Skip to content

Legal centre Privacy Policy

Privacy Policy

Last updated: 5 August 2026

WagePilot is in early access (beta).

This Privacy Policy explains how Trystan Clarke, a sole trader trading as WhealBit ("WagePilot", "we", "us" or "our"), collects, uses and protects personal data for which we are the controller. This covers people whose data we decide how and why to process: account holders and the individuals named as billing or administrative contacts on an account; visitors to our marketing website at wagepilot.co.uk; people who contact us for support or general enquiries; and people on our marketing list. It also explains, at a high level, the data we handle as a processor on behalf of our business customers when they use WagePilot to manage their staff. This notice forms part of our legal suite and should be read alongside our Terms of Service, Data Processing Agreement, Cookie Policy and Sub-processors list.

1. Who we are and how to contact us

WagePilot is a UK software-as-a-service product for staff time and attendance (rota scheduling, geofenced and QR clock-in/out, kiosk mode, holiday and leave tracking, audited timesheets, labour-cost reporting, National Minimum Wage / National Living Wage guidance checks, Working Time Regulations break tracking, payroll-ready export and in-app staff messaging). WagePilot is not a payroll provider: we do not calculate tax, National Insurance or net pay, and we do not move money.

The controller responsible for the personal data described in this notice is:

  • Legal entity: Trystan Clarke, a sole trader trading as WhealBit
  • Trading address: St Ives, Cornwall
  • Data protection / privacy contact: info@whealbit.co.uk
  • General contact: wagepilot.co.uk

For any question about this notice, to exercise your rights, or to raise a privacy concern, please contact us at info@whealbit.co.uk. We are registered with the Information Commissioner's Office (ICO), the UK's data protection regulator, under registration reference [ICO registration reference — to be completed before go-live].

This notice describes our data-protection practices. It does not vary, expand or replace the contractual rights, warranties, disclaimers and limitations of liability set out in our Terms of Service, which govern the commercial relationship between us and our customers. If there is any conflict on a commercial matter, the Terms of Service prevail; nothing in this notice creates any warranty or contractual commitment beyond those in the Terms of Service or beyond what data protection law requires.

2. Scope of this notice - and what it does not cover

This notice covers personal data for which we are the controller. It does not cover the personal data that our business customers (employers) enter into WagePilot about their own staff. For that staff data the employer is the controller and we act only as a processor following the employer's instructions. This notice is therefore not the privacy notice for any employee whose data an employer manages in WagePilot. If you are an employee or worker and want to know how your employer uses WagePilot to handle your data, please ask your employer, who is responsible for telling you under Articles 13 and 14 of the UK GDPR.

The processor terms that govern our handling of staff data on an employer's behalf are set out in our Data Processing Agreement. Section 9 below explains the controller/processor split in plain terms.

3. The personal data we collect (as controller)

We collect and process the following categories of personal data about account holders, billing/administrative contacts, website visitors and enquirers:

  • Account data: business or organisation name, the account-holder's name, work email address, role/job title, and login credentials (passwords are stored only in hashed form by our authentication provider).
  • Billing data: billing contact name and email, subscription plan, billing address and transaction history. We do not collect or store full payment-card details. Card data is collected and processed directly by Stripe, our payments provider, which acts as an independent controller for that card data. Stripe is PCI-DSS Level 1 certified and acts as an independent controller for card data.
  • Usage, device and log data: IP address, browser and device type, operating system, approximate location derived from IP, pages and features used, timestamps, diagnostic and security logs. We use this to operate, secure and improve the Service.
  • Cookies and similar technologies: set on our marketing website as described in our Cookie Policy. Non-essential cookies (such as analytics) are set only with your consent.
  • Support and communications data: the content of messages, emails and enquiries you send us, and our replies.
  • Marketing data: your contact details and your marketing preferences, where you have signed up to hear from us or where we contact existing business customers about similar products.

Where we ask you to provide data to enter into or perform our contract with you (for example, to open and bill an account), providing it is a contractual requirement; if you do not provide it we will not be able to supply the Service.

4. How we use your data, and our lawful basis for each purpose

Under the UK GDPR we must have a lawful basis for each processing purpose. The table below sets out, for each purpose, the lawful basis we rely on, and - where that basis is legitimate interests - the specific interest in question.

