Legal
Privacy Policy
Last updated: 16 September 2026
This Privacy Policy explains how Simply Works LTD, trading as Simply Link, uses personal data when we decide the purposes and means of the processing.
1. Who we are and when this policy applies
Simply Link is operated by Simply Works LTD (Company No. 16219998), registered in England and Wales, with registered office at 5 The Roundhouse, Fore Street, Bodmin, PL31 2HG.
Simply Works is the controller for personal data where we decide why and how it is processed, including merchant account administration, subscription billing, platform security, fraud and abuse prevention, legal compliance, support, and our own service analytics.
Merchants using Simply Link are normally separate controllers for the personal data they hold about their own customers. Where a merchant instructs Simply Works to store or use Customer Personal Data solely to provide Simply Link to that merchant, Simply Works normally acts as the merchant's processor. That processing is governed by our Data Processing Addendum (DPA). The merchant is responsible for its own privacy information and lawful basis for that customer relationship.
Stripe and some other providers may act as independent controllers for processing they determine under their own legal obligations and services. Their privacy notices apply to that processing.
2. Personal data we receive
Depending on how you use Simply Link, we may receive or generate:
- Merchant account data: name, email address, account identifiers, authentication information, profile details and support communications.
- Business and onboarding data: business name, profession or service type, business description, intended use, estimated payment volume, postcode area, website and information used for onboarding or risk checks.
- Customer data supplied by merchants: customer names, email addresses and other supported customer information that a merchant chooses to save or use.
- Service and payment-request data: service names and descriptions, request titles and descriptions, prices, currency, due dates, deposit and balance information, request status, publication state, secure-link identifiers and related history.
- Payment and refund data: payment status, amount paid or outstanding, Stripe references, payment type, refunds, disputes, chargebacks and relevant timestamps. We do not receive or store customers' full card details entered into Stripe Checkout.
- Communication data: reminder settings, schedules, message wording, recipient information, email type, delivery status, provider identifiers, receipt information and relevant timestamps.
- Subscription and Stripe connection data: subscription status, billing references, connected-account identifiers, Stripe capabilities and verification or account status relevant to providing the Service.
- Merchant branding: display name, business description, logo, brand colours and other supported presentation settings.
- Technical and security data: IP address, browser and device information, request and application logs, authentication events, fraud and risk signals, rate-limit information, security events and diagnostic data.
- Usage and analytics data: privacy-friendly website and product usage information, such as pages viewed, traffic source, device/browser category and aggregated performance information, depending on the analytics tools in use.
3. Where personal data comes from
We may receive personal data:
- directly from a merchant when they sign up, configure their account, contact us or use Simply Link;
- from a merchant about their customer when the merchant creates a customer, payment request or communication;
- from customers or payers when they open a payment link, interact with Simply Link, or complete payment through Stripe;
- from Stripe in connection with connected accounts, payments, subscriptions, refunds, disputes and risk or compliance information;
- from our hosting, email, authentication, analytics and security providers as part of operating the Service; and
- from publicly available business information where reasonably necessary for verification, fraud prevention or support.
4. How and why we use personal data
UK data protection law requires a lawful basis when Simply Works processes personal data as controller. The basis depends on the purpose.
| Purpose | Typical lawful basis |
|---|---|
| Create and administer merchant accounts, authenticate users, provide requested features, manage Pro subscriptions and provide support. | Contract; legitimate interests where needed to administer the business relationship. |
| Connect merchants with Stripe, reconcile platform state, administer fees and subscription billing, and support payment-related operations. | Contract; legal obligation where applicable; legitimate interests in operating and reconciling the Service. |
| Protect accounts and the Service, prevent fraud and abuse, apply rate limits and risk controls, investigate suspicious activity and enforce our Terms. | Legitimate interests in security, fraud prevention and protecting users; legal obligation where applicable. |
| Maintain financial, compliance, dispute and legal records, respond to lawful requests and establish or defend legal claims. | Legal obligation; legitimate interests in compliance and legal claims. |
| Understand aggregate usage, diagnose problems, monitor performance and improve Simply Link. | Legitimate interests in maintaining and improving the Service, using proportionate and privacy-conscious analytics. |
| Send optional product news, offers or marketing to merchants who choose to receive it. | Consent, where consent is required or relied upon. You can withdraw it at any time. |
Where Simply Works acts only as a processor for Customer Personal Data, the merchant determines the relevant lawful basis and our processing is governed by the DPA rather than the controller lawful bases listed above.
