Back

Privacy Policy

Last updated: 28 September 2026

1. Who we are

Settled ("we", "us") operates a platform that lets freelancers and creatives collect payment from clients automatically. For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we are the data controller for the personal data described in this policy.

2. What data we collect

  • Account data — name, email address, password (stored only as a secure hash), and sign-in method.
  • Business profile — trading name, business address, postcode, tax/VAT ID, and bank or payout details you provide at signup.
  • Invoice data — invoice amounts, currency, client names and addresses, payment windows, and work-completion status.
  • Client data — client name, email and billing address entered on an invoice, and the fact of their payment authorisation.
  • Payment data — card details are collected and stored by Stripe, not by us. We receive only tokens, last-four digits and payment status.
  • Review data — scores and tags creatives leave about clients' payment behaviour.
  • Technical data — IP address, browser type and usage logs needed to run and secure the service.

3. How we use it and our lawful bases

  • To provide the service (performance of a contract) — creating invoices, processing authorisations, capturing and paying out funds.
  • To meet legal obligations (legal obligation) — tax records, anti-money-laundering and fraud-prevention checks carried out with Stripe.
  • To improve and secure the platform (legitimate interests) — analytics, debugging, preventing abuse of disputes and reviews.
  • Marketing emails (consent) — only where you have opted in; you can withdraw at any time.

4. Who we share it with

  • Stripe — to process payments, verify identity and pay out funds. Stripe acts as an independent controller for its own regulatory checks.
  • Hosting and database providers — to store and serve the platform securely.
  • The other party to your invoice — clients see the creative's business details on invoices; creatives see the client details they were given.
  • Authorities — where required by law, court order or to prevent fraud.

We never sell your personal data.

5. International transfers

Some providers (including Stripe) process data outside the UK. Where this happens we rely on safeguards recognised under UK GDPR, such as the UK International Data Transfer Agreement, adequacy regulations, or standard contractual clauses.

6. How long we keep it

Account and invoice records are kept while your account is active and for up to 6 years afterwards to meet tax and accounting obligations. Payment card data is retained by Stripe under its own policies. Review data is kept while the reviewed relationship remains active on the platform.

7. Your rights

Under UK GDPR you have the right to:

  • access a copy of your personal data;
  • correct inaccurate data;
  • request erasure, where we have no overriding legal reason to keep it;
  • restrict or object to certain processing, including direct marketing;
  • data portability for data you provided to us;
  • withdraw consent at any time where processing is based on consent.

To exercise any right, contact us using the details in the app. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk or on 0303 123 1113.

8. Cookies

We use only essential cookies and local storage needed to keep you signed in and run the service. We do not use advertising or third-party tracking cookies.

9. Security

Data is encrypted in transit and at rest. Payment details are handled entirely by Stripe's PCI-DSS-compliant infrastructure. Access to personal data is limited to what is needed to operate the service.

10. Changes

We may update this policy from time to time. Material changes will be flagged in the app or by email before they take effect.

This template is provided for guidance and is not legal advice. Have a solicitor review it before launch.