Skip to main content

Privacy Notice

Last updated: 29 July 2026

This notice explains what MTD for Landlords processes, how we protect your data, and your privacy rights.

1. Status of This Notice and Who We Are

MTD for Landlords is operated by Joel Zeal, trading as MTD for Landlords. For privacy questions or rights requests, contact legal@landlordtax.app. This notice does not replace advice from a solicitor or qualified data-protection professional.

2. Data-Protection Roles

For account administration, product operation, billing, security, support, and product analytics, the operator expects to act as a data controller. Where a landlord uploads information about tenants, payees, joint owners, or other people, the landlord may be the controller and the operator may act as a processor. Where an accountant or delegate handles a landlord's records, the roles may differ again. Those controller/processor arrangements, including whether a data-processing agreement is required, remain subject to legal review and are a production release gate. For the declared direct-taxpayer release, local accountant or delegate access is bookkeeping-only. It does not let that person authorise HMRC OAuth or submit to HMRC; the authenticated taxpayer must perform those actions. HMRC, Stripe, and regulated Open Banking participants may act as controllers in their own right for some processing. Their exact roles must be recorded in the subprocessor and data-sharing register.

3. Personal Data We Process

Depending on the features you use, the Service may process: Account and identity data • Name, email address, internal user ID, account type, authentication metadata, notification settings, login activity, invitations, referrals, and delegated-access records • Tax-profile information such as National Insurance number, qualifying-income inputs, accounting basis, HMRC business identifiers, and HMRC connection scope Property and financial records • Property addresses, types, ownership shares, income, expenses, dates, descriptions, merchant or reference text, categories, notes, import history, raw import rows, rules, and receipt attachments • Bank institution and account metadata, imported Open Banking transactions, sync status, consent status, and audit events when Open Banking is enabled HMRC integration data • OAuth access and refresh tokens, expiry and scope metadata, business and individual details returned by HMRC, obligations, status information, calculations, submission attempts, responses, references, and audit records • Fraud-prevention context required for HMRC API calls, which can include IP address and port, timestamp, device identifier, user agent, time zone, screen and window dimensions, do-not-track value, internal user identifier, and multi-factor-authentication metadata when available Billing, support, and product operation • Subscription and invoice status, Stripe identifiers, card brand, last four digits and expiry metadata (not full card number or CVC) • Support messages, feedback, uploaded feedback files, email-delivery events, service logs, error diagnostics, rate-limit records, and monitoring events • Optional analytics events and user identity details only after the relevant browser preference has been granted • Transaction description, normalised merchant, amount, direction, and available category labels sent to OpenAI for inference only when the optional AI suggestion path is enabled and invoked Bank transaction descriptions and attachments can reveal information about other people and may incidentally reveal sensitive matters. Upload only what is necessary for tax record keeping.

4. Where Data Comes From

Data may come directly from you; from an accountant, delegate, or client who is authorised to act; from CSV files and attachments you upload; from TrueLayer and participating banks after an Open Banking consent; from HMRC after OAuth authorisation; from Stripe during billing; and automatically from the browser, device, network, and application logs. The Service does not ask for or store HMRC Government Gateway passwords or online-banking login credentials.

5. Purposes and Proposed Lawful Bases

The proposed lawful-basis mapping is a draft and requires DPO or legal approval: Contract • Create and administer accounts; store records; provide imports, categorisation, summaries, exports, delegated access, support, and billing • Carry out HMRC or Open Banking actions that a user has expressly initiated or configured Legitimate interests • Protect accounts, prevent abuse, diagnose faults, monitor reliability, maintain audit evidence, and improve the Service • Each material legitimate-interest use requires a documented balancing assessment Legal obligation • Meet obligations that apply directly to the operator, including valid legal requests and data-protection duties • A user's own tax record-keeping duty does not automatically give the operator a lawful basis to retain every record Consent • Optional product analytics, optional support-chat loading, and marketing where consent is required • Consent can be withdrawn through Cookie settings or the relevant communication controls without affecting earlier lawful processing Fraud-prevention information sent to HMRC supports HMRC's API security requirements. The final notice must identify the approved lawful basis and retention for this processing.

6. Service Providers and Data Sharing

The current codebase can use the following providers. A current contract, role, location, retention period, security review, and transfer mechanism must be recorded for each before production: • Supabase and its infrastructure providers — authentication, PostgreSQL database, storage, and platform services • Vercel — web hosting, content delivery, and serverless execution • Stripe — subscriptions and payment processing • Resend — transactional email delivery • HMRC — MTD OAuth, tax information, obligations, calculations, submissions, and fraud-prevention data • TrueLayer and participating financial institutions — Open Banking consent, account metadata, and transaction access when enabled • OpenAI — optional transaction-category inference when enabled and invoked • PostHog — optional product analytics after browser preference • Sentry — application error and security diagnostics; browser session replay is disabled • Crisp — optional support chat after browser preference • Upstash — distributed rate limiting when configured • A configured monitoring-webhook recipient — operational alerts • Google Fonts — font delivery, which can expose request metadata such as IP address We also disclose data where required by law, to protect legal rights, or during a properly governed business transfer. We do not sell financial records for advertising. This list is a transparency draft, not evidence that every provider has passed final due diligence.

