LetzPool LetzPool Request Access
LEGAL · DATA PROTECTION

Privacy Policy

LetzPool Platform — Data Protection and Privacy Notice

Company No. 17063044 Effective Date June 2026

This Privacy Policy explains how LetzPool Ltd ("LetzPool", "we", "us") collects, uses, stores, and shares personal data when you use the LetzPool platform. It also describes your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

LetzPool is the data controller for personal data processed in connection with platform governance, pool management, and member communications. Stripe Technology Europe Limited acts as an independent data controller for personal data it processes in connection with its own regulated obligations, including identity verification, payment processing, card issuance, and refund execution.

Contents

01 Who We Are

LetzPool Ltd is incorporated in England and Wales (Company Number: 17063044). Our platform is a pooled-entity spend governance service built on Stripe's licensed payment infrastructure. We act as data controller in respect of personal data we collect and process. Stripe acts as data processor for certain data processing activities performed on our behalf and as independent data controller for its own regulated obligations.

02 Data We Collect

2.1 — Identity and Verification Data

To onboard as an Authorised Member, you must complete identity verification via Stripe Identity. This involves:

  • Government-issued identity document (e.g. passport, driving licence);
  • Biometric selfie and liveness check;
  • Verification outcome (pass/fail) communicated to LetzPool by Stripe webhook.

LetzPool receives only the verification outcome from Stripe. LetzPool does not receive, store, or process the underlying document images or biometric data — these are processed and retained by Stripe in accordance with Stripe's own privacy policy.

2.2 — Account and Pool Data

We collect and process:

  • Your name and email address, provided at registration;
  • Pool membership status (INVITED, ACTIVE, SUSPENDED, LEFT);
  • Pool governance data: pool name, creation date, active member count, pool status;
  • Stripe Customer ID and Stripe Card ID (tokenised references — not raw payment card data).

2.3 — Financial Event Data

We maintain a canonical, append-only ledger of all financial events affecting your pool. This includes:

  • Contribution events (PaymentIntent confirmed, amount, timestamp);
  • Spend authorisation and settlement events (amount, merchant category, timestamp);
  • Dissolution and refund events (refund amount, status, timestamp);
  • Chargeback and dispute events where applicable.

All financial event data is derived exclusively from confirmed Stripe webhook events. The canonical pool balance is the single source of truth; individual member balances are never stored — equity per member is derived on demand from the pool balance and active member count.

2.4 — Support and Dispute Data

Where you submit a support request or transaction dispute via the platform, we collect:

  • Ticket type and description;
  • Stripe transaction reference identifiers;
  • Timestamp of submission.

Support ticket records are append-only and cannot be modified or deleted by any member. This ensures an unalterable audit log for regulatory and dispute purposes.

2.5 — Technical Data

We collect standard technical data in connection with platform operation, including:

  • IP address and device information at the time of account creation and authentication;
  • Webhook event identifiers received from Stripe (used for idempotency and audit purposes);
  • Server-side logs generated in connection with platform events.

03 How We Use Your Data

We process your personal data on the following legal bases:

3.1 — Performance of a Contract (UK GDPR Article 6(1)(b))

We process identity, account, pool governance, and financial event data to:

  • Admit you as an Authorised Member following identity verification;
  • Maintain the canonical pool balance and enforce the Equal Ownership Fairness model;
  • Issue Stripe Issuing virtual cards and enforce spend controls on your behalf;
  • Execute dissolution and equal Refund-to-Source on pool closure.

3.2 — Legal Obligation (UK GDPR Article 6(1)(c))

We process data to comply with applicable legal obligations, including:

  • Anti-money laundering obligations under the Proceeds of Crime Act 2002 and the Money Laundering Regulations 2017;
  • Suspicious activity reporting obligations where applicable thresholds are met;
  • Financial record retention obligations.

3.3 — Legitimate Interests (UK GDPR Article 6(1)(f))

We process technical and audit log data in pursuit of our legitimate interests in:

  • Preventing fraud, abuse, and financial crime;
  • Maintaining platform integrity and security;
  • Providing evidence in dispute and chargeback proceedings.

