Privacy Policy
How we collect, use, share, and protect your personal information
Introduction
GoSavis Limited ("GoSavis", "we", "our", or "us") provides a platform that connects people who need local services with the businesses and individuals that supply them. This Privacy Policy explains what personal information we collect when you use our customer site or the GoSavis Business operator surface, why we collect it, who we share it with, and the rights you have over it.
We have written this policy to be plain rather than legalistic. Where a section needs to be precise for legal reasons, we have tried to follow each precise statement with a sentence in ordinary language. If anything here is unclear, please get in touch using the contact details at the bottom of this page and we will do our best to explain.
This policy provides information about our processing; it is not a request for blanket consent. Where we rely on consent for a specific optional activity, we ask separately and you can withdraw it. We notify account holders about material changes where the change affects how their information is used.
Who is the data controller
The data controller for personal information processed through GoSavis is GoSavis Limited, registered in England and Wales under company number 12899784. Our registered office is 32 Eyre Street, Sheffield, England, S1 4QZ. We are registered with the Information Commissioner's Office under registration reference ZC244835. The individual accountable for data protection at GoSavis is Raymond Mawanda, and if you have any questions about how your information is handled you can reach him at privacy@gosavis.com. For statutory enquiries you may also contact the Information Commissioner's Office (ICO), which is the UK supervisory authority for data protection.
Information we collect
Information you give us directly
The information we collect depends on the features you use. It can include:
Account details: Your name, the email address you sign in with, a phone number if you have provided one, and any password you set. Passwords are never stored in readable form
Profile details: Your username, display photo, biography, contact and location visibility choices, service area, portfolio, favourites and other preferences
Booking and service data: Listings, availability, booking times, service locations, prices, cancellation conditions, notes, intake answers and booking history
Payment and payout records: Payment status, amount, currency, card brand and last four digits where returned by Stripe, tokenised payment-method and customer references, tips, fees, refunds, disputes and operator payout status. Stripe receives the raw card or bank details used in its payment components; GoSavis does not store raw card numbers
Business billing records: Where a business adds a card or a Bacs Direct Debit in Billing for GoSavis to collect what it owes us under the Operator Agreement: for a Direct Debit, the last four digits of the bank account, the mandate reference and whether the mandate is pending, active or ended, and for a card, its brand, last four digits and expiry. We also keep a record of the authorisation given with the payment method: the text agreed to, the version of the Operator Agreement in force, the account user who gave it, when, the IP address and user agent it was given from, and when and why it ended. With these we keep the business’s statements, the collections made from its payment method and the emails we send about them. Stripe collects the card or bank details on its own form or page, and GoSavis never receives a card number, bank account number or sort code
Communications: Messages, comments, reviews, posts, reports, complaints, appeals, support enquiries, feedback and any media you upload. With these we keep whether a message request is waiting, accepted or declined, which covered photos you chose to view, whether you chose to receive updates about a report you made, and the moderation decisions about your content
Business and verification details: Trading and legal names, registration and tax identifiers, business addresses, licences, insurance, ownership or representative details, identity documents, proof of address, date of birth where required for verification, and Stripe account status
Optional special requests: Information you choose to put in booking notes or operator intake answers. This may reveal health, disability, religious or other sensitive information. Share only what the business genuinely needs to provide the service, and do not include another person's sensitive information without authority
Information we collect automatically
We collect IP address, browser and device type, user agent, session and device identifiers, authentication and security events, approximate route information, timestamps, crash details and actions needed to prevent fraud or investigate a failure. If you ask to use your location, the browser supplies coordinates which we use to find nearby services and translate the coordinates into a place. Location preferences may remain on the device until you clear or change them.
Counting views of a business profile
When you open a business profile, we count the view so that businesses can see how often their profile is seen. To count each visitor only once a day, we combine your IP address and browser type with a key that changes every day and is deleted once the day ends, and keep only the code that results, so your address cannot be recovered from it and your visits cannot be linked from one day to the next. No cookie is used. We do not count the business itself or its team, automated visitors such as search engine crawlers, or a browser sending the Global Privacy Control signal. We rely on legitimate interests for this: giving businesses an accurate figure for how often their profile is seen. The daily records are deleted after 8 days.
