QuarterFile

We’ll email you the day it opens

Filing opens for the 7 February 2027 quarter. No account, no card.

We store your email address to tell you when QuarterFile opens, and to send one reminder before each quarterly deadline, until you unsubscribe. Nothing else. How we handle your data.

Privacy policy

What we hold, and why

  • Account data (email, name, notification preferences): to run your account. Lawful basis: contract.
  • Business details (business name, type, ownership share, accounting basis): to prepare your updates. Lawful basis: contract.
  • Transaction records (dates, descriptions, amounts, categories): your digital records. Financial data, held with elevated care. Lawful basis: contract.
  • HMRC connection tokens: encrypted with a dedicated key service, never readable by staff tooling, used solely to file on your instruction. Lawful basis: contract.
  • Your National Insurance number: HMRC’s MTD APIs require it to identify your tax record, so we hold it while your HMRC connection exists: encrypted with a dedicated key service, never shown in the app, and deleted when you disconnect or delete your account. We also keep a one-way cryptographic fingerprint derived from it (the number cannot be recovered from it) solely so the free first quarter can’t be redeemed twice. Lawful bases: contract; legitimate interest (preventing offer abuse) for the fingerprint.
  • Reminder-list email (if you used the checker or deadlines page before signing up): to send the reminders you asked for, together with which MTD start date applies to you, based on your checker answers. Lawful basis: consent. Every email has a one-click unsubscribe link. Unsubscribing deletes the entry, address and all; we keep only a one-way hash of the address on a suppression list, which we cannot read back into an email address, so that you are never re-added and never mailed again.
  • Email events (deliveries, bounces, complaints): to keep reminders working and to stop mailing addresses that bounce. Lawful basis: legitimate interest.
  • Abuse limits on our forms: when you use the reminder form or the contact form we store a one-way fingerprint of your IP address and of your email address, with a count, so that one source can’t flood the form or use it to mail somebody else. Neither fingerprint can be read back into an address, and both are deleted within 48 hours. Lawful basis: legitimate interest (keeping the forms usable and preventing abuse).
  • Time-on-task measurements (off unless you turn them on): how long you actively spend preparing a quarter and how many lines you typed or imported, stored on your filing receipt and shown back to you. First-party only, never shared, no advertising. Lawful basis: consent. The switch is in Settings, under “Your data”: it starts off, you can turn it on or off whenever you like, and turning it off stops the measurement immediately. If you file a quarter with it on, the figure is written onto that quarter’s receipt, which we keep (see “How long we keep it”).
  • In-app prompt records: which prompts and tips you were shown, dismissed or clicked (including upgrade prompts and checkout starts), so we don’t show them again and so we can tell whether they help. Lawful basis: legitimate interest (running and improving the product); deleted with your account.
  • Support correspondence (your name, email address, your message and any receipt reference you include): kept in the support mailbox so we can handle follow-ups and see what we’ve already told you. Lawful basis: legitimate interest (running support).

We hold HMRC identifiers only where the API requires them, and nothing speculative. We do not train AI models on your data, and our contract with our AI subprocessor does not permit your data to be used to train theirs.

Signing in

There is no password: you sign in with a one-time link we email you, or with Google. That’s deliberate: a one-time link that expires beats a password that can be guessed, reused or leaked. Your sign-in data (your email address, and the record that you have an account) is handled by Google as our processor, on the global sign-in infrastructure it runs for every service, so it may be stored outside the UK, including in the United States. That transfer is covered by our data processing agreement with Google and the UK International Data Transfer Addendum. Choosing “Continue with Google” also means Google, under its own privacy policy, knows you use QuarterFile; the email link doesn’t use a Google account, though the sign-in system behind it is still run by Google as our processor, as above.

AI category suggestions

When you import a bank statement or add a transaction, the description and amount of each line may be sent to our AI subprocessor to suggest a tax category. Before anything leaves our servers we strip account numbers, sort codes and long reference numbers out of the description, so what the model sees is the merchant or payer name and the amount.

That processing runs in the UK, and it is covered by our data processing agreement with that subprocessor: it acts as our processor, on our instructions only, and your data is contractually excluded from training its models. Suggestions are exactly that: nothing is ever filed until you confirm it, and you can ignore or change any suggestion.

