1. Introduction & who we are
Taskwren is a United Kingdom marketplace connecting customers with independent local service providers. The data controller responsible for your personal data is:
- Controller: TASKWREN LIMITED
- Registered office: 71-75 Shelton Street Covent Garden London WC2H 9JQ UNITED KINGDOM
- Company number: 17389116
- Contact for privacy matters: support@taskwren.com
2. Who this policy covers
This policy applies to customers and providers who use the Platform, and to visitors to our website and apps. Providers and customers can each see limited information about the other where it is needed to arrange and carry out a booking (for example a first name, the service address, and messages) — when you do so, you must also handle that information responsibly and lawfully.
3. The personal data we collect
We collect and process the following categories of personal data:
Account & profile data
Your name, email address, telephone number (required), a password (which we only ever store as a secure one-way bcrypt hash — we never store it in readable form), and optionally a profile photo. Providers additionally provide a business profile: display name, description, experience, languages, tools and vehicles, portfolio/work photos, hourly rate, availability, and service details.
Location data
The address, postcode, and precise geographic coordinates (latitude/longitude) you provide or that your device supplies (with your permission), and a service radius. We use this to match customers with nearby providers, to calculate distance, and to enable the provider to attend the correct address for a booking. Geocoding (turning an address or postcode into coordinates, and vice versa) is carried out in the app using OpenStreetMap/Nominatim and postcodes.io.
Booking & service data
Details of the bookings you make or accept: the service, date, time, service address, duration, description, notes (including any information you choose to give about pets, parking, or access), the price breakdown, status, completion details, and cancellation information.
Payment data
Payments are processed by Stripe. Your full card number is entered into Stripe and does not reach our servers; we store only limited details such as the card brand and last four digits, your Stripe customer/payment references, and the amounts and status of your bookings, invoices, tips, refunds, and (for providers) payouts. For providers, Stripe collects the identity and bank details needed to verify you and pay you ("Know Your Customer" information); those details are provided directly to Stripe and are not stored by us.
Communications & content
Messages you send through in-booking chat (including any images), the reviews and ratings you post, feedback you give about the Platform, and the content of support requests and any escalations. Chat images are stored privately and shared only with the other party to the booking.
Support data
When you contact support we process the content of your tickets and messages, your name and role, the subject and category, and related booking information, so we can help you and keep a record.
Device & technical data
Push-notification device tokens (so we can send you notifications), notification preferences, and technical information needed to operate the app and keep it secure — including, for security purposes, limited network and device information (such as an IP address and device/browser details) associated with your login sessions. Our mobile app uses a crash-reporting tool that collects diagnostic information if the app crashes.
Special categories & sensitive information
We do not intentionally seek special-category data. However, information you volunteer in free-text fields, notes, or messages (for example about health, pets/allergies, or your household) may include sensitive information. Please share only what is necessary. Where you provide such information as part of a booking, we process it to fulfil the booking on the basis of your provision of it to us.
4. Where we get your data
- From you — when you register, complete your profile, make or accept bookings, message, review, pay, or contact support.
- From your device — location (with permission), push tokens, and technical/diagnostic data.
- From Stripe — payment status, card brand/last-4, and (for providers) verification and payout status.
- From the other party to a booking — a customer and provider each receive limited information about the other to carry out the booking.
5. How and why we use your data
We only use your personal data where the law allows. The table below sets out our main purposes and the lawful basis for each.
| Purpose | Data used | Lawful basis (UK GDPR) |
|---|---|---|
| Create and manage your account; authenticate you | Account, contact, security data | Performance of a contract; our legitimate interests in account security |
| Operate the marketplace — match customers and providers, arrange and manage bookings | Profile, location, booking data | Performance of a contract |
| Take payment, pay providers, handle invoices, tips, and refunds | Payment, booking, and (for providers) payout data | Performance of a contract; legal obligation (financial records) |
| Enable messaging, reviews, and ratings | Communications and content | Performance of a contract; legitimate interests in a trusted marketplace |
| Provide support and resolve disputes and escalations | Support, booking, and account data | Performance of a contract; legitimate interests in resolving issues |
| Send service messages (e.g. booking confirmations, one-time passcodes, cancellations) | Contact and booking data | Performance of a contract; legitimate interests |
| Send push notifications you have enabled | Device token, preferences | Consent (device permission) / legitimate interests, per your preferences |
| Keep the Platform secure, prevent fraud and abuse, and debug problems | Technical, security, and usage data | Legitimate interests; legal obligation |
| Comply with law and respond to lawful requests | As required | Legal obligation |
Where we rely on legitimate interests, we have balanced those interests against your rights. You can object to that processing (see section 11). Where we rely on consent (for example device push permissions), you can withdraw it at any time.
