Privacy policy
Last updated 20 August 2026.
This describes what we collect, why, and what you can do about it. It is written to match what the software actually does rather than to cover every eventuality.
Who is responsible
MILE TALLY PRO LIMITED of 223 Great Gregorie, Basildon, England, SS16 5QU is the data controller for the personal data described here. Our ICO registration number is ZC036453. For anything in this policy, write to office@miletallypro.co.uk.
What we do not do
We do not track your location. There is no GPS, no background location access and no app on your phone doing either. The postcodes you type are the record — which is what HMRC asks to see anyway. We also do not sell personal data, and we do not use it for advertising.
What we collect
When you create an account
- Your first and last name.
- Your email address.
- Whether you are employed or self-employed — it changes what your mileage figure means, so the dashboard and the report need it.
- A password, handled entirely by Firebase Authentication. It is never sent to our own servers and we cannot read it.
When you log a trip
- The start and end postcodes, the date, and the reason you give for the journey.
- The calculated distance, and which journeys belong to the same multi-stop round.
Postcodes identify an area, not an address — but a home postcode paired with a date is still personal data, and it is treated as such.
Settings and billing
- What you drive, and what your employer reimburses per mile, if you tell us.
- Your subscription status, plan, renewal date and Stripe customer reference. We never see or store your card details — those go straight to Stripe.
Automatically
- Standard server logs, which include IP addresses, for security and diagnosing faults.
- Google Analytics, for aggregate usage — how many people visit, which pages they reach. You can refuse it with any standard blocker and the service works identically.
Why we are allowed to hold it
- To provide the service (contract)
- Your account, trips, settings and reports. Without these there is no product to deliver.
- To take payment (contract)
- Subscription and billing records.
- To keep the service working and secure (legitimate interests)
- Server logs, abuse prevention, and aggregate analytics. We think this is what you would reasonably expect of anything running on the internet.
- To meet our own obligations (legal obligation)
- Accounting and tax records relating to payments you have made.
Who else sees it
Only the services needed to run the product. Each gets the minimum it needs to do its job:
- Google Firebase
- Authentication and the database holding your account, trips and settings. Data is held in Google Cloud.
- Stripe
- Payments and subscription management. Stripe collects your card details directly and is its own controller for them.
- Google Maps Routes API
- Receives a pair of coordinates to calculate a driving distance. It is not told who is asking.
- postcodes.io
- Confirms a postcode exists and returns its coordinates before we pay for a route lookup. It receives the postcode alone, with no account attached.
- Resend
- Sends trial reminders, expiry notices and password reset emails.
- Google Analytics
- Aggregate website usage.
Some of these process data outside the UK. Where they do, transfers rely on the UK International Data Transfer Agreement or Addendum, or on adequacy regulations.
We will also disclose data where the law requires it. We will not hand your trip history to anyone else — including an employer — without your instruction or a legal obligation.
A note on the route cache
Distances between postcode pairs are cached and shared across all accounts, because the drive between two postcodes is the same journey whoever makes it. The cache holds two postcodes and a distance. It records no account, no date and no reason, so it cannot be used to work out who travelled where.
How long we keep it
- Your account and trips: until you delete them. Deleting your account erases your trips, profile and billing record, and cancels any live subscription.
- Payment records: retained by Stripe, and by us where tax law requires it — normally six years.
- Server logs: a short rolling window, kept only for diagnosis and security.
Export before you delete. HMRC generally expects mileage records to be kept for at least five years after the filing deadline, and once erased we cannot recover them.
Your rights
Under UK GDPR you can ask us to:
- give you a copy of your data — the PDF and CSV export does most of this instantly;
- correct anything wrong, most of which you can edit yourself;
- delete your data, which the account page does immediately;
- restrict or object to how we use it;
- send your data to another service.
Email office@miletallypro.co.uk. We will answer within one month. If you are unhappy with the response you can complain to the Information Commissioner’s Office at ico.org.uk, though we would rather you gave us the chance to put it right first.
Cookies
We set one essential cookie to keep you signed in. It is httpOnly — JavaScript on the page cannot read it — and it is not used for tracking. Google Analytics sets its own cookies for aggregate usage; blocking them does not affect the service.
Security
How the service is built to protect your records is described on the security page.
Changes
If we change this policy in a way that materially affects you, we will email the address on your account before it takes effect.