Legal · Privacy

Trayd Privacy Policy

This policy explains how we handle personal data when you use Trayd – the app and web dashboard for running a trades business. It is written to comply with the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Acts 1988–2018.

Version1.0
Last updatedSeptember 2026
EffectiveSeptember 2026
Privacy contactinfo@trayd.ie

Please read this carefully. When you create an account or are added to one by your employer, you'll be asked to confirm you've read it. This confirmation is an acknowledgement, not consent – our lawful bases for processing are set out in Section 4.

01Who we are

Trayd is operated by Trayd Ltd, a company registered in Ireland with its registered office in Limerick, Ireland. In this policy, "Trayd", "we", "us" and "our" refer to that company.

For the data described in Section 2 as ours, we are the data controller. For any privacy matter, including requests about your data, contact info@trayd.ie.

02Our two roles: when we are responsible, and when your employer is

Trayd holds different kinds of data, and our legal responsibility differs for each. This matters for knowing who to contact about your data.

When Trayd is the controller

For data we decide how to use ourselves, Trayd is the data controller. This covers the business owner's account and billing details, data about how the platform is used, and our own marketing and support records. You can contact us directly about this data.

When your employer is the controller

If you are a tradesperson or apprentice, your employer (the business that owns the Trayd account) adds you to the platform and decides what is recorded about you: your jobs, hours, location at check-in, leave, certifications and any documents they upload. For that data your employer is the data controller and Trayd is the data processor, acting only on their instructions under a Data Processing Agreement. To access, correct or delete that data, contact your employer first. We will support them in responding to you.

Your customers' details

Businesses using Trayd record details of their own customers – names, site addresses, contact details and invoices. For that data too, the business is the controller and Trayd is the processor. If you are a customer of a Trayd business and have a query about your data, contact that business.

03What data we collect

The data on Trayd depends on your role. This table summarises what is held and who is responsible for it.

CategoryExamplesWho is controller
Account detailsName, email, phone number, business name, role (Owner / Tradesperson / Apprentice), login codeOwner: Trayd. Employees: employer.
Job and work recordsJobs logged, start and completion times, labour hours, notes, materials used, tasksEmployer
Location dataA single GPS position and timestamp captured when an employee checks in to a job. No live tracking (see Section 5)Employer
Photos and documentsBefore/after job photos, receipts, delivery dockets, handwritten notes, trade certificatesEmployer
Customer detailsCustomer name, site address, contact details, invoice contentEmployer
InventoryVan stock levels per employee, reorder alertsEmployer
Leave and attendanceAnnual leave, on-call rota, sick leave recordsEmployer
Health-related dataReason for sick leave, only where the employee chooses to give one – special category data (see Section 7)Employer
CertificationsSafe Pass, RGI, RECI, CSCS and other trade certificates, with expiry datesEmployer
Billing dataSubscription tier, billing contact, payment status. Card details are handled by our payment provider; we never store full card numbersTrayd
Usage and technical dataLogin records, device type and OS, app version, IP address, error and crash logs, cookies on trayd.ie (see our Cookie Policy)Trayd
Support and marketingEmails and feedback you send us, marketing preferencesTrayd

We do not ask for, and you should not upload, data we don't need. Where a free-text field exists (job notes, feedback), please keep it to what's relevant to the work.

04How and why we use your data

We use personal data to run the platform and provide the service. The lawful basis under GDPR depends on the purpose.

What we doLawful basis (GDPR)
Create and manage accounts, provide core featuresPerformance of a contract – Art. 6(1)(b)
Let employers manage staff, jobs, leave, certifications and recordsEmployer's legitimate interests, or their legal obligations as an employer – Art. 6(1)(f) / (c)
Record on-site attendance when an employee checks in to a jobEmployer's legitimate interests in verifying work done and supporting invoices – Art. 6(1)(f)
Read receipts and assemble draft invoicesPerformance of a contract – Art. 6(1)(b)
Send service messages (login codes, certification expiry reminders, reorder alerts, invoice-ready notices)Performance of a contract – Art. 6(1)(b)
Keep the platform secure and working (logs, error monitoring, abuse prevention)Our legitimate interests in a secure, reliable service – Art. 6(1)(f)
Bill subscriptions and keep accounting recordsContract – Art. 6(1)(b); legal obligation for tax records – Art. 6(1)(c)
Tell business owners about Trayd features and updatesOur legitimate interests in promoting our service to existing customers – Art. 6(1)(f). You can opt out at any time via the unsubscribe link or by emailing us. We never market to employees added by their employer.
Improve the service using aggregated, anonymised usage dataOur legitimate interests – Art. 6(1)(f). Anonymised data is no longer personal data.
Respond to legal or regulatory requestsLegal obligation – Art. 6(1)(c)

Where we rely on legitimate interests, we have checked that our interest is not overridden by your rights. You can ask us for details of that assessment.

