Privacy Policy
Draft for launch preparation · Last updated 25 August 2026
Important: this is a practical launch draft and should be reviewed against your final business structure, data-retention choices and any legal advice before public launch.
1. Who this policy is for
This policy explains how In The Middle handles personal information when someone creates an account, manages a business profile, stores customer details, creates invoices, records payments or sends invoice and receipt emails.
2. Information we may process
Depending on how the service is used, this can include account details, business contact details, customer names and contact information, invoice and job information, payment records, tax-related identifiers entered by the user, and technical information needed to operate and secure the service.
3. Why we use information
We use information to provide the invoicing service, authenticate users, create and store invoices and receipts, send requested emails, record payments, provide support, maintain security, prevent misuse, and meet applicable legal or accounting obligations.
4. Legal bases
Where UK data-protection law applies, processing may be based on performance of a contract, legitimate interests in operating and securing the service, compliance with legal obligations, or consent where consent is the appropriate basis.
5. Service providers
The service is built to use specialist providers for hosting, authentication/database services and transactional email. Current integrations include Supabase for authentication/database services, Vercel for hosting, Resend for transactional email and Stripe for optional card-payment processing/connected business accounts. These providers process information as needed to provide their services and are subject to their own contractual and privacy terms.
6. Customer information entered by businesses
A business using In The Middle is responsible for having an appropriate basis to enter and use its customers’ personal information. In The Middle provides the software used to store and process that information on the business user’s instructions.
7. Retention
Information should be retained only for as long as needed for the service, legitimate business records and applicable legal or accounting requirements. A final public version of this policy should state the retention periods adopted for account data, invoices, payment records and support/security logs.
8. Security
We use technical controls intended to limit access between businesses, protect authentication sessions and keep server-side credentials out of browser-exposed configuration. No online service can guarantee absolute security.
9. International processing
Some service providers may process information outside the United Kingdom. Where required, appropriate contractual or other lawful transfer safeguards should be used by the relevant provider.
10. Your rights
Depending on the circumstances, individuals may have rights to access, correct, erase or restrict use of their personal information, object to certain processing, or request data portability. They may also have the right to complain to the UK Information Commissioner’s Office.
11. Contact
Privacy questions can be sent to support@example.com.