PurposeData usedLawful basis (UK GDPR Article 6)
Creating and administering your account; providing the Service to youAccount data, usage dataPerformance of a contract (Art 6(1)(b))
Taking payment and managing your subscription, trial and renewalsBilling dataPerformance of a contract (Art 6(1)(b))
Keeping tax and accounting records of transactionsBilling dataLegal obligation (Art 6(1)(c)) - UK tax and company law
Securing the Service, preventing and detecting fraud and abuse, maintaining logs and backupsAccount data, usage/device/log dataLegitimate interests (Art 6(1)(f)) - our interest in running a secure, reliable, fraud-resistant service and protecting our customers and us
Responding to your support requests and enquiriesSupport and communications dataPerformance of a contract (Art 6(1)(b)) where you are a customer, otherwise legitimate interests (Art 6(1)(f)) - our interest in answering and helping the people who contact us
Improving and developing the Service (aggregated/diagnostic analysis)Usage/device/log dataLegitimate interests (Art 6(1)(f)) - our interest in understanding and improving how the Service is used
Sending service messages you need (e.g. billing, security and important changes)Account and billing dataPerformance of a contract (Art 6(1)(b))
Sending marketing about our products to existing business customersMarketing dataLegitimate interests (Art 6(1)(f)) - our interest in promoting similar products to existing business customers, subject to an opt-out (see Section 17 for the PECR soft opt-in conditions)
Sending marketing to people who are not existing customersMarketing dataConsent (Art 6(1)(a))
Setting non-essential cookies and similar analytics/marketing technologiesCookie dataConsent (Art 6(1)(a))

Where we rely on legitimate interests, we carry out and document a balancing assessment for each such purpose to confirm that our interests are not overridden by your interests, rights and freedoms. You can ask us for more information about the relevant assessment, and you have the right to object (see Section 12).

Where we rely on consent (for example, certain marketing or non-essential cookies), you can withdraw your consent at any time - this is as easy as giving it - by using the unsubscribe link in any marketing email, by changing your cookie settings, or by contacting us at info@whealbit.co.uk. Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it.

5. Location data (clock-in events only)

Where an employer enables location features, WagePilot currently captures a device's location only at the precise moment a person clocks in or out, in order to confirm the clock event happened at or near the relevant workplace. We do not track location continuously, between clock events, or in the background, except that, as a controller in our own right and for security purposes, we may derive only approximate, IP-based location from log data as described in Section 3. When location features are used, the employer (not WagePilot) is the controller of that staff location data and is responsible for telling its staff about it.

6. Special-category data (leave reasons and health information)

This is primarily relevant to the staff data we handle as a processor, but we explain it here for transparency. Where an employer records the reason for a member of staff's leave or absence, that reason may reveal information about a person's health, which is special-category data under Article 9 of the UK GDPR. In that situation the employer is the controller and is responsible for identifying both an Article 6 lawful basis and an Article 9 condition (typically the employment condition in Article 9(2)(b), supported by the condition in Schedule 1 Part 1 of the Data Protection Act 2018, which requires the employer to keep an Appropriate Policy Document in place). As a processor we apply heightened technical and organisational measures to free-text leave-reason data and to any optional kiosk clock-event photo, and we encourage employers to minimise the health detail they record.

The optional kiosk photo is captured only as an audit image of a clock event. Whether such an image is biometric special-category data under Article 9 depends on how it is processed: a facial image becomes biometric special-category data only when it is processed through a specific technical means that allows a person to be uniquely identified. WagePilot does not currently perform facial recognition, biometric matching, liveness detection or any similar technical processing on these images. We have confirmed that no part of the clock-in pipeline performs face-matching or facial recognition; clock-in photos are stored only as audit images, and we will re-verify this whenever clock-in or photo features change. Provided the photo is used only as an audit image in this way, it is not biometric special-category data; it nonetheless remains personal data and is minimised, handled proportionately and retained only for as long as needed. If this ever changes - for example, if the photo were used to verify or uniquely identify a person - it would be treated as special-category data and the relevant Article 9 condition would have to be satisfied by the employer as controller.

7. Cookies and similar technologies

Our marketing website uses cookies and similar technologies. Strictly necessary cookies (needed to run the site and keep it secure) are always set. Non-essential cookies (such as analytics and any marketing technologies) are set only after you give consent through our cookie banner, where rejecting is as easy as accepting and you can change or withdraw your choice at any time. Full details, including the cookies used and how to manage them, are in our Cookie Policy.

8. Sharing your data and our sub-processors

We do not sell your personal data within the meaning of applicable law, and we do not disclose it to third parties for their own marketing or monetisation. We share personal data only with the trusted service providers we use to run WagePilot (our sub-processors), and where we are required or permitted by law. We require each sub-processor, under a written contract, to provide guarantees and undertake obligations consistent with Article 28 of the UK GDPR, including appropriate security and confidentiality measures; each sub-processor is engaged under its standard Article 28 data processing agreement (to be confirmed executed before launch). Subject to the limitations of liability in our Terms of Service, we remain responsible to you for our sub-processors' handling of personal data we are responsible for, except where a provider acts as an independent controller (as noted below).