Where we rely on legitimate interests, those interests include operating and securing Simply Link, preventing fraud, protecting merchants and customers, improving the Service, managing our business relationship, and establishing or defending legal claims. We consider the necessity and impact of the processing and do not rely on legitimate interests where your rights and interests override ours.
5. Public payment requests and merchant-entered content
A live Simply Link payment request is available through a shareable bearer link. Anyone who obtains that URL may be able to open the public-facing payment page. Depending on the request and merchant settings, the page can display the merchant's name or branding, business description, request title, request description, amount, due-date information, deposit or balance information and payment status relevant to the customer experience.
Simply Link does not intentionally publish a saved customer's structured email address merely because it is attached to a payment request. However, free-text content entered by a merchant can be displayed publicly through the payment page. Merchants are therefore instructed not to put private or sensitive personal information into public-facing payment-request fields.
Payment and receipt pages are transactional pages rather than public marketing content. We may use technical measures intended to discourage compliant search engines from indexing them, but a bearer URL can still be forwarded, copied, recorded or accessed by someone who obtains it. No indexing instruction is a substitute for careful sharing by the merchant.
6. Stripe and payment processing
Simply Link uses Stripe Connect and Stripe Checkout. Customers enter card details into Stripe's hosted checkout environment rather than into Simply Link. Stripe processes payment information under Stripe's own agreements and privacy documentation.
We exchange information with Stripe where necessary to connect merchant accounts, create and reconcile checkouts, record payment status, calculate or collect applicable platform fees, support refunds and disputes, manage Pro subscriptions, prevent fraud, and comply with legal or Stripe requirements.
Depending on the processing, Stripe may act as an independent controller or in another role defined by its own legal terms. We do not treat necessary Stripe processing as optional marketing consent merely because a merchant uses Simply Link.
7. Fraud, safety checks and automated processing
We use automated rules, indicators and manual review to protect Simply Link, Stripe, merchants and customers from fraud, prohibited activity and security threats. Signals may include business information, onboarding responses, payment patterns, disputes or chargebacks, account status, IP or device information, technical events and content relevant to restricted activity.
These controls can result in requests for information, temporary restrictions, payment requests becoming unavailable, checkout quarantine, account review, suspension or blocking. Some protective controls may operate automatically where rapid action is necessary.
Where UK data protection law gives you rights in relation to a decision based solely on automated processing that produces legal or similarly significant effects, you may contact us to request the safeguards available to you, which may include human intervention, expressing your point of view or contesting the decision. We may still need to maintain restrictions required for security, fraud prevention, law or Stripe compliance while a review takes place.
8. Who we share personal data with
We share personal data only where reasonably necessary for the purposes described in this Policy, including with:
- Stripe: connected-account, payment, subscription, refund, dispute, risk and compliance services.
- Supabase: managed database, authentication and storage infrastructure.
- Vercel: application hosting, delivery, infrastructure, logs and privacy-friendly Web Analytics.
- Resend: transactional email delivery for supported reminders, receipts, notifications and operational communications.
- Professional advisers: lawyers, accountants, insurers, security advisers and other professional advisers where reasonably necessary.
- Authorities and regulators: courts, law-enforcement bodies, regulators, tax authorities or other public bodies where disclosure is required or permitted by law.
- Business transfers: a genuine prospective or actual buyer, investor, lender or successor involved in a corporate transaction, subject to appropriate confidentiality and legal safeguards.
We do not sell personal data to advertisers and do not rent merchant or customer personal data to third parties for their own direct marketing.
9. International transfers
Some providers may process personal data outside the UK. Where UK data protection law treats a transfer as a restricted transfer, we use a permitted transfer mechanism where required. Depending on the destination and provider, this may include UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or another safeguard permitted by UK law, together with any required transfer risk assessment.
