Who is responsible
PayroScope is responsible for personal data used to provide the service. Privacy questions can be sent to info@payroscope.com.
What we collect
We store account details such as your name, email address and securely hashed password; the financial planning information you choose to enter; project memberships and invitations; subscription identifiers supplied by Stripe; support messages; and limited security and diagnostic data such as request identifiers, IP address, browser details and error reports.
Our product analytics records anonymous page categories and named actions, such as opening pricing, starting checkout or creating an account. When you are signed in, it also uses a one-way opaque analytics identifier so activity across pages can be counted as one account; it does not receive your name, email address, project identifiers, financial values, form entries, notes, full URLs or session recordings. Browser crash reports include the error, application release and static route name, but exclude PayroScope request data and user details.
If you choose to connect a bank, PayroScope receives read-only account details, balances and transaction history through Plaid. PayroScope never receives your online-banking password and cannot make payments or move money. Bank linking requires a fresh strong-authentication check using a passkey, an authenticator-app code or a recovery code. Please avoid placing unnecessary sensitive information in free-text notes or support messages.
Why we use it
- To create your forecasts, save your choices and provide the service under our contract with you.
- To process subscriptions and maintain billing records.
- To secure, troubleshoot and improve PayroScope where our legitimate interests do not override your rights.
- To meet legal, tax and fraud-prevention obligations.
- To send optional communications only where you have asked for them or the law otherwise permits.
Who receives data
We use service providers only where needed to operate PayroScope. These may include hosting and database providers, transactional email delivery, Stripe for payments, Plaid for an optional read-only bank connection, PostHog for privacy-limited product analytics, and Sentry for error monitoring. Each provider receives only the data needed for its role. Project members can see information in projects you explicitly share with them.
International transfers
Some providers may process data outside the UK. Where that happens, we use an applicable adequacy decision or contractual safeguards required by data-protection law.
Retention and deletion
Account and planning data is kept while your account is active. When you disconnect a bank, PayroScope immediately revokes local access and automatically erases the disconnected connection, imported accounts, balances and bank transaction history after 30 days. You can permanently erase that imported bank data sooner from the bank connection page after confirming your password. Self-service account closure archives the account and projects you own, removes access and reserves the email for support-led recovery. You can ask support for permanent erasure, subject to information we must retain for legal, security or billing reasons. Limited backup copies expire under the operator's documented backup schedule and remain subject to its access controls.
Your choices and rights
You can correct profile information, download a versioned project archive and close your account from within PayroScope. Depending on the law that applies, you may also ask for access, correction, deletion, restriction, portability or objection, and complain to the UK Information Commissioner's Office.
Cookies
PayroScope uses strictly necessary session and security cookies to keep you signed in and protect forms. Stripe may set necessary cookies when you enter its hosted checkout or billing portal. PayroScope configures product analytics to use memory only, with cookies and browser persistence disabled. We do not use advertising cookies.
Changes
Material changes will be explained in the product or by email before they take effect where required.