Privacy policy
What we collect, and how we look after it.
What personal data EasyTaskr collects, why, who it goes to, how long we keep it and the rights you have, under the UK GDPR.
Last updated: 7 October 2026
Talk to usContents · 15 sections
1. Who we are
EasyTaskr ("we", "us", "our") is a product of Tech Me Today Ltd, a company registered in England and Wales (company no. 15917255), registered office 244 Humberstone Lane, Leicester, England, LE4 9JN. We are registered with the Information Commissioner’s Office (ICO) as a data controller, registration no. ZB944663.
This policy explains what personal data we collect when you visit easytaskr.com, apply for or use the EasyTaskr platform (including app.easytaskr.com, admin.easytaskr.com, partner.easytaskr.com, our signing service and our social media features, "GoGo Social"), why we use it, who we share it with and the rights you have. It is written for the UK GDPR and the Data Protection Act 2018.
Questions about this policy or your data go to privacy@easytaskr.com.
2. Our role: controller and processor
We are the controller of the personal data we collect to run our own business: visitors to our website, people who contact us or apply for an account, and the account holders and users of the businesses we serve.
Our customers (the businesses that use EasyTaskr) also store personal data about their own customers, suppliers and staff in the platform: names, phone numbers, delivery addresses, orders and invoices, for example. For that data the business is the controller and we are its processor. We handle it only on that business’s instructions and only to provide the service to it. If you are a customer of a business that uses EasyTaskr, please contact that business first about your data; we will help them answer you.
3. Information we collect
3.1 Account information
When you apply for or register an EasyTaskr account, we collect your name, email address, phone number, business name, business address and your role within the organisation. For business accounts we may also collect VAT or tax identification numbers and billing information.
3.2 Enquiries and applications
When you use our contact form or apply for an account, we collect what you send us: your name, business name, email, phone number, the kind of business you run and your message. We use it to reply and to review the application.
3.3 Usage and device data
When you use the platform we record technical information such as the pages and features used, timestamps, device and browser type, IP address and error reports. We use it to run, secure and fix the service.
3.4 Business data
Depending on the parts you use, the platform stores business data such as products, stock, orders, invoices, customer and supplier records, staff records and financial records. This data belongs to your business and is kept separate from every other business on the platform (see section 2 for our role).
3.5 Social media data (GoGo Social)
When you connect social media accounts through GoGo Social, we collect and store:
• Social media profile information (name, profile picture, page or account ID)
• Authentication tokens (OAuth access and refresh tokens) needed to publish on your behalf
• Content you create through the platform (posts, captions, images, videos, scheduled content)
• Analytics from connected platforms (views, likes, shares, comments, engagement rates)
• Review requests and customer feedback collected through review features
We only access the permissions you grant during the platform’s own authorisation step. We never access your private messages, friend lists or personal content unrelated to your business pages.
3.6 Files you upload
Images, videos and documents you upload (product photos, social content, signed documents and business files) are stored in our cloud storage.
3.7 Consent records
When you use our consent features to get a customer’s permission to feature them in social media content, we store the consent record: the customer’s name, the type of consent, the time and any media it covers.
4. How we use it, and our lawful bases
Under the UK GDPR we need a lawful basis for each use of personal data. Ours are:
• To provide the platform you signed up for: create and run your account, process transactions, send invoices, receipts and confirmations, publish the social content you schedule, and give support. Basis: performance of our contract with you.
• To keep the service secure and working: sign-in protection, fraud and abuse prevention, error monitoring, backups. Basis: our legitimate interests in running a safe, reliable service.
• To improve the platform: understanding which features are used and where people get stuck. Basis: our legitimate interests.
• To reply to enquiries and review account applications. Basis: our legitimate interests, or steps taken at your request before a contract.
• To send service messages about your account, security alerts and important changes. Basis: performance of our contract.
• To send product news, only where you have opted in, with an unsubscribe link in every message. Basis: consent.
• To keep accounting and tax records and answer lawful requests. Basis: legal obligation.
Where we rely on legitimate interests we have weighed them against your rights, and you can object at any time (section 11). We do not make decisions about you with legal or similarly significant effects by automated means alone.
6. AI features
Some features use artificial intelligence: writing product descriptions and captions, reading a supplier invoice or a photo, answering questions about your own business records, and spotting low stock. When you use one, the text, image or records that feature needs are sent to an AI provider to produce the answer. Depending on the feature and on availability, the provider is Anthropic (Claude), OpenAI, Groq or Google (Gemini). The AI assistant also keeps a search index of extracts of your business records with Pinecone, so it can find the right records when you ask.
• We send only what the feature needs, and only for your own business.
• We use these providers’ business API services under data processing terms, not their consumer apps.
• AI suggestions are drafts. The assistant asks before it changes anything, and a person stays responsible for the decision.
