Privacy policy
01. Who we are
Graftap is a WhatsApp-based lead management service for UK tradespeople, operated by Graftap ("we", "us", "our").
We are committed to protecting your personal data and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
02. What data we collect
We collect different types of data depending on how you interact with Graftap.
If you are a tradesperson signing up to Graftap:
- Your name and business name
- Your trade (e.g. plumber, electrician)
- Your WhatsApp mobile number
- Your service area
- Your subscription plan (free or Pro)
- The date you signed up
If you are a customer enquiring through Graftap:
- Your name
- Your phone number
- Your WhatsApp number
- Your full postcode or street address (area shown in lead card — full address only released to tradesperson on job acceptance)
- The nature of the job you need doing
- The urgency of the job
- Any photos of the job you choose to send
Data we generate automatically:
- Caller trust score — a score (0–100) assigned to each phone number based on interaction history with a specific tradesperson. Used to filter spam and prioritise genuine job enquiries. Never shared outside Graftap.
- Conversation metadata — message counts, response times, and session markers used to manage conversation flow. Not readable by humans.
- Spam signals — message rate, content patterns, and repeat contact frequency used to detect and block abusive usage.
If you contact us via our website contact form:
- Your name, email address, trade, and message
We do not collect payment card details directly. Any payments are processed by third-party payment providers subject to their own privacy policies.
03. How we use your data
We use your personal data only for the purposes for which it was collected:
- To provide the Graftap service — routing customer enquiries to the correct tradesperson via WhatsApp
- To manage your account — tracking your lead usage, plan status, and account settings
- To communicate with you — sending lead notifications, account updates, and service messages via WhatsApp
- To improve our service — analysing usage patterns to improve how Graftap works
- To respond to enquiries — replying to messages sent via our contact form
- To comply with legal obligations — retaining records as required by law
We will never sell your personal data to third parties. We will never use your data for advertising purposes without your explicit consent.
04. Lawful basis for processing
Under UK GDPR we must have a lawful basis for processing personal data. Our bases are:
- Contract — processing necessary to provide the Graftap service you have signed up for
- Legitimate interests — improving our service, preventing fraud, and ensuring security
- Legal obligation — where we are required to process data by law
- Consent — where you have explicitly opted in to marketing communications
05. Who we share data with
We share your data only where necessary to provide the service:
- Twilio Inc — our WhatsApp messaging provider. Messages sent through Graftap pass through Twilio's infrastructure. See Twilio's Privacy Policy.
- Supabase Inc — our database provider, where account and lead data is stored securely. See Supabase's Privacy Policy.
- Groq Inc — our AI provider, which processes conversation text to generate responses. Conversations are not stored by Groq beyond the immediate request. See Groq's Privacy Policy.
- Resend Inc — our email provider, used to send transactional emails (welcome emails, payment notifications). See Resend's Privacy Policy.
- Stripe Inc — our payment processor. Stripe handles all payment card data. We do not store card details. See Stripe's Privacy Policy.
- Formspree — processes contact form submissions. See Formspree's Privacy Policy.
All third-party providers are contractually required to handle your data securely and in accordance with UK GDPR. We do not share data with any other third parties without your consent.
Some of our providers are based outside the UK. Where data is transferred internationally, we ensure appropriate safeguards are in place under UK GDPR transfer mechanisms.
06. How long we keep data
We keep your data only for as long as necessary:
- Tradesperson account data — retained for the duration of your account plus 12 months after deletion
- Lead records — retained for 24 months then permanently deleted
- Contact form submissions — retained for 12 months
- WhatsApp conversation data — conversations are held in memory only and not permanently stored. They are cleared when the conversation ends.
- Caller trust scores — retained for the duration of the associated tradesperson account, then deleted. You can request deletion at any time.
- Spam detection data — in-memory only, reset on server restart. Not permanently stored.
You can request deletion of your data at any time — see Your Rights below.
07. Your rights
Under UK GDPR you have the following rights regarding your personal data:
- Right of access — you can request a copy of the data we hold about you
- Right to rectification — you can ask us to correct inaccurate data
- Right to erasure — you can ask us to delete your data ("right to be forgotten")
- Right to restrict processing — you can ask us to limit how we use your data
- Right to data portability — you can request your data in a portable format
- Right to object — you can object to processing based on legitimate interests
- Rights related to automated decision-making — Graftap uses automated scoring (trust scores, opportunity scores) to prioritise and filter leads. You have the right to request human review of any automated decision that significantly affects you.
To exercise any of these rights, contact us at our contact form (graftap.co.uk). We will respond within 30 days.
If you are unhappy with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
08. Cookies
Our website (graftap.co.uk) does not currently use tracking cookies or analytics cookies. We do not use Google Analytics, Facebook Pixel, or any third-party tracking tools.
If this changes, we will update this policy and request your consent before placing any non-essential cookies.
09. Security
We take the security of your personal data seriously. Our security measures include:
- All data stored in Supabase is encrypted at rest
- All data in transit is encrypted using TLS/HTTPS
- API keys and credentials are stored as environment variables, never in code
- Access to the database is restricted to authorised systems only
No method of transmission over the internet is 100% secure. While we use commercially acceptable means to protect your data, we cannot guarantee absolute security.
If you become aware of any security vulnerability in our systems, please contact us immediately at our contact form (graftap.co.uk).
10. Contact us
If you have any questions about this privacy policy or how we handle your personal data, please get in touch:
We may update this privacy policy from time to time. When we do, we will update the "last updated" date at the top of this page. Continued use of Graftap after any changes constitutes acceptance of the updated policy.