ProviderRoleProcessing region
SupabaseDatabase, authentication and file storageSupabase, Inc. processes in the EU (Frankfurt) under its standard Article 28 DPA
VercelWebsite and application hosting; serverless functionsVercel, Inc. processes in the United States under its standard Article 28 DPA with EU SCCs + UK Addendum (to be confirmed before launch)
StripePayment processing (PCI-DSS Level 1). Stripe acts as an independent controller for payment-card data.Stripe (Stripe Payments UK, Ltd.) acts as an independent controller for card data under its own terms
ResendSending transactional and service emailsResend, Inc. processes in the United States under its standard Article 28 DPA with EU SCCs + UK Addendum (to be confirmed before launch)

Our current sub-processor list is maintained at /legal/sub-processors. We may also disclose personal data where required by law, court order or a regulator, or to establish, exercise or defend legal claims. If we sell or reorganise our business, personal data may transfer to the buyer or successor, who will be required to continue to protect it in accordance with applicable data protection law; if the recipient's handling will differ materially from this notice we will tell you and, where the law requires, seek your consent.

9. The controller / processor split, explained plainly

WagePilot wears two hats:

  • We are the controller for account data, billing data, marketing-site visitor data and support enquiries - the data described in this notice. We decide why and how it is processed.
  • We are a processor for the staff data that an employer enters into WagePilot (staff names, contact details, pay rates, rotas, holiday and leave, timesheets, clock-event location and any kiosk photo). The employer is the controller of that data: it decides why and how it is used, and it is responsible for telling its staff about it and for having a lawful basis (and, for health-related leave reasons, an Article 9 condition). We process that data only on the employer's documented instructions, as set out in our Data Processing Agreement.

10. International transfers

We aim to store and process personal data in the United Kingdom or the European Economic Area (the EEA benefits from UK adequacy, so transfers there need no additional safeguard). We keep our database, authentication and file storage with Supabase in the EU (Frankfurt, eu-central-1). Where a provider carries out a transfer to a country that the UK has not deemed adequate (for example, certain support, backup or engineering operations of our hosting, email or payment providers that may take place in the United States), we ensure that an appropriate Article 46 safeguard is in place before the transfer occurs - the ICO International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses with the UK Addendum - supported by a documented transfer risk assessment. For transfers to the United States (Vercel, Resend, Cloudflare, and Stripe acting as controller), the recipient country is the USA and the safeguard is the provider's EU SCCs + UK Addendum together with a transfer risk assessment (to be confirmed executed before launch). You can ask us for details of the safeguard relied on for any specific transfer, and for a copy, at info@whealbit.co.uk. Adequacy and transfer rules are being updated under the Data (Use and Access) Act 2025; we will re-verify and update this section as required.

11. How long we keep your data (retention)

We keep personal data only for as long as necessary for the purposes set out above, then delete or securely anonymise it.

  • Account data: we delete account data within 90 days of account closure, except de-identified statutory pay records retained for up to 6 years, to handle wind-down, disputes and reactivation requests, unless we need to keep it longer for a live dispute.
  • Billing, tax and accounting records: we keep these for at least 6 years to meet UK tax and accounting obligations; this matches our actual practice.
  • Support and marketing data: for as long as needed to handle your enquiry or until you unsubscribe or object, plus a short suppression record so we honour your opt-out.
  • Usage and log data: for up to 90 days for diagnostic logs and 12 months for security logs, appropriate to security, troubleshooting and capacity needs.

Separately, employers (as controllers) must keep certain staff records for statutory minimum periods, and our export and deletion features are designed to support these. These are the employer's obligations, not ours, but for transparency the main UK minimums are:

Record typeMinimum retention
National Minimum Wage / National Living Wage recordsAt least 6 years from the end of the pay reference period
PAYE / payroll recordsAt least 3 years after the end of the relevant tax year
Working Time Regulations records (working hours and night work)At least 2 years from the date they were made
Working Time Regulations 48-hour opt-out agreementsAn up-to-date record of workers who have agreed to opt out (no single fixed period)
Right-to-work check evidenceDuration of employment plus 2 years after it ends, then securely destroyed

12. Your rights

Under the UK GDPR you have the following rights in relation to personal data we hold about you as controller. You can exercise any of them by contacting us at info@whealbit.co.uk. We will respond within one month (extendable by up to two further months for complex requests, in which case we will tell you). We will not charge a fee unless your request is manifestly unfounded or excessive, or repetitive, in which case we may charge a reasonable fee or refuse the request, explaining why.

