Privacy Policy

Last updated: 27 July 2026

Controller: DRS SOFTWARE SOLUTIONS LTD — a company registered in England and Wales, company number 17189542 · Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ · ICO registration: ZC155938 · hello@buckstrail.com

In plain English: You type your financial life into BucksTrail, which means we take privacy unusually seriously. We collect what you give us and what's needed to run the service — nothing more. We never connect to your bank, never sell your data, never show ads, and never use your financial entries for marketing. You can export or delete everything.

1. Scope

This policy explains how we handle personal data when you use buckstrail.com and related services. It is written to meet UK GDPR and the Data Protection Act 2018. DRS SOFTWARE SOLUTIONS LTD is the controller of the personal data described here and is registered with the Information Commissioner's Office under registration number ZC155938.

2. What we collect

What we deliberately do not collect: bank or Open Banking connections, online-banking credentials, full card numbers (these go directly to the payment provider), special-category data. Your financial entries are self-reported information you choose to type; treat the notes field accordingly and avoid entering other people's personal data.

CategoryExamplesSource
Account dataEmail address, password (stored as a secure hash by our authentication provider — we never see it), display preferences (e.g. theme)You
Financial entriesExpenses you log (amount, merchant, category, account tag, notes), renewals, card promotions, recurring payments, calculator inputs and saved scenariosYou
Billing dataSubscription status, plan, invoices, partial card details (brand + last 4) and billing countryYou / our payment providers
Service email dataWhich service emails were sent to you and when (we keep a send-ledger so we never send the same reminder twice)Us
Technical dataIP address, browser type, device type, pages requested, timestamps, error logsAutomatic
Support dataMessages you send to hello@buckstrail.comYou

3. Why we process it (lawful bases)

We do not use automated decision-making producing legal or similarly significant effects. We do not sell personal data, and we do not use your financial entries for advertising or share them for others' marketing.

PurposeDataLawful basis (UK GDPR Art. 6)
Providing the Service — accounts, storing and displaying your entries, reminders, calculatorsAccount, financial entriesContract (Art. 6(1)(b))
Billing, invoicing, membership inclusion while a paid plugin is heldBillingContract; Legal obligation for tax/accounting records (Art. 6(1)(c))
Service emails: receipts, security notices, trial/renewal reminders, reminder notifications you configureAccount, send-ledgerContract; reminder preferences honoured per your Settings
Security: authentication, session management, abuse and fraud prevention, audit loggingAccount, technicalLegitimate interests (Art. 6(1)(f)) — keeping the Service and your data safe
Service improvement and debugging using logs and aggregate, de-identified usage patternsTechnicalLegitimate interests — we do not profile individuals' finances for this
Marketing emailsEmailConsent (Art. 6(1)(a)) — optional, unsubscribable

4. Processors and recipients

We use a small set of service providers ("processors") under data-processing agreements:

We may also disclose data where the law requires (e.g. to HMRC, courts, or regulators), or as part of a business transfer under confidentiality, with notice to you.

ProviderRoleData touchedLocation/transfer basis
SupabaseDatabase, authenticationAccount, financial entriesEU (Ireland) — eu-west-1; UK adequacy for EU
VercelHosting, edge network, logsTechnicalUS/global — UK IDTA / EU SCCs
PaddlePayments — merchant of recordBillingPaddle is the seller of record for your purchase and an independent controller for that transaction, including sales tax and VAT. Global — UK IDTA / EU SCCs
StripePayments — implemented as a fallback provider, not in use at launchBillingGlobal — UK IDTA / EU SCCs; independent controller for its own compliance obligations
ResendTransactional email deliveryEmail address, message content of service emailsUS — UK IDTA / EU SCCs
SentryError monitoring and diagnosticsError events (stack traces, technical context); user id only — no email, financial entries, or request payloadsEU (Frankfurt) — UK adequacy for EU

5. International transfers

Where a provider processes data outside the UK, we rely on UK adequacy regulations where available, and otherwise on the UK International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses, with supplementary measures where appropriate. Details of the mechanism for any given provider are available on request at hello@buckstrail.com.

6. Retention

DataKept for
Account + financial entriesWhile your account exists. Moving to limited access (no active plan) does not delete anything — your data is retained in full and remains exportable. On account deletion: removed from live systems within 30 days, from backups within 30 additional days on backup rotation
Billing records & invoices6 years after the tax year they relate to (UK tax law) — retained even after account deletion, limited to what the law requires
Send-ledger (which reminder emails went out)While your account exists, then deleted with the account
Technical logsRequest and runtime logs are held by our hosting provider for a short rolling period and are not separately stored or retained by us.
Support correspondence24 months after the thread closes

7. Your rights

Under UK GDPR you can: access your data; rectify it; erase it; restrict or object to processing (including any processing based on legitimate interests); port it (export in a machine-readable format); and withdraw consent at any time where consent is the basis (this does not affect prior processing).

Self-service first: export and deletion live in Settings. Anything else: hello@buckstrail.com. We respond within one month. We may need to verify your identity; we will never ask for your password.

You can complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113). We'd appreciate the chance to fix things first, but that is your right regardless.

8. Security

Encryption in transit (TLS) and at rest; row-level security so each account's data is isolated at the database layer; server-side entitlement checks on every paid feature; least-privilege service credentials; hashed passwords via our authentication provider; audit logging of sensitive operations. No system is perfectly secure — if a breach affects your rights we will notify you and the ICO as UK GDPR requires. Security reports: hello@buckstrail.com.

9. Cookies

Covered in the separate Cookie Policy. Short version: essential cookies for login and security run without consent (PECR "strictly necessary"); anything non-essential asks first.

10. Children

The Service is for adults (18+). We do not knowingly collect children's data; if you believe a child has an account, contact hello@buckstrail.com and we will delete it.

11. Changes

We will post changes here and, for material changes, email you at least 30 days before they take effect. The "Last updated" date always reflects the current version.