026, a record of that purchase is retained so that older app builds continue to recognise it. Nothing can be purchased through that route any more. The record will be removed once those builds are no longer in use.
Advice
Check the 30-day backup window against your provider, and that twelve months is the audit log period you'll actually enforce.
Under UK GDPR and EU GDPR you have the right to:
To exercise any of these, email busitools.contact@gmail.com. We will respond within one month. We may ask you to verify your identity first. Exercising your rights is free unless a request is manifestly unfounded or excessive.
If the data is about you as an employee or client of a BusiTools customer, we are only the processor. Please contact that business directly — they control the data. If you contact us, we will pass your request to them.
Depending on your state — including California, Virginia, Colorado, Connecticut and Utah — you may have the right to know what personal information we collect, to access or delete it, to correct it, to obtain a portable copy, and to opt out of sale, sharing or targeted advertising.
We do not sell or share personal information, and we do not use it for targeted advertising or profiling, so there is nothing for you to opt out of. We will not discriminate against you for exercising any privacy right. To make a request, email busitools.contact@gmail.com. You may use an authorised agent, and you may appeal a decision by replying to our response.
Some of our service providers are based in, or process data in, the United States.
Where personal data is transferred outside the UK or the EEA, we rely on appropriate safeguards: the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, the EU Standard Contractual Clauses, or an adequacy decision including the UK–US Data Bridge and the EU–US Data Privacy Framework where the provider is certified under it.
You can request details of the safeguards applying to a specific transfer by emailing us.
Advice
Confirm which transfer mechanism each provider actually relies on.
This section covers our website, busitools.net.
We keep tracking to the minimum. BusiTools uses no advertising, marketing or cross-site tracking cookies, and we never sell your data or feed it to third-party AI models.
Analytics without cookies. We measure basic, aggregated site usage with Vercel Web Analytics and Speed Insights. These are cookieless: they store nothing on your device and do not follow you across other websites.
Essential cookies for signed-in users. When you sign in to the dashboard we set strictly necessary cookies to keep you securely logged in through our authentication provider. These are required for the service to work and, under the UK Privacy and Electronic Communications Regulations, do not require consent. We also keep some preferences in your browser's local storage, such as your sidebar and active-team settings.
No consent banner, and here is why. We run no non-essential tracking, so there is nothing to consent to. If that ever changes we will ask for clear, opt-in consent first, with a reject option just as prominent as the accept one.
BusiTools is a business tool intended for people aged 18 and over, and we do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
If you use BusiTools to manage employees under 18, such as apprentices, you are the controller of those records and responsible for the additional protections that apply to a child's data.
We may update this policy as the service develops. When we do, we will update the "Last Updated" date, post the new version on busitools.net and in the app, and — for changes that materially affect your rights — notify you directly by email or in-app notice before they take effect.
For any question about this policy, your data, or to exercise your rights:
Email: busitools.contact@gmail.com
Operated by: Dungeon Studio Solutions
Address: Northern Ireland, United Kingdom
We aim to respond within 30 days, and within one month where UK or EU data protection law requires it.
Advice
Consider privacy@busitools.net instead of the Gmail address (also used in Items 1 and 8).
If you are unhappy with how we have handled your data, please contact us first so we can try to put it right.
You also have the right to complain to a supervisory authority.
United Kingdom — Information Commissioner's Office: https://ico.org.uk/make-a-complaint/
European Economic Area — the data protection authority in your country of residence, work or the place where the issue arose.
If you have any questions about how we handle your data or wish to exercise your rights, please don't hesitate to contact us.