05Location data

When an employee checks in to a job, the app records the time and the device's location at that moment as proof of attendance on site. This is a single check-in point, not live tracking: Trayd does not track where you are during the job, between jobs, outside working hours, or while the app is closed.

Location is captured only with the device permission you grant. If you decline, jobs can still be started but the attendance record will show that no location was captured. Your employer can see the location and time on the job record and may use it to support an invoice or resolve a dispute.

Employers are responsible for telling their staff that location is recorded at check-in and why. We recommend they include this in their staff handbook or contract.

06Automated processing and AI

Trayd uses automated tools to read receipts, dockets and handwritten notes, and to assemble a draft invoice from the materials, hours, VAT rate and photos logged on a job.

  • Every draft is reviewed and approved by a person at the business before it is sent. Nothing is issued to a customer automatically.
  • Unreadable or uncertain items are flagged for manual review rather than guessed.
  • We do not make decisions about you based solely on automated processing that have legal or similarly significant effects (GDPR Article 22).
  • Your data is not used to train AI models. Our AI providers process it only to return a result to Trayd.

This processing is carried out using AI services from Anthropic and OpenAI. Data sent to these services is processed on servers within the European Union, under agreements that prohibit its use for training and require it to be handled only on our instructions. See Section 8.

07Health and other sensitive data

The only health-related data Trayd holds is the reason an employee gives for sick leave, where they choose to give one. Providing a reason is optional; an employee can record sick leave without one. This is special category data under GDPR Article 9 and gets extra protection.

The lawful basis is the carrying out of obligations in the field of employment law (Article 9(2)(b)), together with Section 46 of the Data Protection Act 2018. Trayd processes it only on the employer's instruction, stores it only within the EU, never sends it to any third party (including our AI providers), and restricts access so it is visible only to owners of the account – not to other team members.

We recommend recording sick leave as a simple absence unless your employer needs more. Please do not enter medical details anywhere else in the app.

08Where your data is handled

Your personal data is stored and processed within the European Union. We use a small number of service providers to run the platform. They process data only on our instructions, under contracts that meet GDPR Article 28.

Our service providers (sub-processors)

ProviderPurposeData location
SupabaseDatabase, file storage, authentication and core platform infrastructureEuropean Union (EU-West)
StripeSubscription billing and card processingEuropean Union (Stripe Payments Europe Ltd, Ireland)
AnthropicReceipt reading and invoice drafting (AI)European Union
OpenAIReceipt reading and invoice drafting (AI)European Union
AppleApp crash and stability reporting for the iOS appEuropean Union

Apple and Google distribute the app through their stores. Beyond the crash reporting listed above, they do not receive your Trayd data. If you open a site address in Google Maps, that happens in the Maps app under Google's own privacy policy.

Transfers outside the EU

We do not currently transfer personal data outside the European Union. If a provider outside the EU is ever introduced, we will rely on an EU adequacy decision or the European Commission's Standard Contractual Clauses, and update this section before any transfer takes place.

Sensitive data stays in the EU

Health-related information and other employee records are held only within our EU-based infrastructure and are never transferred outside the EU or sent to any third party, including our AI providers.

09Who we share data with

We do not sell your data and we do not share it with advertisers. We share it only as needed to run Trayd:

  • With the service providers listed in Section 8, who process data on our instructions.
  • With your employer, where they are the controller of data about you.
  • With your customers, where your business sends them an invoice or job record from Trayd.
  • With professional advisers (lawyers, accountants, auditors) under confidentiality, where needed.
  • Where we are legally required to, for example to comply with a court order, Revenue, or a regulator.
  • With a buyer or successor if the business is sold, merged or restructured. Your data would remain subject to this policy and we would notify you.