Information from operators about their team
A business is the controller for workforce, rota, private customer-management and internal operational information it chooses to place in its private workspace. GoSavis acts as its processor only to the extent we host and handle that information on the business's documented instructions. The Data Processing Addendum governs that limited processor activity. GoSavis and the business otherwise act as independent controllers for their own purposes. In particular, GoSavis is a controller for platform accounts, marketplace discovery, booking orchestration, platform payments and fees, messages and reviews, security, fraud prevention, moderation, support, legal evidence and service administration. A business is a controller for providing its service, managing its workers, keeping its own records and communicating with its customers outside the platform. Team members and customers may contact either party; we will route a request to the party responsible for the relevant processing.
If you use the preview
The preview signs you into a sample account without creating one of your own, so we collect no name, email, or profile information from you. It uses a session cookie to keep you in the sample world while you look around, together with the same technical information described above; the session ends when you leave the preview or close your browser, and anything you did inside it stays in the sample world.
Lawful basis for processing
Under UK and EU data protection law we must rely on a specific lawful basis to process personal information. We rely on the following bases, depending on what we are doing with your data:
Performance of a contract: To create and secure your account, display the profile or listing you requested, operate bookings, provide messaging, process a payment or payout and deliver support connected with the service
Legitimate interests: To prevent fraud, recognise devices, secure the platform, diagnose failures, moderate content, investigate complaints, enforce our terms and improve service performance. We assess whether those interests are overridden by your rights
Consent: For optional external media and analytics technologies, and for direct marketing where we separately offer it. You can withdraw consent without affecting processing that was lawful before withdrawal
Legal obligation: To retain records required by tax, accounting and consumer law, respond to lawful requests, meet payment and anti-fraud duties, and comply with applicable online-safety obligations
Vital interests: In a genuine emergency, where processing is necessary to protect somebody's life or physical safety
GoSavis does not ask customers to place medical records or other special-category information in ordinary booking notes. If a business genuinely needs sensitive information to provide a service, that business is responsible for identifying an Article 9 condition, giving an appropriate notice and collecting no more than necessary. GoSavis processes operator-configured intake answers to deliver the booking and restricts access to the relevant parties.
When a business pays us what it owes under the Operator Agreement, by card or by Bacs Direct Debit, we rely on performance of that agreement to take and manage its payment method and to collect from it, on legal obligation to keep its statements and collections as accounting records, and on legitimate interests to keep the record of its authorisation as evidence that the business agreed to be charged.
How we use your information
We use personal information for the following purposes:
Registering, authenticating and supporting accounts, including email verification, social sign-in, multi-factor authentication and trusted-device controls
Publishing profiles, listings, posts, reviews and other content according to the visibility choices you make
Creating, administering, cancelling and evidencing bookings and the provider conditions that apply to them
Processing online payments, refunds, disputes, platform fees and operator payouts, or recording an agreed pay-on-arrival method
Collecting what a business owes us under the Operator Agreement, from its later card payments and from the card or Bacs Direct Debit it adds, and sending it statements
Delivering messages and notifications between customers, businesses and their teams
Verifying businesses, protecting users, preventing fraud, moderating content and investigating reports or complaints
Answering support requests, handling data rights and maintaining legal, consent and audit records
Measuring and improving the service where the relevant technology is permitted
Search ordering, recommendations, fraud signals and moderation queues may use rules or scoring to prioritise information for review. GoSavis does not currently make a solely automated decision that produces a legal or similarly significant effect on you. Where a human moderator restricts content or an account, the applicable terms explain the notice, appeal and complaint routes. Recommendations and search leave out content under an open report until the report is decided, using the reports we already hold and no analysis of the content itself.
We do not sell personal information. We do not give suppliers permission to use GoSavis account, booking or payment information for their own advertising. Third-party services you deliberately open may process information under their own privacy terms, as explained below and in the Cookie Policy.
How we share your information
We share your personal information only when there is a clear reason to do so. The main categories are described below; outside these we do not share your data with third parties.
