Privacy Policy
This policy explains what personal data Frame Fresh collects, why we need it, who we share it with, how long we keep it and the rights you have under the UK GDPR and the Data Protection Act 2018.
Who we are
Frame Fresh ("we", "us", "our") is a window cleaning and exterior & interior cleaning business operating in Norwich and the surrounding NR postcodes, trading through the website framefresh.co.uk. We are the data controller for the personal data described in this policy.
You can contact us about privacy at any time through the WhatsApp link on this website, or in writing via the contact details shown on our home page. We will respond within one calendar month.
What we collect
- Quote details — postcode and address, property type, window and door counts, the services and frequency you choose, and the price we calculate for you.
- Contact details — name, email address, mobile number and any notes or access instructions you give us.
- Service records — visit dates, completed and skipped cleans, photographs of work where relevant, route and mileage records.
- Billing records — invoices, amounts, payment status and payment references. We do not see or store card numbers.
- Messages — emails, SMS and WhatsApp messages exchanged with you, including reminders and confirmations.
- Technical data — IP address, device and browser type, pages viewed and, where you consent, analytics events. See our Cookie Policy.
We do not knowingly collect special category data, and we do not collect data from children. Our services are offered to adults responsible for a property.
Why we use it, and our lawful basis
- To quote and to clean — performance of a contract, or steps taken at your request before entering one.
- To schedule rounds and send visit reminders — performance of a contract and our legitimate interest in running an efficient, reliable round.
- To invoice and keep accounts — performance of a contract and compliance with our legal obligations (tax and accounting records).
- To follow up an unaccepted quote — legitimate interest; you can ask us to stop at any time and we will.
- Optional analytics and marketing emails — consent, which you can withdraw at any time using the unsubscribe link or by clearing your cookie choice.
- To keep records secure and resolve disputes — legitimate interest and legal obligation.
Who we share it with
We never sell personal data and we do not share it with third-party advertisers. We use a small number of trusted processors and partners, each bound by contract to protect your data:
- Intuit QuickBooks — our accounting system. When you book, we send the details needed to raise and track an invoice: your name, billing address or postcode, email address, the services performed, amounts and payment status. We connect using Intuit's authorised OAuth 2.0 flow and only with the QuickBooks Accounting scope.
- Hosting and database — our website and operations dashboard are hosted on managed cloud infrastructure with access restricted to authorised staff.
- Email, SMS and WhatsApp providers — to deliver quotes, confirmations and clean reminders.
- Mapping and routing services — to plan efficient routes from addresses and postcodes.
- Professional advisers and authorities — our accountant, insurers, or a regulator or court where we are legally required to disclose.
Some providers process data outside the UK. Where that happens we rely on UK adequacy regulations or the International Data Transfer Addendum to the EU Standard Contractual Clauses.
How long we keep it
- Quotes not taken up — up to 12 months, then deleted or anonymised.
- Customer and service records — for the life of the arrangement and 12 months after your last clean.
- Invoices and accounting records — 6 full tax years, as required by HMRC.
- Message and consent logs — up to 24 months, to evidence what was sent and agreed.
How we protect it
Data is stored in access-controlled databases with row-level security, encrypted in transit over HTTPS and encrypted at rest. Access to our operations dashboard is limited to named staff accounts with role-based permissions and multi-factor or single-sign-on login. Integration credentials, including QuickBooks tokens, are held in an encrypted secret store and are never exposed to the public website.
Your rights
You have the right to:
- be told how your data is used — this policy;
- request a copy of the data we hold about you;
- have inaccurate data corrected;
- ask us to erase data we no longer need;
- restrict or object to processing, including profiling for follow-up;
- ask for your data in a portable format;
- withdraw consent for analytics or marketing at any time.
To exercise any right, message us and we will verify your identity before acting. If you are unhappy with our response you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.
Cookies and analytics
We use essential cookies to make the site and quote form work, and optional analytics only if you accept them. Full detail is in our Cookie Policy.
Changes to this policy
We may update this policy as our services or systems change. The date at the top always shows the current version, and material changes will be highlighted on this page.
Related pages