10Data on your device

The Trayd app works offline. Photos, notes and job actions are saved on your phone until you have signal, then synced automatically to our servers. A copy of recent job data remains on the device so the app is fast and usable on site.

  • Protect your device with a passcode or biometric lock; anyone who can unlock your phone can open the app.
  • If your employer removes you from the team, your access is revoked immediately and locally cached data is cleared on next launch.
  • Deleting the app removes all locally stored Trayd data from the device.
  • Photos taken inside the app are stored in Trayd, not in your camera roll, unless you choose to save them.

11How long we keep data

We keep personal data only as long as needed for the purposes above, or as required by law. Employment-related records may need to be kept for a period set by Irish law even after an employee leaves. When data is no longer needed, we delete it or anonymise it.

Type of dataRetention period
Account details (active account)For as long as the account is active
Account details (after closure)Deleted within 90 days of closure, unless a longer period is legally required
Job and work records, photos, location check-ins, customer detailsKept while the account is active; deleted or anonymised within 12 months of closure, or sooner if the business requests full deletion
Employee records, including leave and certificationsRetained for the period required by Irish employment law (generally 3 years after the record is made, per the Organisation of Working Time Act 1997), then deleted
Health-related data (sick leave reasons)Only as long as needed for the employer's record-keeping obligation, then deleted
Invoices and billing records6 years to meet Irish tax and accounting requirements
Usage and technical logsUp to 12 months
Support correspondenceUp to 24 months after the matter is closed
Marketing preferencesUntil you opt out; we then keep a suppression record so we don't contact you again

If a business closes its account and asks for full deletion, we delete all its data – including its employees' and customers' data – within the account-closure period above, except where we must retain records by law.

12Your rights

Under GDPR you have the right to:

  • Access the personal data held about you and get a copy.
  • Correct data that is inaccurate or incomplete.
  • Delete your data, where there is no legal reason to keep it.
  • Restrict or object to certain processing, including processing based on legitimate interests and any direct marketing.
  • Port your data – receive it in a structured, machine-readable format.
  • Withdraw consent at any time, where we rely on consent (for example, non-essential cookies). This does not affect processing already carried out.
  • Not be subject to a solely automated decision with legal or similarly significant effects.

To exercise any right, email info@trayd.ie. Business owners can also delete their account directly in Settings. We may need to verify your identity first. We will respond within one month; for complex requests we may extend this by up to two further months and will tell you if so. There is no fee unless a request is clearly unfounded or excessive.

If you are an employee or a customer of a Trayd business and the request concerns data your employer or that business controls, we will direct you to them and assist them in responding.

13Complaints

If you are unhappy with how we handle your data, please contact us first at info@trayd.ie so we can try to resolve it. You also have the right to lodge a complaint with the Irish supervisory authority:

Data Protection Commission
21 Fitzwilliam Square South, Dublin 2, D02 RD28
www.dataprotection.ie

If you live in another EU country, you may complain to your local supervisory authority instead.

14How we protect your data

We use technical and organisational measures appropriate to the risk, including:

  • Encryption of data in transit (TLS) and at rest.
  • Role-based access controls, so each person sees only the data relevant to their role, and database-level rules that keep each business's data separate.
  • Passwordless login codes that expire, and revocation of access the moment someone is removed from a team.
  • Monitoring, logging and regular review of errors and security events.
  • Restricted internal access: Trayd staff do not access your business data except to provide support you have requested and authorised.

No system is completely secure. If a personal data breach occurs that is likely to result in a risk to you, we will notify the Data Protection Commission within 72 hours as required, and inform affected users and employers without undue delay.

15Children

Trayd is a business tool intended for adults in the workplace. It is not directed at children and we do not knowingly collect data from anyone under 16 as a business owner. Where an apprentice is under 18, their employer is responsible for ensuring any data about them is handled appropriately and that a parent or guardian is informed where required.

16Changes to this policy

We may update this policy as Trayd develops or as the law changes. When we make a significant change – for example, adding a new sub-processor or a new category of data – we will update the version and date at the top, notify you in the app or by email, and, for employers, give notice as required by the Data Processing Agreement. Continued use after the effective date means the updated policy applies.

17Contact

Questions, requests and complaints about this policy or your data:

Trayd privacy teamEmail is the quickest way to reach us.

info@trayd.ie