Privacy notice
How I look after your details.
Flow is one person, and the only data I hold is what I need to clean your windows and get paid for it. This notice explains what that is, in plain words. It is written to meet UK GDPR and the Data Protection Act 2018.
Last updated 9 September 2026.
Who is responsible
The data controller is Harry Wright trading as Flow Window Cleaning, a sole trader based in Cam, Gloucestershire GL11. Contact me at [email protected] for anything in this notice.
ICO registration number: to be confirmed before the customer database goes live.
What I collect, and where it comes from
If you join the round through this website
Your name, address and postcode, a phone number or an email address (whichever you give; one is enough), anything you write in the message box, and a voucher code if you have one. The form also records the time and whether your postcode is on my round.
If I knock on your door
I keep a canvassing log: the address, whether anyone answered, whether you were interested, a pane count if I made one, and any notes you asked me to remember (“try again after 6”). If you say no, I record that so I do not knock again.
If you become a customer
- Your name, email and mobile number.
- Your address and its location on a map, the type of house, the pane count, and access notes such as a gate code or where the dog lives.
- Photographs of the outside of your property where useful for the job (a tricky window, a before-and-after). Never inside, never people.
- Your visit history, what each clean cost, and the receipts and reminders I have sent you.
- Payment records: whether each payment succeeded. Your bank details are held by GoCardless, not by me; card details are held by Stripe. I never see either.
- Referral records: which leaflet was left with you, which codes were redeemed and the discounts that resulted.
Messages
Texts and emails between us are kept with your record so I can see what I have already told you.
Your online account
Customers can sign in at flowwindowcleaning.co.uk/account. When you join, my welcome text or email carries a link to set up your account with a one-time account code (it stops working once used, and expires after 60 days). You choose an email address and a password. Passwords are stored only as a salted hash by Supabase Auth, my sign-in provider; I never see them and cannot read them back. If you forget yours you can reset it from the sign-in page: I email you a one-time link, which expires after an hour. You can also ask for a one-time sign-in link by email instead of using your password. Signing in stores a session token in your browser’s local storage (not a cookie) so you stay signed in on that device until you sign out; signing out or clearing your browser data removes it.
The account shows you the records above that are yours: your next clean, your visits and what each cost, whether each payment has been collected, your discounts and referral code, and your name and number, which you can correct yourself. Messages you send me through it are stored with your record so I can act on them and see what was said. If you pay by card from the account your card details go straight to Stripe, and if you set up a Direct Debit your bank details go straight to GoCardless; neither passes through this website or my database.
From this website
Nothing beyond the form above and, for customers, the online account. There are no cookies, no analytics and no third-party scripts or fonts. My hosting provider keeps ordinary server logs (IP address, pages requested) for security, which I do not use to identify anyone.
Why, and the legal basis
| What I do | Lawful basis (UK GDPR Article 6) |
|---|---|
| Reply to your enquiry and arrange a first visit | Legitimate interests (you asked me to) |
| Quote, schedule, clean, text you the day before, take payment, send receipts | Performance of a contract |
| Keep a canvassing log so I do not knock twice, and to plan the round | Legitimate interests |
| Work out the neighbourhood rate and referral discounts (uses the location of your address) | Performance of a contract |
| Keep records of sales and payments | Legal obligation (tax and accounting law) |
| Prevent abuse of the enquiry form and voucher codes | Legitimate interests |
| Send you anything that is marketing rather than service (rare) | Consent, which you can withdraw at any time |
Service messages (the text the day before, receipts, a rain-off, the neighbourhood rate kicking in) are part of the service and are not marketing. I will not send you marketing unless you have ticked a box asking for it.
Referrals and neighbours
Voucher codes are tied to the customer who was given the leaflet. When a neighbour redeems one, I see that the two addresses are linked and how far apart they are, so I can apply the discounts. Your neighbour is not told your name by me, and you are not told theirs; you will simply see a referral discount appear on your receipts.
Who else handles your data
I do not sell or rent personal data, and I do not share it for anyone else’s marketing. I use these companies as processors, each under a contract that limits what they can do with it:
- Supabase — hosts the database and the code behind the enquiry form and the app.
- GoCardless — collects Direct Debits. Your bank details are given directly to them.
- Stripe — takes card and Apple Pay payments for one-off cleans.
- Twilio — sends the text messages.
- Cloudflare Pages — hosts this website.
- Resend — sends the emails (welcome, receipts, replies).
My accountant may see sales records. I will disclose data if the law requires it, for example to HMRC or on a court order.
Where your data goes
I aim to keep data in the UK or EU. Some of the providers above are US companies or use US infrastructure; where data leaves the UK it is covered by the UK’s data-bridge or adequacy decisions, or by the International Data Transfer Agreement / standard contractual clauses, as appropriate.
How long I keep things
- Canvass notes and enquiries that do not become customers: deleted 12 months after the last contact. A “no thanks” at the door is kept only as an address with no name, so I do not knock again.
- Customer records: kept while you are a customer and for 6 years after your last payment, because tax law requires me to keep sales records that long. After that they are deleted or anonymised.
- Property photos and access notes: deleted when you stop being a customer.
- Messages: kept with your customer record and deleted on the same schedule.
- Direct Debit mandates: cancelled when you leave; GoCardless keeps its own records as required by the Direct Debit scheme.
Your rights
Under UK GDPR you can ask me to:
- tell you what data I hold about you and give you a copy (access);
- correct anything that is wrong (rectification);
- delete your data where I no longer need it (erasure). I will keep the minimum needed for tax records, anonymised where possible;
- stop or limit how I use it (restriction and objection);
- give you your data in a portable format;
- withdraw consent for anything that was based on consent.
Email [email protected] and I will respond within one month. There is no charge. If you are unhappy with how I have handled your data you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113, though I would be grateful for the chance to sort it out first.
Keeping it safe
Data is encrypted in transit and at rest. The database enforces row-level access rules so that only my own signed-in account can read customer data, and a customer signed in to their online account can read only their own; the public website can only submit a join request and read public coverage. My devices are locked and encrypted. If there were ever a breach that put you at risk I would tell you and the ICO within 72 hours.
Cookies and analytics
This website sets no cookies and uses no analytics or tracking. Fonts are served from this site, not from Google. The postcode check and the join form talk directly to my database provider and send only what you type in the box. Signing in to your online account keeps a session token in your browser’s local storage so you stay signed in; that is not a cookie and is not used to track you. If any of this ever changes, this notice will say so first and anything non-essential will ask for consent.
Children
The service is for householders and this site is not aimed at anyone under 18. I do not knowingly collect children’s data.
Changes to this notice
If I change how I use your data I will update this page and, for anything significant, email existing customers. The date at the top tells you when it was last revised.