With other users to fulfil a booking
When a customer books a service, the relevant booking information (the customer's display name, the service requested, the time, and any notes the customer has chosen to share) is sent to the business that will fulfil it. Conversely, when a business confirms or updates a booking, the relevant information is shared back with the customer.
With our service providers
The suppliers used for a journey depend on the feature and environment. Our principal categories and providers are:
Infrastructure and security: Cloudflare for web delivery, security challenges and object storage; Render for application hosting; Neon for the application database; and Azure Key Vault for managed secrets
Payments and business onboarding: Stripe and Stripe Connect for card processing, payment-method references, refunds, disputes, identity or business verification and payouts, and for collecting what a business owes us by card or Bacs Direct Debit. Stripe collects each Direct Debit on our behalf and sends the Direct Debit emails, which confirm the instruction and give notice before each collection, in its own name
Email and notifications: Amazon Web Services, including Amazon SES, for transactional email
Identity: Google or Apple when you deliberately choose the corresponding sign-in option
Maps and location: Mapbox, OpenStreetMap tile services and Nominatim when a map or location lookup is requested
Optional measurement and media: Google Analytics where configured and permitted, and YouTube, Vimeo or TikTok when you allow and load external media
GoSavis also operates an in-house crash-reporting endpoint. It receives a limited error message, bounded stack information, application route and technical context needed to diagnose a failure. It is designed not to collect form contents, booking notes, raw payment data or authentication secrets. If a separately hosted error-monitoring provider is enabled in a future environment, we will update this policy before sending production events to it.
For legal and safety reasons
We may disclose information when we are required to by law, when we receive a valid legal request from a court or regulator, or when disclosure is reasonably necessary to protect the safety of our users, our staff, or the public. Where we can lawfully tell you about such a disclosure, we will.
International transfers
Some providers operate internationally or permit authorised support access from outside the United Kingdom. We first use a UK adequacy regulation where one applies. Otherwise we use the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses or another lawful transfer mechanism, together with a transfer-risk assessment and proportionate technical measures. You can ask
Safeguard enquiries: Email privacy@gosavis.com for more information about the safeguard used for a particular provider and how to obtain a copy, subject to necessary redactions.
How long we keep your information
We apply the following retention criteria and operational periods:
Accounts and profiles: For the life of the account. A closure request disables access and ordinarily enters a 30-day deletion grace period, after which profile data is deleted or anonymised unless a legal, safety or dispute hold applies
Short-lived authentication data: Email-verification and password-reset records normally expire after 7 days. Stale unverified accounts and routine authentication-event records are normally removed after 90 days
Bookings, payments and legal evidence: For the period needed to perform the booking, resolve refunds or disputes, prevent fraud and meet tax, accounting, consumer and legal-claims requirements. Some transaction records may normally be retained for up to 6 years
Business payment methods and authorisations: The record of the authorisation a business gave with its card or Direct Debit is kept while the payment method is in use and for six years from the end of the accounting year in which it ended. When the business’s account is deleted, we first collect what it still owes and cancel its Direct Debit with Stripe, and the IP address and user agent are then removed from the record, which is kept for the rest of that period. Its statements and collections are kept as transaction records
Messages, content, reports and support: While the account or content is active and afterwards only for as long as reasonably needed to provide support, investigate a report, protect users, establish legal claims or comply with law. A moderation decision and any appeal against it are kept for three years from the decision, and a photo removed from a conversation after a report is kept privately as evidence for one year
Verification records: For as long as required to complete verification, maintain trust and payout controls, investigate fraud or meet an applicable legal obligation. Raw documents are restricted and should be removed earlier than the resulting verification record where possible
A deletion request does not erase information another user needs as part of their own booking record or content which must be retained for safety or legal reasons. In those cases we remove or replace account identifiers where possible. Backups age out through their normal cycle and are not restored for ordinary use after deletion.
If the GoSavis service closes, we will tell the people whose personal information we hold, stop processing it and delete it within 90 days. The one exception is financial records that the law requires us to keep for six years: we keep those for that period and then delete them.