7. Cookies and Browser Storage

Necessary cookies and storage can include Supabase authentication/session data, short-lived OAuth state and return-path cookies, security state, local interface preferences, and the cookie-preference record. When the HMRC feature is enabled, the application sets a persistent device identifier used to build HMRC fraud-prevention headers. The current implementation can retain that identifier for up to five years. The necessity, scope, and final retention period require DPO review before production. PostHog analytics and Crisp support chat are optional browser services and must not initialise until the corresponding preference has been granted. You can change those choices using Cookie settings. Sentry error reporting remains part of service security and reliability; session replay has been disabled. Browser settings can clear cookies and local storage, but clearing authentication data will sign you out and clearing an HMRC device identifier can affect device continuity in fraud-prevention headers.

8. HMRC and Open Banking

HMRC features use OAuth so that the Service never receives a Government Gateway password. Tokens are restricted to server-side access. Production HMRC use is disabled until token-storage controls, HMRC production access, endpoint evidence, fraud-header evidence, and the release gate are complete. An HMRC authorisation can permit the Service to retrieve business or individual details, obligations, status, and calculations, as well as send supported information when the user explicitly confirms an available submission. Disconnecting removes the local connection, but it does not delete information already held by HMRC. Open Banking is optional. TrueLayer handles the bank authentication and consent experience; the Service stores encrypted provider tokens and imported transaction data. Disconnect attempts to revoke the provider consent, but imported records remain until separately deleted or the applicable retention rule expires. Provider outages can delay revocation and must be handled through the incident process.

9. Current Product Scope

The declared product scope is staged in-year UK property record preparation. Production HMRC filing is not currently available. End-of-year adjustments and finalisation, losses, other non-mandated income, final tax calculation completion, and the final declaration are not provided by this release. Users must use another supported service, HMRC route, accountant, or tax adviser for those steps. No content in this notice represents HMRC approval, recognition, certification, endorsement, production credentials, or software listing.

10. Retention, Account Closure, and Deletion

The final retention schedule has not yet received legal or DPO approval. The current account-deletion control attempts to remove the Supabase Auth user, user-owned database rows, and receipt objects immediately, and it attempts to revoke active Open Banking consents first. Revocation can fail during a provider outage. Deletion does not remove information already sent to HMRC or records Stripe or another independent controller must retain. Backups, security logs, email records, analytics, support records, and provider copies follow separate schedules and may not disappear immediately. Submitted tax records may need to be retained, but the exact responsibility, period, legal basis, lock behavior, and exception process must be approved and tested. The existing application retention mechanism must not be described as complete evidence until its scheduling and deletion interactions are verified. Until that review is complete, production release is blocked and the Service must not promise a universal 30-day or seven-year period.

11. Your Data-Protection Rights

Subject to the law and applicable exceptions, you may request access, rectification, erasure, restriction, portability, or object to some processing, and you may withdraw consent. The in-product JSON export is a convenience export and is not yet a complete response to every possible subject-access or portability request. Contact legal@landlordtax.app for a full rights request. We may need to verify identity and distinguish your data from information about other people. We aim to respond within one calendar month unless the law permits an extension. You may complain to the Information Commissioner's Office at ico.org.uk. Contacting us first is optional.

12. Automated Suggestions

Rules and optional AI can suggest transaction categories. Suggestions can be wrong and must be reviewed by the user. The Service is not intended to make solely automated decisions that produce legal or similarly significant effects. The DPIA must assess whether bank data, inferred categories, and model-provider processing create additional risks before the AI path is enabled in production.

13. Security and Incidents

Current controls include TLS in transit, server-side secret handling, database row-level policies, access checks, content-security policy, rate limits, audit events, and error monitoring. These controls reduce risk but do not guarantee absolute security. The project's internal release gate requires an independent penetration test, a documented security-control review, incident exercise, restore test, and remediation sign-off before production. These controls do not represent HMRC or legal certification. Suspected personal-data incidents should be reported immediately to legal@landlordtax.app.

14. International Transfers

Some primary database services are expected to operate in Ireland, while hosting, support, analytics, monitoring, payments, email, AI, and banking providers may process data in the UK, EEA, United States, or other locations. The final notice must reflect the actual production configuration. Adequacy, the UK International Data Transfer Agreement or UK Addendum to Standard Contractual Clauses, and transfer-risk assessments must be documented where required. Generic statements about appropriate safeguards are not sufficient evidence.

15. Changes and Contact

Material changes will be versioned and communicated through an appropriate channel. A privacy notice explains processing; continued use is not treated as consent where consent is the required lawful basis. Contact: legal@landlordtax.app Operator details: pending verification Privacy owner/DPO status: pending confirmation Postal address and ICO registration: pending confirmation

Privacy or data request

Contact legal@landlordtax.app or visit the Information Commissioner's Office.