  • Right of access - to be told whether we process your data and to receive a copy of it.
  • Right to rectification - to have inaccurate data corrected and incomplete data completed.
  • Right to erasure ("right to be forgotten") - to have your data deleted in certain circumstances, subject to our legal retention duties (see Section 11).
  • Right to restriction - to have our processing limited in certain circumstances.
  • Right to data portability - to receive certain data you provided in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
  • Right to object - to object to processing based on legitimate interests (including profiling) and to object to direct marketing at any time, in which case we will stop using your data for direct marketing.
  • Right to withdraw consent - where we rely on consent, to withdraw it at any time (see Section 4).
  • Rights relating to automated decision-making - see Section 13.
  • Right to complain to the ICO - see Section 14.

Where you are an employee or worker and your data is held in WagePilot by your employer, your rights requests should generally be directed to your employer as the controller; we will assist the employer in responding as required by our Data Processing Agreement.

13. Automated decision-making, profiling, and our wage and working-time checks

We do not make decisions about you that are based solely on automated processing and that produce legal effects concerning you or similarly significantly affect you. WagePilot's National Minimum Wage / National Living Wage and Working Time checks are guidance only to help employers; they display informational warnings and do not make automated decisions about individuals, do not block pay or shifts, and do not determine any outcome.

For the avoidance of doubt, these checks are informational aids only. WagePilot does not guarantee, and is not responsible for, an employer's compliance with the National Minimum Wage / National Living Wage legislation, the Working Time Regulations, or any other employment, tax or other law. Responsibility for legal compliance rests entirely with the employer. This reflects the position in our Terms of Service, which govern the warranties and liability that apply to the Service. If any feature ever evolves into solely automated decision-making with legal or similarly significant effect, we will update this notice and provide the information and safeguards that Article 22 of the UK GDPR requires.

14. Complaints and the ICO

If you have a concern about how we handle your personal data, please contact us first at info@whealbit.co.uk so we can try to resolve it. You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection (Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF; 0303 123 1113; ico.org.uk):

  • Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
  • Helpline: 0303 123 1113
  • Website: https://ico.org.uk

15. Security

We implement appropriate technical and organisational measures to protect personal data, proportionate to the risk. Our measures currently include, for example, encryption in transit and at rest, access controls and least-privilege tenant isolation in our multi-tenant database, authentication, logging and monitoring, backups and a tested breach-response process, and confidentiality undertakings from people who handle data. Because the right measures change over time, we keep these under review and may vary them, provided they remain appropriate to the risk; this is a description of our practices and not a fixed contractual warranty (see Section 1 and our Terms of Service). If a personal data breach affecting data we control is likely to result in a risk to your rights and freedoms, we will report it to the ICO without undue delay and, where required, within 72 hours of becoming aware of it; where the risk is high, we will also tell affected individuals. For data we process on behalf of an employer, we notify that employer without undue delay so it can meet its own duties. More detail is on our security page.

16. Children and minimum working age

WagePilot is a business tool and is not directed at children. We do not knowingly collect data directly from children through our website or account sign-up. Employers using WagePilot are responsible for ensuring they record staff data lawfully, including complying with minimum working-age and young-worker rules in the UK. If you believe a child has provided us with personal data as a controller, please contact us at info@whealbit.co.uk and we will take appropriate steps.

17. Marketing choices

You can opt out of marketing at any time by using the unsubscribe link in any marketing email or by contacting us at info@whealbit.co.uk. We will still send you essential service messages (for example, about billing, security or important changes to the Service) where we are entitled to do so, as these are not marketing.

Where we send marketing emails to existing business customers about our similar products, we rely on the "soft opt-in" under the Privacy and Electronic Communications Regulations (PECR): we contact you only where we obtained your contact details in the course of a sale (or negotiations for a sale) of similar services, we offer an opt-out at the point we collect your details and in every message, and we stop as soon as you opt out. The soft opt-in applies to individual and sole-trader subscribers; messages to corporate-body recipients fall outside PECR Regulation 22 but we still offer an opt-out in every message.

18. Changes to this notice

We may update this notice from time to time to reflect changes in the Service, our practices or the law (including ongoing reforms under the Data (Use and Access) Act 2025). When we make material changes we will update the "last updated" date shown with this notice and give reasonable advance notice by email or in the Service before they take effect, and where a change requires your consent we will obtain it. Please review this notice periodically.

19. How to contact us

For any privacy question or to exercise your rights, contact our data protection contact at info@whealbit.co.uk, or write to us at St Ives, Cornwall. Our legal entity and registration details are set out in Section 1.

From £29/mo · never per head

Free forever on one site · no card · cancel anytime

Start free