RenoCommand Privacy Policy
Last Modified: 14 December 2025
1. Introduction
RenoCommand is operated by RenoCommand Limited (“we”, “us”, “our”, or “Company”). This Privacy Policy explains how we collect, use, store, and protect your personal data when you use RenoCommand (including our website and related applications). We are the data controller of your personal data.
RenoCommand is an online platform designed to help homeowners and self‑builders plan and deliver their renovation projects through integrated project management and financial management tools.
If you have any questions about how we process your data, please contact: support@renocommand.co.uk.
We are committed to compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and all applicable data protection laws.
2. Data Controller and Contact Information
RenoCommand Limited is the data controller responsible for your personal data.
Email (privacy contact): support@renocommand.co.uk
Address: RenoCommand Limited, Unit A, 82 James Carter Road, Mildenhall, IP28 7DE
You have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at www.ico.org.uk.
3. Personal Data We Collect
We collect personal data that you provide to us and data we collect automatically when you use RenoCommand.
3.1 Data You Provide to Us
When you register for an account, use our services, or contact us, we collect:
-
Account Registration: Full name, email address, encrypted password, phone number (optional), billing address, and payment identifiers as processed by Stripe (we do not see or store full card numbers).
-
Project Management Data: Project names and descriptions, timelines, tasks, attachments (including photos and other media), and collaborator details you choose to add.
-
Financial Management Data: Budgets, expenses, receipts, supplier and contractor details, and project financial summaries.
-
Permitted Development Checker Data: Property information, description of proposed works, and local authority information you input.
-
Communication Data: Emails, in‑app messages, support tickets, and feedback.
You confirm that any personal data you provide is accurate and, where it relates to other individuals (e.g. collaborators, contractors), that you have informed them and obtained consent where required.
You may browse public content without registering, but an account is required for core RenoCommand features.
3.2 Data We Collect Automatically
When you access RenoCommand, we automatically collect:
-
Device and Technical Information: Device type, operating system, browser type and version, IP address, and language/time‑zone settings.
-
Usage and Activity Data: Pages and features used, time spent, clicks, searches, uploads, and performance metrics (e.g. errors and load times).
-
Location Information: Approximate geographic location derived from IP address and any address you provide in project data.
4. Analytics and PostHog
We use PostHog solely for first‑party product analytics — to understand and improve RenoCommand. We never use PostHog for advertising, profiling, or cross‑site tracking, and we do not share analytics data with advertising networks.
We do not forward your IP address to PostHog; it is overridden server‑side before the event is sent.
To recognise repeat visits and connect pages viewed in a single visit, we use a session identifier that exists only in your browser's memory while a page is open. It is never written to cookies, localStorage, or sessionStorage, and it is gone as soon as you reload the page or close the tab.
If you browse RenoCommand before creating an account, we may store a short‑lived anonymous identifier in your browser's localStorage so that, if you later sign up, we can connect that anonymous browsing to your new account. This identifier expires automatically within 48 hours of being created, and is deleted immediately the moment you sign in — it is not retained any longer than necessary for this purpose.
We use this analytics data to:
-
Monitor performance and reliability of the platform.
-
Prioritise features and improvements based on aggregated usage patterns.
You can turn analytics off at any time using the "Allow usage analytics" toggle in the site footer. Switching it off stops analytics collection going forward (it does not retroactively delete data already collected) and immediately removes the anonymous identifier described above from your browser.
5. Cookies and Similar Technologies
5.1 Essential Authentication Cookies Only
RenoCommand currently uses only essential cookies that are strictly necessary for the service to function.
These cookies are used to authenticate you, keep you logged in, and protect your account (e.g. Supabase auth/session cookies and security‑related flags).
They are first‑party cookies controlled by RenoCommand and are set when you log in or interact with secure parts of the platform.
We do not currently use functional, analytical, or marketing cookies (such as advertising trackers, A/B testing cookies, or cookie‑based analytics).
Because our cookies are strictly necessary for providing the service you request (secure login and session management), they fall within the “strictly necessary” exemption under UK PECR and do not require opt‑in consent. You cannot use RenoCommand without these essential cookies because they are required to authenticate and protect your account.
5.2 Analytics Storage and the Statistical Purposes Exemption
In addition to essential cookies, we use two small pieces of browser storage for analytics, described fully in Section 4: a short‑lived anonymous identifier (localStorage, expires within 48 hours or on sign‑in) and your analytics opt‑out preference (localStorage, persists until you change it). Neither is used for advertising, cross‑site tracking, or building an individual profile beyond aggregated product analytics.
