Privacy notice
What HubTrack does with personal data, where it is kept, and what you can ask us to do with it.
In effect from 30 July 2026
Who we are
HubTrack is operated by United Applications Ltd, a company registered in England and Wales, company number 16955835, registered office 20 Wenlock Road, London, N1 7GU.
For data we hold about you as a user of HubTrack, we are the data controller. For the job records, documents and company information you put into HubTrack, your employer is the controller and we act as their processor.
The practical difference: if you want your account details corrected, ask us. If you want something changed in your company’s job records, ask your employer — we act on their instructions for that data.
What we collect
When you create an account
- Your first name and surname
- Your work email address
- Your company name
- A password, which is stored only as a hash — we cannot read it, and neither can anyone who obtains the database
- If you turn on two-step verification, the secret your authenticator app uses
If you sign in with Microsoft or Google instead, we receive your email address and name from them. We do not receive your password, and we ask for nothing beyond your name and address.
When you use HubTrack
The job records, documents, prices and compliance paperwork you enter or upload. This is your employer’s data rather than ours, and we use it only to provide the service.
What the system records about actions
HubTrack keeps an audit trail of who did what and when. It records the user account that performed an action, not free text about you. This is the point of a compliance product: a sign-off that cannot be traced is not a sign-off.
Two things we deliberately do not store
These are unusual enough to state plainly, because most services do the opposite.
- Rate-limiting and security monitoring hold no readable identifiers. To detect repeated failed sign-ins we store a SHA-256 hash of the email address or IP address involved, never the value itself. The system can tell that the same address is being attacked without holding a list of who is being attacked.
- Error reports carry no identity. When something breaks we send a report to our error-tracking provider with request bodies, cookies, headers, user identity and IP addresses removed before transmission. Coarse city-level location is still derived by that provider from the connection.
Where your data is held
All of it is in the UK or the EU. There is no international transfer of personal data outside the UK and EU, which means there is no transfer risk assessment or set of standard contractual clauses sitting behind this notice.
| Who | What they hold | Where |
|---|---|---|
| Supabase | The database and all uploaded files, including account details and the audit trail | London, UK |
| Vercel | Serves the application; holds data in transit and in server logs | London, UK |
| Resend | Transactional email in transit — invitations, verification and password resets | Ireland, EU |
| Sentry | Error reports, scrubbed of identity as described above | Germany, EU |
How long we keep it
| What | Kept for |
|---|---|
| Your account | While it exists |
| Job records and documents | While your company is open |
| Audit trail and compliance sign-offs | Indefinitely — see below |
| Database backups | 7 days, rolling |
| Off-site backups | 365 days — see below |
| Error reports | 90 days |
The audit trail is permanent, on purpose
Compliance sign-offs and the audit trail are kept indefinitely and cannot be edited or deleted — the database physically refuses, for everyone including us. A record of who approved a safety document, which can later be altered, is worth nothing to the person relying on it.
If your account is deleted, your identifier stays in that trail. Anonymising the person who signed something off would destroy the evidence the record exists to provide.
Erasure, and what our backups mean for it
You can ask us to erase personal data we hold about you, and we will action it in the live system straight away. There is a limit you should know about before you ask rather than after.
Erasure requests are actioned in live systems immediately. Backup copies are held under a technical immutability control for 365 days and expire on a rolling schedule; erased data is not restored from backup, and is not used for any purpose while it remains there.
The reason is ransomware. Our off-site backups are written so that nobody can alter or delete them before they expire — not us, not anyone who steals our credentials, not the company storing them. That is what makes them survive an attack, and it is the same property that stops us reaching in to remove one person early.
The right to erasure is also not absolute. It yields to legal obligation and to the establishment or defence of legal claims, which is exactly what a construction compliance record exists for. What we will always erase is anything not needed for that purpose.
Your rights
Under UK GDPR you can ask us for a copy of your data, ask us to correct it, ask us to erase it, object to how we use it, or ask us to restrict that use. You can also complain to the Information Commissioner’s Office, though we would rather you came to us first so we can put it right.
Ask by emailing us at the address below. We will respond within one month.
Cookies
HubTrack sets cookies to keep you signed in and to protect against cross-site request forgery. That is all — there is no advertising, no analytics following you between sites, and no third-party tracking.
Changes to this notice
If we change how we handle personal data, we will update this page and change the date at the top. Material changes will be told to you directly rather than left here to be discovered.
Contact
Email support@unitedapplications.io with anything about this notice or about data we hold.