You can contact us for more information about the safeguards relevant to our processing. Where we act as a processor for a merchant, international transfers of Customer Personal Data are also addressed in the DPA.
10. How long we keep personal data
We keep personal data only for as long as reasonably necessary for the purpose for which it is held, taking account of the nature of the information, account status, payment and dispute history, security needs, legal limitation periods, and accounting, tax, regulatory or other legal requirements.
In practice:
- merchant account and profile information is generally kept while the account is active and for a reasonable period afterwards where required for closure, support, security, disputes or legal obligations;
- payment, subscription, refund, chargeback and accounting records may be retained for the period required by financial, tax, legal or dispute obligations;
- operational and security logs are retained for limited periods appropriate to troubleshooting, security and fraud prevention, subject to provider and legal requirements;
- marketing preferences are kept as needed to honour your choice, including a record of an opt-out where necessary; and
- Customer Personal Data processed on behalf of merchants is deleted or returned in accordance with the DPA, subject to lawful retention and protected backup rotation.
We may retain a minimal record longer where necessary to establish, exercise or defend legal claims, demonstrate compliance, prevent fraud or honour a suppression request.
11. Security
We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures include access controls, authentication, encryption in transit, managed infrastructure security, secret management, database access controls, monitoring, rate limiting and other safeguards appropriate to the Service and risk.
No internet service can guarantee absolute security. Merchants must also protect their login credentials, devices and payment-request links and use the Service in accordance with our security instructions and Terms.
12. Your data-protection rights
Depending on the circumstances and applicable law, you may have rights to:
- ask whether we process your personal data and obtain access to it;
- ask us to correct inaccurate or incomplete personal data;
- ask us to erase personal data in circumstances where the right to erasure applies;
- ask us to restrict processing in circumstances where the right to restriction applies;
- receive certain personal data in a portable format and ask for it to be transmitted to another controller where the right to portability applies;
- object to processing based on legitimate interests, including raising circumstances particular to you;
- object at any time to direct marketing;
- withdraw consent at any time where we rely on consent, without affecting processing carried out lawfully before withdrawal; and
- exercise applicable rights relating to solely automated decisions with legal or similarly significant effects.
These rights are not absolute and exemptions may apply. We may need to verify your identity before fulfilling a request.
If your request concerns Customer Personal Data controlled by a Simply Link merchant, we may need to refer you to that merchant or assist the merchant under our DPA rather than decide the request ourselves.
13. Complaints and contacting the ICO
We would like the opportunity to address a data-protection concern first. Contact us at support@simply-link.co.uk.
You also have the right to complain to the UK Information Commissioner's Office (ICO), the UK supervisory authority for data protection. Information about making a complaint is available at ico.org.uk.
14. Cookies, browser storage and analytics
We use strictly necessary cookies or browser storage where needed for authentication, security and account functionality. We also use Vercel Web Analytics to understand aggregate website usage without using it for cross-site advertising tracking.
If we introduce non-essential cookies or tracking that requires consent, we will request that consent before enabling it where required by law. See our Cookie Policy for more detail.
15. Whether you have to provide personal data
Some information is necessary to create and secure an account, connect Stripe, process payments, administer subscriptions or meet legal and compliance requirements. If required information is not provided, we may be unable to create or maintain an account, enable payments, provide a particular feature, or complete a compliance review.
Marketing information is optional. A merchant's decision to enter additional customer information beyond what is needed for a payment workflow is also subject to the merchant's own responsibilities as controller.
16. Changes to this Privacy Policy
We may update this Policy to reflect changes to the Service, our providers, law or how we process personal data. We will update the date at the top of the page. If a change is material, we will take reasonable steps to draw it to the attention of affected merchants, for example by email or an account notice where appropriate.
17. Contact details
For privacy questions or to exercise a right relating to processing for which Simply Works is controller, contact:
Simply Works LTD
Company No. 16219998 · Registered in England and Wales
Registered office: 5 The Roundhouse, Fore Street, Bodmin, PL31 2HG
Email: support@simply-link.co.uk