04 Data Retention

We retain personal data for the following periods:

  • Financial transaction records (pool ledger, ActivityEvent log, contribution and refund records): retained for 7 years from the date of the relevant transaction, in accordance with applicable UK financial record-keeping requirements.
  • KYC verification status records: retained for 5 years from the end of the relevant business relationship (i.e. from the date your membership in all pools is terminated), in accordance with the Money Laundering Regulations 2017.
  • Support ticket and dispute records: retained for 7 years from submission, as part of the immutable audit trail required for regulatory and dispute purposes.
  • Account and identity data (name, email, Stripe Customer ID): retained for the duration of your relationship with LetzPool and for 5 years thereafter, or for such longer period as is required by applicable law.

After the applicable retention period, personal data is securely deleted or anonymised.

05 Data Sharing

5.1 — Stripe Technology Europe Limited

Stripe is our primary infrastructure partner and processes personal data in connection with:

  • Identity verification (Stripe Identity);
  • Payment processing (Stripe PaymentIntents);
  • Card issuance and spend authorisation (Stripe Issuing);
  • Dissolution refunds (Stripe Refunds API);
  • Fraud screening (Stripe Radar).

LetzPool is in the process of executing a Data Processing Agreement with Stripe prior to commercial launch. Stripe also acts as an independent data controller in respect of its own regulated KYC, AML, and financial crime obligations. Stripe's privacy policy is available at stripe.com/privacy.

5.2 — Supabase Inc.

LetzPool's backend infrastructure is hosted on Supabase (PostgreSQL database and Deno Edge Functions). Supabase processes personal data as a data processor on our behalf, under a Data Processing Agreement. Data is stored in the EU/UK region.

5.3 — Legal and Regulatory Disclosure

We may disclose personal data to law enforcement, regulators, or other authorities where required by applicable law, including where we are required to file suspicious activity reports under the Proceeds of Crime Act 2002.

5.4 — No Sale of Personal Data

LetzPool does not sell, rent, or otherwise commercialise your personal data to third parties.

06 International Transfers

LetzPool's primary data processing infrastructure is located in the UK and EU. Where personal data is transferred outside the UK or EU (for example, in connection with Stripe's global infrastructure), such transfers are conducted under appropriate safeguards, including UK International Data Transfer Agreements or EU Standard Contractual Clauses, as applicable.

07 Your Rights

Under the UK GDPR you have the following rights in respect of your personal data:

  • Right of access: you may request a copy of the personal data we hold about you;
  • Right to rectification: you may request correction of inaccurate personal data;
  • Right to erasure: you may request deletion of your personal data, subject to our legal retention obligations. Financial transaction records and KYC records are exempt from erasure under UK GDPR Article 17(3)(b) for the duration of the applicable retention period;
  • Right to restriction: you may request that we restrict processing of your data in certain circumstances;
  • Right to data portability: you may request your data in a structured, machine-readable format where processing is based on consent or contract;
  • Right to object: you may object to processing based on legitimate interests.

To exercise any of these rights, contact us at: privacy@letzpool.co.uk. We will respond within one calendar month of receipt of your request.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe we have not handled your personal data in accordance with applicable law.

08 Security

LetzPool implements the following technical and organisational measures to protect your personal data:

  • All financial state mutations are executed by SECURITY DEFINER database functions, accessible only by the platform service role;
  • Webhook events from Stripe are validated by cryptographic signature verification before processing;
  • The ActivityEvent ledger is append-only; no UPDATE or DELETE permissions are granted to the application database role;
  • Row-Level Security (RLS) policies ensure that members can access only their own pool and account data;
  • All data in transit is encrypted via TLS. Data at rest is encrypted by Supabase's managed PostgreSQL infrastructure.

09 Cookies

LetzPool's web platform uses only strictly necessary cookies required for authentication and session management. No advertising, tracking, or analytics cookies are set without your consent.

10 Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to Authorised Members with reasonable notice before they take effect. The current version of this Privacy Policy is always available at letzpool.co.uk/privacy.

11 Contact

Privacy Queries & Data Rights

LetzPool Ltd

privacy@letzpool.co.uk

Co. No. 17063044 · England and Wales

Complaints

Information Commissioner's Office

ico.org.uk

0303 123 1113