Privacy Policy
Last updated: 10 March 2026
1. Who We Are
GoFix is a quoting and job management application for UK tradespeople, operated by RAVE AI (rave-ai.com). For the purposes of UK data protection law, RAVE AI is the data controller for personal data processed through GoFix.
For data protection enquiries, contact us at: [email protected]
2. What Data We Collect and Why
We collect only the data necessary to provide the GoFix service. The table below sets out exactly what we collect, why, and the lawful basis under UK GDPR.
| Data | Purpose | Lawful basis |
|---|---|---|
| Name and email address | Account creation, login, and communications | Contract (Art. 6(1)(b)) |
| Password (hashed with bcrypt — never stored in plain text) | Secure account authentication | Contract (Art. 6(1)(b)) |
| Trade type and hourly rate | Pre-filling quote defaults to save you time | Contract (Art. 6(1)(b)) |
| Company name, address, phone, website, logo | Appearing on your PDF quotes (Pro users) | Contract (Art. 6(1)(b)) |
| Company registration number and VAT number | Appearing on your PDF quotes (Pro users) | Contract (Art. 6(1)(b)) |
| Quote data (job title, address, labour, materials, costs, totals) | Core quoting functionality | Contract (Art. 6(1)(b)) |
| Client names, emails, and phone numbers | Client management and quote history | Contract (Art. 6(1)(b)) |
| Job status and progression | Job tracking functionality | Contract (Art. 6(1)(b)) |
| Stripe customer and subscription IDs | Processing Pro subscription payments | Contract (Art. 6(1)(b)) |
| Session cookie (httpOnly, Secure) | Keeping you logged in | Legitimate interests (Art. 6(1)(f)) |
| Anonymous page view analytics (Umami) | Understanding how the app is used to improve it — only if you consent | Consent (Art. 6(1)(a)) |
3. Your Clients' Data
When you enter client contact details into GoFix, you are the data controller for that information and we act as your data processor. You are responsible for ensuring you have a lawful basis to store your clients' personal data (for example, a legitimate interest in managing your business relationships). We process client data solely to provide the GoFix service to you.
4. Cookies
We use two types of cookies:
- Session cookie (strictly necessary) — a single httpOnly, Secure cookie that keeps you logged in. This cookie does not track you across other websites. No consent is required under PECR as it is essential for the service to function.
- Analytics (optional) — if you consent, we use Umami Analytics, a privacy-focused, GDPR-compliant tool. Umami does not use cookies and does not collect personally identifiable information — only anonymous page view counts. You can withdraw consent at any time via the cookie banner.
5. Data Sharing
We do not sell your personal data. We share data only with the following third-party processors, each bound by a data processing agreement:
- Stripe, Inc. — payment processing for GoFix Pro subscriptions. Stripe processes your payment details directly and is PCI DSS compliant. We never see or store your card number. See Stripe's Privacy Policy.
- Amazon Web Services (AWS S3) — secure cloud storage for uploaded business logos. AWS is ISO 27001 certified.
- Umami Analytics — anonymous, cookieless analytics (only if you consent). No personally identifiable data is shared.
We do not transfer your personal data outside the UK or EEA except where the above third parties operate under Standard Contractual Clauses or equivalent safeguards approved by the ICO.
6. Data Retention
- Account data — retained for the life of your account and deleted within 30 days of account deletion.
- Quote, job, and client data — deleted immediately when you delete your account.
- Uploaded logos — deleted from AWS S3 within 30 days of account deletion.
- Stripe payment records — Stripe retains transaction records for up to 7 years for financial compliance. We do not control this retention period.
- Session cookies — expire after 12 months or when you sign out, whichever is sooner.
7. Your Rights Under UK GDPR
You have the following rights. Most can be exercised directly within the app:
Right of access (Art. 15)
Download a copy of all your personal data via Settings → Your Data Rights → Download my data.
Right to rectification (Art. 16)
Update your name, email, trade details, and business profile at any time in Settings.
Right to erasure (Art. 17)
Permanently delete your account and all associated data via Settings → Your Data Rights → Delete my account. Deletion is immediate and irreversible.
Right to data portability (Art. 20)
Export your data in machine-readable JSON format via Settings → Your Data Rights → Download my data.
Right to object (Art. 21)
Withdraw consent for analytics cookies at any time via the cookie banner.
Right to restrict processing (Art. 18)
Contact us at [email protected] to request restriction of processing.
If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).
8. Security
We take appropriate technical and organisational measures to protect your personal data, including:
- Passwords hashed using bcrypt (12 rounds) — we never store plain-text passwords
- All data transmitted over HTTPS/TLS
- Session cookies are httpOnly and Secure, preventing client-side access
- Database access restricted to the application server only
- Uploaded files stored in private S3 buckets
9. Children
GoFix is intended for adults operating trade or service businesses. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, please contact us at [email protected] and we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you by email or in-app notification. Continued use of GoFix after changes constitutes acceptance of the updated policy.