Fraud-prevention headers (HMRC legal requirement)

UK law requires all software that talks to HMRC’s APIs to send fraud-prevention data with every call. When you connect to HMRC, check your obligations, or file an update, we collect exactly the required set (no more) and send it to HMRC. If we can’t collect one of these honestly, we leave it out rather than send a made-up value:

WhatWhere it comes fromWhy
Connection methodA fixed value: a web app filing through our own serverTells HMRC how the submission reached them
Device IDA random identifier we create in your browserIdentifies the device to HMRC’s fraud systems
Account IDYour QuarterFile account identifierRequired for HMRC’s fraud prevention
TimezoneYour device timezone (e.g. UTC+01:00)Part of HMRC’s required device profile
Screen detailsScreen size, window size, colour depth, scalingPart of HMRC’s required device profile
IP addressYour public IP address as our server sees it, and the time we read itRequired for HMRC’s fraud prevention
Browser user agentYour browser and operating system name/versionRequired for HMRC’s fraud prevention
Do Not Track settingWhether your browser sends “Do Not Track”Part of HMRC’s required device profile
Vendor detailsQuarterFile’s software name and version, our server’s IP, and the fact your request came through itIdentifies the software submitting to HMRC

This data goes to HMRC (the legal basis is legal obligation). We keep an audit log of the calls we make (which call, whether it succeeded, and the reference HMRC gave it, never the payload and never your National Insurance number) for security.

Where your data lives

Your records live on our cloud provider’s infrastructure in the UK, encrypted at rest, with the sensitive fields (HMRC tokens and your National Insurance number) encrypted again under a key we hold in a dedicated key service in the UK. AI category suggestions run in the UK too, and emails are sent via Amazon Web Services from the UK. Our web servers (which render the pages and pass your requests through, but never store your records) run in our cloud provider’s data centres in the European Economic Area; everything that is stored or decrypted, apart from sign-in data (see “Signing in”), stays in the UK. Subprocessors: Google (database, encryption keys and AI category suggestions in the UK, web-page serving in the European Economic Area, and sign-in, under our data processing agreement with Google), Amazon Web Services (email delivery), and Stripe (payments; card details never touch our servers, and Stripe processes some data in the US under the UK International Data Transfer Agreement, a copy of which is available on request via the privacy contact at the top of this page). Our public forms also load Google reCAPTCHA Enterprise, only to confirm a submission isn’t automated; we use the token it issues solely to verify that submission.

How long we keep it

  • Your records and account data: while your account is active, then deleted when you delete your account. That includes your transactions, businesses, import settings, HMRC tokens and National Insurance number.
  • Filed-submission receipts: kept for six years after the 31 January that closes the tax year, then deleted. A receipt is the evidence of what was filed, on what date, under which HMRC reference: the thing you would need if a submission were ever queried, and the thing HMRC’s record-keeping rules expect you to be able to produce years later. Six years is the later of the two clocks that matter. HMRC asks you to keep business records at least five years after the 31 January deadline, and a claim arising from the filing can be brought for six years. A receipt for the 2026-27 tax year is finalised by 31 January 2028, so it is kept until 31 January 2034. We do not keep it beyond that, because the law that protects your data does not let us hold records longer than we can justify. A receipt holds the category totals we sent, the tax year and quarter, the HMRC reference and the timestamp. It never contains your National Insurance number. This is a legal hold that survives account deletion, and while it lasts a receipt cannot be edited or deleted by anyone, including us.
  • Security audit log: 24 months, then deleted. It records which calls we made and whether they succeeded, never the payloads and never your National Insurance number. It survives account deletion, so we can still answer what happened on an account that no longer exists.
  • Send receipts: one row per email we send you, so a repeated job can never email you twice. A row records which email it was and when, never the message. The ones tied to your account are deleted with it; the reminder-list ones are deleted after 400 days.
  • Billing records: kept by Stripe for six years, as UK tax law requires.
  • The free-quarter fingerprint (one-way, non-reversible): kept to prevent repeat redemption of the offer.
  • The pre-signup reminder list: the entry is deleted immediately on unsubscribe or on request. Only a one-way hash of the address stays behind, on the suppression list, so you are never re-added or re-mailed.
  • Bounce/complaint suppression entries: kept as one-way hashes, so we don’t email addresses that asked us not to, or that bounce.

Your rights

Access, rectification, erasure, portability, restriction, objection (the full UK GDPR set). Where we rely on your consent (the reminder list and time-on-task measurement), you can also withdraw it at any time, without affecting anything done before you withdrew: unsubscribe from any reminder email, or turn measurement off in Settings. Your transactions export as CSV, self-serve in Settings, and every filed receipt stays viewable and printable from your overview. Deletion is self-serve in Settings too; it removes your records, tokens, National Insurance number, and respects the legal holds listed above. A receipt we have to keep keeps the figures it was issued with, including any time measurement it carries: a receipt that could be partially rewritten wouldn’t be evidence of anything. Anything else: . You can complain to the ICO at ico.org.uk.

If you also joined the reminder list, deleting your account removes that entry too, but only once the email address on the account has been confirmed, so someone else can’t wipe your reminders by claiming your address. If your address isn’t confirmed, either confirm it and delete again, use the one-click unsubscribe link in any reminder email, or email the privacy address at the top of this page and we’ll remove it for you.