1. Who we are
TrustBadger is operated by HIPPOGLOW LTD, a company registered in England and Wales, trading as TrustBadger. We are the data controller for personal data you provide to us.
- Registered address: 128 City Road, London, United Kingdom, EC1V 2NX
- Privacy contact: hello@trustbadger.app
- ICO registration: ZC053643 (registered 2 December 2025, renewed annually)
2. What we collect
Account information
- Email address (used to sign in and contact you)
- Display name (shown to you and your co-owner)
- Password hash (we never see the plaintext; Firebase Authentication handles hashing)
- Account creation date
Property data
- Property addresses, purchase dates, purchase prices and current-value estimates
- Deposits, mortgage amounts and monthly payment amounts
- The contribution entries, categories, notes and dates you log
- Audit trail of changes, disputes, and flags
- Your formula configuration (what counts toward the split)
Subscription information
- Stripe customer ID and subscription status
- Trial start/end dates
- Card details are held by Stripe; we never see or store them
Technical information
- IP address and browser user-agent on requests, used for abuse prevention and error logging
- Anonymised pageview data (only if you consent to analytics cookies, see Cookie Policy)
We don't collect special category data (health, biometrics, political views, etc). Please don't put any in the notes field.
3. Why we collect it (lawful basis)
- Contract performance.To run the account and subscription you've signed up for.
- Legitimate interest. To keep the service secure and prevent abuse.
- Legal obligation. To keep billing records for HMRC and respond to lawful requests from authorities.
- Consent. For analytics cookies; you can withdraw at any time via the cookie preferences link.
4. Who we share it with
We use a short list of processors to keep the lights on. Each is bound by a data-processing agreement. None of them sell your data.
- Google Firebase (Firebase Authentication and Cloud Firestore). Stores your account and property data. We use the
eur3region (Europe); your records are hosted on servers in the EU. - Stripe. Handles payment, subscription billing, and the customer portal. Stripe may process data in the US under standard contractual clauses.
- Google Firebase App Hosting. Hosts and serves the application from Google's infrastructure in the EU.
- Google Analytics 4. Anonymised usage analytics, only if you opt in. See the Cookie Policy for details.
We don't sell your data. We don't use it to train AI models. We don't share it with marketers or advertisers.
5. International transfers
Your account and property records live in the EU (Firebaseeur3). Stripe and Google Analytics may process data in the United States. Where that happens, transfers are covered by UK International Data Transfer Agreements, the EU-US Data Privacy Framework, or standard contractual clauses.
6. How long we keep it
- While your account is active. Your records stay for as long as you use TrustBadger.
- After you delete your account. We delete your user profile and property records within 30 days.
- Billing records. We keep minimal invoice information (customer ID, payment amounts, dates) for 7 years to comply with UK tax law (HMRC).
- Backup retention. Backups are rotated out within 30 days after deletion.
7. Your rights
Under UK GDPR you have the right to:
- Accessa copy of the personal data we hold about you (you can export most of it from the app's Export page).
- Rectify inaccurate data (you can edit most of it in the app).
- Erase your data by deleting your account.
- Restrict processing or object to it.
- Data portability (export in a structured, machine-readable format).
- Withdraw consent for analytics at any time via cookie preferences.
- Complainto the ICO (ico.org.uk) if you think we're getting it wrong. We'd rather you email us first so we can put it right.
To exercise any of these rights, email hello@trustbadger.app. We'll respond within 30 days. We may ask you to verify your identity first.
8. Cookies and tracking
We use the minimum cookies needed to keep you signed in (“strictly necessary”) and, only with your consent, Google Analytics 4 for anonymised usage stats. No advertising or cross-site tracking cookies are set. Full detail is on the Cookie Policy page.
9. Security
We use Firebase Authentication for sign-in (credentials never touch our servers), TLS (HTTPS) everywhere, and Firestore security rules that make property records visible only to the two people on that property. No system is 100% secure, but we take this seriously.
10. Children
TrustBadger is not intended for anyone under 18. We don't knowingly collect data from children. If you think a child has signed up, email us and we'll delete the account.
11. Changes to this policy
We'll publish material changes here and notify you by email where required. Small edits (typos, clearer wording) may happen without notice. The “Last updated” date at the top of this page always reflects the current version.
12. Contact
HIPPOGLOW LTD (trading as TrustBadger), 128 City Road, London, United Kingdom, EC1V 2NX. Email hello@trustbadger.app.