EPC Ledger ("we", "us") provides a grant-matching and portfolio tracking tool for UK landlords. This policy explains what personal data we collect, why, and what rights you have over it, under UK GDPR and the Data Protection Act 2018. It doesn't cover how the service itself works or its legal status — see our Terms & Conditions for that, including the fact that EPC Ledger is an informational tool only, not financial, legal, or tax advice, and not affiliated with HM Government or any local authority.
What we collect
- Account data— your name, email address, and a securely hashed password (we never store your password in plain text). If you sign in via a magic link instead, we don't store a password at all.
- Property data — addresses and postcodes you add, and the Energy Performance Certificate data we look up against them from the gov.uk EPC Register (a public register).
- Eligibility information— your answers to the eligibility questionnaire: local authority, region, heating fuel, prior grant history, and whether a tenant is on a qualifying means-tested benefit. That last one is recorded as a yes/no flag only — we don't ask which benefit or how much, precisely to minimise the sensitive data we hold.
- Billing data — handled by Stripe. We store only your Stripe customer and subscription IDs; your card details never reach our servers.
- Technical data — standard web request data (IP address, browser type, pages visited) collected automatically for error tracking and performance monitoring.
Why we process it, and on what basis
- To provide the service (necessary to perform our contract with you) — matching your properties to grant schemes, running the portfolio ledger, sending the account emails described below.
- To process payments (necessary to perform our contract with you) — via Stripe.
- To keep the service secure and working (our legitimate interest) — error tracking, performance monitoring, fraud prevention.
- To meet legal obligations — for example, retaining billing records for tax purposes.
Who we share data with
We don't sell your data. We share it only with the specific service providers ("processors") that make the product work:
- Stripe (payment processing) — see Stripe's privacy policy.
- Resend (transactional email delivery — account, match, and billing notifications).
- Microsoft Azure(hosting — our servers and database run in Azure's UK South region).
- Sentry and Azure Application Insights (error tracking and performance monitoring).
We also query the gov.uk EPC Register with property postcodes to retrieve public Energy Performance Certificate data — this is a lookup against a public register, not a disclosure of your personal data to it.
How long we keep it
We keep your account data for as long as your account is active, and for a reasonable period afterwards for legal, accounting, and dispute-resolution purposes. You can request deletion at any time — see "Your rights" below.
Cookies
We use a single essential session cookie to keep you signed in. We don't use third-party advertising or tracking cookies.
International transfers
Our hosting and database are in the UK. Some of our processors (Stripe, Resend) may process data outside the UK; where they do, this happens under their own standard contractual safeguards.
Your rights
Under UK GDPR, you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data deleted ("the right to be forgotten");
- restrict or object to certain processing;
- receive your data in a portable format; and
- complain to the Information Commissioner's Office if you think we've got something wrong.
To exercise any of these, contact us using the details below.
Children
EPC Ledger is a business tool for landlords and isn't intended for use by anyone under 18.
Changes to this policy
If we make material changes, we'll update the date at the top of this page and, where appropriate, notify you directly.
Contact us
Questions about this policy or your data: [email protected]
See also our Terms & Conditions.