• If you would rather your business did not use AI features, tell us at support@easytaskr.com and we will switch them off.
7. Who we share it with
We do not sell, rent or trade personal data, and we do not share it for advertising.
We use the following service providers (processors), each under a written contract that limits them to acting on our instructions. Some are used only when the feature that needs them is switched on:
• DigitalOcean: hosting, database, file storage and backups (London region)
• Resend: sending account and transactional emails
• Twilio: WhatsApp and text messages that you choose to send
• Sentry: error monitoring (technical details of errors)
• Anthropic, OpenAI, Groq and Google: the AI features in section 6
• Pinecone: the AI assistant’s search index (section 6)
• Stripe: card payments, where card payments are switched on
• Mapbox or OpenStreetMap: looking up addresses and drawing delivery maps
• ImprovMX: forwarding email sent to our @easytaskr.com addresses
We also share data:
• With social media platforms, when you publish through GoGo Social. They receive the content under their own terms and privacy policies.
• With Google, if you choose to sign in with your Google account.
• When the law requires it, for example a court order or a request from a regulator.
• With a buyer or successor, if the business or its assets are sold, under the same protections.
• With anyone else, only with your consent.
8. International transfers
Our platform, database and file storage are hosted with DigitalOcean in its London (UK) region. Some of the providers in section 7, including the AI providers, Twilio, Resend and Sentry, are based in or process data in the United States or elsewhere outside the UK. Where personal data leaves the UK we rely on a UK adequacy decision (including the UK Extension to the EU-US Data Privacy Framework where the provider is certified) or on the UK International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses. You can ask us for details at privacy@easytaskr.com.
9. How long we keep it
We keep personal data only as long as we need it:
• Account data: for the life of your subscription, plus 90 days after the account is closed
• Business data (orders, invoices, products): for the life of your subscription; we export it for you on request before the account closes
• Social media tokens: deleted when you disconnect the platform or close your account
• Social media content and analytics: for the life of your subscription
• Consent records: 7 years, so the consent can be shown if it is questioned
• Usage logs: 12 months, for security and analytics
• Enquiries and applications that do not become an account: for as long as we need them to answer you, then deleted
• Accounting records about our own customers: as long as UK tax law requires (normally 6 years)
• Backups: kept on a rolling schedule and deleted as they age out, so deleted data can remain in a backup until that backup expires. Backups are used only to restore the service.
You can ask us to delete your data at any time at privacy@easytaskr.com.
10. How we protect it
We protect personal data with technical and organisational measures, including:
• Encryption in transit: every connection uses HTTPS (TLS)
• Encryption at rest for secrets: platform tokens are encrypted with AES-256-GCM; passwords are stored only as bcrypt hashes
• Each business’s data is kept separate: every request is checked against the business it belongs to
• Role-based permissions inside each business, and optional two-step sign-in
• Rate limits and sign-in protection against password guessing
• Access to production systems limited to named people, with platform administration restricted to approved networks
• Daily database backups
No system is perfectly secure. If a breach affects your personal data and is likely to put you at risk, we will tell you and the ICO as the law requires. More detail is on our Security page at easytaskr.com/security.
11. Your rights
Under the UK GDPR you have the right to:
• Access: get a copy of the personal data we hold about you
• Rectification: have inaccurate or incomplete data corrected
• Erasure: have your data deleted ("right to be forgotten")
• Restriction: ask us to limit how we use your data
• Portability: receive your data in a structured, machine-readable format
• Objection: object to uses based on our legitimate interests, and to direct marketing at any time
• Withdraw consent: where we rely on consent, withdraw it at any time
To use any of these rights, email privacy@easytaskr.com. We answer within one month, and it is free in almost all cases. We may need to confirm who you are first. If your data was put into EasyTaskr by a business you deal with, we will pass your request to that business (section 2).
For social media data, you can also disconnect a platform at any time, which stops all collection from it and deletes our tokens.
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK data protection regulator: https://ico.org.uk/make-a-complaint or 0303 123 1113.
13. Children
EasyTaskr is a business platform and is not meant for anyone under 16. We do not knowingly collect personal data from children. If you believe we have, contact privacy@easytaskr.com and we will delete it.
14. Changes to this policy
We may update this policy from time to time. We will post the new version on this page and change the "Last updated" date. For significant changes we will also email the address on your account before they take effect.
15. Contact us
For anything about this policy or your personal data:
• Privacy and data requests: privacy@easytaskr.com
• General support: support@easytaskr.com
• By post: Data Protection, Tech Me Today Ltd, 244 Humberstone Lane, Leicester, England, LE4 9JN
5. Social media platform integration
5.1 Platform connections
5.2 Data we access from platforms
5.3 Tokens
5.4 Publishing