Privacy Policy
Last updated: 24 May 2026
Summary: Woodcutter collects only the data needed to run the joinery quote-builder service. We do not sell, rent, or share your personal data for marketing or advertising, ever. You have full rights over your data under UK GDPR.
This policy explains how Woodcutter, operated by Woodcutter DP ("we", "us", "our"), collects, stores, and uses personal data when you use the Woodcutter web app and mobile app. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We are the data controller for personal data processed through our website at woodcutterdp.co.uk and our application at app.woodcutterdp.co.uk.
1. Data We Collect
When you use Woodcutter, we collect and store:
- Account information: Username, optional email address, password (hashed with bcrypt).
- Business profile: Business name, contact name, address, phone, email, VAT number, bank details (used on quotes and invoices you generate). Provided by you in Settings.
- Client records: Names, addresses, phone numbers, email addresses, and notes for the customers you quote. Entered by you.
- Quote and job data: Job descriptions, line items, day rates, material costs, internal notes, status.
- Site visit data: On-site notes, dimensions, and photos you capture during quote visits. Photos have their GPS / EXIF metadata stripped on upload.
- Usage data: Login timestamps and IP addresses (kept short-term for security only).
We do not collect special-category personal data (health, biometric, racial or ethnic origin, religious belief, sexual orientation, political opinion, trade-union membership, or genetic data).
2. How We Protect Your Data
- Passwords are hashed using bcrypt and are never stored in plaintext.
- All connections to Woodcutter are encrypted via HTTPS/TLS.
- Photos uploaded from the mobile app have GPS / location metadata stripped on the server before storage.
- The database and uploaded photos are hosted on a private virtual server (Hetzner, Germany, EU) accessible only to authorised administrators.
- Security headers (HSTS, X-Frame-Options, Permissions-Policy) are enforced on all pages.
- Rate limiting is applied to authentication endpoints to prevent brute-force attacks.
- Nightly encrypted database backups are taken, with off-site copies retained for 30 days.
- Mobile clients authenticate using a bearer token issued at login; tokens are stored only on the device's secure preferences.
3. Why We Collect It (Legal Basis under UK GDPR)
We process personal data on the following legal bases:
- Performance of a contract — to provide the platform features you signed up for: quote generation, client management, site visit capture, invoicing.
- Legal obligation — to retain financial records (invoices, transaction logs) for the period required by UK tax and company law (6 years).
- Legitimate interests — to maintain platform security, prevent fraud and abuse, respond to support enquiries, monitor service performance, and improve the product. We balance these interests against your rights.
- Consent — for any optional processing not covered by the above. You may withdraw consent at any time.
4. Who Can See Your Data
Your data is only accessible to you (the account holder). We do not sell, rent, or share your personal data for marketing or advertising purposes, ever. We may share your data with the following processors strictly to operate the service or comply with law:
- Hetzner Online GmbH (hosting provider, Germany, EU) — stores your data on our behalf as a data processor.
- Cloudflare (CDN and DNS provider, USA / global) — protects the service from abuse and accelerates connections.
- Legal authorities — where we are required to disclose data by law, court order, or to protect the rights of Woodcutter or others.
International transfers. Where data is transferred internationally, the transfer is protected by an adequacy decision (where one applies) or by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, ensuring an essentially equivalent level of protection.
Technical support access. Authorised Woodcutter staff may access your account in view-only or administrative mode to provide technical support, investigate billing or security issues, diagnose errors you have reported, or comply with a lawful request. All such access is logged internally. We will not access your account for any other purpose, and we will not modify, export, or share your data beyond what is necessary to resolve a specific support or security issue.
5. Customer Data You Enter (Client Records)
When you enter your own customers' details into Woodcutter to build a quote, you are the data controller for that customer information, and Woodcutter DP is the data processor. You are responsible for having a lawful basis to process your customers' personal data and for providing your customers with appropriate privacy information. We process that data only on your instructions, for the purpose of providing the service to you.
6. Data Retention
- Account data is retained for as long as your account is active.
- If you request account deletion, all personal data is permanently removed within 30 days, except records we are legally required to retain.
- Financial records (invoices, quote totals) may be retained for 6 years after the end of the relevant tax year, as required by HMRC under UK tax law.
- Audit log entries are retained for up to 12 months for security purposes.
- Accounts inactive for more than 24 months may be flagged for deletion. We will notify you by email before any action is taken.
7. Cookies & Local Storage
- Session cookie: A single cookie keeps you logged in to the web app. Marked Secure, HttpOnly, and SameSite=Lax.
- Bearer token (mobile): Stored in the device's secure preferences. Cleared on logout.
No tracking cookies, analytics cookies, or advertising cookies are used.
8. Your Rights (UK GDPR)
You have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion of your data ("right to be forgotten"), subject to legal retention requirements.
- Restriction of processing — ask us to limit how we use your data while a query about it is being resolved.
- Portability — receive your data in a structured, machine-readable format.
- Object — to any processing based on legitimate interests.
- Withdraw consent — where processing is based on consent, you may withdraw it at any time. This does not affect the lawfulness of processing carried out before withdrawal.
- Not be subject to automated decision-making — we do not make decisions that produce legal or significant effects on you based solely on automated processing.
To exercise any right, contact info@woodcutterdp.co.uk. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).
9. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will:
- Notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach.
- Notify affected users directly via email without undue delay.
- Document all breaches internally regardless of severity.
10. Children
Woodcutter is intended for use by joinery professionals and tradespeople. It is not directed at, and not intended for, children under the age of 16. We do not knowingly collect personal data from children.
11. Changes to This Policy
We may update this policy from time to time. The date at the top of this page will reflect the most recent revision. Material changes will be communicated via email or an in-app banner.
12. Contact & Data Controller
Data Controller: Woodcutter DP
Email: info@woodcutterdp.co.uk
Website: woodcutterdp.co.uk