Pencil

Legal

Privacy policy

Last updated: 1 October 2026.

This policy explains how Pencil handles personal data under the UK GDPR and the Data Protection Act 2018. It sits alongside our terms of service. It is written for people in the United Kingdom.

Who we are

Pencil is the trading name of the operator of getpencil.co.uk and app.getpencil.co.uk (“we”, “us”). We are based in the United Kingdom. We have not yet published a limited-company name, company number, or registered office on this site. When we incorporate or appoint a named controller, we will update this page. Until then, the controller of your account data is the operator of those domains.

For privacy requests, use the contact details on getpencil.co.uk. You can also complain to the Information Commissioner’s Office at ico.org.uk.

Who this policy covers

It covers visitors to the marketing site, people who start a trial, and people who use Pencil as a tradesperson.

It also explains how we handle messages, names, phone numbers, addresses, job notes, quotes, invoices, and photos that relate to your customers (homeowners and other clients). For that customer data, you are the controller and we are the processor. We only process it to provide Pencil to you. We do not use it to market to your customers, and Pencil does not message them first.

Data we collect about you

When you sign up or use the Service we typically process:

  • Your mobile number (stored in international format) and whether you accepted the terms.
  • Account and membership status, including trial start and end dates.
  • Messages you send to Pencil, drafts we generate for you, and whether you send, edit, or copy them.
  • Quotes, invoices, job notes, calendar details you connect, and files or photos you upload or forward.
  • Technical logs: IP address, device/browser, timestamps, and error data needed to run and secure the Service.
  • Later: billing details (name, email, VAT number if you give one, last four digits of a card via Stripe). We do not take payment from your customers.

We do not create an account from an inbound WhatsApp until you have signed up on the web and messaged us first.

Customer data you put into Pencil

If you forward a chat, connect WhatsApp Business, or type a customer’s details, we will store that content so we can draft replies, bookings, quotes, and invoices for you. That can include names, phone numbers, addresses, job photos, and whatever else appears in the thread.

You must only put in data you are allowed to use for your business. You are responsible for telling your customers what you do with their information, if the law requires it. We do not seek special category data (for example health) or children’s data, but it can appear in a job photo or a message. If it does, we still only process it as your processor to run the Service.

Why we use the data (lawful bases)

For your account we rely mainly on contract (UK GDPR Article 6(1)(b)): we need the data to run the trial and the Service you asked for.

We rely on legitimate interests (Article 6(1)(f)) for security, abuse prevention, diagnosing faults, and understanding how the product is used at an aggregate level, where those interests are not overridden by your rights.

We rely on legal obligation (Article 6(1)(c)) where we must keep records (for example tax, once we bill you).

We do not treat ticking “I accept the terms” as GDPR consent. If we ever need consent (for example a non-essential cookie or optional marketing email), we will ask separately and you can withdraw it.

For customer data, our lawful basis as processor is that you have instructed us to process it under the terms. You must have your own lawful basis for collecting it (usually your contract with the customer, or legitimate interests in quoting the job).

AI drafts

We use third-party artificial intelligence systems to suggest replies, quotes, and related text. A human (you) decides what is sent to a customer. We do not use that process to make solely automated decisions that produce legal or similarly significant effects about you or your customers (UK GDPR Article 22).

We do not use your customer chats to train a public model for other businesses. Provider terms may allow limited technical processing; we will not opt in to a provider using your content to train their models, where we can turn that off.

Who we share data with

We do not sell personal data. We use other companies to run Pencil (“processors” or, for WhatsApp, a platform you also have a relationship with):

  • Vercel — hosting the website and app.
  • Supabase — database, file storage, and related backend services.
  • Meta / WhatsApp — delivery of WhatsApp messages. Meta’s terms and privacy policy apply to WhatsApp itself. We do not control Meta.
  • Google — Gemini, to generate drafts.
  • Stripe — membership payments when billing is live. Stripe is an independent controller of card data it collects. Pencil does not collect job payments from homeowners, and we do not use Stripe Connect for that.

We may share data if the law requires it, or if we transfer the business (we would still protect the data as the law requires).

International transfers

Some providers are in, or can access data from, countries outside the UK (including the United States). Where the UK does not treat that country as adequate, we rely on the UK International Data Transfer Agreement, the UK Addendum to the EU standard contractual clauses, or another transfer tool permitted by UK GDPR Chapter V.

How long we keep it

  • Account and membership records: for as long as the account is open, then up to 12 months after closure (longer if we must keep them for tax or a dispute).
  • Messages, media, quotes, and job records: for as long as the account is open. After you close the account, we delete or irreversibly anonymise them within 90 days, except where we must keep a copy (for example a legal claim).
  • Security and server logs: typically 90 days.
  • Unfinished or abusive sign-up attempts: up to 12 months, so we can enforce “one trial per person” fairly.

Your rights

You can ask us for a copy of your personal data, to correct it, to delete it, to restrict or object to certain processing, and to receive it in a portable form, in the circumstances set out in UK GDPR. You can also complain to the ICO.

Those rights apply to your account data. If a customer of yours wants their data deleted, they should contact you first. We will help you as processor where the request is valid and we still hold the data.

We may need to verify the request. We will not delete data we are required to keep.

Cookies

The public marketing site is intended to work without advertising cookies. The product on app.getpencil.co.uk uses cookies or similar storage that are necessary to run the account (for example a session). Those are exempt from PECR consent.

If we later add analytics or marketing cookies, we will update this policy and ask for consent where PECR requires it.

Children

Pencil is for people running a trade, aged 18 or over. We do not knowingly create accounts for children.

Security and messaging

We use access controls, encryption in transit, and database-level restrictions so other tradespeople cannot read your account. No method of transmission is completely secure.

We send electronic marketing only where privacy and electronic communications law permits it. Marketing messages will explain how to opt out, and you may object to direct marketing at any time.

Changes

We will change this policy when the product or the law changes. The date at the top is the current version. If a change is material, we will take reasonable steps to tell account holders (for example a notice in the product).