Last updated 17 July 2026

Trust & security

This page is maintained by TradeFlow to answer common questions about how we handle installer and customer data. It describes our current practices, not an independent certification.

Who we are

TradeFlow is operated as a UK sole trader providing pipeline and growth services to MCS-certified heat pump installers. For the purposes of UK GDPR, TradeFlow is the data controller for information collected through gettradeflow.uk and the controller-or-processor for information shared with us by installer clients, depending on the engagement.

Questions about this page, data requests, or a suspected security issue: hello@gettradeflow.uk.

What data we collect

  • Enquiry & booking data — name, email, company, and anything you write when contacting us or booking a pipeline review.
  • Client pipeline data — during an engagement, the installer data you share with us (lead volumes, conversion metrics, CRM exports). We only use this to deliver the work agreed with you.
  • Payment data — processed by Stripe. We never see or store full card numbers.
  • Basic technical data — standard server logs (IP, user agent, timestamps) used to keep the site running and secure.

How we protect it

  • Data is encrypted in transit (HTTPS/TLS) and at rest by our hosting and database providers.
  • Access to production systems is limited to the TradeFlow operator, protected by strong unique passwords and multi-factor authentication where the provider supports it.
  • Application-level row-level security is enabled on the database so records are scoped to their owner.
  • Stripe webhooks are signature-verified before any payment event is recorded (see webhook status).
  • Backups are handled by our managed database provider on their standard schedule.

Subprocessors

We use a small number of trusted providers to run TradeFlow. Each is bound by their own security and data-processing terms:

ProviderPurposeRegion
Lovable Cloud (Supabase)Hosting, database, authEU
CloudflareCDN, DNS, edge runtimeGlobal
StripePayment processingUK / EU / US
Cal.comBooking schedulingEU
ResendTransactional emailEU / US
Google AnalyticsSite analyticsUS

International transfers (e.g. to US-based providers) rely on the UK–US Data Bridge and Standard Contractual Clauses as offered by each provider.

Retention & deletion

We keep enquiry and client data for as long as we have an active relationship, and for up to 24 months afterwards so we can answer follow-up questions and meet UK tax and accounting obligations. You can ask us to delete your data sooner at any time by emailing hello@gettradeflow.uk. We respond within 30 days.

Your rights (UK GDPR)

If your data is held by TradeFlow you have the right to access, correct, delete, restrict, or port it, and to object to processing. Contact us at the address above and we will action your request within 30 days. You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk).

Cookies & analytics

We use privacy-respecting analytics to understand which pages are read. Cookies are limited to what's needed to run the site and measure aggregate usage. No advertising cookies are set.

Reporting a security issue

If you believe you've found a vulnerability, please email hello@gettradeflow.uk with details and steps to reproduce. We'll acknowledge within 2 business days and keep you updated as we investigate.

Compliance status

TradeFlow follows UK GDPR and the practices described above. TradeFlow is not currently certified against SOC 2, ISO 27001, or HIPAA. We rely on the underlying certifications of our subprocessors (for example Stripe's PCI DSS Level 1 and Supabase's SOC 2 Type II) for the parts of the service they operate. If your procurement process needs specific documentation or a signed DPA, email us and we'll work through it with you.

See where your pipeline is leaking.

A 30-minute call. No pitch deck. Just a clear look at your enquiry-to-install funnel.

Book a demo