We rely on the UK PECR “statistical purposes” exemption for this analytics storage. That exemption requires that there be a simple and free way for you to object, and that we stop collecting if you do — both of which are satisfied by the “Allow usage analytics” toggle in the site footer.
5.3 Transparency About Cookies and Storage
We provide this information so you understand:
-
What cookies and storage are used (authentication/session management, and the analytics identifiers described above).
-
Why they are necessary or used (secure access to your account and data, and understanding product usage).
If we later introduce storage or cookies for advertising or marketing purposes, we will update this policy and implement a consent mechanism where required.
6. Lawful Bases for Processing
We process your personal data on the following legal bases under UK GDPR:
-
Performance of Contract: To create and manage your account, provide RenoCommand features, process payments and subscriptions, and deliver customer support.
-
Legal Obligation: To comply with tax, accounting, and regulatory requirements, and to respond to lawful requests from authorities.
-
Legitimate Interests: To maintain and improve our platform, perform security monitoring, detect fraud or misuse, and run product analytics as described above. We balance these interests against your rights and freedoms and only process data where our interests are not overridden.
-
Consent: For activities such as email marketing or optional communications where consent is explicitly requested. You can withdraw consent at any time.
7. How We Use Your Data
We use your personal data to:
-
Provide and operate RenoCommand, including project and financial management functionality.
-
Communicate with you about your account, billing, platform updates, and support requests.
-
Improve and secure the platform, including through product analytics using PostHog as described in Section 4.
-
Enforce our terms and comply with legal obligations.
8. Sharing Your Data (Third‑Party Processors)
We share data with carefully selected processors that act on our instructions:
-
Supabase (EU): Database and hosting for project and customer data.
-
Stripe (US): Secure payment processing for subscriptions and billing.
-
PostHog (EU): First‑party product analytics as described in Section 4.
-
Zoho Mail (UK or EU region): Email delivery and support communications.
Each provider is bound by a Data Processing Agreement and appropriate safeguards.
We may also share data:
-
Where required by law or to protect our rights, users, or the public.
-
In aggregated or anonymised form that does not identify individuals.
9. International Transfers
Where data is transferred outside the UK or EU (for example, to Stripe in the US), we use appropriate safeguards such as the UK International Data Transfer Agreement, UK Addendum to the EU Standard Contractual Clauses, or transfers to countries with adequacy decisions.
You may contact us for details of current safeguards for specific services.
10. Data Security
We implement technical and organisational measures to protect your data, including encryption in transit, encrypted storage of sensitive data (such as passwords), access controls, and security monitoring. Payment card details are processed by Stripe and are not stored by us.
You are responsible for keeping your password confidential and notifying us if you suspect unauthorised access to your account.
11. Your Rights
Under UK GDPR you have rights including:
-
Access to your personal data.
-
Rectification of inaccurate data.
-
Erasure (“right to be forgotten”) in certain circumstances.
-
Restriction of processing in certain circumstances.
-
Data portability for information you provided to us.
-
Objection to processing based on legitimate interests or direct marketing.
-
Rights relating to automated decision‑making, where applicable.
To exercise any of these rights, contact support@renocommand.co.uk. We will respond within one month, subject to legal extensions where permitted.
12. Data Retention
We retain data only as long as necessary for the purposes described:
-
Account and Profile Data: Kept while your account is active, then deleted or anonymised within a short period after closure, subject to legal retention requirements.
-
Project and Financial Data: Retained while your account is active; certain financial records (e.g. invoices, transaction records) may be kept for up to 6 years to meet tax and accounting obligations.
-
Support and Communication Data: Retained for a limited period after resolution to help with audits, disputes, or service improvement.
-
Analytics Data (PostHog): Event data is retained only as long as needed for trend analysis and service improvement, after which it is anonymised or deleted in accordance with our internal retention policies and PostHog’s configuration. The browser‑side anonymous identifier described in Section 4 is deleted automatically within 48 hours, or immediately on sign‑in if sooner.
13. Children’s Privacy
RenoCommand is not intended for individuals under 18. We do not knowingly collect personal data from children under 18. If you believe a child has provided data to us, please contact us so we can delete it.
14. Changes to This Policy
We may update this Privacy Policy to reflect changes in our services, technology, or legal requirements. Material changes will be communicated by email or a prominent notice within RenoCommand, and the “Last Modified” date will be updated.
15. Contact
If you have questions about this Privacy Policy or our data practices, contact:
Email: support@renocommand.co.uk
Address: RenoCommand Limited, Unit A, 82 James Carter Road, Mildenhall, IP28 7DE