Your rights
Depending on the processing and the law that applies, you may have the right to be informed, obtain access, correct inaccurate information, request erasure, restrict processing, object to processing based on legitimate interests, obtain portable information you supplied under consent or contract, and withdraw consent. You have an absolute right to object to direct marketing. These rights have legal limits, for example where we must keep a transaction record or another person's rights are affected.
Account settings provide some correction, visibility and closure controls. For access, restriction, objection, portability or anything unavailable in the product, email privacy@gosavis.com. We may ask for proportionate identity evidence. We normally respond within one calendar month and do not charge a fee unless a request is manifestly unfounded or excessive and the law permits it.
You can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint/, or to the supervisory authority where you live or work. We would appreciate the opportunity to investigate your concern first.
How we keep your information secure
We use measures designed for the sensitivity and risk of the information involved. These include TLS in transit, restricted private storage for identity documents, tokenised payment components, hashed passwords, HttpOnly session cookies, multi-factor and step-up authentication, least-privilege production access, request and rate-limit controls, audit records and monitoring. Supplier security controls apply to information held in their systems.
No online service can guarantee absolute security. If a personal-data breach creates a legal duty to notify you or a regulator, we will do so within the applicable period and provide the information required by law.
Children
An account and a booking contract are intended for people aged 18 or over. Our children’s access assessment concludes that public pages, listings and user content are nevertheless likely to be accessed by children because they can be viewed without highly effective age assurance. We therefore treat those parts of GoSavis as likely to be accessed by children and apply the corresponding safety duties. If you believe a child has created an account or disclosed personal information, contact
Child privacy report: privacy@gosavis.com
If someone else booked a service for you
This section is for you if someone booked a service for you on GoSavis and gave us your details to do so. It explains what we hold about you, where it came from and what we do with it. You do not need a GoSavis account to use any of the rights it describes.
Who we are: GoSavis Limited, registered in England and Wales under company number 12899784, with its registered office at 32 Eyre Street, Sheffield, England, S1 4QZ, is the controller of these details. You can reach us at privacy@gosavis.com.
What we hold: Your name and the phone number or email address the person who made the booking gave us. Where they told us that you are below the age of majority where the service is delivered (18 in the United Kingdom), we also hold that fact. Where we emailed you about the booking, we keep a record of that email and whether it was sent.
Where it came from: From the person who made the booking, not from you.
Why we use it: So that the business can provide the service to you: it needs to know who it is serving and how to reach you. Where the contact given is an email address, we use it to send you one email when the booking is made, saying who booked what for you, with whom and when. Where you were marked as below the age of majority, we also use that to protect you: the booking is held for the business to accept rather than confirmed automatically, the person who made the booking must confirm that a parent or guardian has agreed and we record that confirmation, and the business is told before it provides the service. We do not use your details for marketing.
Our lawful basis: Legitimate interests: the interest of the person who made the booking, of the business and of you in the service reaching the person it was booked for.
Who receives it: The business providing the service, and those of its staff who handle its bookings, see your name, the contact given and, where it applies, that you are below the age of majority. The suppliers that host GoSavis and send its email, listed under "How we share your information", handle these details for us.
How long we keep it: With the booking record, for as long as that record is kept, as described under "How long we keep your information". If the person who made the booking closes their GoSavis account, your name and contact details are removed from the booking, and from our record of any email we sent you, when their account is deleted. Where you were marked as below the age of majority, that fact stays on the business's record of the booking without your name or contact details.
Your rights: You have the rights described under "Your rights", including to see these details, to have them corrected or deleted, and to object to our using them; some have legal limits, which that section explains. You do not need an account to use them: email privacy@gosavis.com, naming the business and the date of the booking if you can. You can also complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint/.
Changes to this policy
We may revise this policy from time to time as the product, our suppliers, or the law change. The date at the top of this page reflects the most recent revision, and we will notify you about material changes through the channels you have chosen for service updates so that you have a meaningful opportunity to read them before they take effect.
Contact
If you have any questions about this policy, want to exercise one of the rights described above, or would like to raise a concern about how your information is being handled, please get in touch using the details below.
Privacy enquiries: privacy@gosavis.com
General support: support@gosavis.com
Telephone: 0114 551 9990
Response time: Within 5 business days, and within one calendar month for formal rights requests