7. Our service providers & sub-processors
We use the following trusted providers to operate the Platform. Each processes only the data needed for its role.
| Provider | Role | Data involved |
|---|---|---|
| Stripe | Payment processing, card storage, provider identity verification (KYC) and payouts | Card details, amounts, customer/provider identifiers; provider bank & identity data |
| Amazon Web Services (AWS) | Cloud hosting, database, and media storage — hosted in the UK (London / eu-west-2 region) | All personal data at rest (database and files) |
| Google (Firebase Cloud Messaging & Crashlytics) | Delivering push notifications; crash/diagnostic reporting for the mobile app | Device push tokens, notification content; crash diagnostics |
| Resend | Sending transactional email (verification, passcodes, booking and cancellation notices) | Email address and message content |
| OpenAI | Powering Wren, our automated support assistant, which replies to you directly in a support conversation; and, separately, drafting suggested replies for a member of our support team to review before they send them | The recent messages in that support conversation, your first name, and — only where your question is about a booking — details of your recent bookings |
| OpenStreetMap / Nominatim & postcodes.io | Geocoding addresses/postcodes and providing map tiles in the app | Address/postcode or coordinates you enter |
We keep this list under review and update it as our providers change. If you would like more detail about a particular provider, please contact us.
8. International data transfers
We host your personal data in the United Kingdom (AWS London region). Some of our service providers (for example Stripe, Google, and OpenAI) may process limited data outside the UK, including in the United States or the European Economic Area. Where data is transferred outside the UK, we rely on appropriate safeguards recognised under UK data protection law — such as UK "adequacy" regulations, the UK International Data Transfer Agreement or Addendum, or equivalent contractual protections — so that your data continues to be protected. You can ask us for more information about these safeguards.
9. How long we keep your data
We keep personal data only for as long as we need it for the purposes described in this policy. In general:
- Account and profile data — while your account is active, and for a reasonable period afterwards to handle any follow-up, disputes, or legal claims.
- Booking, payment, and financial records — retained to meet our legal and tax obligations. In the UK, financial records are generally kept for at least six years.
- Messages, reviews, and support records — kept while relevant to the marketplace and any dispute, then deleted or anonymised.
- Security logs and tokens — short-lived (for example login tokens expire quickly; one-time passcodes expire within minutes).
When you deactivate your account, we suspend it and cancel active bookings; we may retain certain information where we have a legal reason or legitimate need to do so (for example financial records and dispute history). You can ask us to erase your data — see section 11.
10. How we protect your data
We use appropriate technical and organisational measures to protect your data, including:
- encryption of data in transit (TLS) and at rest;
- storing passwords only as one-way bcrypt hashes, and session/one-time-passcode tokens only in hashed form;
- keeping card and bank data out of our systems by relying on Stripe's PCI-DSS certified platform;
- serving private files (such as chat images) only through short-lived, access-controlled links;
- access controls, rate limiting, monitoring, and alerting; and
- hosting within the UK with a reputable cloud provider.
No system is completely secure, but we work to protect your data and to notify you and the ICO of a personal data breach where the law requires.
11. Your data protection rights
Under UK data protection law you have the right to:
- be informed about how we use your data (this policy);
- access a copy of the personal data we hold about you;
- rectify inaccurate or incomplete data;
- erase your data ("right to be forgotten") in certain circumstances;
- restrict or object to our processing in certain circumstances, including processing based on legitimate interests;
- data portability — receive certain data in a portable format; and
- withdraw consent at any time where we rely on consent.
To exercise any of these rights, contact us using the details in section 16. We will respond within one month (which we may extend for complex requests, telling you if so). Exercising your rights is free, and we will not treat you differently for doing so. Note that some rights are qualified — for example we may need to keep certain records to meet legal obligations even after an erasure request.
12. Automated decisions & profiling
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. Our automated support assistant, Wren, replies to you directly in support conversations, and its replies are not read by a member of our team before you see them. Wren can only send messages: it has no means of issuing a refund, cancelling or changing a booking, altering a payment, or changing your account, and you can ask to be passed to a person at any time. Where we use AI in other ways to help our team — for example drafting a reply for an agent to review — a person remains responsible for the decision.
13. Children
The Platform is intended for people aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can remove it.
15. Changes to this policy
We may update this policy from time to time. If we make a significant change we will take reasonable steps to tell you. The "last updated" date at the top shows when it was last revised. Please review it periodically.
16. Contact us & complaints
To exercise your rights or ask about this policy, contact:
- Data controller: TASKWREN LIMITED
- Registered office: 71-75 Shelton Street Covent Garden London WC2H 9JQ UNITED KINGDOM
- Privacy contact: support@taskwren.com
If you are unhappy with how we have handled your data, you have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk, by calling 0303 123 1113, or by writing to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. We would, however, appreciate the chance to address your concerns first.
See also our Terms & Conditions and Cookie Policy.
